Privacy Policy
This Privacy Policy ("Policy") explains what information Refunduly ("Refunduly," "we," "us," "our") collects, how we use, share, protect, and retain it, how long we keep it, and the rights and choices you have. It applies to the Refunduly website, web application, progressive web app, notification emails, and related services (together, the "Service").
The Service is offered only to residents of the United States and Canada.
The short version: we collect your account details and the order information you choose to connect, and we use them to find you refund and price-drop opportunities. We do not sell or rent your personal information, we do not show you ads, and we do not disclose your personal information to advertisers or data brokers.
KEY POINTS — PLEASE READ
WE READ THE ORDER EMAIL YOU SEND US. That is the product. Section 7 sets out exactly what happens to every message, including what we delete and when.
PLEASE DO NOT SEND US SENSITIVE INFORMATION. Section 4 explains what not to forward and what happens if you do. You are responsible for what you choose to send us.
WE MAY USE INFORMATION COLLECTED THROUGH THE SERVICE TO DEVELOP AND TRAIN MODELS AND ALGORITHMS (SECTION 5.8), AND WE MAY CREATE, USE, AND LICENSE DE-IDENTIFIED AND AGGREGATE INFORMATION, INCLUDING ON COMMERCIAL TERMS (SECTIONS 5.9 AND 9.5). De-identified and aggregate information does not identify you, and we do not attempt to re-identify it.
THIS POLICY MAY CHANGE, AND CHANGES TAKE EFFECT WHEN POSTED (SECTION 18).
THIS POLICY FORMS PART OF OUR TERMS OF SERVICE. The Terms govern your use of the Service. The disclaimers in Terms Section 24 and the limitations of liability in Terms Section 25 apply to claims arising under this Policy to the fullest extent the law permits. If you reside in the United States, Terms Section 29 requires most disputes — including disputes about this Policy — to be resolved by individual arbitration, and waives your right to a jury trial and to participate in a class action. If you reside in Canada, Terms Section 29.10 carves you out of those provisions.
Contents
- Scope — What This Policy Covers
- Definitions
- Information We Collect
- Information You Should Not Send Us
- How and Why We Use Information
- What We Do Not Do
- Email Content: Exactly What Happens to It
- Google User Data
- Who We Share Information With
- Where Your Information Is Processed
- Security
- Retention and Deletion
- Your Rights and Choices
- Email, Notifications, and Communications
- Cookies and Similar Technologies
- Children
- Automated Processing
- Changes to This Policy
- Contact and Accountability
- Additional Information for Canadian Residents
1. Scope — What This Policy Covers
1.1 What this Policy covers. This Policy covers the Service: the Refunduly website and marketing pages, the web application and progressive web app, the email intake address we assign to your account, our notification and digest emails, and any successor or additional service we make available under our Terms of Service.
1.2 What this Policy does not cover. This Policy does not apply to:
- Retailers. Amazon, Best Buy, and any other merchant, marketplace, or seller you buy from. Your relationship with them, including anything you do with your account there in response to something the Service shows you, is governed by their terms and their privacy policies.
- Third-party websites and services that we link to, that link to us, or that you reach from the Service, including any product page, checkout page, or retailer help page. We do not control them, we are not responsible for their practices, and your use of them is at your own risk.
- Your email provider. Gmail, Outlook, and any other mail service you use to forward messages to us handle your mail under their own policies, before and after anything reaches us.
- Payment processing by Stripe. Stripe collects and processes your payment details directly, as its own controller, under its own privacy policy. We never receive your card number.
We encourage you to read the privacy policies of any third party whose services you use.
1.3 Who is responsible. Refunduly is the business that operates the Service and is the party responsible for the personal information described here — the "data controller," or the equivalent term under the law that applies to you. Our contact details are in Section 19.
1.4 Where the Service is offered. The Service is offered only to residents of the United States and Canada. We do not offer it to, target it at, market it to, or knowingly serve users located in the European Union, the European Economic Area, the United Kingdom, Switzerland, or anywhere else. If you access the Service from outside the United States or Canada, you do so on your own initiative, at your own risk, and you are responsible for compliance with any local law — see Terms Section 3.4.
