Privacy Policy
Last updated: November 10, 2025
1. Introduction
TrustRoas ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our platform to verify and display e-commerce revenue and Facebook Ads spend data.
2. Information We Collect
2.1 Account Information
- Email address (via Google or Twitter OAuth)
- Twitter/X username and profile picture
- Google profile information (name, email, avatar)
2.2 Business Data (Read-Only Access)
🔒 Important: We only request READ-ONLY access. We NEVER write, modify, or post on your behalf.
From Facebook Ads (via Facebook Marketing API):
- Ad account ID and name
- Total ad spend (30 days and 3 years)
- Impressions and clicks
- Action destinations (optional)
- We DO NOT access: ad creatives, audience data, targeting details, or personal customer information
From Shopify (via Shopify Admin API - Optional):
- Store name and domain
- Order totals and revenue (aggregate only)
- We DO NOT access: customer data, emails, addresses, product details, or inventory
3. How We Use Your Information
- Display verified ad spend and revenue on public leaderboard
- Calculate aggregated metrics (for agencies managing multiple clients)
- Update data daily via automated sync
- Send email notifications (approval/rejection) if you opt-in
- Improve our service and user experience
4. Public Information
The following information is displayed publicly on TrustRoas:
- Entity name (agency, freelancer, or store)
- Total ad spend (verified via Facebook API)
- Total revenue (verified via Shopify API, if connected)
- Entity type (agency/freelancer/store)
- Client count (for agencies)
- Twitter/X handle (if provided)
- Description and category
✓ Privacy Option: You can hide Shopify store names if you enable "Hide client names" during setup.
5. Data Security
- All API access tokens are encrypted before storage
- We use Supabase for secure database hosting
- All connections use HTTPS/SSL encryption
- We implement Row Level Security (RLS) policies
- Access tokens are stored server-side only (never exposed to client)
6. Third-Party Services
We use the following third-party services:
- Supabase: Authentication and database hosting
- Facebook (Meta): OAuth and Marketing API for ad spend verification
- Shopify: OAuth and Admin API for revenue verification (optional)
- Stripe: Payment processing for sponsor spots
- Resend: Email notifications (optional)
7. Your Rights
You have the right to:
- Access your data at any time via your dashboard
- Request deletion of your account and all associated data
- Disconnect Facebook or Shopify integrations at any time
- Enable privacy mode to hide client store names
- Update your information anytime
8. Data Retention
We retain your data as long as your account is active. If you delete your account or we reject your submission, all associated data is permanently deleted from our servers. Historical revenue snapshots in our analytics table may be retained for up to 90 days.
9. Cookies
We use essential cookies for authentication and session management (via Supabase Auth). We do not use tracking cookies or analytics cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this policy.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: privacy@trustroas.com
- Website: trustroas.com