Privacy
Effective April 27, 2026
What we collect
Email address — when you sign up. Used to send you the magic-link sign-in, the per-signal alerts you subscribe to, and the weekly digest.
Page-view + click events — which signal cards, issuers, BDCs, and industries you click into. Stored against a persistent session_id cookie (UUID generated in your browser's localStorage). When you sign in, we link thesession_id to your account so we can attribute pre-login activity to you.
Hashed IP address — sha256(ip + daily-rotating salt), truncated to 32 chars. Used purely for rate-limiting and abuse detection. Raw IPs are never stored.
User-agent string — for the same purpose, plus mobile-vs-desktop diagnostics.
Referrer + page path — when you land on a page from a shared link or external site, we record the referrer and current path so we can measure attribution for shared content.
What we don't collect
- Real names, phone numbers, addresses, government IDs
- Payment card numbers or bank details (we don't charge yet — when we do, payment processing will be handled by Stripe and qRate will never see your card data)
- Browsing data outside qRate.co
- Data from any third-party data broker
- Biometric or location data
Sub-processors
We share data with the minimum set of vendors needed to run the service:
- Supabase — auth, database, magic-link delivery. Stores your subscriber row, alerts preferences, and session.
- Resend — transactional email delivery (sign-in link, signal alerts, weekly digest). Receives your email address and the message contents.
- Vercel — hosting + edge network. Receives request metadata (path, user-agent, hashed IP via standard logs).
We don't sell your data to anyone. We don't share it with ad networks or analytics vendors.
Cookies
We use the minimum set of cookies needed for the service to work:
sb-*— Supabase auth session cookies. Required for you to stay signed in.qrate_session_id(in localStorage, not a cookie) — persistent session UUID for analytics.qrate_attribution_share_id— set when you land via a shared link, expires in 30 days. Used to attribute the share if you sign up afterwards.
We don't use ad-tracking cookies, third-party analytics cookies, or anything resembling cross-site tracking.
Retention
Account data — kept for as long as your account exists. Delete your account by emailing data@q-rate.co; we'll process within 7 days.
Event logs (page-views, click events) — kept up to 13 months. Older events are pruned in monthly batches.
Hashed IPs — 90 days, then zeroed.
Your rights
You can:
- Access — ask us for a copy of all data we hold about you. Email data@q-rate.co.
- Correct — same email, tell us what's wrong.
- Delete — same email. Account row, alerts, event log all wiped within 7 days.
- Export — JSON dump of your account + your event log on request.
- Unsubscribe — every email has an unsubscribe link; you can also turn off per-signal alerts at /alerts while keeping the weekly digest, or turn both off.
Security
Email + Supabase auth secures account access. The database enforces row-level security so authenticated requests can only read their own subscriber row. Service-role keys live only in server-side environments. We rotate API credentials when they're ever exposed.
No internet service is unbreakable. If we discover a breach affecting your data, we'll notify you by email within 72 hours.
Changes
We'll update this page and bump the effective date when the policy changes. For material changes (new categories of data, new sub-processors handling personal data, retention extensions) we'll email account holders.
Contact
qRate Inc. · data@q-rate.co · Terms