1.5 No admission of applicability. We provide the disclosures in this Policy, and honor the rights described in it, in the interest of transparency and as a matter of good practice. Nothing in this Policy is, or should be construed as, an admission, acknowledgment, or representation that any particular privacy or data-protection statute applies to Refunduly, or that Refunduly meets any applicability or jurisdictional threshold under any such statute — whether that threshold is based on revenue, on the number of consumers whose information is processed, on revenue derived from selling or sharing personal information, or on anything else. We reserve all rights, defenses, and objections available to us under applicable law, including the right to assert that a given statute does not apply to us, to a particular individual, or to a particular processing activity. Where a statute does apply, the rights and disclosures in this Policy are provided only to the extent of, and subject to every exemption and limitation in, that statute.
2. Definitions
- "Account" means the account you register to access the Service.
- "Applicable Law" means the laws, regulations, and rules that apply to you or to us in connection with the Service.
- "De-identified Information" means information that does not identify, and cannot reasonably be linked, directly or indirectly, to you or to any household or device, including aggregate statistics derived from information about many users.
- "Intake Address" means the unique email address we assign to your Account for receiving forwarded order email.
- "Order Data" means order and purchase information you connect to the Service, whether by forwarding email to your Intake Address or, where offered, by connecting an email account, together with anything we extract or derive from it.
- "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you — or as Applicable Law otherwise defines that term or the equivalent term "personal data" or "personal information." Personal Information does not include De-identified Information or aggregate information.
- "Processor" means a service provider that processes Personal Information on our behalf and on our instructions.
- "Sensitive Information" means the categories of information that Applicable Law treats as sensitive or as a special category — including government identification numbers, financial account and payment card numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, health and medical information, genetic and biometric data, and information about sex life or sexual orientation.
- "Service" has the meaning given in the introduction.
3. Information We Collect
We collect different information depending on how you use the Service. For each category below we state what we collect and why.
3.1 Visitors to our website. If you browse our marketing pages without an Account, we collect technical information automatically — your IP address, browser type and version, operating system, the pages you request, referring page, and timestamps — in server and network logs, together with any strictly necessary cookies described in Section 15.
Why: to serve the site, keep it secure, detect and prevent abuse, and diagnose errors.
3.2 Information you give us directly. If you contact us — by email, through a support request, or by replying to one of our messages — we collect what you choose to put in the message, including any Personal Information in it, and our reply.
Why: to answer you, to keep a record of the request, and to establish, exercise, or defend legal claims.
3.3 Account information.
- If you sign in with Google: your name, email address, and profile picture, via Google's basic sign-in scopes only (
openid,email,profile). - If you sign up with email and password: your email address and a cryptographically hashed password — we never store, and can never see, the password itself — plus email-verification and password-reset tokens, which are stored only as hashes, are single-use, and are short-lived.
- In either case: your Account identifier, your plan, your notification preferences, and your Intake Address.
Why: to create and operate your Account, authenticate you, verify your email address, let you reset your password, and manage your Intake Address.
3.4 Order information — only through methods you actively set up.
- Email forwarding (default): order-related emails you forward, or auto-forward, to your Intake Address. From these we extract structured Order Data: item name, price, quantity, order number, retailer, product URL or identifier, purchase date, and — from later retailer emails — return, refund, and cancellation status. Section 7 describes exactly what happens to the message itself.
- Gmail connection (optional, where offered): if you explicitly connect a Gmail account, we detect order-confirmation emails automatically using a restricted Google API scope. The OAuth refresh token we receive is stored encrypted. See Sections 8 and 11.
Why: to detect your orders and monitor them for refund and price-drop opportunities — the core function of the Service.
3.5 Price-tracking data. Current and historical prices for the products in your orders, obtained from third-party price-data providers using product identifiers only (for example, a product's ASIN). No Personal Information is sent to those providers.
Why: to detect price drops and calculate what a refund, price adjustment, or return-and-rebuy would be worth.
3.6 Payment information. If you subscribe to Pro, Stripe collects and processes your payment details directly. We receive and store only a Stripe customer reference, your subscription status, plan, and billing dates. We never receive or store your card number.
Why: to take payment for Pro, manage renewals and cancellations, and keep the tax and accounting records the law requires.
