This Privacy Policy describes how PullThisCard (the "Service") collects, uses, and shares information when you use it, whether you're located in the United States, Canada, or elsewhere. It applies to the web application available at pullthiscard.com and the backend services that support it.
PullThisCard does not require you to create an account. There is no login, no password, and no name or email address collected by the Service itself in order to use it. Most of what makes the Service feel personalized (your saved wallet, your theme choice, custom cards you've added) lives in your own browser, not on our servers.
The Service stores the following directly in your browser's local storage, scoped to your device and browser only:
None of this is transmitted to or stored on our servers as part of normal use of the Service. It stays in your browser unless you clear it or switch devices.
When the Service calculates a card recommendation, your browser sends a request to our backend containing:
This request is processed to generate a recommendation and is not stored as a persistent record tied to you individually. Standard web server request logs (which may include your IP address and timestamp, generated automatically by our hosting provider) are retained only as long as our hosting provider's standard infrastructure logging practices dictate.
If you grant permission when prompted, the Service uses your browser's Geolocation API to get an approximate location, used only to improve the relevance of merchant search results (so searching "YMCA" shows nearby branches rather than ones across the country). This location:
If you decline or your browser doesn't support this, the Service works exactly as it does otherwise; merchant search simply isn't location-biased.
When you search for a merchant that isn't in our built-in list, your search text (and your approximate location, if you've granted permission) is sent to Google's Places API to find a match. We receive back a business name, a general category, and a Google place identifier, not any personal information about you from Google. This is covered further in Section 4.
If you use the PullThisCard Chrome extension, it detects when you've reached a checkout page (using signals like the store's platform, a recognized domain, or the page's own site-name metadata) and sends the same request described above under "Information sent to our servers" β your wallet's card names, the detected merchant/category, and your selected country β to calculate a recommendation shown in an on-page banner. The extension does not read card numbers, passwords, or page content beyond these specific checkout-detection signals, and does not run analytics or tracking of any kind. A full, permission-by-permission breakdown is published separately at Browser Extension: Permissions & Privacy, so it can be kept current with the extension's actual version independent of this policy's own revision schedule.
We use the information described above to:
We do not use this information for targeted advertising, and we do not sell personal information.
The Service currently uses your browser's local storage (not cookies) to remember your wallet, preferences, and custom entries between visits. Local storage stays on your device and is not automatically sent to our servers the way a cookie is sent with every request.
If we add analytics or advertising features in the future that use cookies, we will update this section and provide any consent mechanism required by applicable law (including Quebec's Law 25 and Canada's broader privacy framework) before doing so.
Information stored in your browser persists until you clear your browser's site data or use a different browser/device. We don't control or have access to this.
Error reports submitted through "Report Error" are currently retained in our hosting provider's standard application logs. [UPDATE THIS SECTION once a real database/retention schedule for these reports is in place. As of this draft, there isn't a formal retention period defined beyond standard log retention.]
The California Consumer Privacy Act (CCPA), as amended by the CPRA, gives covered businesses' customers the right to know what personal information has been collected, request deletion, and not be discriminated against for exercising these rights.
Worth being accurate about: the CCPA only applies to a business that meets at least one specific threshold: annual gross revenue over roughly $26.6 million, buying/selling/sharing the personal information of 100,000+ California consumers or households in a year, or deriving 50%+ of revenue from selling/sharing personal information. [A new, small service is unlikely to meet any of these thresholds yet, but whether the CCPA currently applies to this specific business is a factual determination based on actual revenue and user volume, and should be confirmed with a lawyer rather than assumed either way.]
Regardless of whether the CCPA's specific legal thresholds are met, the practical reality described throughout this policy still applies: the Service is built to avoid collecting directly identifying personal information in the first place, and we do not sell personal information to data brokers or third parties.
Residents of other U.S. states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, and others) have broadly similar rights, generally subject to similar size/volume thresholds under their respective state laws. [Confirm exact applicable state laws and thresholds with a lawyer.]
The Personal Information Protection and Electronic Documents Act (PIPEDA) gives you the right to know why your personal information is collected, to access information we hold about you, and to challenge its accuracy. As described above, the Service is built to minimize the personal information it collects in the first place, and most user data is held locally in your browser rather than on our servers.
Quebec's Law 25 applies to any business of any size that collects, uses, or discloses personal information of people in Quebec. Unlike some U.S. state laws, there is no revenue or company-size exemption. Because the Service is available to Quebec residents, Law 25 likely applies to it regardless of how small the operation is. This means, in addition to the rights above:
[A Quebec-facing privacy policy should be reviewed specifically for Law 25 compliance, including the Privacy Officer designation above, which needs to name a real person before this page is published, and whether a French-language version is required for your situation. French-language UI for the app itself is on the project roadmap but not yet built.]
The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us using the details in Section 13 so we can address it.
We take reasonable measures to protect information transmitted to and processed by the Service, including using HTTPS encryption for all traffic. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Our hosting infrastructure and the third-party services we use (including Google's Places API) may process data on servers located outside of your own country, including in the United States, regardless of whether you are accessing the Service from the U.S. or Canada. By using the Service, you acknowledge that your information may be processed in a country with different data protection laws than your own.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
To ask a question about this policy or exercise a privacy right described above, contact us at hello@pullthiscard.com.