Privacy Policy

Last updated: 22 September 2026

This policy explains what PriceBit (“the Service”) does with personal data. The controller is [legal entity name], [registered address], reachable at office@pricebit.eu.

What we hold

Your account. Your name, email address, a hash of your password (or none at all, if you only ever sign in through a provider), your chosen language, when you registered and when you last signed in.

Company accounts. If you register as a company: the company name, its country, and its VAT and registration numbers where you give them.

Teams. Who belongs to which team and in what role, and the email addresses of people invited but not yet joined.

Carts. The shopping lists you keep in the Service: each cart's name, the country it is for, and the products and shop listings you put in it with their quantities. They are yours alone - no other account, and no administrator, can see them - and they are deleted with your account.

Security. If you turn on two-factor authentication, its secret and your recovery codes, both encrypted. API tokens are stored hashed, not in a form we can read back. Your active sessions, with the IP address and browser they were started from, so you can review and end them. We also keep a history of sign-ins to your account - when each happened, whether it used a password, a passkey or a linked provider, and the IP address and browser the request carried - so that access to an account can be reviewed after the fact. It is visible only to our administrators. When your account is signed into from an address and a kind of browser it has not been signed into from before, we tell you - in the application and by email, whatever your email alerts setting - so that you can act on it if it was not you.

Administrator access to your account. Our administrators can sign in as your account in order to see what you see - to reproduce a fault you report, or to answer a question about your own screens. While they do, the Service behaves for them exactly as it does for you: they can see everything you can see and do everything you can do, including changing your details and setting a new password for the account without knowing the current one. Every such period is recorded - which administrator, whose account, when it began and ended, and the IP address and browser their request carried - and that record is what makes those actions attributable to them rather than to you. You can ask us at any time whether your account has been entered this way, and by whom.

Messages you send us. If you use the contact form we keep what you wrote - your name, your email address, the subject and the message - together with our reply, so the conversation stays readable. Alongside it we record how the message reached us: the IP address the request came from, the browser's user-agent string, the page you sent it from, the language your browser asked for, and any forwarding headers the request carried. We keep that to tell one sender from another, to recognise repeat abuse, and to spot messages sent by scripts rather than by people. It is visible only to our administrators.

Files uploaded by administrators. Our administrators can upload a logo for each retailer we track. Those images are stored on our own servers and served publicly to anyone using the Service - they are pictures of shop brands, not of people, and nothing you upload about yourself is stored anywhere: the Service has no profile picture upload. What appears beside your name is your initials, drawn by us - or, if you sign in with a provider such as Google, the profile picture you have there, which we copy onto our own servers when you sign in (see Sign-in providers below). Either way it is served by us: your browser never requests a picture of you from anybody else.

We do not ask for payment details, and we do not profile you or make automated decisions about you.

Why we hold it

  • To provide the Service and the account you asked for - performing our contract with you.
  • To keep accounts secure: signing in, verifying your address, two-factor authentication, and the sign-in and session records above - our legitimate interest in protecting the Service and your account.
  • To support you and to keep the Service working: an administrator signing in as your account, and the record kept of it - our legitimate interest in diagnosing faults, and yours in that access being accountable.
  • To answer messages you send us, and to keep the contact form usable: the technical details recorded with a message are our legitimate interest in telling senders apart and in refusing automated abuse.
  • To meet legal obligations, such as retaining company and VAT details where accounting rules require it.

Cookies and browser storage

We sell nothing to anybody. The pages you can read may show advertising served by Google AdSense, which uses cookies, and we measure how the Service is used; both are described below with the rest.

What we cannot do without. These are set whatever you choose, because without them the Service does not work or does not do what you just asked it to.

  • Session cookie - keeps you signed in. Essential; the Service cannot work without it.
  • Security token - a cookie that protects forms you submit from being sent by another site on your behalf.
  • Language cookie - set only when you pick a language, so the first page of your next visit is already in it. Encrypted, httpOnly, and kept for a year.

What we ask about. The first time you arrive we ask whether we may remember your preferences on this device: the theme you chose, whether the menu is a narrow rail, and which menu groups you left open. They are kept in your browser's local storage, belong to the device rather than the account, and are never sent to us.

The same answer governs Google Analytics and Google AdSense, both described under Others who receive data below: decline, and neither script is loaded and neither sets its cookies.

If you decline, we stop writing them and delete any we already had, and the Service simply forgets those choices between visits. Your answer itself is kept in the same storage - it is the only way to honour it, and to stop asking you every time.

Others who receive data

Google Analytics. On the pages anybody can reach and on your own pages as a reader - never in the administrator area - the Service loads Google's gtag.js and reports which pages were viewed. Google therefore receives your IP address, the page you are on, and a random identifier they store in cookies on your device (_ga and one named for our property). We use it to see which pages are worth keeping and which are never found; we do not use it for advertising, and we ask for no report that identifies anybody. It is loaded only if you have not declined the question described above, and declining also stops the cookies being set at all. You can opt out at any time through that answer, or with Google's own browser add-on.

