Security
We can read your numbers. We cannot touch your money.
To show your real sales, we connect to your payment account in view-only mode. We can see the numbers, and that is all we can do.
In plain terms
We can look, not touch
We cannot take payments, issue refunds, move money or change any setting in your account.
We keep numbers, not people
We keep payment amounts and dates. Your customers' names and addresses stay with you.
Sensitive details are locked
Account access and bank details are encrypted with bank-grade security and never shown again.
You can leave any time
Disconnect with one click and we stop looking straight away.
For the technically minded: view-only, enforced three ways
- 1. The key cannot write. We only accept restricted keys (rk_). Full secret keys (sk_) are refused before they are saved, with no exceptions.
- 2. Our code cannot write. The Stripe client that reads your account sends GET requests only; anything else throws before it leaves our servers. It is a separate module from the code that bills subscriptions and pays partners, and a test enforces it.
- 3. You can check. Each permission is listed below and in Stripe. We probe every permission once, read-only, when you connect, and name any that are missing.
Permissions we ask for, all Read
- Customers Read
- Subscriptions Read
- Invoices Read
- Charges and refunds Read
- Products Read
- Prices Read
- Coupons Read
- Promotion codes Read
- Disputes Read
- Account details (name, country, currency) Read
What we store, and why
| Data | What exactly | Used for |
|---|---|---|
| Payments | Amount, tax, currency, date, refunds, discount code, which product | Your sales figures and partner earnings |
| Customers | Stripe customer id, sign-up date, country, email domain, and a scrambled (hashed) copy of the email that cannot be turned back into it | Knowing which partner brought which customer. Names and addresses are not stored |
| Subscriptions | Status, price, billing period, start and cancel dates | Monthly revenue, growth and cancellations |
| Your view-only key | Encrypted (AES-256-GCM) and tied to your connection | Updating your numbers. Never shown again |
| Google Search Console and Analytics (optional) | Encrypted access token, daily visitor totals, top countries, pages and channels | The website traffic section on your page |
| Partner bank details | Encrypted; only the team member sending your payment can open them, and every time is logged | Paying partners |
Disconnect
One click on the Connections page, or delete the key in Stripe. We stop updating straight away, and your page shows when the numbers were last checked.
Your account
Sign in with a passkey, two-step codes or backup codes. Important changes ask you to confirm it is you, and we email you about sign-ins from new devices. Every money and admin action is logged.
Report a vulnerability
Email legal@threecommas.example with details and steps to reproduce. We reply within two business days and do not pursue good-faith research.
More detail in the privacy policy and the data processing agreement.