§1Who we are
TrustMyRevenue is operated by Omnymous, LLC, a Delaware limited liability company, which is the controller of the personal data described here. This policy covers trustmyrevenue.com and the badge embed. Contact: info@trustmyrevenue.com.
§2What we collect
Account. Your email address; if you sign in with Google, your Google account identifier and profile photo. Login is passwordless — there is no password to collect.
Identity. The pseudonym we assign you; an optional display name you may type (always labeled unverified); and, only if you choose to reveal, your X handle, X account identifier, and X profile photo.
Profile particulars. Your country and birth year, collected at onboarding. We store the year only — never a full date of birth.
Store connection.Your store’s domain, name, logo, country, currency, and plan type, plus the read-only access credential you grant us, encrypted at rest (AES-256-GCM). From order data we compute and store aggregate figures only: net sales, total and gross sales, discounts, refunds, order count, average order value, refund rate, and growth over the trailing 30 days.
Content and preferences. Your Lobby posts and your email notification preferences.
Technical. Standard server logs (IP address, user agent, timestamps) used for security and rate limiting.
§3What we deliberately don’t collect
- Your customers’ personal data. We read order data solely to compute totals and keep none of it — buyer names, addresses, and emails are never stored on our systems.
- Passwords. One-time login codes are stored only as keyed hashes with a short expiry, in memory-tier storage — never in our database.
- Behavioral tracking. No advertising trackers, no third-party analytics scripts, no cross-site profiling.
§4How we use your information
We use the data above to:
- operate your profile, the leaderboard, the badge, and the Lobby;
- compute and refresh verified figures, and detect and exclude manipulation (including test and development stores);
- send login codes, and — per your preferences — event emails such as leaderboard broadcasts and personal standing alerts, every one of which carries a one-click unsubscribe;
- moderate public content and keep the service secure.
We do not use your data for advertising.
§5What is public
Being explicit about this matters more here than anywhere else:
- Private by default. A connected store shows nothing publicly until you opt in.
- If you opt a store in, its verified figures, your pseudonym, your country, and your age (derived from birth year) appear on public surfaces.
- If you reveal, your verified X handle and profile photo replace the pseudonym publicly. The reveal is one-way and announced; the “formerly <pseudonym>” note is retained.
- Lobby posts and system events (verifications, rank changes, reveals) are public.
- The commitment log — an append-only record of each pseudonym at signup, kept so identity claims can be audited — is public by design and contains no other personal data.
§6Cookies and local storage
We set one first-party cookie: a presence-only session marker that contains no token or personal data. Your session token and a snapshot of your own profile are kept in your browser’s local storage and sent only to our API. There are no advertising or third-party analytics cookies, so there is no cookie-consent theater to click through.
§7Sharing and processors
We do not sell or rent personal data, and we share it with no one except the infrastructure providers that run the service: Amazon Web Services (hosting, storage, and email delivery). We may disclose data if required by law, or to protect the integrity of the service and its users.
§8Where data lives
Data is processed and stored on AWS infrastructure in the United States. If you use the service from elsewhere (including the EU/EEA), your data is transferred to the US, protected by the safeguards described in this policy.
§9How long we keep data
- Account data — for as long as your account exists.
- Revenue figures — while the account exists; figures from disconnected stores are kept stale-stamped, never displayed as live.
- Login codes — minutes; they expire automatically.
- Server logs — a limited period for security purposes.
Deleting your account removes your profile, store connections and their credentials, revenue figures, and personal data.
§10Your rights
Depending on where you live (including under the GDPR and CCPA), you have the right to access, correct, export, and delete your personal data, and to object to or restrict its processing. You can exercise deletion directly in your account settings, and everything else by emailing info@trustmyrevenue.com. Every non-essential email we send includes a one-click unsubscribe. If you are in the EU/EEA you may also lodge a complaint with your supervisory authority.
§11Age requirement
The service is for adults: you must be 18 or older to create an account, and we verify age at onboarding. If we learn an account belongs to someone under 18, we delete it.
§12Changes to this policy
We may update this policy; the effective date at the top always reflects the current version. For material changes we will give notice by email or on the service before they take effect. See also our Terms of Service.
§13Contact
Omnymous, LLC · info@trustmyrevenue.com