Privacy Policy

Last updated: May 2025

1. Information We Collect

When you use PriceBasket, we may collect the following types of information:

  • Account information: Name, email address, and password (stored as a bcrypt hash — we never store plain-text passwords).
  • Profile data: Optional phone number, city, and pincode you provide to personalise delivery estimates.
  • Usage data: Products you search for, view, and add to cart — used to improve recommendations.
  • Session data: A browser session ID stored in localStorage to support guest cart functionality.
  • Device & log data: IP address, browser type, and page visit timestamps for security and analytics.

2. How We Use Your Information

  • To provide and improve the price comparison service.
  • To send price-drop alerts you have explicitly requested.
  • To authenticate your account and keep it secure.
  • To analyse aggregate usage patterns and improve the product.
  • To comply with legal obligations.

We do not sell your personal data to third parties. We do not use your data for targeted advertising.

3. Cookies & Local Storage

PriceBasket uses the following browser storage:

  • httpOnly refresh token cookie: Stored securely by the browser; used to keep you logged in across sessions. Expires after 7 days of inactivity.
  • localStorage (pb_session_id): A random guest session ID for cart functionality before login.
  • localStorage (pb_client_id): An anonymous analytics identifier to understand aggregate usage patterns.

You can clear all stored data at any time via your browser settings.

4. Data Sharing

We share data only in the following limited circumstances:

  • Service providers: Hosting (Render), database (PostgreSQL), and error monitoring (Sentry) — bound by data processing agreements.
  • Legal requirements: If required by law, court order, or to protect the rights and safety of our users.
  • Platform redirects: When you click "Shop on Blinkit / Zepto / etc.", you are redirected to that platform's website. We pass only the product search query in the URL — no personal data is shared.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law. Price history and anonymised analytics data may be retained indefinitely.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data via your Profile page.
  • Request deletion of your account and associated data.
  • Withdraw consent for email notifications at any time.

To exercise these rights, email us at founder@pricebasket.in.

7. Security

We use industry-standard security measures including bcrypt password hashing, JWT access tokens with short expiry, httpOnly cookies for refresh tokens, HTTPS-only communication, and rate limiting on all authentication endpoints. No system is 100% secure — please use a strong, unique password and contact us immediately if you suspect unauthorised access.

8. Children's Privacy

PriceBasket is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email of material changes. Continued use of PriceBasket after changes constitutes acceptance of the updated policy.

10. Contact Us

For any privacy-related questions or requests, contact us at:

PriceBasket

Email: founder@pricebasket.in

Website: pricebasket.in