Refund Policy Generator for SaaS
Written for the controller/processor split, sub-processor lists, DPAs and enterprise security review.
SaaS refunds are governed less by returns law than by billing mechanics: what happens mid-term, whether annual plans are refundable pro rata, and how a downgrade differs from a cancellation. Consumer cancellation rights still apply where you sell to individuals.
A SaaS company wears two hats simultaneously, and the single biggest failure in SaaS privacy documentation is not separating them. For your own marketing site, billing and support you are a controller. For the customer data your users push into the product you are a processor, acting on their instructions - and the disclosures, the rights, and the deletion obligations are completely different in each role.
That distinction is not academic. It determines who answers a data subject access request, who notifies a regulator after a breach, who signs which contract, and what your policy is allowed to promise. A privacy policy that describes customer-uploaded data as "your data that we use to improve our services" is describing processor data in controller language, and enterprise security reviewers will catch it.
The commercial layer matters as much as the legal one. Every enterprise deal now runs through a security questionnaire that asks for a data processing agreement, a published sub-processor list with change notification, a defined breach notification window, and a sub-processor change-objection right. Having those documents ready shortens sales cycles; not having them stalls deals at procurement.
What a refund policy for a SaaS product has to cover
The distinction between cancelling future renewals and refunding the current term
Pro-rata treatment on annual plans, stated plainly either way
Statutory cancellation rights where you sell to consumers, including the digital-content waiver
Automatic renewal disclosure and the cancellation route, which several regimes now regulate
How refunds interact with usage-based charges already incurred
How a SaaS product actually moves personal data
Customer-uploaded content (processor role)
Whatever your users put into the product, including personal data about their own customers and staff. You process it on instruction, you do not decide its purposes, and you cannot use it for your own ends without a separate basis.
Account, billing and usage data (controller role)
Names, work emails, plan, invoices, feature usage and login history. This is yours to decide about, and your privacy policy is the notice for it.
Product analytics and session recording
Tools like Amplitude, PostHog or a session recorder capture in-app behaviour - which frequently means capturing customer data as a side effect, turning an analytics decision into a processor problem.
Support tickets and screenshots
The fastest route by which processor data ends up in a controller system. A screenshot attached to a ticket lands in a helpdesk with a different retention policy.
AI features processing customer content
If your product sends customer data to a model provider, that provider is a sub-processor, and whether the data is used for training is the first question every enterprise reviewer asks.
Sales and marketing enrichment
Buying contact data and enriching leads is controller processing with a legitimate interests analysis and a notification duty under Article 14 to people whose data you did not collect from them.
Third parties the draft will ask you about
AWS or Google Cloud · Stripe · Twilio and SendGrid · Intercom or Zendesk · Amplitude or PostHog · Datadog or Sentry · HubSpot or Salesforce · OpenAI or Anthropic · Snowflake
The rules that apply
GDPR Article 28
Processor obligations: process only on documented instructions, confidentiality, security, sub-processor authorisation, assistance with rights and breaches, deletion or return at the end, and audit rights.
Sub-processor transparency
Not a statutory list requirement in itself, but the practical standard: a published list, and advance notice with an objection window before adding to it.
Transfer mechanisms in the contract chain
SCCs and the UK Addendum have to flow down to sub-processors, not just sit in the top-level agreement.
Breach notification, contractual and statutory
As a processor you notify your customer without undue delay; as a controller you notify the regulator within 72 hours in the UK and EU.
US state law service-provider terms
CCPA requires specific contract language for a recipient to count as a service provider rather than a sale.
What the generated refund policy contains
The statutory right, stated separately
Consumer cancellation rights exist whatever your policy says, so they are set out first and your goodwill terms second.
Time limits and how they are counted
When the clock starts, whether it runs in calendar or working days, and what stops it.
Condition and evidence requirements
What state goods must come back in, and what proof of purchase you accept.
Who pays return postage
Split between faulty and change-of-mind returns, because the law treats them differently.
Refund method and timing
Original payment method, and the deadline you commit to once goods or notice are received.
Exclusions, stated lawfully
Perishables, personalised goods, unsealed hygiene items and downloaded digital content - the exclusions the law actually permits.
The SaaS compliance document set
Separate the privacy policy from the DPA
The policy covers you as controller. The DPA covers you as processor. Different audiences, different content, different signatures.
Publish a sub-processor list with a subscribe option
Name, purpose, location. Offer email notification of changes and an objection window.
Write the security page procurement actually asks for
Encryption, access control, testing cadence, incident response, and whatever certification you hold - or an honest statement that you hold none yet.
Define the breach notification window in the DPA
A stated number of hours, and an internal process that can meet it.
Decide and document your AI data position
Whether customer content reaches a model provider, whether it is used for training, and how long the provider retains it.
Build deletion and export that actually work
Article 28 requires deletion or return at the end of the relationship, and enterprise contracts require proof.
Where this usually goes wrong
One document covering both roles
The privacy policy describes controller processing. Processor obligations belong in the DPA. Merging them produces a document that over-promises about customer data and under-explains your own.
Training on customer data without saying so
The single fastest way to lose an enterprise deal, and depending on your terms, a breach of the instruction limitation in Article 28.
A sub-processor list that is out of date
If the contract promises notice before adding a sub-processor, adding one silently is a breach of contract as well as a transparency failure.
Support tooling that copies processor data into controller systems
Screenshots, exported CSVs and debug logs move data out of the environment your DPA describes.
No defined breach notification window
"Without undue delay" is the statutory phrase, but enterprise contracts want a number. Not having one is a negotiation cost on every deal.
Free-tier and trial data treated casually
Trial accounts contain real customer data far more often than teams assume, and the same obligations apply.
Frequently asked questions
Is my SaaS company a controller or a processor?
Both, in different respects. You are a controller for your own account, billing, marketing and support data, and a processor for the data your customers put into the product. The documents you publish should make the boundary obvious.
Do I need a data processing agreement?
If you process personal data on behalf of business customers subject to GDPR or UK GDPR, yes - Article 28 requires it in writing. In practice enterprise customers will require one regardless of jurisdiction.
Do I have to publish a sub-processor list?
There is no free-standing statutory duty to publish one, but almost every enterprise DPA requires notice before you add a sub-processor, and a public list is the standard way to meet that.
Can I use customer data to train AI models?
Only with a lawful basis and, where you are a processor, only if your customer has instructed or permitted it. Doing it silently breaches the instruction limitation and, for most enterprise contracts, the agreement itself.
What breach notification window should I commit to?
Common commitments run from 24 to 72 hours from confirmation. Pick one your incident process can actually meet, because a missed contractual deadline is a breach of contract on top of the incident.
Can I run a no-refunds policy?
Not against statutory rights. In the UK and EU a consumer’s cancellation and faulty-goods rights apply regardless of what your policy says, and advertising "no refunds" is itself treated as a misleading practice.
Do digital products have to be refundable?
The cancellation right can be waived for digital content, but only if the customer gave express consent to immediate delivery and acknowledged losing the right. That acknowledgement has to be captured at checkout, not assumed.
How long do I have to issue a refund?
In the UK and EU, within 14 days of receiving the goods back or of the customer proving they returned them. Card scheme rules and marketplace policies often impose something tighter.
Refund Policy Generator for SaaS
Answer a short questionnaire and get a draft written for a SaaS product. Free to start, no card required.
Generate your refund policyOther documents a SaaS product needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.