Legal

Privacy Policy

What information PriceRules collects, how it is used and shared, and the choices you have.

Last updated:
October 2, 2026
Effective:
[EFFECTIVE DATE]

Draft — not yet final

Values shown like [THIS] are not yet confirmed and must be completed and reviewed before this document is relied on.

1.Introduction

This Privacy Policy explains how [LEGAL COMPANY NAME]("PriceRules", "we", "us", or "our") collects, uses, shares, and protects information in connection with the PriceRules website, web application, and API (together, the "Service").

PriceRules is a business service used by organizations to manage customer-specific pricing. This policy should be read together with our Terms of Service.

In short

We use your information to run PriceRules: to sign you in, store and process your workspace data, answer API requests, and enforce plan limits. We do not use analytics or advertising trackers, and we do not sell personal information.

2.Our role: controller and processor

Account and usage information. For information about the people who sign in to PriceRules and how they use the Service, PriceRules decides how that information is used and acts as the data controller.

Customer Data. For the data an organization uploads or sends to PriceRules — such as its products, customer records, and pricing rules — we process it on behalf of that organization and according to its instructions. The organization is responsible for that data and is the controller of any personal information it contains.

[CONFIRM CONTROLLER / PROCESSOR ROLES WITH LEGAL COUNSEL FOR THE JURISDICTIONS YOU SERVE]

3.Information we collect

Account information

  • Your email address, used to create your account and send you one-time sign-in codes.
  • If you sign in with Google: your name, email address, and profile picture as provided by your Google account. We use them to identify you and to display your profile in the application.
  • Authentication records needed to keep you signed in, such as session information.

Workspace information

  • Workspace details, such as the workspace name and settings.
  • Workspace membership and roles (owner, admin, or viewer).
  • Plan and subscription status, and setup progress such as onboarding.

Customer Data

Information your organization adds to PriceRules, including:

  • Products, such as SKUs, names, categories, base prices, currencies, and metadata.
  • Customer records, which may include names, email addresses, regions, external identifiers, and metadata.
  • Pricing rules and their configuration.
  • CSV files uploaded for imports, and error reports generated for rows that fail validation.

API and usage information

  • API keys created in your workspace. They are stored as a one-way hash together with an encrypted copy, not as plain text.
  • Request counts used to apply per-minute rate limits and monthly usage limits.
  • Request metadata generated when API requests are processed, such as request IDs and processing times.
  • Activity log entries describing actions taken in a workspace — for example imports or changes to data — and the user who performed them.

Technical information

When you use the Service, our infrastructure and service providers process technical information needed to deliver it, such as IP addresses, browser and device information, and request logs. This information is used to operate, secure, and troubleshoot the Service.

4.Cookies and similar technologies

PriceRules uses a small number of cookies and browser storage entries that are needed for the application to work. We do not currently use analytics or advertising cookies.

Authentication cookies
Set by our authentication provider (Supabase) to keep you signed in securely.
sidebar_state
Remembers whether the application sidebar is expanded or collapsed. Expires after 7 days.
Local storage
Remembers when you dismiss a usage-limit notice so it is not shown again unnecessarily.

You can block or delete cookies in your browser settings, but you will not be able to stay signed in without authentication cookies. Exact names, durations, and details are listed in our Cookie Policy.

5.How we use information

We use the information described above to:

  • Create and authenticate accounts, including sending one-time sign-in codes.
  • Provide the Service: store workspace data, process imports, and resolve prices through the application and API.
  • Enforce rate limits, usage limits, and workspace permissions.
  • Protect the Service and its users, including detecting and preventing abuse and unauthorized access.
  • Provide support and send messages about the Service, such as security or account notices.
  • Diagnose problems and improve the reliability of the Service.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use Customer Data for advertising.

Legal bases for processing, where required: [LEGAL BASES (E.G. CONTRACT, LEGITIMATE INTERESTS, LEGAL OBLIGATION) — CONFIRM WITH COUNSEL]

6.How we share information

We share information only in the following situations:

  • Within your workspace. Members of a workspace can see workspace data according to their role, including activity log entries that show which user performed an action.
  • With service providers that operate the Service on our behalf, as described below.
  • For legal reasons, when we believe disclosure is required by law, regulation, or legal process, or is necessary to protect the rights, property, or safety of PriceRules, our customers, or others.
  • In a business transfer, as described below.
  • With your consent or at your direction.

7.Service providers

PriceRules uses the following providers to operate the Service:

Supabase
Authentication (one-time email codes and Google sign-in), database, and file storage for imports and error reports.
Google
Sign-in with Google, only if you choose to use it.
[REDIS PROVIDER]
Rate limiting, usage counting, caching of API key lookups, and background job queues for imports and pricing.
[HOSTING PROVIDER]
Hosting and delivery of the website, application, and API.
[EMAIL DELIVERY PROVIDER]
Delivery of sign-in code emails, sent through our authentication provider.

These providers may process information only to provide their services to us. [CONFIRM THE FULL SUBPROCESSOR LIST AND WHERE IT WILL BE PUBLISHED]

8.Business transfers

If PriceRules is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will take reasonable steps to ensure the information remains protected under terms consistent with this policy.

9.Data retention

  • Account information is kept while your account is active.
  • Customer Data is kept while the workspace that contains it exists. Workspace owners and admins can delete a workspace from the workspace Settings.
  • Rate-limit counters expire automatically after a short window, and monthly usage counters expire at the end of the usage period.

Retention after deletion: [HOW LONG DATA, UPLOADED FILES, ACTIVITY LOGS, AND BACKUPS ARE KEPT AFTER A WORKSPACE OR ACCOUNT IS DELETED]

We may keep information for longer where required by law or to resolve disputes and enforce our agreements.

10.Data security

We use measures designed to protect information, including:

  • Role-based access controls within each workspace.
  • Storing API keys as a one-way hash and an encrypted copy rather than as plain text.
  • Rate limits on the API to reduce abuse.
  • Passwordless sign-in through one-time email codes or Google.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a security issue, contact [SECURITY CONTACT EMAIL].

11.International data transfers

Information may be stored and processed in countries other than the one where you are located.

Primary data location: [DATA STORAGE REGION]. Safeguards for transfers: [TRANSFER MECHANISM, IF APPLICABLE]

12.Your rights and choices

Depending on where you are located, you may have rights regarding your personal information, such as the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your information.
  • Object to or restrict certain processing.
  • Receive a copy of your information in a portable format.

How to make a request

Contact us at [PRIVACY CONTACT EMAIL]. We may need to verify your identity before completing a request. Workspace owners and admins can also delete a workspace directly from the workspace Settings.

Information in Customer Data

If your information was added to PriceRules by an organization — for example, as one of its customer records — please contact that organization. We will assist it in responding to your request.

Right to complain to a supervisory authority: [APPLICABLE AUTHORITY / JURISDICTION-SPECIFIC RIGHTS]

13.Children's privacy

PriceRules is a business service and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take appropriate steps to delete it.

14.Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. If a change is material, we will provide notice, for example by email or in the application, before it takes effect.

15.Contact

Questions or requests about this Privacy Policy can be sent to:

Company
[LEGAL COMPANY NAME]
Address
[BUSINESS ADDRESS]
Privacy email
[PRIVACY CONTACT EMAIL]