UPDATED SEPTEMBER 10, 2026

Privacy Policy

At WallMRR, we build ambient television displays for software founders and teams. Our revenue telemetry is designed around data minimization: we only process what is needed to put your numbers on the screen. We do not sell your data, we do not profile your customers, and we do not run marketing trackers.

1

Core Privacy Principles

We believe privacy policies should reflect what software actually does rather than legal boilerplate. WallMRR operates under four non-negotiable rules:

  • Zero advertising trackers: We do not embed Facebook Pixels, Google Tag Manager, LinkedIn Insights, or third-party behavioral ad trackers.
  • Cookieless analytics: We use privacy-preserving web analytics that do not store cookies or track you across distinct domains.
  • Encrypted credentials: Integration keys (Stripe, RevenueCat, Polar) are encrypted at rest with AES-GCM and never echoed back to client web browsers.
  • Data sovereignty: You can disconnect any data source or delete your account at any time, purging your credentials and cached telemetry immediately.
2

Information We Collect

To provide ambient revenue metrics, WallMRR processes specific categories of information:

A. Account & Authentication

Your email address, chosen public handle, and authentication timestamps provided via email magic link or OAuth through Supabase Auth.

B. Connected Provider Credentials

Restricted API keys, secret keys, or organization access tokens you provide to link Stripe, RevenueCat, or Polar. We strongly advocate providing read-only restricted keys where supported.

C. Aggregated Metric Snapshots

Normalized monthly recurring revenue (MRR), annual recurring revenue (ARR), subscriber count, currency breakdown, and timestamped sale celebration events (e.g. amount, currency, plan description). We do not ingest customer billing addresses, full credit card numbers, or end-user identity documents.

D. Paired Screen Telemetry

Ephemeral 6-character pairing codes, device user-agent strings (e.g. TV browser, kiosk Raspberry Pi), resolution dimensions, and last-seen heartbeat pings.

3

Cookies & Tracking Technologies

WallMRR does not use advertising cookies, marketing pixels, or tracking cookies. Because we only use strictly necessary functional cookies and cookieless telemetry, you will not be interrupted by annoying cookie consent popups.

NameCategoryPurpose
sb-*-auth-tokenStrictly NecessaryMaintains secure user login and session state through Supabase.
wallmrr_active_projectStrictly NecessaryRemembers your currently active project in dashboard views.
wallmrr_pending_handleStrictly NecessaryTemporarily preserves your chosen handle during registration redirect.

Cookieless Web Analytics

We use Vercel Web Analytics to measure site performance and popular pages. It does not drop cookies, does not store persistent device identifiers, and does not track you across other websites or sessions.

4

How We Use Your Data

We process your information strictly for the following purposes:

  • Delivering Ambient Telemetry: Fetching, converting, and formatting your real-time revenue onto paired TV screens, browsers, and mobile displays.
  • Triggering Real-Time Moments: Broadcasting sale celebrations (confetti, sounds, and badges) over secure Server-Sent Events (SSE) channels.
  • Optional Public Profile Pages: Rendering your public wall (/u/[handle]) only if you explicitly choose to publish your metrics.
  • Account Management & Billing: Managing your subscription tier (Free, Pro, Studio) and transmitting invoice receipts via Polar.
5

Subprocessors & Storage

We work with trusted infrastructure providers to host WallMRR:

Supabase Inc.

Database and authentication infrastructure hosted on AWS in us-east-1.

Polar Sh Inc.

Merchant of record, subscription billing, and tax compliance.

Vercel Inc.

Global edge CDN, Next.js frontend hosting, and cookieless telemetry.

Railway Corp.

Containerized backend execution for our Go API service.

6

Your Rights & Data Deletion

Under regulations like the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), you retain complete control over your personal data:

  • Right to Disconnect: You can disconnect your Stripe, RevenueCat, or Polar connections in your dashboard at any time. When disconnected, your stored API token is permanently deleted.
  • Right to Erasure (Forget Me): You can request full deletion of your account and all associated metrics by navigating to Dashboard Settings or contacting us.
  • Right to Export: You can export your metric history and account configuration at any time.
7

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, reach out directly:

privacy@wallmrr.com