ValidRev

Legal

ValidRev - Privacy Policy

Last updated: April 12, 2026

1. Introduction

ValidRev ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights with respect to that data. By using the Platform, you agree to the practices described in this policy.

2. Data We Collect

a) Account Information

When you register, we collect your name, email address, and password (stored as a secure hash). If you sign in via a third-party provider (e.g. Google), we receive basic profile information from that provider.

b) Profile Information

You may optionally provide additional profile information such as your bio, website, Twitter handle, and country.

c) Store Revenue Data

When you connect a Shopify or WooCommerce store, we collect and store:

This data is pulled directly from your store's API. Access tokens used to retrieve this data are stored encrypted using AES-256 encryption.

  • Monthly revenue, net revenue, and refund figures
  • Order counts, customer counts, new vs returning customer breakdown
  • Derived metrics: average order value, MoM growth, refund rate, repeat customer rate
  • Store metadata: store name, currency, country, category

d) Transaction Data

When a store sale is initiated, we collect offer amounts, accepted prices, commission calculations, and escrow transaction references. We do not store full payment card details - these are handled by Stripe and Escrow.com.

e) KYC Data

If KYC verification is required, identity documents and verification results are handled by a third-party KYC provider. We store only the verification status (none / pending / approved / rejected) and the date of verification.

f) Usage Data

We automatically collect standard usage information including IP addresses, browser type, device information, pages visited, and session duration. This is used to maintain platform security and improve the user experience.

g) Communications

Messages sent between buyers and sellers through the Platform's messaging system are stored in our database. These are accessible to both parties and to ValidRev for dispute resolution purposes.

3. How We Use Your Data

We use the data we collect to:

  • Operate and maintain the Platform
  • Display verified store revenue data publicly on leaderboards, profiles, and the activity feed
  • Match buyers with relevant stores based on saved searches and preferences
  • Process listing payments via Stripe
  • Facilitate store transactions through Escrow.com
  • Send transactional emails (offer notifications, deal updates, sync alerts) via Resend
  • Detect fraud, abuse, and violations of our Terms
  • Improve Platform performance and user experience

Data Sales and Advertising

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

4. Public Data

The following data is displayed publicly on the Platform by default when you publish a store listing:

  • Store name, category, country, and description
  • Monthly revenue, order counts, growth metrics, and other performance data synced from your store's API
  • Your public profile (name, bio, country) if you have not enabled the anonymous listing option

Anonymous and Private Modes

If you enable anonymous listing mode, your name, store URL, and identifying details are hidden from public view. Revenue data remains publicly visible as it is the core purpose of the Platform.

If you set your profile to private, your profile page will not be publicly listed, but your store's revenue data may still appear on public leaderboards if your listing is active.

5. Data Sharing

We share data with third parties only as necessary to operate the Platform:

  • Stripe - payment processing for listing tier fees
  • Escrow.com - transaction escrow for store sales
  • Third-party KYC provider - identity verification for buyers
  • Supabase - database hosting (PostgreSQL)
  • Upstash - Redis caching for background job queuing
  • Resend - transactional email delivery
  • Inngest - background job processing for store data syncs

Provider Obligations

All third-party providers are contractually obligated to handle your data securely and in accordance with applicable privacy law. We do not authorize them to use your data for their own marketing purposes.

6. Data Retention

We retain your account and store data for as long as your account is active. If you delete your account:

  • Your profile, store connections, and personal data are deleted within 30 days
  • Transaction records are retained for 7 years for legal and financial compliance purposes
  • Aggregated, anonymized revenue data may be retained indefinitely for platform analytics

Deletion Requests

You may request deletion of your data at any time by contacting us at privacy@validrev.com. Certain data may be retained where required by law or legitimate business interests (e.g. completed transactions).

7. Cookies and Tracking

We use cookies and similar technologies for:

  • Session management (keeping you logged in)
  • Security (CSRF protection, fraud detection)
  • Analytics (understanding how the Platform is used)

Cookie Controls

You can disable cookies in your browser settings, but this may affect Platform functionality. We do not use third-party advertising cookies.

8. Security

We take the security of your data seriously. Measures we employ include:

  • AES-256 encryption for all stored store API access tokens
  • HTTPS for all data transmission
  • Secure password hashing
  • Role-based access controls on the database
  • Regular security reviews

Incident Response

No system is 100% secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Request deletion of your personal data
  • Object to or restrict our processing of your data
  • Request a portable copy of your data

How to Exercise Rights

To exercise any of these rights, contact us at privacy@validrev.com. We will respond within 30 days.

10. Children's Privacy

The Platform is not intended for users under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact

For privacy-related questions or requests, contact us at: privacy@validrev.com