Privacy Policy.
Last updated July 27, 2026
The short version, which does not replace what follows. We collect what the service needs and not more. Revenue credentials and payout details are encrypted and no procedure returns them to anyone, including you. Our view counting uses a key that is thrown away daily, so it cannot follow you between days. We do not sell your data and we run no advertising trackers. What you put on a listing is public; your email, your credentials and your messages are not.
1. Who we are
vettedstartup.com is operated by RHXO Technology, LLC, a New Jersey limited liability company (“Vetted Startup”, “we”, “us”), the controller of the personal data described here, at 35 Hudson St, Jersey City, NJ 07302. For privacy questions, write to privacy@vettedstartup.com.
2. What we collect
Account data. Email address, username, display name, and a password hash if you set one. If you sign in with Apple or Google, we receive a stable identifier for you and your email address from them, and nothing else. Apple’s Hide My Email gives us a relay address rather than your real one, which is fine and works normally.
Profile data you choose to add. Avatar, bio, links, and social handles.
Listing data. Everything you enter about a startup, plus what we read from a revenue platform you connect, plus logos and screenshots you upload.
Revenue platform credentials. See “Revenue platform credentials” below. They are treated differently from everything else here.
Payout details. Bank, PayPal or stablecoin details, if you give them to us to receive an affiliate payout. See “Payout details” below.
Content you publish. Comments, posts, founder updates, offers and messages.
Usage data. Which listings were viewed and clicked, aggregated daily. See “How we count views, and why it is not tracking”, which explains why this is less identifying than it sounds.
Technical data. IP address and user agent, in transient web-server logs, used for security and abuse prevention.
Approximate location on a contact message. When you use the contact form we look up a rough location from your IP address, at country, region and city level, and store that with your message so we can see where an enquiry came from. The IP address itself is not stored on the message. Only the derived location is, and city level is the honest limit of what an IP lookup knows. The lookup is done by a third-party service that receives the address for that request and nothing else.
We do not collect payment card details. We never see them.
3. How we use it
- to operate your account, your listings and your conversations;
- to verify revenue at the source and to keep a verified badge accurate, including removing it when a connection stops working;
- to rank the trending board and the leaderboard;
- to send notifications you have not turned off, and transactional email you cannot turn off: password reset, email verification, a revenue key that has expired, an offer on your listing, and a change of state in a deal you are part of;
- to create an escrow transaction when you and a counterparty choose to use one;
- to attribute an affiliate referral and pay it;
- to detect and prevent fraud, ranking manipulation and abuse;
- to meet legal obligations.
4. Legal bases
Where the GDPR or UK GDPR applies, we rely on:
- Contract, to give you the service you signed up for, including verification, listings and escrow;
- Legitimate interests, for security, abuse prevention, ranking integrity, and operating a public marketplace;
- Consent, for optional notification channels, which you can withdraw at any time in your dashboard;
- Legal obligation, where we must keep or disclose records.
5. Revenue platform credentials
When you connect Stripe, Shopify or another revenue platform, we store the credential you give us encrypted at rest with AES-256-GCM under a key held only on our server and never in the database.
We use it to read, and only to read. We request revenue and subscription figures and the account’s own identity. We never create a charge, never move money, never modify a customer, never write anything, and never see your customers’ payment details.
No procedure returns a stored credential to anyone, including you. Once saved it can be replaced or deleted, never displayed. We never share credentials with any third party.
Where the platform offers a restricted or read-only key, use one. Disconnecting a source stops future syncing immediately.
One revenue account can back only one listing across the whole service, which is how we stop the same revenue being claimed twice.
6. Payout details
Bank, PayPal and stablecoin details are stored encrypted at rest with AES-256-GCM, the same as revenue credentials.
No procedure returns them to you. Your dashboard shows a masked label only, such as the last four digits. Exactly one internal, restricted, audited path can decrypt them, and it exists so a payout can be made.
We validate what you enter before saving, including bank routing check digits and IBAN checksums, because a payout is one-way and a mistyped number reaches a real but wrong account.
7. How we count views, and why it is not tracking
Ranking a trending board needs to know that two views came from different people. It does not need to know who they are, and we built it so we cannot know.
A visitor is identified to the ranking system by a keyed hash that mixes request characteristics with a secret salt, and the salt is rotated every day. That has three consequences worth stating plainly:
- the value cannot be reversed into an IP address, a cookie, or an account;
- it does not follow anyone across days, so it cannot be used to build a profile of a person over time;
- it exists to deduplicate votes and views, and it is used for nothing else.