3.7 Usage, device, and technical data. Sign-in session data held in cookies; IP address, browser, and request information in server logs; in-app notification state; your notification preferences; error and crash reports; and, where we have enabled product analytics, events describing which pages you viewed and which features you used. Error reports are tied to your internal Account identifier only — not your name or email address — and our error-reporting pipeline strips credentials and tokens before an event leaves our systems.
Why: to operate and secure the Service, detect and prevent abuse, diagnose and fix errors, and understand in aggregate how the Service is used so we can improve it.
3.8 Information from third parties. We receive: your basic profile from Google if you use Google sign-in; subscription and payment status from Stripe; delivery, bounce, and complaint events from our email provider; and product and price data from price-data providers. We do not buy Personal Information from data brokers, and we do not enrich or append to your profile from commercial data sources.
4. Information You Should Not Send Us
Because you decide what email reaches your Intake Address, this section matters. Read it before you set up forwarding.
4.1 Do not send us Sensitive Information. We do not need, want, or ask for Sensitive Information, and the Service does not extract it. Please do not forward, upload, or otherwise send us any Sensitive Information, and please do not set up a forwarding rule broad enough to sweep it in. If Sensitive Information nevertheless reaches us inside an email you send, we do not extract it, we do not build records from it, we do not use or disclose it for any purpose that would give rise to a right to limit its use under Applicable Law, and it is deleted on the schedule in Sections 7 and 12 along with the rest of the message. You send us such information at your own risk, and to the fullest extent the law permits we are not responsible for it.
4.2 Do not send us other people's information. An order email may incidentally mention someone other than you — a gift recipient's name and shipping address, for example. We do not extract, use, or build records from that information; it exists only inside raw email content and is deleted on the schedule in Sections 7 and 12. Please do not forward emails containing other people's orders.
4.3 Your representations about what you send. By forwarding email to your Intake Address, connecting a mail account, or otherwise submitting content to the Service, you represent and warrant, each time, that: (a) you are the intended recipient of that content or are otherwise entitled to possess and disclose it; (b) you have the right to send it to us and to have us process it as this Policy describes; and (c) doing so does not breach any law, contract, confidentiality obligation, or third-party right. You are responsible for what you send us and, as set out in Terms Section 26, for claims arising from it.
4.4 Mail sent to your Intake Address by others. Your Intake Address is a credential — anyone who has it can send mail to it. Mail that arrives at your Intake Address is processed as content associated with your Account, whoever sent it, and it is your responsibility to keep the address confidential and to tell us promptly if it is exposed. We can rotate it on request. See Terms Sections 4.3 and 9.4.
4.5 We may refuse, quarantine, or discard. We may quarantine, decline to process, or delete any message sent to the Service — including any message that fails an authenticity check, appears to be spam or an attack, is disproportionately large or frequent, or that we reasonably believe should not have been sent to us. We are under no obligation to process, store, retain, or return any message, and to the fullest extent the law permits we are not liable for declining to.
5. How and Why We Use Information
We use the information described in Section 3 for the purposes below.
5.1 Providing the Service. To detect your orders, track prices, identify refund, price-adjustment, price-match, and return-and-rebuy opportunities, calculate what an opportunity is worth, and show it to you.
5.2 Notifying you. To send in-app notifications and, according to your settings, alert emails, digest emails, and — if you enable it and where the feature is available — push notifications.
5.3 Running your Account. Sign-in, session management, email verification, password reset, Intake Address management, and support.
5.4 Billing. To process Pro subscriptions, renewals, cancellations, and refunds through Stripe, and to keep tax and accounting records.
5.5 Security, integrity, and abuse prevention. To authenticate inbound email, detect and investigate fraud, abuse, scraping, automated access, and violations of our Terms, protect the Service and its users, and enforce our Terms and this Policy.
5.6 Diagnostics and improvement. To identify and repair errors, monitor performance, understand in aggregate how the Service is used, test changes, and develop new features, products, and services.
5.7 Legal and business purposes. To comply with Applicable Law; to respond to lawful requests, subpoenas, court orders, and regulatory investigations; to establish, exercise, or defend legal claims; to resolve complaints and disputes; to enforce our agreements; and to evaluate, negotiate, or complete a corporate transaction of the kind described in Section 9.4.
