Privacy notice
Status
The owner approved the product rules on this page for price, cancellation, refunds, and account deletion. This is not a counsel-reviewed legal agreement. A legal entity, postal address, and governing law are not stated.
A legal entity name, postal address, and governing law are not stated because they are not in the product record.
Public homepage
The public homepage is static HTML and CSS. It does not collect account passwords or payment cards.
The public homepage loads fonts from Google.
Account data
The application stores an account email, an optional name, and a hashed password.
Billing rows store the plan, subscription status, Stripe customer id, Stripe subscription id, Stripe price id, and the current period end when Stripe sends one.
Password-reset records store a hash of the token, an expiry one hour after creation, and the time the token was used. The raw token is not stored. Reset email is sent only when a mail transport is configured.
If the browser stored a referral code before registration, that short string is saved on the account.
Lookups and marketplace data
Lookup history stores the search text, a normalized query, the count of comparable results, and the time. It does not store the listing payload.
Search text is sent to the eBay Browse API and the Etsy Open API v3 only when those credentials are configured.
Without those credentials, or when demo mode is on, CompCheck uses labeled demo fixtures and does not present them as live listings.
Pasting an eBay or Etsy URL searches by words from that link. CompCheck does not open or value that specific listing.
- Sold or completed-sale prices are not collected and are not invented.
- Shipping is stored on a result only when the official response includes it. Etsy search results often omit it.
Payments
CompCheck does not store payment card numbers.
Stripe receives the account email, optional name, and an internal user id when a checkout customer is created.
Live charges are off. CompCheck loads live Stripe keys only when STRIPE_LIVE_BILLING is exactly enabled, and that gate is off. Test mode does not charge real money.
Stripe test mode does not charge real money. Promotion codes are passed through to Stripe Checkout when checkout is available.
Analytics
Browser analytics stay in local storage on that browser, capped at the latest 100 events. No third-party analytics script is loaded by the app.
Events are limited to landing clicks, lookup attempts, signup, checkout started, and page views, plus the path and time.
Retention
CompCheck does not delete account records on an automatic timer.
Lookup history stores the search text, a normalized query, the count of comparable results, and the time. It does not store the listing payload.
Password-reset records store a hash of the token, an expiry one hour after creation, and the time the token was used. The raw token is not stored. Reset email is sent only when a mail transport is configured.
Monthly lookup counts stay until an operator deletes the account.
There is no self-serve delete button. When a deletion request is completed, the operator deletes the account email, name, password hash, sessions, password-reset records, monthly lookup counts, and lookup query text for that account.
Before that deletion, the operator copies the Stripe customer id, subscription id, and price id into private billing notes. Those identifiers can be payment records. No statutory retention period is stated, because counsel has not set one. This notice is not a counsel-reviewed retention schedule.
Account deletion
There is no self-serve account deletion.
There is no self-serve delete button. When a deletion request is completed, the operator deletes the account email, name, password hash, sessions, password-reset records, monthly lookup counts, and lookup query text for that account.
Before that deletion, the operator copies the Stripe customer id, subscription id, and price id into private billing notes. Those identifiers can be payment records. No statutory retention period is stated, because counsel has not set one. This notice is not a counsel-reviewed retention schedule.
To ask for account deletion, email the support address and include the account email. The request is handled by an operator. No response-time commitment is stated.
Lookup history stores the search text, a normalized query, the count of comparable results, and the time. It does not store the listing payload.
Password-reset records store a hash of the token, an expiry one hour after creation, and the time the token was used. The raw token is not stored. Reset email is sent only when a mail transport is configured.
Billing rows store the plan, subscription status, Stripe customer id, Stripe subscription id, Stripe price id, and the current period end when Stripe sends one.
Contact
Support email: compcheck@protocat.net.
Mail for protocat.net is directed to Cloudflare Email Routing. Public DNS shows Cloudflare mail exchangers and an SPF record that includes Cloudflare. Delivery to compcheck@protocat.net was not proven: the Cloudflare API was not authorized, and a direct SMTP check could not connect. Do not treat this inbox as monitored until a message is delivered.
Do not send passwords, API keys, or payment card numbers.