RevMRR logo
Product How it works Pricing FAQ Contact Get sponsored

Legal & Privacy

Privacy Policy

Our Commitment to Radical Transparency:

At RevMRR, we treat your privacy with the same clarity and integrity we apply to startup metrics. We do not sell your personal data, we do not install invasive third-party ad tracking pixels, and we connect to financial providers solely via strictly read-only scopes.

Contents

1. Scope & Data Controller 2. Information We Collect 3. Payment Provider Connections 4. Legal Bases for Processing 5. How We Use Information 6. What We Do NOT Do 7. Third-Party Service Providers 8. Cookies & Local Storage 9. Data Retention & Deletion 10. Data Security & Architecture 11. Your Privacy Rights (GDPR & CCPA) 12. Children’s Privacy 13. International Data Transfers 14. Policy Updates & Inquiries

1. Scope & Data Controller

This Privacy Policy outlines how RevMRR (“RevMRR,” “we,” “us,” or “our”) collects, processes, stores, and protects personal information when you visit our website, submit or claim a business listing, use our acquisition marketplace, post to the feed, or connect external accounts (the “Services”).

For the purposes of the General Data Protection Regulation (GDPR) and relevant global data protection laws, RevMRR acts as the data controller for the personal information processed through our platform.

2. Information We Collect

We collect personal information across the following categories:

  • Account & Authentication Data: Your email address and authentication session tokens when you sign in using magic login codes or single sign-on authentication.
  • Founder & Profile Information: Founder names, job titles, bios, profile images, and social profile links (such as X/Twitter, LinkedIn, or GitHub) associated with your claimed startup.
  • Startup & Listing Details: Company names, websites, product descriptions, founding dates, categories, tech stack metadata, funding history, and self-reported business metrics (such as MRR, ARR, growth rate, and customer volume).
  • Marketplace & Offer Data: For startups listed for sale or acquisition inquiries, asking prices, transaction structures, multiple expectations, and direct message communications between buyers and sellers.
  • Community & Feed Interactions: Posts, discussions, comments, startup saves/bookmarks, and likes submitted on the RevMRR community feed.
  • Technical & Log Information: IP addresses (anonymized or hashed where appropriate for abuse detection), browser user agent strings, HTTP request headers, and device types to ensure server security and rate limiting.

3. Payment Provider Connections & Revenue Verification

Strictly Read-Only Financial Scopes:

When you connect a payment gateway (such as Stripe) to verify your startup’s revenue for a verification badge:

  • We request read-only access limited strictly to checking aggregate subscription metrics, gross volume, and recurring revenue.
  • We never request or obtain permissions to transfer funds, initiate charges, or modify your billing setup.
  • We never store or publish your customers’ personal identities, credit card numbers, or granular customer invoices. Only aggregated, anonymized metric totals (e.g. $12,400 MRR) that you choose to publish are displayed on your profile.

4. Legal Bases for Processing (GDPR)

Under the GDPR and equivalent data protection regulations, we process your personal data under the following lawful bases:

  • Contractual Necessity: To fulfill our service agreement with you, manage your account, authenticate your sessions, and display your claimed startup profiles.
  • Legitimate Interests: To protect platform integrity, prevent fraudulent metrics, maintain verification badge reliability, and guard against malicious bots and denial-of-service attacks.
  • Legal Obligations: To comply with mandatory statutory, accounting, or regulatory requirements.
  • Consent: Where you have voluntarily opted in to receive marketing communications or promotional newsletters. You may revoke consent at any time.

5. How We Use Your Information

We use the data collected strictly for legitimate business and platform purposes:

  • Operating, maintaining, and improving the startup directory and intelligence algorithms.
  • Validating founder identity, company domain authenticity, and revenue verification requests.
  • Facilitating direct communication between prospective startup acquirers and verified sellers.
  • Delivering authentication emails, transaction receipts, and customer support responses.
  • Enforcing our Terms of Service and preventing bot scraping, manipulation, or abuse.

6. What We Do NOT Do

No Selling or Renting of Data

We never sell, rent, or trade your personal information, contact lists, or browsing patterns to commercial data brokers or third-party marketers.

No Behavioral Ad Trackers

We do not deploy third-party advertising tracking scripts, social media pixels (e.g. Meta Pixel), or cross-site behavioral retargeting cookies.

7. Third-Party Service Providers & Subprocessors

We share data only with vetted infrastructure partners and technical subprocessors strictly necessary to operate RevMRR:

  • Hosting & Edge Network: Cloudflare and serverless edge infrastructure for globally distributed content delivery, DDoS protection, and SSL encryption.
  • Database Storage: Managed cloud PostgreSQL (Neon) with enterprise-grade encryption at rest and in transit.
  • Payment Gateways: Stripe for processing advertising sponsor slots and billing entitlements. We do not store credit card numbers on our servers.
  • Email Delivery: Transactional email providers for delivering one-time login codes and critical account notifications.

8. Cookies & Local Storage

RevMRR utilizes a strictly minimal set of first-party cookies (such as revmrr_session) to keep you signed in securely and protect against CSRF attacks.

For questions about cookies, storage keys, or browser controls, please contact us via the Contact page.

9. Data Retention & Deletion

We retain your personal information only for as long as necessary to provide the Services, maintain accurate historical directory archives, resolve disputes, and comply with statutory obligations:

  • Active Accounts: Maintained until you request deletion of your account.
  • Authentication Codes: Transient login codes expire and are purged within minutes.
  • Transactional Records: Financial invoices and sponsor purchase receipts are retained as required by tax and corporate reporting laws (typically 7 years).

10. Data Security & Architecture

We implement industry-standard administrative, physical, and technical safeguards to protect your personal data from unauthorized access, loss, or alteration. All web communications utilize TLS 1.3 encryption in transit, databases are encrypted at rest with AES-256, and administrative access is governed by strict principle-of-least-privilege access controls.

11. Your Privacy Rights (GDPR & CCPA/CPRA)

Depending on your location, you may have specific statutory rights concerning your personal information:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete information.
  • Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your personal profile and account credentials.
  • Right to Restrict or Object: Restrict or object to certain processing activities based on legitimate interests.
  • Right to Data Portability: Obtain your personal data in a structured, machine-readable format.
  • California Privacy Rights: Under the CCPA/CPRA, California residents have the right to know what personal data is collected and request deletion. RevMRR does not “sell” or “share” personal data as defined under the CCPA.

To exercise any of these rights, please submit a request via our Contact page. We respond to all verified requests within thirty (30) days.

12. Children’s Privacy

RevMRR is intended strictly for professional founders, builders, and business acquirers. We do not knowingly collect or solicit personal data from anyone under the age of 18. If we become aware that we have collected information from a child under 18, we will promptly delete such records.

13. International Data Transfers

RevMRR operates globally and utilizes distributed cloud infrastructure located in the United States and other regions. If you access the Services from outside the United States, your information will be transferred and processed in jurisdictions that may have different data protection laws. We ensure appropriate transfer safeguards, including Standard Contractual Clauses (SCCs), to protect your personal information.

14. Policy Updates & Contact Inquiries

We may periodically update this Privacy Policy to reflect changes in our platform practices or relevant regulations. When material modifications occur, we will revise this page.

If you have questions, concerns, or data privacy inquiries, please contact our privacy team through our Contact page or review our Terms of Service.

RevMRR

Startup Revenue Intelligence

Discover. Analyze. Grow.

Product

What’s inside How it works Pricing FAQ

Company

Contact support@revmrr.com

Legal

Terms of Service Privacy Policy Refund & Cancellation

© RevMRR. All rights reserved.