5.8 Model and algorithm development. We may use information collected through the Service — including Order Data, email content, price data, and usage data — to develop, train, test, evaluate, and improve the models, algorithms, parsers, classifiers, and other software used to operate and improve the Service and to build new features. Two limits apply and are not discretionary:
- Google data is excluded. Information obtained through Google APIs, including anything obtained through a Gmail connection, is not used to develop, improve, or train generalized artificial-intelligence or machine-learning models, and is used only as Section 8 and the Google API Services User Data Policy permit. Where those rules and this Section 5.8 conflict, Section 8 controls.
- We do not disclose your email content or Order Data to any third party for that third party's own model training.
5.9 De-identified and aggregate information. We may create De-identified Information and aggregate statistics from information collected through the Service — for example, how many orders the Service monitors, how often a price drop is detected, average savings by retailer or product category, or how prices move over time — and we may use, publish, disclose, and license that information to third parties, including on commercial terms we determine, for any lawful purpose and without restriction. In doing so we commit, and require our recipients to comply, as follows:
- we take reasonable measures to ensure De-identified Information cannot be associated with, or reasonably linked to, you, your household, or your device;
- we maintain and use it only in de-identified form, and we do not attempt to re-identify it, except solely to test that our de-identification works; and
- we contractually require any recipient to maintain it in de-identified form, not to attempt re-identification, and not to disclose it onward except on the same terms.
De-identified Information and aggregate information are not Personal Information, and disclosing them is not a sale or sharing of Personal Information.
6. What We Do Not Do
These commitments are stated precisely; read them together with Sections 5.8 and 5.9.
- We do not sell or rent your Personal Information — to anyone, in any form. We have not sold Personal Information.
- We do not show you ads, and we do not disclose your Personal Information to advertisers, ad networks, or data brokers.
- We do not "share" your Personal Information for cross-context behavioral advertising, as the California Consumer Privacy Act defines that term.
- We do not disclose your Personal Information to retailers or to price-data providers.
- We do not use your email content or Order Data for marketing, advertising, advertising attribution, or advertising analytics — ours or anyone else's. Nothing we learn from your email is used to decide what to market to you or to anyone else.
- We do not profile you, score you, rank you, or infer characteristics about you, and we do not collect Personal Information for the purpose of drawing such inferences.
- We do not read your inbox. We receive only what you forward to your Intake Address or, if you connect a mail account, what a restricted scope matches.
- We do not store your card number, and we do not store your password in plaintext — ever.
7. Email Content: Exactly What Happens to It
Because reading your order email is the heart of the Service, here is the whole pipeline.
7.1 Authentication. Every message arriving at your Intake Address is checked for authenticity, including sender verification, and matched to your Account by the Intake Address itself. Messages that fail authenticity checks are quarantined and are not processed into your Account.
7.2 If we can parse it as an order, refund, or cancellation email: we keep the extracted structured Order Data described in Section 3.4 and delete the raw email content.
7.3 If it looks like a receipt but is from a retailer we cannot parse yet: we keep the raw content encrypted, for up to 30 days, solely so that we can import your order if we add support for that retailer. After 30 days it is permanently deleted.
7.4 If it is not order-related: we keep only minimal metadata — sender, subject, timestamp, and outcome — for abuse prevention and troubleshooting. The content is not retained.
7.5 Human access. We do not routinely read your email content. A person may access it only where you have asked us to (for example, to debug a message that failed to import), where it is necessary to investigate a security incident or suspected abuse, or where Applicable Law requires it. Where you connect a Google account, the stricter rules in Section 8 apply instead.
8. Google User Data
8.1 Limited Use. Refunduly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
8.2 What that means here. For data accessed through the optional Gmail connection:
- Strict scope. We use it only to detect order-related emails and to provide the features described in this Policy, and we extract only what the Service needs — retailer, item, price, quantity, order number, product identifier, purchase date, and return, refund, and cancellation status. We do not read or extract personal, non-commercial correspondence.
- No human access. We do not allow anyone to read it, except with your explicit permission, for security purposes, to comply with Applicable Law, or where the data has been aggregated and is used for internal operations.
- No advertising, and no generalized model training. We do not use it to serve or target advertising, and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.
