Skip to main content

Legal document

Privacy Policy

This Policy explains what SaveAtCost.co collects, why it is used, which service providers receive it, how long it is kept, and the choices available to you.

Last updated:

1. Scope and controller

This Policy applies to the SaveAtCost.co website, account dashboard, browser extension, and related support. The entity responsible for the processing described here is the operator of SaveAtCost.co.

It does not govern a retailer, Stripe-hosted checkout or portal pages, or other third-party websites and services that publish their own privacy notices.

2. Information we collect

  • Account and profile data: first and last name, email address, password hash, email-verification status, role, account dates, and login/security status.
  • Membership and preference data: primary and optional secondary Costco membership numbers, membership level, Costco Visa indicator, and optional email preferences.
  • Purchase and receipt data: receipt and order identifiers, membership number shown on the receipt, warehouse number/name, region, channel, transaction date and type, item numbers and descriptions, quantities, prices, discounts, taxes, returns, fuel details, and totals.
  • Derived and shopping-planning data: spending totals, trips, frequently purchased and unique items, price observations and trends, possible adjustment matches, saved shopping-list items, suggestion dismiss/snooze/block preferences, notification settings, and other dashboard summaries. Personalized shopping predictions, scores, and explanations are calculated on demand and are not stored as prediction records.
  • Authentication and security data: password-reset and verification records, rotating session records, browser-extension device authorization, rate-limit buckets, request identifiers, security events, and IP-derived abuse-prevention signals.
  • Billing data: Stripe customer and subscription identifiers, tier, status, trial and renewal dates, and payment-event records. SaveAtCost does not store full payment-card numbers.
  • Communications: support messages and the delivery status of account emails. ZeptoMail open and click tracking are disabled in the implemented email client.
  • Device and usage data: browser-supplied request information, page/API path, HTTP method and status, timestamps, error details, and receipt-filter interface state stored for the browser tab.

3. Location information

The application does not request GPS or precise device location. Receipt data may identify a warehouse and its address, city, state, or region. IP addresses or related network information may indicate an approximate area and may be processed for security, rate limiting, hosting, and delivery.

4. Browser-extension data flow

When you actively use the extension on supported retailer pages, it reads retailer-session values locally to request your order and receipt records, then sends supported purchase data to your authenticated SaveAtCost account. The extension also stores SaveAtCost connection tokens and short-lived cached data in extension storage.

SaveAtCost does not ask for or store your Costco password, and the extension is designed for supported Costco pages rather than general browsing-history tracking. Retailer session data remains subject to the retailer and browser environment.

5. Why we use information

  • Create, verify, secure, authenticate, and support accounts and browser-extension connections.
  • Import, organize, search, display, export, and delete receipt and order history.
  • Calculate spending summaries, price observations, trends, on-demand shopping suggestions, estimated list totals, and possible price-adjustment matches.
  • Store and apply shopping-list actions and suggestion preferences, including add, check, remove, dismiss, snooze, block, and restore actions.
  • Provide Free and Pro features, Stripe checkout, subscription status, cancellation access, and billing support.
  • Send account verification and recovery email and, when enabled, available product or price messages.
  • Prevent abuse, enforce access boundaries, investigate errors, maintain service reliability, and comply with law.
  • Improve matching, validation, performance, and interface behavior using operational information and de-identified or aggregated analysis where appropriate.

7. When information is disclosed

We disclose information only as reasonably needed to operate the Service, complete a request, protect rights and systems, comply with law, or support a business transaction. Service providers must receive only the information needed for their role.

RecipientPurpose and information involved
MongoDBStores account, receipt, derived analytics, security, and service records.
RailwayHosts the Nuxt/Nitro application and processes network requests and operational logs.
StripeProcesses checkout and billing and returns customer, subscription, status, and event identifiers.
ZeptoMailReceives recipient name/email and message content to deliver verification and recovery email.
Cloudflare TurnstileReceives browser and challenge data to evaluate bot and abuse risk on authentication forms.
Google FontsReceives a font request and ordinary network information such as IP address and browser headers.
Costco Wholesale CorporationYou interact directly with the retailer; the extension uses your retailer session locally to request order and receipt information.

8. Sale, advertising, and analytics

The implemented Service does not contain first-party advertising, behavioral-advertising pixels, affiliate tracking, or a product-analytics script. We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined. If these practices change, this Policy and any required consent or opt-out controls must be updated before the change is enabled.

9. Cookies and local browser storage

The website uses HTTP-only access and refresh cookies needed to keep an account signed in and secure. A receipt-filter preference may be stored in session storage until the browser tab or session ends. Turnstile and Stripe may use their own necessary technologies when you interact with their widgets or hosted pages. See the Cookie Policy for names, purposes, duration, and controls.

10. Retention

Account, membership, receipt, saved-list, suggestion-preference, notification-preference, and derived dashboard data are generally retained while the account is active. Rotating sessions, one-time verification and recovery records, rate-limit buckets, import locks, and payment-event deduplication records use expiration or bounded-retention fields. Operational records are kept only as long as reasonably needed for security, reliability, disputes, and legal obligations.

When an eligible account-deletion request completes, the application deletes the user’s account, receipts, derived analytics, saved-list records, suggestion preferences, settings, sessions, and other measured owned records from the active database. Some information may remain temporarily in backups or where retention is required for billing, fraud prevention, legal obligations, or disputes, then be deleted or isolated under the applicable retention process.

11. Security

The code uses password hashing, short-lived access tokens, rotating refresh sessions, HTTP-only cookies, email verification, account lockout, rate limits, Turnstile, origin and method checks, authorization controls, signed Stripe webhooks, security headers, and sanitized operational logging. No service can promise absolute security. Use a unique password and contact support promptly if you suspect unauthorized access.

12. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of personal information; object to or restrict certain processing; withdraw consent; appeal a decision; or complain to a privacy authority. These rights can have exceptions. We will verify requests and respond as required by applicable law.

  • Update profile, membership, personalized-suggestion, and optional email preferences in account settings.
  • Download the account JSON export from account settings.
  • Request permanent account deletion from account settings after resolving an active or unresolved subscription.
  • For another privacy request, email support@saveatcost.co with the account email and the request type. Do not send a password, full payment-card number, or retailer password.

13. Children

The Service is not directed to anyone under 18, and we do not knowingly create accounts for children. If you believe a child provided personal information, contact support@saveatcost.co so the report can be reviewed and appropriate deletion steps taken.

14. International transfers

Service providers and infrastructure may process information in countries other than where you live. Where required, the responsible operator must use a lawful transfer mechanism and appropriate safeguards. The operator’s legal identity and establishment location still require confirmation in the public legal configuration.

15. Changes and contact

We may update this Policy as the Service or law changes and will update the date above. We will provide additional notice for material changes when required. Questions and privacy requests may be sent to support@saveatcost.co. The verified operator name and postal address must be configured before this draft is treated as final.

Questions about this document?

Email support@saveatcost.co. Do not include a password, full payment-card number, or retailer-session token.