1. Information We Collect
When you create an account, we collect:
- Account information: your name, email address, and password (hashed)
- Store preferences: the Home Depot store locations you choose to monitor
- Subscription data: plan type and billing information (processed by Stripe; we do not store card numbers)
- Usage data: pages visited, features used, and last access time to improve the service
- Attribution data: how you found us (referral source, UTM parameters) to understand which channels bring users
2. Cookies and Local Storage
We use cookies and browser local storage for:
- Authentication: keeping you signed in across sessions (Supabase auth tokens)
- Preferences: your filter settings, theme choice, and cookie consent status
- Analytics: Simple Analytics (privacy-friendly, no personal data collected) to understand site usage
We do not use third-party tracking cookies. We do not sell or share your data with advertisers.
3. How We Use Your Information
- To provide and improve the clearance deal monitoring service
- To send you deal digest emails for your monitored stores (you can unsubscribe anytime)
- To process payments through Stripe
- To detect and prevent abuse (rate limiting, trial cycling prevention)
- To communicate service updates and account-related notices
4. Data Sharing
We share data only with:
- Supabase: database and authentication hosting
- Stripe: payment processing
- Resend: transactional email delivery
- Cloudflare: website hosting and CDN
We do not sell your personal information to third parties.
5. Email Communications
We may send you:
- Transactional emails: account verification, password resets, subscription confirmations
- Deal digest emails: clearance deals from your monitored stores
- Onboarding emails: getting started guidance after signup
All marketing emails include a one-click unsubscribe link. You can also manage email preferences from your account settings.
6. Data Retention
- Account data is retained as long as your account is active
- Clearance product data is retained for analytics and price history purposes
- You can request account deletion by contacting us; we will delete your data within 30 days
7. Security
We protect your data through:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Row-level security policies on the database
- Hashed passwords (never stored in plaintext)
- Rate limiting on all API endpoints
- Server-side access controls for plan-gated features
8. Your Rights
You have the right to:
- Access your personal data (available in your account settings)
- Correct inaccurate data
- Delete your account and associated data
- Unsubscribe from marketing emails at any time
- Export your data upon request
9. Children
Endless is not intended for users under 13 years of age. We do not knowingly collect information from children.
10. Changes
We may update this policy from time to time. Significant changes will be communicated via email or a notice on the site.
11. Contact
For privacy questions or data requests, contact us at [email protected].