PullThisCard

Privacy Policy
Last updated: [DATE OF PUBLICATION]  Β·  Applies to users in the United States and Canada
Before you publish this: this policy was written to accurately describe how PullThisCard's actual code handles data today: what it stores in your browser, what it sends to Google, what it logs server-side. It has not been reviewed by a lawyer. Canada's federal privacy law (PIPEDA) and Quebec's Law 25 carry real penalties for inaccurate or inadequate privacy disclosures, and affiliate programs typically review this document specifically, so get a lawyer's review before publishing or submitting it anywhere.

1. Scope of This Policy

This Privacy Policy describes how PullThisCard (the "Service") collects, uses, and shares information when you use it, whether you're located in the United States, Canada, or elsewhere. It applies to the web application available at pullthiscard.com and the backend services that support it.

PullThisCard does not require you to create an account. There is no login, no password, and no name or email address collected by the Service itself in order to use it. Most of what makes the Service feel personalized (your saved wallet, your theme choice, custom cards you've added) lives in your own browser, not on our servers.

2. Information We Collect

Information stored in your browser (not on our servers)

The Service stores the following directly in your browser's local storage, scoped to your device and browser only:

None of this is transmitted to or stored on our servers as part of normal use of the Service. It stays in your browser unless you clear it or switch devices.

Information sent to our servers

When the Service calculates a card recommendation, your browser sends a request to our backend containing:

This request is processed to generate a recommendation and is not stored as a persistent record tied to you individually. Standard web server request logs (which may include your IP address and timestamp, generated automatically by our hosting provider) are retained only as long as our hosting provider's standard infrastructure logging practices dictate.

Location information

If you grant permission when prompted, the Service uses your browser's Geolocation API to get an approximate location, used only to improve the relevance of merchant search results (so searching "YMCA" shows nearby branches rather than ones across the country). This location:

If you decline or your browser doesn't support this, the Service works exactly as it does otherwise; merchant search simply isn't location-biased.

Information from merchant search (Google Places)

When you search for a merchant that isn't in our built-in list, your search text (and your approximate location, if you've granted permission) is sent to Google's Places API to find a match. We receive back a business name, a general category, and a Google place identifier, not any personal information about you from Google. This is covered further in Section 4.

Information collected via the browser extension

If you use the PullThisCard Chrome extension, it detects when you've reached a checkout page (using signals like the store's platform, a recognized domain, or the page's own site-name metadata) and sends the same request described above under "Information sent to our servers" β€” your wallet's card names, the detected merchant/category, and your selected country β€” to calculate a recommendation shown in an on-page banner. The extension does not read card numbers, passwords, or page content beyond these specific checkout-detection signals, and does not run analytics or tracking of any kind. A full, permission-by-permission breakdown is published separately at Browser Extension: Permissions & Privacy, so it can be kept current with the extension's actual version independent of this policy's own revision schedule.

3. How We Use Information

We use the information described above to:

We do not use this information for targeted advertising, and we do not sell personal information.

4. How We Share Information

WhoWhat's sharedWhy
Google (Places API)Your merchant search text, and your approximate location if you've granted permissionTo find and categorize the merchant you searched for
Vercel (hosting provider)Standard request data needed to serve the Service (IP address, request logs)To run the application. This is infrastructure, not a marketing relationship
Affiliate partners / card issuersNothing automatically. If you click a link to apply for a card, you leave our Service and interact directly with that company's own site, under their own privacy policy.You chose to click through to apply

We do not share information with data brokers, and we do not share information for cross-context behavioral advertising.

5. Local Storage vs. Cookies

The Service currently uses your browser's local storage (not cookies) to remember your wallet, preferences, and custom entries between visits. Local storage stays on your device and is not automatically sent to our servers the way a cookie is sent with every request.

If we add analytics or advertising features in the future that use cookies, we will update this section and provide any consent mechanism required by applicable law (including Quebec's Law 25 and Canada's broader privacy framework) before doing so.

6. Data Retention

Information stored in your browser persists until you clear your browser's site data or use a different browser/device. We don't control or have access to this.

Error reports submitted through "Report Error" are currently retained in our hosting provider's standard application logs. [UPDATE THIS SECTION once a real database/retention schedule for these reports is in place. As of this draft, there isn't a formal retention period defined beyond standard log retention.]

7. Your Privacy Rights: United States

πŸ‡ΊπŸ‡Έ If you are a California resident

The California Consumer Privacy Act (CCPA), as amended by the CPRA, gives covered businesses' customers the right to know what personal information has been collected, request deletion, and not be discriminated against for exercising these rights.

Worth being accurate about: the CCPA only applies to a business that meets at least one specific threshold: annual gross revenue over roughly $26.6 million, buying/selling/sharing the personal information of 100,000+ California consumers or households in a year, or deriving 50%+ of revenue from selling/sharing personal information. [A new, small service is unlikely to meet any of these thresholds yet, but whether the CCPA currently applies to this specific business is a factual determination based on actual revenue and user volume, and should be confirmed with a lawyer rather than assumed either way.]

Regardless of whether the CCPA's specific legal thresholds are met, the practical reality described throughout this policy still applies: the Service is built to avoid collecting directly identifying personal information in the first place, and we do not sell personal information to data brokers or third parties.

Residents of other U.S. states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, and others) have broadly similar rights, generally subject to similar size/volume thresholds under their respective state laws. [Confirm exact applicable state laws and thresholds with a lawyer.]

8. Your Privacy Rights: Canada

πŸ‡¨πŸ‡¦ PIPEDA (federal)

The Personal Information Protection and Electronic Documents Act (PIPEDA) gives you the right to know why your personal information is collected, to access information we hold about you, and to challenge its accuracy. As described above, the Service is built to minimize the personal information it collects in the first place, and most user data is held locally in your browser rather than on our servers.

If you are a Quebec resident (Law 25)

Quebec's Law 25 applies to any business of any size that collects, uses, or discloses personal information of people in Quebec. Unlike some U.S. state laws, there is no revenue or company-size exemption. Because the Service is available to Quebec residents, Law 25 likely applies to it regardless of how small the operation is. This means, in addition to the rights above:

[A Quebec-facing privacy policy should be reviewed specifically for Law 25 compliance, including the Privacy Officer designation above, which needs to name a real person before this page is published, and whether a French-language version is required for your situation. French-language UI for the app itself is on the project roadmap but not yet built.]

9. Children's Privacy

The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us using the details in Section 13 so we can address it.

10. Data Security

We take reasonable measures to protect information transmitted to and processed by the Service, including using HTTPS encryption for all traffic. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Cross-Border Data Transfers

Our hosting infrastructure and the third-party services we use (including Google's Places API) may process data on servers located outside of your own country, including in the United States, regardless of whether you are accessing the Service from the U.S. or Canada. By using the Service, you acknowledge that your information may be processed in a country with different data protection laws than your own.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

13. Contact / How to Exercise Your Rights

To ask a question about this policy or exercise a privacy right described above, contact us at hello@pullthiscard.com.