- No onward transfer. We do not transfer it to anyone except as necessary to provide or improve those features, to comply with Applicable Law, or as part of a merger, acquisition, or sale of assets with your explicit prior consent.
8.3 No generalized model training. We do not use data obtained through Google APIs to develop, improve, or train generalized artificial-intelligence or machine-learning models. This limit overrides Section 5.8 and is not subject to change by any other part of this Policy.
8.4 Disconnecting. You can disconnect a Gmail connection at any time in the app, or revoke our access at myaccount.google.com/permissions. Revoking access stops future collection; it does not by itself delete Order Data already extracted — use the deletion path in Section 12.3 for that.
9. Who We Share Information With
9.1 Processors. We disclose Personal Information to service providers that help us run the Service, bound by confidentiality and data-protection obligations, only for the purposes we specify, and only to the extent their function requires:
| Provider | Function | What they handle |
|---|---|---|
| Render | Application and database hosting | All service data, encrypted as described in Section 11 |
| Stripe | Payments | Your payment details, collected by them directly; subscription status |
| Resend | Email infrastructure | Inbound intake email, transiently; outbound notification email |
| Sign-in; optional Gmail connection | OAuth identity; Gmail data if you connect it | |
| Keepa | Price data | Product identifiers only — no Personal Information |
| Sentry | Error monitoring | Error reports carrying an internal Account identifier only |
| PostHog | Product analytics, where enabled | Usage events |
| Cloudflare | Marketing-site hosting and network | Website traffic metadata |
We may add, replace, or remove providers. Where we do, we update this table in a new version of this Policy.
9.2 Legal, regulatory, and protective disclosure. We may disclose information, including Personal Information, to the extent Applicable Law permits: in response to a subpoena, court order, warrant, or other legal process; at the request of a government or regulatory authority conducting an investigation; where we believe in good faith that disclosure is necessary or appropriate to comply with Applicable Law, to enforce our Terms or this Policy, to detect or prevent fraud, abuse, or a security incident, to establish, exercise, or defend legal claims, or to protect the rights, property, life, health, security, or safety of Refunduly, our users, or any third party. Where we are legally permitted and it is practicable to do so, we will tell you before we disclose.
9.3 Between us and you. Nothing in Section 9.2 obliges us to contest a legal process on your behalf, and we are not liable for a disclosure made in good-faith reliance on it.
9.4 Business transfers. If Refunduly is involved in a merger, acquisition, financing, reorganization, bankruptcy, insolvency, receivership, sale of assets, or any similar transaction — including during confidential negotiations for one — information we hold, including Personal Information, may be disclosed, transferred, or assigned as part of it, and may become an asset of the acquirer. The acquirer will be required to handle Personal Information in accordance with this Policy or to give you prior notice of materially different practices. See Terms Section 31.3.
9.5 De-identified and aggregate information. We may disclose and license De-identified Information and aggregate statistics to third parties as described in Section 5.9, including on commercial terms. This is not a disclosure of Personal Information.
9.6 At your direction. We disclose information to a third party where you tell us to.
10. Where Your Information Is Processed
Our providers process data in the United States. If you are in Canada, your information will be transferred to, stored in, and processed in the United States, where privacy laws differ from Canadian law and where your information may be accessible to United States courts, law enforcement, and national-security authorities under the law of that country. By using the Service you consent to that transfer. We select providers with recognized security practices regardless of where they operate, and we require them by contract to protect the information they handle for us.
11. Security
11.1 What we do. We maintain administrative, technical, and physical measures designed to protect information within our systems, including:
- Encryption in transit — all connections to the Service use TLS.
- Encryption at rest — OAuth refresh tokens and retained raw email content are encrypted with AES-256-GCM.
- Password hashing — passwords are hashed with scrypt, a modern, deliberately slow password-hashing algorithm. Verification and reset tokens are stored only as SHA-256 hashes and are single-use and short-lived.
- Access control — access to production systems and data is restricted to those who need it.
- Log and error hygiene — internal identifiers, not names or email addresses, are used in error reports, and credentials and tokens are stripped before an error event leaves our systems.
- Webhook authentication — inbound webhooks are signature-verified before any payload is parsed or stored.
