Legal
Privacy Policy
Last updated: July 16, 2026
Who we are
Metricneed (metricneed.com) is operated by Uneed Platform, 20 rue du calvaire de grillaud, 44100 Nantes, France. For any privacy question or request, contact us at [email protected].
Data we collect
- Account data. Your email address and a hashed password, managed by our authentication provider (Supabase Auth). We never see or store your password in plain text.
- Provider API keys. The API credentials you enter to connect a payment provider (Stripe, Polar, Lemon Squeezy, Creem, RevenueCat). They are encrypted at rest with AES-256-GCM and are only ever decrypted server-side to read your revenue data. We recommend using read-only keys where your provider supports them.
- Revenue data. Products, subscriptions, transactions, refunds and customer records (including your customers' names and email addresses) synced from the providers you connect. For this data, you remain the data controller and Metricneed acts as a processor on your behalf.
- Billing data. Paid plans are sold and processed by Creem as our merchant of record. We only receive your plan, billing interval and subscription status — never your card details.
How we use your data
We use your data solely to provide the service: syncing revenue from your connected providers, computing your metrics, and supporting you when you ask. We run no analytics or tracking, we show no ads, and we never sell or share your data with third parties for marketing purposes.
Where your data lives
Your data is stored in a PostgreSQL database managed by Supabase. The application itself runs on a virtual private server we operate. All traffic between your browser, our servers and your providers' APIs is encrypted in transit (TLS).
Subprocessors
- Supabase — database hosting and authentication.
- Creem — merchant of record for paid plans (payment, invoicing, tax).
- Our hosting provider — the server infrastructure running the application.
Retention and deletion
We keep your data for as long as your account exists. Deleting a connection removes its credentials; deleting your account (or asking us at [email protected]) removes your account data and the revenue data synced on your behalf. Downgrading a plan never deletes data — extra connections are paused and older history is hidden, not erased.
Security
Provider credentials are encrypted at rest with AES-256-GCM, database access is restricted with row-level security, and credentials are only used server-side. If we become aware of a breach affecting your data, we will notify you without undue delay.
Your rights
Under the GDPR you can request access to, rectification of, or erasure of your personal data, ask for a portable copy, and object to or restrict certain processing. Write to [email protected] and we will respond within 30 days. You may also lodge a complaint with your supervisory authority (in France, the CNIL).
Cookies
We only use essential cookies: your Supabase session (to keep you signed in) and a small onboarding flag. No tracking or advertising cookies.
Changes to this policy
If we make material changes to this policy, we will update the date above and, where the change is significant, notify you by email or in the app. Questions? Reach us at [email protected].