Privacy Policy
Last updated 30 September 2026
What VerifyArr stores about you, why, and how to get rid of it. Everything listed here is something the service actually collects — there is no list of things we might do one day.
Who is responsible
VerifyArr is the controller of the personal data described here. Questions, or any request under this policy: legal@verifyarr.com.
What we collect, and why
- Your account. Email address, name, a public handle, and your password stored only as a hash. Needed to have an account at all.
- Your profile, if you fill it in. Avatar, bio, X and website links. Optional, and public.
- Your startup and listing. Name, description, category, website, asking price, and the contact channel buyers use to reach you. Public once the listing is live, except the contact details, which are released only to a signed-in buyer with a confirmed email address.
- Revenue data from Stripe. If you connect a startup, we store your Stripe restricted key encrypted, along with the account id and the last four characters of the key so you can tell which one it is. We read charges, refunds and balance transactions to compute monthly recurring revenue, growth, churn and customer counts. We never have permission to move money.
- Sessions. A hashed session token, the IP address and browser user-agent the session started from, and when it was last used. This is what lets you see and revoke your own logged-in devices.
- Activity on listings. Which listings you save, and the first time you reveal a seller's contact details. Sellers see counts, not who you are.
- Messages. What you write to another member, who it was to and when, the startup it was about if you sent it from a startup's page, and how far each of you has read. The person you wrote to can read it and nobody else on the site can. We may read a conversation to investigate a report of abuse.
- Comments. What you post on a startup's page and when. Comments are public: anyone can read them, signed in or not, next to your name, handle and avatar. A comment you delete leaves the page, and we keep a copy so that a report about it can still be investigated.
- Listing views. Counted once per visitor per day using a one-way hash of the date, IP address and user-agent, keyed with a server secret. The hash cannot be turned back into an IP address, and no raw IP is stored against a view.
- Site visits. Which pages are opened, counted the same way, plus the name of the website that linked you here (for example reddit.com, never the full address). Hashes are deleted once their day is over, leaving only daily totals. No cookie is set for this.
- Email preferences. Which kinds of notification you have unsubscribed from.
- Administrative records. Moderation decisions and their reasons, and an audit log of admin actions.
Who else sees it
Stripe, because that is where verified revenue comes from — we read your account through the key you gave us, under Stripe's own privacy terms. Our email provider, to deliver the email described below, which for an unread message or a comment on your startup includes the writer's name and its opening lines. Our hosting and database providers, which store the data on our behalf.
That is the whole list. We do not sell personal data, share it with advertisers, or pass it to anyone else except where the law requires it.
Email we send
Account email — confirming your address, resetting your password, and telling you your password changed — cannot be turned off, because switching it off would make the account unsafe.
Notifications can be. A broken revenue sync, a listing approved or rejected, a message that has waited unread, and a comment on your startup each carry an unsubscribe link, and one click stops that kind for good. Messages still reach your inbox on the site, and comments still appear on your startup's page.
How long we keep it
Your account data stays until you delete your account. Sessions expire 30 days after last use. Revenue snapshots are kept while the startup exists, because the MRR chart is a history. Aggregate market statistics, which identify no one, are kept indefinitely.
Messages are kept indefinitely, including after an account in the conversation is deleted. They cannot be edited or unsent.
When you delete your account we remove your profile and take your listings off the market. Messages you sent stay in the other person's copy of the conversation, shown as from a deleted user, because that conversation is their record too. Comments you posted are taken off the pages they were on. We keep moderation and audit records, and any record we are legally required to hold, for as long as we need them.
Your rights
You can see and correct most of your data directly in your settings, and delete your account there. You can also ask us for a copy of what we hold, ask us to correct or delete it, or object to a particular use. Email legal@verifyarr.com and we will respond within 30 days.
You also have the right to complain to a data protection authority. We are based in Sweden, where that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se); you can also complain to the authority where you live.
Security
Passwords are hashed with Argon2id. Stripe keys are encrypted at rest with a key that is not stored alongside them, and are never shown back to you in full or sent in any email. Sessions are stored as hashes, so a leak of the database does not hand anyone a working login.
Changes
If we change what we collect or what we do with it, we will email account holders before the change takes effect. The date at the top shows when this wording last changed.