Back

Privacy Policy

Last updated 16 May 2026

MVPHub.com is operated by Zealand Design Media, an Auckland, New Zealand software studio. This Privacy Policy explains what information we collect, why we use it, where it is processed, and how you can contact us about your rights.


1. Information we collect

Account and profile data

We collect account details such as name, username, email address, password hash, avatar, role, seller profile details, public seller profile fields, support contact details, and account status.

Seller, listing, and submission data

When you submit or manage listings, we collect listing content, categories, tags, stack choices, pricing, variants, screenshots, demo URLs, source ZIP metadata, GitHub repository metadata, release metadata, documentation, license fields, readiness notes, review decisions, rejection reasons, and admin/seller change history.

Payment and payout data

We use Stripe and Stripe Connect for payments. MVPHub may store Stripe customer IDs, checkout session IDs, payment intent IDs, charge IDs, connected account IDs, onboarding status, charges/payout capability flags, account country, currency, disabled reasons, refund/dispute metadata, order records, platform fee records, seller net amounts, and payout-related summaries.

MVPHub does not store full card numbers, bank account numbers, SSNs, tax IDs, government identity documents, or Stripe passwords.

GitHub integration data

If a seller connects GitHub, we may store GitHub App installation IDs, selected repository owner/name, repo ID, default branch, release tags, release archive metadata, sync status, and authorization status. We use this data to sync source-code releases and attach deliverables to listings.

Download and fulfillment data

We store order records, download grants, grant-to-asset links, download token metadata, signed URL events, download events, buyer/seller IDs, asset IDs, variant IDs, IP-derived request metadata, user-agent metadata, and rate-limit counters needed to deliver purchases and prevent abuse.

Upload, malware, and asset security data

For uploaded or synced deliverables, we may store file names, sizes, MIME types, storage keys, storage provider metadata, checksums, archive inspection metadata, malware scan results, quarantine status, review status, reviewer notes, and eligibility flags.

Support, installation, and communications data

We collect support tickets, installation-support requests, message content, request scope, admin replies, email delivery metadata, notification preferences, and unsubscribe tokens.

Analytics, logs, and security data

We collect operational logs, security events, request metadata, device/browser information, approximate location from IP address, page events, referral data, listing events, vote/bookmark/comment/review activity, Redis or in-memory rate-limit data, and abuse-prevention signals. We may use privacy-focused analytics such as a self-hosted OpenPanel instance.


2. How we use information

We use information to:

  • create accounts and authenticate users;
  • operate buyer checkout, seller payouts, refunds, disputes, and order fulfillment;
  • review, approve, publish, rank, moderate, and remove listings;
  • sync GitHub releases and manage source-code deliverables;
  • create signed download URLs and enforce grant limits;
  • scan uploads, quarantine risky assets, and prevent malware distribution;
  • provide support, installation help, account deletion handling, and operational notices;
  • prevent fraud, abuse, spam, account takeover, payment abuse, and policy violations;
  • maintain logs, debug incidents, run tests, improve reliability, and comply with legal obligations;
  • send service emails, support replies, product notices, and marketing where permitted.

3. Processors and third parties

We may share data with providers that help us operate MVPHub, including:

  • Stripe for payments, Connect onboarding, refunds, disputes, fraud controls, tax/payment compliance, and payouts;
  • GitHub for repository installation, release metadata, and source archive access when sellers authorize it;
  • S3-compatible storage providers, including Wasabi or AWS S3, for uploaded and synced deliverables;
  • email providers for transactional and support email;
  • a self-hosted OpenPanel instance where configured, for privacy-focused usage analytics;
  • Redis or database providers for rate limits, queues, sessions, grants, and abuse prevention;
  • hosting, logging, monitoring, and security providers for infrastructure operation.

We do not sell personal information.


4. Public information

Public listings, seller profiles, display names, usernames, avatars, listing descriptions, screenshots, comments, reviews, votes, ratings, and sponsored-placement labels may be visible publicly. Do not submit secrets, private keys, credentials, or confidential customer data into public fields.


5. Retention

We keep data for as long as needed to provide MVPHub, meet legal obligations, resolve disputes, prevent abuse, support buyers and sellers, and maintain accounting/payment records.

Some data may be retained after account deletion when needed for legal, tax, payment, fraud, audit, security, dispute, or buyer-access reasons. Where appropriate, we may anonymize or restrict retained data instead of deleting it.


6. International transfers

MVPHub is operated from New Zealand and may use service providers in other countries. By using MVPHub, you understand that information may be processed outside your country, subject to appropriate contractual, technical, and organizational safeguards where required.


7. Security

We use reasonable technical and organizational measures to protect data, including HTTPS, access controls, signed URLs, asset eligibility checks, malware scanning workflows, audit logs, and provider-managed security controls. No internet service can guarantee perfect security.


8. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data. You can update some account and seller profile information in your account settings.

To request deletion, export, or another privacy action, contact data@mvphub.com or support@mvphub.com.


9. Children

MVPHub is not intended for children under 18, and we do not knowingly collect personal information from children.


10. Changes

We may update this Privacy Policy as MVPHub changes. The updated policy will be posted on this page with a new updated date.


11. Contact

Privacy questions can be sent to:

Last updated: 2026-05-16.