Legal document
Privacy Policy
This Policy explains what SaveAtCost.co collects, why it is used, which service providers receive it, how long it is kept, and the choices available to you.
Last updated:
1. Scope and controller
This Policy applies to the SaveAtCost.co website, account dashboard, browser extension, and related support. The entity responsible for the processing described here is the operator of SaveAtCost.co.
It does not govern a retailer, Stripe-hosted checkout or portal pages, or other third-party websites and services that publish their own privacy notices.
2. Information we collect
- Account and profile data: first and last name, email address, password hash, email-verification status, role, account dates, and login/security status.
- Membership and preference data: primary and optional secondary Costco membership numbers, membership level, Costco Visa indicator, and optional email preferences.
- Purchase and receipt data: receipt and order identifiers, membership number shown on the receipt, warehouse number/name, region, channel, transaction date and type, item numbers and descriptions, quantities, prices, discounts, taxes, returns, fuel details, and totals.
- Derived and shopping-planning data: spending totals, trips, frequently purchased and unique items, price observations and trends, possible adjustment matches, saved shopping-list items, suggestion dismiss/snooze/block preferences, notification settings, and other dashboard summaries. Personalized shopping predictions, scores, and explanations are calculated on demand and are not stored as prediction records.
- Authentication and security data: password-reset and verification records, rotating session records, browser-extension device authorization, rate-limit buckets, request identifiers, security events, and IP-derived abuse-prevention signals.
- Billing data: Stripe customer and subscription identifiers, tier, status, trial and renewal dates, and payment-event records. SaveAtCost does not store full payment-card numbers.
- Communications: support messages and the delivery status of account emails. ZeptoMail open and click tracking are disabled in the implemented email client.
- Device and usage data: browser-supplied request information, page/API path, HTTP method and status, timestamps, error details, and receipt-filter interface state stored for the browser tab.
3. Location information
The application does not request GPS or precise device location. Receipt data may identify a warehouse and its address, city, state, or region. IP addresses or related network information may indicate an approximate area and may be processed for security, rate limiting, hosting, and delivery.
4. Browser-extension data flow
When you actively use the extension on supported retailer pages, it reads retailer-session values locally to request your order and receipt records, then sends supported purchase data to your authenticated SaveAtCost account. The extension also stores SaveAtCost connection tokens and short-lived cached data in extension storage.
SaveAtCost does not ask for or store your Costco password, and the extension is designed for supported Costco pages rather than general browsing-history tracking. Retailer session data remains subject to the retailer and browser environment.
5. Why we use information
- Create, verify, secure, authenticate, and support accounts and browser-extension connections.
- Import, organize, search, display, export, and delete receipt and order history.
- Calculate spending summaries, price observations, trends, on-demand shopping suggestions, estimated list totals, and possible price-adjustment matches.
- Store and apply shopping-list actions and suggestion preferences, including add, check, remove, dismiss, snooze, block, and restore actions.
- Provide Free and Pro features, Stripe checkout, subscription status, cancellation access, and billing support.
- Send account verification and recovery email and, when enabled, available product or price messages.
- Prevent abuse, enforce access boundaries, investigate errors, maintain service reliability, and comply with law.
- Improve matching, validation, performance, and interface behavior using operational information and de-identified or aggregated analysis where appropriate.
6. Legal bases where applicable
Where a law requires a legal basis, processing may rely on performance of our contract with you; our legitimate interests in operating, securing, troubleshooting, and improving the Service; your consent for optional communications where required; and compliance with legal, tax, fraud-prevention, or dispute obligations. You may withdraw consent for future optional processing without affecting earlier lawful processing.
7. When information is disclosed
We disclose information only as reasonably needed to operate the Service, complete a request, protect rights and systems, comply with law, or support a business transaction. Service providers must receive only the information needed for their role.
| Recipient | Purpose and information involved |
|---|---|
| MongoDB | Stores account, receipt, derived analytics, security, and service records. |
| Railway | Hosts the Nuxt/Nitro application and processes network requests and operational logs. |
| Stripe | Processes checkout and billing and returns customer, subscription, status, and event identifiers. |
| ZeptoMail | Receives recipient name/email and message content to deliver verification and recovery email. |
| Cloudflare Turnstile | Receives browser and challenge data to evaluate bot and abuse risk on authentication forms. |
| Google Fonts | Receives a font request and ordinary network information such as IP address and browser headers. |
| Costco Wholesale Corporation | You interact directly with the retailer; the extension uses your retailer session locally to request order and receipt information. |
8. Sale, advertising, and analytics
The implemented Service does not contain first-party advertising, behavioral-advertising pixels, affiliate tracking, or a product-analytics script. We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined. If these practices change, this Policy and any required consent or opt-out controls must be updated before the change is enabled.
10. Retention
Account, membership, receipt, saved-list, suggestion-preference, notification-preference, and derived dashboard data are generally retained while the account is active. Rotating sessions, one-time verification and recovery records, rate-limit buckets, import locks, and payment-event deduplication records use expiration or bounded-retention fields. Operational records are kept only as long as reasonably needed for security, reliability, disputes, and legal obligations.
When an eligible account-deletion request completes, the application deletes the user’s account, receipts, derived analytics, saved-list records, suggestion preferences, settings, sessions, and other measured owned records from the active database. Some information may remain temporarily in backups or where retention is required for billing, fraud prevention, legal obligations, or disputes, then be deleted or isolated under the applicable retention process.
11. Security
The code uses password hashing, short-lived access tokens, rotating refresh sessions, HTTP-only cookies, email verification, account lockout, rate limits, Turnstile, origin and method checks, authorization controls, signed Stripe webhooks, security headers, and sanitized operational logging. No service can promise absolute security. Use a unique password and contact support promptly if you suspect unauthorized access.
12. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of personal information; object to or restrict certain processing; withdraw consent; appeal a decision; or complain to a privacy authority. These rights can have exceptions. We will verify requests and respond as required by applicable law.
- Update profile, membership, personalized-suggestion, and optional email preferences in account settings.
- Download the account JSON export from account settings.
- Request permanent account deletion from account settings after resolving an active or unresolved subscription.
- For another privacy request, email support@saveatcost.co with the account email and the request type. Do not send a password, full payment-card number, or retailer password.
13. Children
The Service is not directed to anyone under 18, and we do not knowingly create accounts for children. If you believe a child provided personal information, contact support@saveatcost.co so the report can be reviewed and appropriate deletion steps taken.
14. International transfers
Service providers and infrastructure may process information in countries other than where you live. Where required, the responsible operator must use a lawful transfer mechanism and appropriate safeguards. The operator’s legal identity and establishment location still require confirmation in the public legal configuration.
15. Changes and contact
We may update this Policy as the Service or law changes and will update the date above. We will provide additional notice for material changes when required. Questions and privacy requests may be sent to support@saveatcost.co. The verified operator name and postal address must be configured before this draft is treated as final.
Questions about this document?
Email support@saveatcost.co. Do not include a password, full payment-card number, or retailer-session token.