11.2 No guarantee. No method of transmission over the internet and no method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your information, we cannot and do not guarantee, warrant, or ensure that unauthorized access, disclosure, alteration, or loss will never occur, and to the fullest extent the law permits we disclaim liability for it. See Terms Sections 18, 24, and 25.
11.3 Your responsibilities. The security of your information depends in part on you. You are responsible for keeping your password and your Intake Address confidential, for using a strong and unique password, for the security of the devices, browsers, and email accounts you use to reach the Service, and for telling us promptly at legal@refunduly.com if you believe your Account or Intake Address has been compromised. We are not responsible for a compromise that results from your failure to do so.
11.4 Breach notification. If a breach of security affecting your Personal Information occurs, we will notify you and the relevant authorities to the extent and within the time Applicable Law requires — including the breach-of-safeguards rules under Canada's Personal Information Protection and Electronic Documents Act and applicable United States state breach-notification statutes — without unreasonable delay. Providing that notification is the full extent of our obligation to you in respect of a breach, except as Applicable Law otherwise requires.
12. Retention and Deletion
12.1 How long we keep things.
| Data | Kept for |
|---|---|
| Structured order, price, and refund data | While your Account is active |
| Raw parsed emails | Deleted after parsing |
| Unparsed receipt-like emails (encrypted) | Up to 30 days, then deleted |
| Non-receipt email content | Not retained (metadata only) |
| Verification and reset tokens | Hours (single-use), then deleted |
| Server logs and error reports | Rotated on a short schedule by our providers |
| Billing records | As long as tax and accounting law requires |
12.2 When we keep things longer. Notwithstanding the table above, we may retain information for as long as is reasonably necessary, and Applicable Law permits, to: comply with a legal, regulatory, tax, audit, or accounting obligation; establish, exercise, or defend a legal claim, including where we reasonably anticipate litigation or a dispute; respond to or document a complaint, request, or regulatory inquiry; preserve information subject to a legal hold or lawful preservation request; maintain records of fraud, abuse, security incidents, and terminated or suspended Accounts so that we can prevent recurrence; and keep the records necessary to demonstrate our own compliance with this Policy. In determining an appropriate period we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, whether those purposes can be achieved by other means, and applicable legal requirements.
12.3 Deleting your Account. Email legal@refunduly.com from your Account email address and we will delete your Account — including your orders, price history, connected email sources, retained inbound email content, and notification history — except for information covered by Sections 12.2 and 12.4. We act on deletion requests within the time Applicable Law requires. Deletion is permanent and cannot be reversed, and we cannot restore information once it has been deleted.
12.4 Backups. Deleted information may persist in encrypted backups for a period after it is removed from live systems, until those backups are rotated out on their normal schedule. Backups are not used to restore individual Accounts and are not used to answer access requests, and information held in them is not otherwise processed.
12.5 We may delete information. We may delete information from our systems, without notice to you, once we determine it is no longer necessary for the purposes described in this Policy. We do not undertake to store your information indefinitely, and — except where Applicable Law requires otherwise — we are not liable for the deletion or loss of any information. Keep your own copies of anything you need.
13. Your Rights and Choices
13.1 Your rights. Depending on where you live, you may have the right to:
- access the Personal Information we hold about you and obtain a copy of it;
- know what we collect, use, disclose, and retain — this Policy is that disclosure;
- correct inaccurate or incomplete Personal Information;
- delete your Personal Information (Section 12.3);
- port your Personal Information to another party, in a structured, commonly used, machine-readable format, where the right applies and it is technically feasible;
- withdraw consent to optional processing — for example, by disconnecting a mail account or unsubscribing from non-essential email;
- opt out of the sale or sharing of Personal Information, of targeted advertising, and of profiling with legal or similarly significant effects. As Section 6 explains, we do none of those things, so there is nothing to opt out of; and
- not be discriminated against for exercising any of these rights. We do not deny anyone goods or services, charge different prices, or provide a different level of quality because they exercised a privacy right.
13.2 How to make a request. Email legal@refunduly.com from your Account email address, describing what you want.
13.3 Verification. We will ask you to verify control of the Account before we act, and we may require information that matches what we already hold. We may decline a request we cannot verify, and we may decline a request where Applicable Law permits or requires us to.
