Privacy Policy
Last updated 16 May 2026
MVPHub.com is operated by Zealand Design Media, an Auckland, New Zealand software studio. This Privacy Policy explains what information we collect, why we use it, where it is processed, and how you can contact us about your rights.
1. Information we collect
Account and profile data
We collect account details such as name, username, email address, password hash, avatar, role, seller profile details, public seller profile fields, support contact details, and account status.
Seller, listing, and submission data
When you submit or manage listings, we collect listing content, categories, tags, stack choices, pricing, variants, screenshots, demo URLs, source ZIP metadata, GitHub repository metadata, release metadata, documentation, license fields, readiness notes, review decisions, rejection reasons, and admin/seller change history.
Payment and payout data
We use Stripe and Stripe Connect for payments. MVPHub may store Stripe customer IDs, checkout session IDs, payment intent IDs, charge IDs, connected account IDs, onboarding status, charges/payout capability flags, account country, currency, disabled reasons, refund/dispute metadata, order records, platform fee records, seller net amounts, and payout-related summaries.
MVPHub does not store full card numbers, bank account numbers, SSNs, tax IDs, government identity documents, or Stripe passwords.
GitHub integration data
If a seller connects GitHub, we may store GitHub App installation IDs, selected repository owner/name, repo ID, default branch, release tags, release archive metadata, sync status, and authorization status. We use this data to sync source-code releases and attach deliverables to listings.
Download and fulfillment data
We store order records, download grants, grant-to-asset links, download token metadata, signed URL events, download events, buyer/seller IDs, asset IDs, variant IDs, IP-derived request metadata, user-agent metadata, and rate-limit counters needed to deliver purchases and prevent abuse.
Upload, malware, and asset security data
For uploaded or synced deliverables, we may store file names, sizes, MIME types, storage keys, storage provider metadata, checksums, archive inspection metadata, malware scan results, quarantine status, review status, reviewer notes, and eligibility flags.
Support, installation, and communications data
We collect support tickets, installation-support requests, message content, request scope, admin replies, email delivery metadata, notification preferences, and unsubscribe tokens.
Analytics, logs, and security data
We collect operational logs, security events, request metadata, device/browser information, approximate location from IP address, page events, referral data, listing events, vote/bookmark/comment/review activity, Redis or in-memory rate-limit data, and abuse-prevention signals. We may use privacy-focused analytics such as a self-hosted OpenPanel instance.
2. How we use information
We use information to:
- create accounts and authenticate users;
- operate buyer checkout, seller payouts, refunds, disputes, and order fulfillment;
- review, approve, publish, rank, moderate, and remove listings;
- sync GitHub releases and manage source-code deliverables;
- create signed download URLs and enforce grant limits;
- scan uploads, quarantine risky assets, and prevent malware distribution;
- provide support, installation help, account deletion handling, and operational notices;
- prevent fraud, abuse, spam, account takeover, payment abuse, and policy violations;
- maintain logs, debug incidents, run tests, improve reliability, and comply with legal obligations;
- send service emails, support replies, product notices, and marketing where permitted.
3. Processors and third parties
We may share data with providers that help us operate MVPHub, including:
- Stripe for payments, Connect onboarding, refunds, disputes, fraud controls, tax/payment compliance, and payouts;
- GitHub for repository installation, release metadata, and source archive access when sellers authorize it;
- S3-compatible storage providers, including Wasabi or AWS S3, for uploaded and synced deliverables;
- email providers for transactional and support email;
- a self-hosted OpenPanel instance where configured, for privacy-focused usage analytics;
- Redis or database providers for rate limits, queues, sessions, grants, and abuse prevention;
- hosting, logging, monitoring, and security providers for infrastructure operation.
We do not sell personal information.
4. Public information
Public listings, seller profiles, display names, usernames, avatars, listing descriptions, screenshots, comments, reviews, votes, ratings, and sponsored-placement labels may be visible publicly. Do not submit secrets, private keys, credentials, or confidential customer data into public fields.
5. Retention
We keep data for as long as needed to provide MVPHub, meet legal obligations, resolve disputes, prevent abuse, support buyers and sellers, and maintain accounting/payment records.
Some data may be retained after account deletion when needed for legal, tax, payment, fraud, audit, security, dispute, or buyer-access reasons. Where appropriate, we may anonymize or restrict retained data instead of deleting it.
6. International transfers
MVPHub is operated from New Zealand and may use service providers in other countries. By using MVPHub, you understand that information may be processed outside your country, subject to appropriate contractual, technical, and organizational safeguards where required.
7. Security
We use reasonable technical and organizational measures to protect data, including HTTPS, access controls, signed URLs, asset eligibility checks, malware scanning workflows, audit logs, and provider-managed security controls. No internet service can guarantee perfect security.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data. You can update some account and seller profile information in your account settings.
To request deletion, export, or another privacy action, contact data@mvphub.com or support@mvphub.com.
9. Children
MVPHub is not intended for children under 18, and we do not knowingly collect personal information from children.
10. Changes
We may update this Privacy Policy as MVPHub changes. The updated policy will be posted on this page with a new updated date.
11. Contact
Privacy questions can be sent to:
Last updated: 2026-05-16.