ownitsafely

Privacy Policy

Effective: May 12, 2026

This Privacy Policy describes how [OPERATOR_NAME] (“we”) collects and uses personal information when you use ownitsafely.com. Plain English, no surprises.

What we collect

  • Account: your email address and a one-way hash of your password (we never see or store the plaintext).
  • Watchlist data: the product names, model numbers, UPCs, manufacturers, and types you choose to add.
  • Alerts:which recalls we’ve flagged for you and which you’ve dismissed.
  • Technical: server logs (IP address, request paths, timestamps) for security and operations. Sentry receives stack traces from errors. None of this is sold or used for advertising.

What we don’t collect

We don’t use third-party advertising cookies, social trackers, or analytics that profile individuals. We don’t ask for your name, address, phone number, or payment info. We don’t buy data about you from data brokers.

How we use it

  • Match your watchlist against new and existing CPSC recalls and send you alert emails.
  • Verify your email and handle password resets.
  • Operate the service: keep you logged in, fix bugs.

Who we share it with

We don’t sell or rent your data. We share only with the specific service providers needed to operate ownitsafely:

  • Supabase — hosts our database (US region).
  • Render — runs our backend API (US region).
  • Vercel — serves our website (US region).
  • Resend — delivers our outbound emails.
  • Cloudflare — DNS + email routing for our addresses (support@, legal@, etc.).
  • Sentry — receives error reports for debugging.

All providers are bound by their own data-processing agreements with us; none use your data for their own purposes.

Cookies and tokens

When you log in, we set two cookies (access_token and refresh_token). They’re httpOnly (your browser’s JavaScript can’t read them) and only used to keep you logged in. No third-party cookies, no ad pixels.

How long we keep it

For as long as your account is active. If you delete your account (account settings → Delete), we remove your watchlist, alerts, and tokens immediately. Server logs are retained for up to 30 days for security purposes.

Your rights

You can:

  • See your watchlist and alerts at any time inside your account.
  • Change your email or password from your account page.
  • Delete your account, which removes all your data from our database.
  • Email support@ownitsafely.com with any question or correction request.

If you’re in California, Colorado, or another state with consumer-privacy laws, the rights above already cover what those laws require. If you need a formal request handled, email legal@ownitsafely.com.

Children

ownitsafely is intended for adults. We don’t knowingly collect personal information from anyone under 13. If you think we have, email legal@ownitsafely.com and we’ll delete it.

Changes to this policy

If we change anything material we’ll update the effective date and email anyone with an active account. The latest version is always at this URL.

Contact

Questions: support@ownitsafely.com.
Privacy / legal: legal@ownitsafely.com.
Security reports: security@ownitsafely.com.

See also our Terms of Service.