The short version: Gleam connects to your Stripe account to read your subscription and revenue data. We use that data only to power your dashboard and daily digest. We do not sell your data to anyone, ever. We never modify or delete anything in your Stripe account.
01
Gleam Revenue ("Gleam", "we", "us", "our") is a software-as-a-service company headquartered in New Zealand. We operate the Gleam Revenue platform at gleamrevenue.com, which provides MRR analytics and churn insights for SaaS founders and early-stage businesses.
This Privacy Policy explains how we collect, use, store, and protect information when you use our platform. By using Gleam, you agree to the practices described here.
02
When you sign up for Gleam, we collect your email address. We use magic-link authentication — we do not collect or store passwords.
When you connect your Stripe account via OAuth, Gleam reads and stores the following data from your Stripe account to power the dashboard:
Important: Gleam connects to your Stripe account using OAuth with read-write permissions granted by Stripe's protocol. However, Gleam only ever reads your data. We never create, modify, cancel, refund, or delete anything in your Stripe account. Our codebase contains automated tests that fail if any write call is ever introduced.
We collect standard application logs and error reports to maintain and improve the service. This includes page views, feature usage, and error events. This data is processed by Sentry (error monitoring) and Vercel (hosting analytics).
If you contact us by email, we retain that correspondence to respond to your enquiry and improve our support.
03
We use the data we collect exclusively to provide and improve the Gleam service. Specifically:
We do not use your data for advertising, profiling, or any purpose other than operating the Gleam service for your benefit.
04
We do not sell, rent, license, or otherwise transfer your personal information or your customers' data to any third party for commercial purposes. This is unconditional and applies regardless of any future changes to our business.
05
Gleam uses the following third-party services to operate the platform. Each service has access only to the data necessary for its specific function:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database hosting (PostgreSQL) | All application data stored encrypted at rest in their data centres |
| Vercel | Application hosting and deployment | Application code and server logs |
| Resend | Transactional email (digests, magic-link sign-in) | Your email address and digest content |
| Inngest | Background job scheduling (Stripe sync, digest delivery) | Job metadata and event payloads |
| Sentry | Error monitoring and application health | Error logs and stack traces (PII is scrubbed before transmission) |
| Stripe | Payment processing for Gleam subscriptions | Your billing information for your Gleam subscription |
All third-party providers are contractually required to handle data securely and are prohibited from using your data for their own commercial purposes.
06
When you disconnect a Stripe account from Gleam, the historical sync data is preserved so your charts remain intact. You can request full deletion at any time (see Section 08).
07
We take the security of your data seriously. The following measures are in place:
No system is perfectly secure. If you discover a security vulnerability, please contact us immediately at hello@gleamrevenue.com.
08
Under the New Zealand Privacy Act 2020 and applicable privacy laws, you have the following rights regarding your personal information:
To exercise any of these rights, contact us at hello@gleamrevenue.com. We will respond within 20 working days as required by the New Zealand Privacy Act 2020.
09
Gleam uses a single session cookie to maintain your authenticated session after you sign in via magic-link. This cookie is strictly necessary for the service to function and does not track you across other websites. We do not use advertising cookies, tracking pixels, or analytics cookies.
10
Gleam is a business tool intended for adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
11
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and, for material changes, notify you by email. Your continued use of Gleam after a change is posted constitutes acceptance of the updated policy.
12
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Gleam Revenue
Email: hello@gleamrevenue.com
Website: gleamrevenue.com
Jurisdiction: New Zealand
You also have the right to make a complaint to the Office of the Privacy Commissioner of New Zealand at privacy.org.nz.