Google AdSense. On the same pages - never in the administrator area - the Service loads Google's AdSense script so that Google can show advertising. Google therefore receives your IP address, the page you are on and what browser you use, and stores cookies on your device to show ads, measure them and limit how often you see the same one; where the law and your choices allow, it may use them to show ads based on your interests. We do not send Google your account, what you search for or what you follow, and we do not choose which ad you see. It is loaded only if you have not declined the question described above. How Google uses this data is set out at policies.google.com/technologies/partner-sites, and you can turn off personalised ads at adssettings.google.com.

Sign-in providers. If you choose to sign in with a provider such as Google, we receive your name, email address, whether the provider has verified it, and the address of the profile picture you have with them. We fetch that picture once, from our server, store a copy on our own servers and show it as your avatar; we fetch it again only when you have changed it at the provider. It is kept while your account exists and deleted when your account is removed permanently. We do not receive your password, and we ask for nothing else.

Email delivery. Messages such as address verification, password resets and team invitations are sent through OneSignal, Inc. in the United States, who processes the recipient address and the message.

Shops, through their product pictures. A price we list is shown with a picture of the product. Where we have chosen a picture ourselves it comes from our own servers; otherwise it is the picture the shop publishes, and your browser fetches it directly from the shop, or from the service the shop uses to host its pictures. That happens on the home page, on every page that lists prices, and in a price alert email if your mail client loads its images. Like any image request it carries your IP address and what browser you use; we tell your browser not to add our website's address to it. We send the shop nothing else - not your account, and not what you searched for or follow. What the shop or its provider does with the request is set out in their own privacy policies, not ours.

Hosting. The Service and its database run on infrastructure provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in their data centres in Germany. Everything we hold is therefore stored inside the European Union; the others named above receive only what is described against each of them.

We do not sell personal data.

Data sent outside the European Union

Everything we hold ourselves stays in the European Union, on the servers described above. Two of the companies named in the section above are in the United States - Google and OneSignal - so the data described against each of them is transferred there.

A shop's product picture can also be fetched from outside the European Union, because that is where the shop keeps it: several shops use picture services run by companies outside the European Union, most of them in the United States, and the shops in Serbia serve theirs from Serbia. Your browser then sends the request described under Shops, through their product pictures to that country directly. We pass nothing to those services ourselves.

Both transfers rely on the EU-U.S. Data Privacy Framework, the European Commission's adequacy decision for organisations that have certified under it. We checked each against the U.S. Department of Commerce's public list rather than taking the company's word for it, and both certifications were active when this policy was last updated:

  • Google LLC - certified, covering the products and services it supplies, valid to 13 September 2027.
  • OneSignal - certified, covering the messaging platform we send mail through, valid to 3 March 2027.

You can look either of them up yourself at dataprivacyframework.gov, and you can ask us for a copy of what we relied on.

If that framework is ever withdrawn or a certification lapses, we will move the transfer onto another lawful basis or stop making it, and we will say so here. That is not a remote possibility: the framework replaced two earlier arrangements that were struck down, and it is itself under appeal before the Court of Justice.

How long we keep it

Account data is kept while the account exists.

Deleting your account hides it and the teams it owns; both can be restored for [retention period] on request, after which they are removed permanently. Two consequences are deliberate: API tokens are revoked immediately and permanently, and your email address stays reserved so that a new account cannot be attached to the old one's history. Reserving the address means we keep it after deletion - that is the trade-off, and if you would rather it were erased entirely, write to us.

Messages sent through the contact form, and the technical details recorded with them, are kept for [message retention period] after the conversation is closed, and then deleted.

The sign-in history, and the record of administrators signing in as your account, are kept for 180 days, and then deleted. Notifications you have read are deleted 90 days after you read them; unread ones stay until you read or delete them.

Sessions expire on their own, and you can end them yourself from your profile page.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or export it, and you can object to processing we base on legitimate interests. Most of it you can do yourself: your profile page lets you change your name and address, change your password, review sessions and delete your account.

Write to office@pricebit.eu and we will respond within [response period]. If you are not satisfied you may complain to [supervisory authority].

Security

Passwords are hashed, never stored in a readable form, and checked against known breached-password lists when set. API tokens are stored hashed. Two-factor secrets and recovery codes are encrypted. Traffic is served over HTTPS.

Signing in as another account is limited to administrators, is never possible for another administrator's account, and always leaves the record described above.

No service can promise perfect security, but if a breach affects your data we will tell you and the relevant authority as the law requires.

Children

The Service is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

We may update this policy. If a change materially affects you we will tell you by email, or in the Service, before it takes effect.

Contact

[legal entity name] [registered address] office@pricebit.eu