13.4 Limits on requests. So that we can handle requests fairly and securely:
- We may decline or charge a reasonable fee for a request that is manifestly unfounded, excessive, repetitive, or unreasonably burdensome, where Applicable Law permits.
- We may limit how often you may exercise a right, to the extent Applicable Law permits — for example, twice in any twelve-month period for access requests under the California Consumer Privacy Act.
- We may be unable to provide all of the information requested, or to act on part of a request, where doing so would compromise the security or integrity of the Service, reveal a trade secret or confidential commercial information, disclose another person's information, or conflict with a legal obligation. Where we decline, we will tell you why.
- Following a deletion request, we may retain information as described in Sections 12.2 and 12.4, including records of the request itself, for audit and record-keeping purposes.
Otherwise, we do not charge for these requests, and we respond within the time Applicable Law requires.
13.5 Authorized agents. You may use an authorized agent to make a request on your behalf where Applicable Law allows. We may require written authorization signed by you, proof of the agent's authority, and verification of your own identity directly with us, and we may deny a request from an agent who does not provide it.
13.6 Appeals. If we deny a request and the law of your state or province gives you a right to appeal, you may appeal by replying to our decision with "Privacy Rights Appeal" in the subject line and enough information for us to identify the original request and the basis for the appeal. We will review and respond within the statutory period. If we deny the appeal, we will tell you how to complain to your Attorney General or other regulator.
13.7 Regulators. If you are unsatisfied with our response, you may contact your privacy regulator — in Canada, the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information for Quebec residents; in the United States, your state Attorney General. We ask, as a courtesy, that you raise the issue with us first.
14. Email, Notifications, and Communications
14.1 Service messages. Messages that are part of providing the Service you signed up for — order detected, price-drop alert, deadline reminder, email verification, password reset, security notices, billing and receipt messages, and administrative announcements — are sent because you have an Account. Alert and digest emails can be turned off in Settings → Notifications. We reserve the right to send you service-related and administrative messages that you cannot opt out of, for as long as you have an Account. If you do not wish to receive them, close your Account under Section 12.3.
14.2 Marketing and product updates. Promotional email and product-update email are sent only with your express opt-in — the toggle is off by default. Every such message carries a working unsubscribe link, which we honor promptly, consistent with CAN-SPAM and Canada's Anti-Spam Legislation. You may also unsubscribe by emailing legal@refunduly.com. It may take a short time for an opt-out to take effect across our systems.
14.3 Push and in-app notifications. Where the feature is available and you enable it, we send push notifications to a device you have permitted. You can revoke that permission at any time in your browser or device settings, or turn the notifications off in Settings → Notifications.
14.4 Delivery. We use a third-party email provider and cannot guarantee that any message will be delivered, delivered on time, or not filtered as spam. See Terms Sections 7 and 19.
15. Cookies and Similar Technologies
15.1 What they are. Cookies are small text files placed on your device by a website. Related technologies include pixel tags and web beacons — small images used, usually with cookies, to record that a page or message was opened. In this Policy "cookies" covers all of them.
15.2 What we use.
| Category | What it does | Can you turn it off? |
|---|---|---|
| Strictly necessary | Keeps you signed in, maintains your session, and protects against cross-site request forgery and other attacks. The Service does not work without these. | No |
| Functional | Remembers preferences and interface choices. | Yes, in your browser — some features may then behave inconsistently |
| Analytics | Where we have enabled product analytics, tells us which pages and features are used, so we can improve them. Not used for advertising. | Yes, in your browser |
15.3 What we do not use. We do not use advertising cookies, cross-site tracking cookies, or third-party advertising pixels, and we do not permit third parties to collect information about your activity across other sites through the Service.
15.4 Managing cookies. Most browsers accept cookies by default; you can change that in your browser settings, and you can delete existing cookies at any time. If you block strictly necessary cookies you will not be able to sign in.
15.5 Do Not Track and Global Privacy Control. Because we do not sell or share Personal Information and do not conduct cross-context behavioral advertising, browser signals such as Do Not Track and Global Privacy Control do not change how we process your information — there is no ad tracking to switch off. We honor such signals to the extent Applicable Law requires. Any preference you set applies only to the browser or device on which you set it.
