AD SPOTS · FOR BRANDS

Put your brand next to the numbers Shopify merchants check all day.

Merchants

Store owners, not browsers

Every 10s

Fair rotation, every page

20/20

Spots left

How it works

Your brand gets a spot in the sponsor rotation: the side rails on desktop and the scrolling strip on phones, on every leaderboard, the live demo and the homepage. Spots take turns every 10 seconds, so every sponsor gets the same share of the screen. You send a logo, a name, one line and a link.

Why sponsor

  • Your buyers, in one place. People who run Shopify stores and Meta ads — the ones who buy apps, logistics, creative and agencies.
  • They keep the tab open. The podium moves with every order, so they come back to it all day.
  • Clean by design. No pixels, no tracking, no data. Sponsors never see a store, a name or a number — you get impressions and clicks.

Pricing

Month by month, priced on request while we're in beta.

20 spots available now.

Write to sponsors@roastify.club →
or copy it: All the details →

Running a store yourself? These spots are for brands that sell to merchants — your store competes on the podium.

Security

Sealed by design

In e-commerce your store is your edge, so we hide all of it. Its name, its full address, your Shopify and Meta logins: sealed before they reach our database, with keys the database never holds. We never know which store is yours.

AES-256-GCMA key per accountBlind indexesHTTPS + HSTS
Who sees what

We run the kitchen. We don't get a seat at the table.

🙈 We never see

  • Your store's name
  • Its full Shopify address
  • Which store is yours
  • Your Shopify and Meta logins, your ad account IDs
  • Room names, nicknames, roasts, chat and prizes

👀 We see

  • •Random ids like c7k2mq9x4w…
  • •Daily numbers next to those ids: sales, orders, sessions, ad spend
  • •Currency, time zone, when a store last synced
  • •Sealed values: rf2: followed by scrambled bytes

🍗 Your room sees

Only what you share with it: your store's name — or a codename — and its daily numbers.

Showing the name is your call, and it happens only on the page your friends open. On our side it stays sealed. Change your mind? Hide it any time, in any room.

About you: the most we hold is the basics you sign up with — a name and an email — and even those are sealed in the database. They're opened only to show them to you, or to email you something you asked for.

The lock

How the encryption works

Master key

Lives only in the server's environment. Never in the database, never in a backup.

↓ HKDF-SHA256 derives a separate key for every job ↓

Account keys

one per account · AES-256-GCM

email · name · store names · shop addresses · Shopify & Meta logins · ad accounts

Room keys

one per room · AES-256-GCM

room name · aliases · nicknames · roasts · chat · challenge titles & prizes

Fingerprint key

one for lookups · HMAC-SHA256

email and shop fingerprints — to sign you in and stop a store being connected twice

  1. 01

    You connect a store

    Its name, its address and its credentials are sealed with your account's own key the moment they arrive. The database only ever stores the sealed version.

  2. 02

    Every value is bound to you

    The seal records whose value it is and what it is. Copied into someone else's account or into another field, it refuses to open. Change a single bit, same.

  3. 03

    We find you without reading you

    To sign you in, we look up a keyed fingerprint of your email. It matches, but nobody can turn it back into an address — or test guesses against it — without the server's key.

  4. 04

    Opened only where it's needed

    Your store's name is opened only inside the page your room loads, for its members. The address and tokens only for the seconds a sync talks to Shopify and Meta. Nothing is written down in the clear.

Proof, not promises

See what we see

Fictitious exampleA made-up account — Sam Example and Sample Socks Co. don't exist — sealed for real, with the same keys and the same code as yours, every time this page loads. Your own account is stored exactly like this; we never put anyone's real name, store or email on a page.

FieldIn our databaseWhat its owner sees
Accountc7k2mq9x4wb83nd0e5tqv1yha random id—
Emailrf2:snMkNE…xw0z (72 chars)kept to sign you in, reach you about your account and share important updates about ROAStify — news and offers only if you said yessam.example@example.com
Email fingerprint285d2577e7…3856 (64 chars)finds you at sign-in, can't be turned back into an email—
Namerf2:IEpIG0…OZEe (56 chars)Sam Example
Password$2b$12$… (60 chars)bcrypt: one-way, nobody can read it back—
Store namerf2:HLvVCK…Sg2g (63 chars)Sample Socks Co.
Shop addressrf2:8BV7yH…RhzY (76 chars)sample-socks.myshopify.com
Shopify credentialsrf2:lVhGud…mqcM (79 chars)never shown, not even to its owner
A day of numbersc9w4hz2rkt… · 2026-10-02 · 612000 · 81not sealed, so the podium can add them up — but next to a random id, not a name$6,120 · 81 orders
Ad accountrf2:ZWP1CG…YiTw (55 chars)act_1234567890
A roomrf2:XoG1iO…9m5w (58 chars)Example Crew
The honest part

What encryption can't do

We keep your email

It's sealed like the rest, but it's the one thing we open on purpose: to sign you in, send password resets, reach you about your account and share important updates about ROAStify — and, only if you said yes, news and offers. One switch in your account settings turns those off.

Syncing needs the address

Every ten minutes the server opens your shop's address and token in memory, for the few seconds Shopify needs to answer. They're never written down in the clear, and never logged.

Numbers aren't sealed

Daily sales, orders, sessions and ad spend are stored as they are, so the server can rank the podium — and so are a store's niche and main market, so benchmarks can group them. They sit next to random ids, not names.

Someone holds the master key

Whoever runs the server could, in theory, open everything — true of any app that works while you sleep. The key isn't in the database or its backups, there's no admin panel, and no screen shows a store to anyone but its own room.

Money

What it costs us to run this

ROAStify · monthly bill

1 small servera few $

Investors to pay back$0

Ad networks$0

Data sold$0 · never

Paid bythe sponsor spots

ROAStify runs on one small server that costs us a few dollars a month. That's the whole bill: no investors to pay back, no ad network, no data deals.

The sponsor spots around the leaderboard cover it — and sponsors never see a name or a number.

Your data isn't the product. It couldn't be: it's sealed.

For the nerds

Technical details

Encryption
AES-256-GCM, a fresh random 96-bit IV for every value, 128-bit authentication tag.
Bound to its owner
Every value carries who it belongs to and which field it is as authenticated data: moved anywhere else, it fails to open.
Keys
HKDF-SHA256 derives one key per account and one per room from a 256-bit master key held only in the server's environment — not in the database, not in backups.
Lookups
HMAC-SHA256 blind indexes over the normalised email, shop address and ad account ID.
Passwords
bcrypt with cost 12. Sessions are signed, versioned, HttpOnly cookies.
In transit
HTTPS everywhere with HSTS and a strict Content Security Policy.
Addresses and logs
Room links are random. Shop addresses are scrubbed from sync logs before they're written, and the logs are gone after a week.
Deleting
Delete your account and everything sealed with its key goes with it. Disconnect a store and its whole history is deleted.

Questions, or found a hole? Write to hello@roastify.club. What we read from Shopify and Meta, and why: Privacy.