Privacy Policy

Last updated September 28, 2026

This policy explains how MetricMirror (“we”) handles information in MetricMirror.

Information we collect

  • Account information — your name, email, business details, and login data (including Google sign-in if you use it).
  • Customer Data — information businesses add about their own customers and leads (names, contact details, jobs, notes, feedback, ad spend). We process it on the business’s behalf, as a service provider/processor.
  • Feedback and form submissions — ratings, comments and lead-form entries submitted by a business’s customers, along with ad-tracking parameters (such as UTM tags, gclid or fbclid) present on the page.
  • Billing — handled by Stripe; we don’t store full card numbers.
  • Usage and device data — logs, IP address and browser information used for security and troubleshooting.

How we use it

To provide the Service (including sending emails and texts a business requests), secure it, provide support, process payments, and improve the product. We don’t sell personal information and don’t use Customer Data for advertising.

Sharing

We share information only with subprocessors that help run the Service — Supabase (database and hosting), Vercel (hosting), Stripe (payments), Resend (email delivery), Twilio (text messages) and Google (sign-in and business lookup) — or when required by law.

Messages to a business’s customers

If you received a review request, text or email from a business through MetricMirror, that business controls your information. Every email has an unsubscribe link, and you can reply STOP to any text to opt out. Contact the business directly for other requests.

Retention and deletion

We keep data while an account is active. After a subscription ends, a business's data is kept for 90 days (so it can be exported or restored by resubscribing) and then deleted. Businesses can also export or delete their data from Settings at any time; deleted data is removed from our live systems promptly and from backups on their normal rotation. To enforce our one-free-trial policy we keep a record of email addresses and payment-card fingerprints (not card numbers) that have used a trial, even after an account is deleted.

Security

Data is encrypted in transit, access is restricted per business with database row-level security, and API keys are stored only as hashes.

Your rights

Depending on where you live (for example California under the CCPA/CPRA), you may have rights to access, correct, delete or port your personal information. Email support@metricmirror.app to make a request.

Children

The Service is for businesses and isn’t directed at children under 13.

Changes

We’ll post updates here and notify account owners of material changes.