16. Children
The Service is for adults 18 and over. We do not knowingly collect Personal Information from anyone under 18, and we do not knowingly sell or share the Personal Information of anyone under 16. If we learn that we hold information from someone under 18, we will delete it and terminate the Account. If you believe a child has provided us information, contact legal@refunduly.com.
17. Automated Processing
The Service is automated: software reads the order email you connect, extracts structured Order Data, compares prices, and decides when to send you a notification. These are informational alerts only. No automated processing we perform produces a decision that has a legal effect on you or that similarly significantly affects you — we do not score, rank, profile, or make eligibility decisions about you, and nothing the Service does affects your credit, insurance, employment, housing, or access to any service. A person always decides whether to act on an alert: you. The alerts may be wrong, late, or absent; see Terms Sections 6, 7, and 24.
18. Changes to This Policy
18.1 We may change this Policy. We may update this Policy at any time to reflect changes in the Service, in our practices, in the providers we use, or in Applicable Law.
18.2 When a change takes effect. When we update this Policy we post the revised version on this page and update the "last updated" date shown above. The revised Policy takes effect when it is posted, except where Applicable Law requires advance notice or your consent, in which case we will provide that notice or seek that consent before the change applies to you.
18.3 Your continued use. Each version is numbered and preserved. By continuing to use the Service after a revised Policy takes effect, you accept it. If you do not agree with a change, stop using the Service and close your Account under Section 12.3. We encourage you to review this page periodically.
18.4 Relationship to the Terms. This Section 18 governs changes to this Policy and controls over Terms Section 30 in respect of them, as Terms Section 1.3 provides. Terms Section 30 continues to govern changes to the Terms themselves.
19. Contact and Accountability
Refunduly is the business responsible for the Personal Information described in this Policy. The role below is accountable for privacy compliance — including for the purposes of Canada's Personal Information Protection and Electronic Documents Act and Quebec's Act respecting the protection of personal information in the private sector — and is where requests under Section 13 should be sent:
We investigate every complaint we receive about this Policy or our handling of information, and we aim to resolve it promptly. We ask that you cooperate with that process and give us the information we need to do it.
20. Additional Information for Canadian Residents
This Section applies to residents of Canada, and supplements the rest of this Policy. Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") applies to us regardless of our size, so nothing in Section 1.5 limits this Section.
20.1 Consent. We collect, use, and disclose your Personal Information with your consent, or as PIPEDA and applicable provincial law otherwise permit or require. By creating an Account and using the Service you consent to the collection, use, and disclosure described in this Policy, including the transfer to and processing in the United States described in Section 10 and the creation and licensing of De-identified Information described in Sections 5.9 and 9.5. Where you connect a mail account, that connection is a separate, express, opt-in consent.
Withdrawing consent. You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice, by emailing legal@refunduly.com. Withdrawing consent to processing that is necessary to provide the Service means we can no longer provide it, and we may close your Account. Withdrawal does not affect the lawfulness of processing carried out before it.
20.2 Accountability. The role identified in Section 19 is the individual accountable for our compliance with PIPEDA and, for Quebec residents, is the person responsible for the protection of personal information under Quebec's private-sector privacy law.
20.3 Transfers for processing. As Section 10 states, our Processors are located in the United States. Transferring Personal Information to a Processor for processing does not require your consent beyond that described in this Policy, but you should know that while it is in another country it is subject to the law of that country and may be accessible to that country's courts and authorities. We use contractual and other means to require a comparable level of protection.
20.4 Access and correction. You may request access to, and correction of, the Personal Information under our control, as described in Section 13. We will respond within the time PIPEDA requires. We may refuse access where the law requires or permits us to — for example, where granting it would reveal Personal Information about another person, would compromise the security of the Service, or would reveal confidential commercial information — and where we refuse we will tell you why and inform you of your right to complain.
20.5 Automated decision-making. Section 17 applies. We do not use your Personal Information to render a decision based exclusively on automated processing that produces legal or similarly significant effects.
20.6 Complaints. Complaints go first to legal@refunduly.com. If you are unsatisfied with our response you may complain to the Office of the Privacy Commissioner of Canada, or — if you are a Quebec resident — to the Commission d'accès à l'information du Québec.