Privacy

Privacy policy

Verified Operator is designed to prove a limited commercial fact without turning customer or payment details into public data. This policy describes the information used by the service.

Last updated: 8 September 2026

Information you give us

We may receive your name, email address, profile name, handle, bio, business details, social or website links, privacy choices, and messages or feedback you send.

Exactly what connected sources let us read

From connected payment sources, we read payments, refunds, disputes, amounts, dates, and hashed customer identifiers. We use these records to calculate revenue, activity, customer counts, refund rates, coverage, and milestones.

We do not read or store card data. We do not store customer names or customer email addresses. Customer identifiers are hashed so repeat activity can be counted without publishing or retaining the source identifier.

Source keys and connections

Source keys are kept server-side and encrypted at rest. They are used only to read the records needed for the credential. You can revoke a key at the connected provider, and you can disconnect the source in Verified Operator.

Disconnecting freezes the history already observed but does not delete it. The profile can then show that the connection is no longer live. This preserves the meaning of earlier records without implying a current connection.

Shopify data and deletion

For Shopify, we read shop identity, order and transaction identifiers, dates, currencies, payment amounts, refunds, dispute status, and a customer identifier used only to count repeat activity. We do not request customer names, email addresses, phone numbers, or addresses. Individual orders and customer identifiers are never published.

We retain the records needed to maintain the revenue history you keep with us. Uninstalling the Shopify app stops access. When Shopify sends its store-deletion notification, we erase the store connection and imported records and rebuild the remaining totals. Customer-deletion notifications erase the matching order records; a restricted one-way suppression marker prevents future refreshes from restoring them. Those markers are removed when the store records are erased.

You can also request deletion through hello@verifiedoperator.com. We verify the request and respond within 30 days. Deletion can reduce totals that depended on the removed records. Restricted backups expire under our infrastructure providers’ backup schedules and are not used for ordinary processing; deletion must be reapplied before any restored data returns to service.

We do not use Shopify customer data for advertising, sell it, or make decisions about individual customers. The merchant determines the lawful basis for processing their order records and sends us applicable customer rights requests.

What is public by default

Revenue figures are public as ranges by default, not exact amounts. A public profile may also show the operator name and handle, tier, source names, coverage windows, connection state, finalised milestones, active periods, and profile links. Available privacy controls can show an exact value, a range, or only that a value was verified.

Demo profiles are fictional and visibly marked as demos. Founding applications, email addresses, source keys, raw transaction records, and customer hashes are not public.

How we use and share information

We use information to operate the service, calculate source-connected figures, prevent abuse, respond to applications and support requests, improve the product, and meet legal obligations. We do not sell personal information.

Infrastructure, database, hosting, email, and security vendors may process limited information for us under appropriate contractual and technical safeguards. We may disclose information when legally required or when needed to protect people, the service, or its users.

Retention, security, and deletion

We retain information while it is needed to operate the credential, keep source-derived history coherent, prevent abuse, or meet legal requirements. No online system is risk-free, but we limit access, keep keys server-side, and use encryption for source credentials.

To request deletion of your account, profile, application, or associated personal information, email hello@verifiedoperator.com from the address connected to the record. We may ask you to confirm the request and will explain any information we must retain.

Changes and questions

We may update this policy as sources and product features change. The date above shows the latest revision. Send privacy questions to hello@verifiedoperator.com.