Security and privacy
forbzz Trust Center
Plain-language details about the exact Stripe access needed, what becomes public, and how to remove access.- Verified Source
- Read Only
- Encrypted
- User Controlled
Security practices
- Stripe credentials are encrypted before storage using AES-256-GCM.
- Credential cookies are HTTP-only, same-site, and secure in production.
- Raw Stripe keys are not returned to the browser after submission.
- Only the masked key, status, and update time are shown in the interface.
- Write operations are rate limited and require an authenticated Google session.
- You can remove the stored Stripe credential in forbzz or revoke the key in Stripe.
Data handling
We store profile fields, Google sign-in identity, legal acceptance timestamps, encrypted Stripe credentials, masked key metadata, selected profile visibility, selected metric visibility, and dashboard summaries calculated from Stripe.
We do not store card numbers, bank account numbers, Stripe passwords, webhook signing secrets, browser draft copies of your Stripe key, or instructions that can move money.
What can become public
New profiles start private. If you publish a profile, public visitors may see your display name or alias, company, bio, source of wealth, profile image, stated citizenship and age when provided, verification status, currency, ranking position, achievements, referral badges, and privacy-safe metric labels.
Your email address and full Stripe API key are not intended to be public. Exact revenue values are shown publicly only if you select Exact values for metric visibility; the default metric mode is Rounded values.
Stripe permission boundary
forbzz only calls Stripe Balance and Balance transaction read endpoints. Use a live restricted key with those two read permissions; the server verifies those reads with Stripe before saving the key, then uses balance transactions to calculate net volume after fees, refunds, disputes, and reversals.
Do not grant write permissions. The app does not request permission to create payments, refunds, transfers, payouts, customers, subscriptions, products, account changes, webhook secrets, or any action that moves money.
Deletion and revocation
Disconnecting removes the stored Stripe credential and stops future dashboard updates from that key. Revoking the key in your Stripe Dashboard is the fastest way to stop future Stripe API access, even if you cannot reach forbzz.
For profile deletion, privacy, or data access requests, email privacy@forbzz.com.
Privacy policy
We do not sell user data. Stripe-derived data is used to calculate analytics and ranking summaries for the product. Read the full Privacy Policy for collection, sharing, retention, and rights details.
Operator and affiliation
forbzz is operated under the forbzz brand. Security and legal questions can be sent to legal@forbzz.com.
forbzz is an independent founder ranking product and is not affiliated with or endorsed by Forbes or Stripe.