PricedLowest

Privacy Notice

Version privacy_v2026_07 · controller: PricedLowest Inc.

1. What we collect and why

Email (sign-in and order updates — contract), order details and amounts (contract, tax/AML), ship-to details passed to the fulfilling partner (contract — minimized: name, address, phone only, never payment data), dispute photographs (contract and consumer-law compliance), IP addresses and user agents in consent records (legal obligation, Art. 7(1) accountability).

2. Who processes it

Stripe (payments — PCI scope never touches us), vetted manufacturing and fulfillment partners (fulfillment only, under data-processing agreements with SCCs for cross-border transfers), email delivery (transactional only — no marketing lists, no ad networks, no data sales. Ever.)

3. Retention

Order financial records (amounts, statuses — no PII after erasure): 7 years, tax/AML. Consent proofs (hash-chained, tamper-evident): retained as legal proof of consent. Uploads and dispute evidence: deleted 30 days after delivery or case closure. Magic-link tokens: 15 minutes, single-use, stored only as hashes.

4. Your rights (self-serve)

Access (Art. 15) and erasure (Art. 17) are self-serve from your Account → Your data. Erasure pseudonymizes PII everywhere; financial records persist without PII per tax/AML obligations; consent proofs persist as required by Art. 7(1). You also have rights to rectification, portability, restriction, and objection — contact privacy@pricedlowest.com and we respond within 30 days.

5. Security

TLS everywhere, HMAC-signed webhooks, hash-chained consent ledger, payment data held exclusively by Stripe (we never see card numbers), role-gated admin console with no existence disclosure to non-admins.

6. Contact & complaints

Data controller: PricedLowest Inc. — privacy@pricedlowest.com. EU/UK users may lodge a complaint with their supervisory authority; we'd appreciate the chance to fix it first.