We do not store a per-view record beyond what deduplication needs, and that working data is deleted after 35 days. The ranking reads daily totals, not individual views. A founder’s own visits to their own listing are excluded from the statistics.
We do not use third-party advertising or analytics trackers, and we do not sell or share personal data for advertising.
8. Cookies
We set very few, and none for advertising:
- Session cookie. Keeps you signed in for 30 days. HTTP-only, secure, and required for the service to work.
- Referral cookie. Records which affiliate link brought you here, so a referral can be attributed if you create an account.
- Interface preferences. Small values such as whether a panel is collapsed, or that a prompt has been dismissed.
- Sign-in with Apple or Google. Those providers may set their own cookies during the sign-in flow, under their own policies.
9. What is public
This is a public marketplace, so assume anything on a listing page is public and will be indexed by search engines: the listing, its verified revenue figures and charts, your comments and posts, founder updates, your username, display name, avatar and bio.
Not public: your email address, your revenue credentials, your payout details, your direct messages, the listings you follow, your saved searches, and your notification settings. Following is private and no follower count is shown on a listing.
Anonymous listings. Anonymous mode hides the founder, not the startup. Your name, photo and profile are removed from the listing, from the discussion on it, and from messages a buyer sends you, and the listing does not appear on your public profile. The startup itself stays fully visible: name, website, logo, category and verified revenue, because that is the point of the listing. You can still reply to questions on the page, shown as the founder without a name. Anonymity is masking on our surfaces, not a guarantee that nobody can infer who you are from what you choose to publish.
10. Who we share with
We do not sell personal data. We share it only with providers that process it for us, each for a single purpose:
- Escrow.com, the licensed escrow provider. When you enter a transaction we pass the parties’ email addresses and the transaction terms so it can create the escrow. It becomes an independent controller of that data under its own privacy policy, and it, not us, holds the funds.
- Revenue platforms you connect, which receive our read requests.
- Postmark, to deliver email.
- OpenAI, to categorise a listing. We send the listing’s name, website address, tagline and text from its public website. We do not send your account details, and the only thing we ask for back is a category. Their API terms commit to not training on what is sent.
- An IP geolocation service, when you submit the contact form. Your IP address is sent so we can record roughly where the message came from. We keep the country, region and city, and we do not keep the address.
- Apple and Google, if you use their sign-in.
- Our hosting provider, which stores the database and the media you upload on servers we control.
- A payment provider, where we still process a payment or a payout directly.
We may also disclose data where legally required, to protect our rights or someone’s safety, or to a successor in a merger or acquisition, in which case this policy continues to apply until replaced.
11. How long we keep it
- Account and listing data: while your account is open, and afterwards only where we must keep it.
- Per-view working data: 35 days, then deleted.
- Daily aggregated statistics and ranking history: kept, because they are not identifying.
- Revenue history: kept for as long as the listing exists, so a chart does not lose its past. Disconnecting a source does not retract history already published.
- Domain claim tokens: 7 days, with a limited number of verification attempts, then dead.
- Transaction and deal records: kept as long as needed for accounting, tax and dispute purposes, typically several years. A deal is reconstructed from an append-only event log, which we do not edit or delete.
- Email delivery records: kept so we never send the same notification twice.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict your data, to object to processing based on legitimate interests, and to withdraw consent. You can do much of this yourself: edit or delete a listing, change your notification settings, or close your account from your dashboard.
For anything else, write to privacy@vettedstartup.com. We will respond within 30 days. We may need to verify who you are first.
Two honest limits. Deleting your account does not remove a comment that others have replied to, because that would damage a public conversation; we will disassociate it from your identity where we can. And we cannot delete records we must keep for a completed transaction.
If you are in the EEA or the UK you may also complain to your local data protection authority.
13. Security
Everything is served over HTTPS. Revenue credentials and payout details are encrypted at rest, as described above. Passwords are stored as bcrypt hashes and never in a recoverable form. Administrative functions require an individual authenticated account with an explicit permission, not a shared secret, so that every action is attributable to a person.
No system is perfectly secure. If you find a vulnerability, please tell us at privacy@vettedstartup.com before disclosing it publicly, and we will work with you.
14. International transfers
We operate from, and store data in, facilities that may be outside your country. Where we transfer personal data out of the EEA or the UK, we rely on an adequacy decision or on standard contractual clauses. Our providers, including the escrow provider and our email provider, may process data in other countries under their own safeguards.
15. Children
The service is not for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us data, write to privacy@vettedstartup.com and we will delete it.
16. Changes
We will update this page when our practices change and revise the date at the top. If a change is material we will give notice before it takes effect. See also our Terms of Service.