Please, also keep in mind that even if your startup doesn't process users' private information (such as financial data or email), your website/application could still be hacked to distribute malware, either exploiting users' browsers or inserting trojans to be downloaded.
For instance, I browse sites I trust with javascript and flash enabled in Noscript, increasing the surface attack.
Also, users are taught to avoid only untrusted websites/applications - and they could blindly trust your startup downloading trojans.