Last updated September 27, 2026
This is a starting template describing how the software behaves. Have it reviewed for your jurisdiction before launch.
What we collect
- Account data: your email, name, username, and any profile details you choose to add.
- Content you submit: products, descriptions, images, messages to founders and reports.
- Activity: upvotes and follows, linked to your account so we can prevent duplicates.
- Aggregate analytics: page and product views and outbound clicks. We store a salted, rotating hash instead of your IP address or user agent, and we don't build cross-site profiles. We honour Do Not Track for search analytics.
- Stripe credentials (founders): restricted read-only keys, encrypted at rest and used only to calculate revenue totals. We store the totals, not your customers or transactions.
- Payments: handled by our payment provider. We receive the payment status and amount, never card details.
How we use it
To run the service: show products and rankings, verify revenue, deliver messages and notifications, prevent abuse, and process paid placements. We don't sell personal data.
Retention
- Daily view deduplication records are deleted after 90 days.
- Raw analytics events are deleted after about 13 months; aggregate daily totals are kept.
- Rate-limit records are deleted after a day.
- Account data is kept until you delete your account.
Your choices
You can edit your profile, delete products and disconnect Stripe at any time from your dashboard. To delete your account or export your data, contact us.
Processors
We use Supabase (database, auth, storage), our hosting provider, a payment provider for paid placements, an email provider for transactional email and, optionally, privacy-friendly analytics.