Privacy Policy
Last updated October 8, 2026
SlabbedMRR ("we", "us") turns a startup's verified revenue into a collectible card. This policy explains what we collect, why, who helps us run the service, and the choices you have.
Who is responsible: SlabbedMRR. Contact: hi@slabbedmrr.com.
1. What we collect
When you add a startup
- A read-only API key for your payment provider (Stripe, RevenueCat, Paddle, Polar, Lemon Squeezy, Dodo Payments, Creem or Whop). We encrypt it before storing it and use it only to read revenue data. We store the last four characters so you can recognise it.
- Revenue metrics we read with that key: monthly recurring revenue (MRR), growth, retention, active subscriptions, all-time revenue and the date of your first sale. We also store an identifier for your payment account (for example a Stripe account ID or a list of product IDs) so you can recover access with a key from the same account.
- Startup details you give us or we find: name, tagline, description, website, logo.
- Your X (Twitter) handle, if you add one, and your public X profile picture, or a photo you upload instead.
- A private manage link. We store only a scrambled (hashed) version of its secret part, never the link itself.
When you unlock a special edition
- The link to your public X post and its author's handle, which we check against X's public embed service.
When you visit the site
- Basic technical data our hosting provider processes to deliver the site (such as IP address and browser type).
- For rate limiting on the recovery page, a scrambled (hashed) version of your IP address with the time of each attempt. We can't turn it back into your IP address. Unlocks and photo refreshes are limited per startup and don't record your IP address.
We don't ask for your name, email address or password, and we don't use advertising or tracking cookies. Your browser may store small items locally (for example whether you've already opened a card, or your manage link on your own device); they stay on your device.
2. What's public
SlabbedMRR is a public showcase. Your card, startup details, X handle and photo, and the revenue metrics shown on the card (including MRR) are public on your card page, the leaderboard and share images, and anyone can share them. Don't add a startup if you don't want these numbers public. Your API key, manage link and payment account identifiers are never public.
3. Why we use it
- To create, grade and refresh your card every day, and mint a new one each month (to provide the service you asked for).
- To verify that a special-edition post really comes from your X account.
- To let you edit, recover or delete your startup.
- To keep the service secure and prevent abuse (rate limits, error logs).
4. Who helps us
We use these providers to run SlabbedMRR. They process data only to provide their service to us.
- Vercel (website hosting, scheduled jobs).
- Supabase (database and file storage, hosted in Tokyo, Japan (ap-northeast-1)).
- Your payment provider, which we call with your read-only key.
- Unavatar (fetches your public X profile picture; while you type your handle when adding a startup, your browser loads the preview picture from Unavatar directly).
- X (public post embed service, used to verify unlock posts).
- Google favicon service (fallback to find your website's icon).
Some of these providers may process data outside your country, including in the United States, under their own safeguards.
5. How long we keep it
We keep your startup, cards and key until you delete your startup. When you delete it from your manage page, we delete your startup, its cards, your key, your logos and photo. The unlock and photo-refresh counters belong to your startup and are deleted with it. Recovery-attempt records (a hashed IP address and a time) aren't linked to any startup and are currently kept indefinitely. Backups held by our providers may keep copies for a short period before they're overwritten.
6. Your choices and rights
- Delete your startup any time from your manage page.
- Revoke your API key in your payment provider's dashboard any time; your card then stops updating.
- Edit your details, handle and photo from your manage page.
- Depending on where you live (for example under the EU/UK GDPR), you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to complain to your data protection authority. Contact us at hi@slabbedmrr.com.
7. Security
We encrypt API keys before storage, store only hashes of manage links and IP addresses, and the database can't be reached directly from the browser. No system is perfectly secure; if you think something is wrong, email hi@slabbedmrr.com.
8. Children
SlabbedMRR is not meant for anyone under 16.
9. Changes
We'll update this page if anything changes and change the date at the top.
Questions: hi@slabbedmrr.com