Legal
Privacy Policy
Last updated: July 20, 2026
1. Who we are
RevenueShot (“we”, “us”) provides a web application that generates revenue showcase cards using metrics from your Stripe account. This policy explains what we collect and how we use it.
2. Information we collect
- Account data: email, name, password hash, plan status.
- Stripe connection: encrypted restricted API key, key fingerprint, last four characters, livemode flag, cached metrics (MRR, ARR, customers, growth, history), sync timestamps.
- Cards & shares: product name, handle, logo URL, theme, display metrics snapshot, generated share images, leaderboard preference.
- Billing: if you purchase Pro, payment is processed by Stripe; we store customer / subscription identifiers, not full card numbers.
- Technical data: standard logs (IP, user agent, error traces) for security and reliability.
3. How we use information
We use data to operate the Service: authenticate you, compute metrics from Stripe, generate cards and share images, enforce plan limits, process payments, prevent abuse, improve reliability, and communicate about the product when appropriate.
4. Stripe keys
API keys you provide are encrypted at rest using industry-standard cryptography (AES-GCM with a server-side secret). We never display the full key again. Use a restricted, read-only key. You can disconnect at any time; we then delete the stored key material for that connection. We recommend rotating keys periodically in the Stripe Dashboard.
5. Sharing
We do not sell your personal data. We share data with processors needed to run the Service (for example: hosting, database, email if enabled, and Stripe for payments). Public leaderboard and share pages only show content you choose to publish or share links you create.
6. Retention
We retain account and card data while your account is active. Share images expire after a limited period. You may request account deletion by contacting us; we will delete or anonymize personal data except where we must retain records for legal or billing reasons.
7. Security
We use encryption in transit (HTTPS in production), encrypted key storage, hashed passwords, and access controls. No method of transmission or storage is 100% secure; report issues to [email protected].
8. Your rights (GDPR & similar laws)
If you are in the EEA/UK (or another region with similar rights), you can exercise:
- Access & portability: download a JSON export of your account data from Settings → Privacy & data.
- Erasure: permanently delete your account and related data (cards, encrypted Stripe key, passkeys, OAuth links) from the same Settings panel.
- Rectification: update name/profile and reconnect Stripe to refresh metrics.
- Restriction / objection: disconnect Stripe or remove leaderboard visibility anytime.
We process account data to perform the contract (provide the Service), and security logs based on legitimate interests. Pro payments are processed by Stripe as a payment processor.
8b. Cookies
We use essential cookies only (session authentication and security). We do not use advertising trackers or third-party marketing pixels. A short notice appears on first visit.
9. Children
The Service is not directed to children under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy by posting a new version with a revised “Last updated” date. Material changes may be highlighted in the product or by email when practical.
11. Contact
Privacy questions: [email protected].