Privacy Policy
Last updated: June 28, 2026
This Privacy Policy explains how PriceTrail ("we", "us", "our") collects, uses, and shares information when you use our website and dashboard (the "Service"). If you are located in the European Union or California, additional rights and disclosures apply — see Sections 6, 7, and 9 below.
1. Information We Collect
We collect the following categories of personal data:
- Account information: email address, hashed password (for email/password sign-in), or OAuth identity token (for Google sign-in via Supabase Auth).
- Tracked product data: product URLs, product names, current and historical prices, and your alert thresholds (the price at which you want to be notified).
- Notification preferences: web push subscription endpoints (browser push tokens), webhook URLs, and API keys you configure for outbound integrations.
- Billing information: your Stripe customer ID, subscription tier, billing status, and payment method metadata (e.g., card last four digits and expiry) as recorded by Stripe. We do not store full card numbers.
- Usage and log data: IP address, browser type, operating system, pages visited, and timestamps, recorded automatically when you use the Service.
- Error telemetry: stack traces and browser/device metadata captured by Sentry when errors occur. PII scrubbing is applied before transmission.
2. How We Use Your Information and Lawful Basis (GDPR Art. 6)
The list below sets out each processing activity, its purpose, and the lawful basis under GDPR Article 6 where applicable.
- Providing the Service — tracking prices, sending price-drop alerts, managing your account and subscription. Lawful basis: performance of a contract (Art. 6(1)(b)).
- Processing payments — charging your payment method via Stripe, managing subscription renewals and cancellations. Lawful basis: performance of a contract (Art. 6(1)(b)).
- Security and fraud prevention — monitoring for abuse, unauthorized access, and anomalous activity. Lawful basis: legitimate interests (Art. 6(1)(f)) — our legitimate interest in keeping the Service secure and reliable.
- Service reliability and debugging — using error telemetry (Sentry) and application logs (Railway) to diagnose and fix issues. Lawful basis: legitimate interests (Art. 6(1)(f)).
- Marketing emails — sending promotional or newsletter emails (only if you opt in). Lawful basis: consent (Art. 6(1)(a)). You may withdraw consent at any time via the unsubscribe link in any marketing email.
- Web push notifications — sending browser push alerts only after you grant permission in your browser. Lawful basis: consent (Art. 6(1)(a)). You may revoke push permission at any time in your browser settings or from your account Settings page.
- Legal compliance — retaining records as required by applicable law. Lawful basis: legal obligation (Art. 6(1)(c)).
3. Cookies
We use only strictly necessary cookies. These are session cookies set by Supabase Auth to keep you signed in and maintain your authenticated session. We do not use third-party advertising cookies, tracking pixels, or analytics cookies that send data to external services.
4. Sub-processors
We share personal data with the following third-party sub-processors. Each processes data only as necessary to perform their service on our behalf. Where a Data Processing Agreement (DPA) has not yet been formally executed, we have noted this below.
- Stripe — payment processing and billing. Data location: USA and EU (Stripe Ireland Ltd processes EU customer data, providing an adequacy basis within the EEA). DPA: stripe.com/legal/dpa. SCCs: included in DPA. DPA status: accepted via Stripe's online DPA portal.
- Supabase — authentication and database hosting. Data location: EU-West (AWS eu-west-1). DPA: supabase.com/legal/dpa. SCCs: included in DPA. DPA status: accepted via Supabase's online DPA portal.
- Sentry — error monitoring and stack traces. Data location: USA (Sentry EU data region not currently enabled; error telemetry is therefore processed in the USA under Standard Contractual Clauses). DPA: sentry.io/legal/dpa. SCCs: Module 2 (Controller → Processor). DPA status: accepted via Sentry's online DPA portal. PII scrubbing is applied before transmission.
- Railway — application hosting and log storage. Data location: EU-West (GCP europe-west1). DPA: Railway does not currently publish a standard DPA; their privacy policy is available at railway.com/legal/privacy. Application logs are retained for up to 30 days and automatically deleted by the platform. We limit personal data present in application logs to the minimum necessary.
- Resend — transactional email delivery (price alerts, account notifications). Data location: USA (EU region not currently enabled; email delivery is processed in the USA under Standard Contractual Clauses). DPA: resend.com/legal/dpa. SCCs: included in DPA. DPA status: accepted via Resend's online DPA portal.
- CloudAMQP — message queue for price-check job processing. Data location: EU-West (CloudAMQP EU cluster). DPA: not formally published; see cloudamqp.com/privacy_policy.html. Message payloads contain product URLs and internal job identifiers; no end-user PII is intentionally transmitted to CloudAMQP.
- ScraperAPI — web scraping proxy for price data collection. Data location: USA. DPA: not formally published (contact sales@scraperapi.com for a custom DPA). ScraperAPI receives outbound HTTP requests from our servers and returns publicly available webpage content. No EU end-user personal data is intentionally transmitted to ScraperAPI; requests carry only our server IP address and the target product URL.
5. Data Retention
- Account and price history data: retained for the lifetime of your account. If you delete your account, we will delete or irreversibly anonymize your personal data within 30 days, except where retention is required by law (e.g., billing records for tax purposes).
- Application logs (Railway): retained for up to 30 days, after which they are automatically deleted by the hosting platform.
- Error reports (Sentry): retained for 90 days in accordance with the active Sentry plan defaults, after which they are automatically deleted.
- Billing records: retained for 7 years as required by UK tax and accounting law (HMRC record-keeping requirements).
6. Your Rights (EU / GDPR)
If you are located in the European Economic Area or United Kingdom, you have the following rights under the GDPR:
- Access (Art. 15): request a copy of the personal data we hold about you.
- Rectification (Art. 16): ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17): ask us to delete your personal data ("right to be forgotten"), subject to legal retention obligations.
- Portability (Art. 20): receive your data in a structured, machine-readable format and transfer it to another controller.
- Objection (Art. 21): object to processing based on legitimate interests, including objecting to direct marketing.
- Restriction (Art. 18): ask us to restrict processing while a dispute is resolved.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, submit a Data Subject Access Request (DSAR) by email to hi@pricetrail.co. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (for example, the ICO in the UK or the DPC in Ireland).
7. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
8. Security
We use industry-standard measures to protect your information, including TLS encryption in transit, access controls on our infrastructure, and PII scrubbing in error telemetry. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights.
Categories of personal information we collect:
- Identifiers (email address, IP address, device identifiers)
- Commercial information (subscription tier, billing status, payment method metadata)
- Internet or other electronic network activity (browsing history within the Service, log data)
- Inferences drawn from the above (e.g., product categories you track)
We do not sell your personal information and have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.
Under the CCPA/CPRA you have the right to: (a) know what personal information we collect and how it is used and disclosed; (b) request deletion of your personal information; (c) request correction of inaccurate personal information; (d) opt out of the sale or sharing of your personal information (not applicable — we do not sell or share); and (e) non-discrimination for exercising these rights.
To submit a CCPA request, email hi@pricetrail.co. We will respond within 45 days.
10. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email to the address on your account and by posting a prominent notice in the Service at least 14 days before the changes take effect. The updated policy will carry a new "Last updated" date at the top of this page.
12. Contact
For questions about this Privacy Policy, DSARs, or to exercise your data rights, contact Michele Fasciano (trading as PriceTrail) by email at hi@pricetrail.co. As an individual sole trader based in the United Kingdom, PriceTrail is subject to UK GDPR. Users in the EU may also contact the relevant supervisory authority in their country of residence. We do not currently maintain a formal EU representative under GDPR Article 27, but all data rights requests are handled directly and promptly by email.