Privacy Policy
Last updated: March 22, 2026
1. Data controller
The data controller for personal data collected on this website is PricingCanary.
For any questions regarding the protection of your data, contact us by email: hello@pricingcanary.com
2. Personal data collected
We apply the principle of data minimization: only information strictly necessary for the operation of the service is collected.
Account data
- Email address (identification and communication)
- Name (optional, account personalization)
- Password (stored as a bcrypt hash, never in plain text)
Monitoring data
- Competitor pricing page URLs submitted by the user
- Pricing snapshots extracted from monitored pages
- Change detection results and impact analysis
- Technical metadata: extraction timestamps, confidence scores
Technical data
- IP address (activity logs and security)
- Actions performed on the account (sign-in, modifications, etc.)
Cookies
- Session cookie (essential): user authentication
- Cookie preferences cookie (essential): remembering your choices
- Analytics cookies (optional, subject to consent): audience measurement
- Marketing cookies (optional, subject to consent): personalization
3. Legal basis for processing
Each processing activity relies on a legal basis:
| Processing | Legal basis |
|---|---|
| Account creation and management | Contract performance |
| Pricing monitoring and alerts | Contract performance |
| Payment and billing (Stripe) | Contract performance |
| Activity logs and security | Legitimate interest |
| Analytics cookies | Consent |
| Marketing cookies | Consent |
4. Retention periods
| Data | Duration |
|---|---|
| Pricing snapshots | Stored for the duration of your subscription (core product value) |
| Activity logs | 90 days, then automatic deletion |
| Pending invitations | 30 days, then automatic deletion |
| Account data | Until account deletion by the user |
| Billing data | Retained by Stripe in accordance with tax obligations |
Automatic deletion is handled by a scheduled process that runs daily.
5. Sub-processors and transfers
Your data is processed by the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and storage | Cloud (US/EU) |
| Vercel | Application hosting | Cloud (US/EU) |
| Stripe | Payment and billing | US/EU |
| Web data providers | Public pricing page data collection | Cloud |
| AI processing providers | Pricing data extraction and analysis | US/EU |
Data protection. Where sub-processors operate outside of your jurisdiction, appropriate safeguards are in place (e.g., Standard Contractual Clauses, data processing agreements).
6. Data security
- Encryption in transit: all communications are protected by TLS 1.3
- Encryption at rest: database is encrypted (AES-256 via Supabase)
- Passwords: hashed with bcrypt, never stored in plain text
- Data isolation: each team can only access their own monitors and data
- Payment security: all card data is handled by Stripe (PCI-DSS compliant), never touches our servers
7. Your rights
You have the following rights regarding your personal data:
- Right of access: obtain a copy of your data. Available in Settings > General or by email.
- Right to rectification: correct your information from your account settings.
- Right to erasure: permanently delete your account and all your data from Settings > Security. Deletion is immediate and irreversible (monitors, snapshots, alerts, history).
- Right to data portability: export your data in a structured format (JSON) from your account settings.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw consent: withdraw your consent to cookies at any time via the cookie banner.
To exercise your rights, contact us at hello@pricingcanary.com. We respond within 30 days.
8. Complaints
If you believe that the processing of your data is not compliant, you may file a complaint with the relevant data protection authority in your jurisdiction.
9. Changes to this policy
This policy may be updated to reflect changes to the service or applicable regulations. The date of the last update is shown at the top of this page. In case of substantial changes, registered users will be notified by email.