Back to ShopBoard

YOUR COLLECTION. YOUR SPACE.

Privacy Policy

A clear look at the information behind your good finds.

Last updated:

1. Who we are and what this policy covers

ShopBoard is operated by Aymen Hachicha. This policy covers the ShopBoard website, web application, Chrome extension, and the API that supports them. ShopBoard helps you save products you choose, organize your collection, ask questions about saved products, and keep notes with your finds.

For privacy questions or requests, contact aymen.hachicha@icloud.com.

2. Information we handle

Automatic product detection happens locally in your browser. With access to HTTP and HTTPS websites, the extension inspects the page URL, product metadata, and purchase controls to recognize single product pages and display a ShopBoard save button. This detection makes no network requests and sends no page content or browsing history to ShopBoard. Opening the popup also reads the current tab’s URL locally to fill the save field. A product page snapshot is sent to ShopBoard when you explicitly choose to save it using the page button or popup. We receive the URLs you save, not a record of your full browsing history. If you paste a product link into the web app, our server attempts to read that public page.

3. How we use information

We use this information to authenticate you, connect the extension to your account, save and display your collection, extract product details, answer your product questions, and apply your settings. We also use necessary technical information to operate and secure the service, prevent abuse, and investigate errors.

We do not sell user data. We do not use or transfer it for purposes unrelated to ShopBoard’s single purpose, for creditworthiness or lending decisions, or for personalized advertising.

4. Sharing, AI processing, and third-party services

AI and authentication providers can process information outside your country. The configured Qwen endpoint uses Alibaba Cloud’s Singapore region. Provider processing and retention are governed by the applicable provider terms and policies; this policy does not promise that a provider immediately deletes requests or never uses them for model improvement.

We transfer user data only as needed to provide or improve ShopBoard’s single purpose, for security, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent. ShopBoard’s use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. ShopBoard’s use of extension user data adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

5. Storage, security, and retention

Your collection and account records are stored in ShopBoard’s server-hosted database, not solely on your computer. Production connections to ShopBoard use HTTPS. The web session cookie is HTTP-only and secure in production, and the server stores session-token hashes rather than the raw tokens. Account-scoped access controls limit collection access to the signed-in account. No internet service can guarantee absolute security.

Account and collection records remain available until you delete the relevant products or your account. Deleting a product removes its associated conversations and notifications from the active application database. Deleting your account removes its profile, saved products, notes, conversations, pairing records, notifications, and sessions from that database.

Reminders are currently unavailable. Previously saved reminder dates, notes, and notification records may remain stored until you delete the relevant product or your account. We no longer process these dates or deliver reminder notifications.

Sessions expire after 30 days; temporary account-pairing codes expire after five minutes. Expired server records are cleaned up automatically. Signing out in the extension disconnects it and clears its session token. Signing out of the web app ends that web session, not other connected sessions. Infrastructure logs, backups, and third-party provider records are separate from the active application database and may follow their own retention periods. Contact us with questions about these records or a deletion request.

6. Your choices and privacy requests

You choose which products to save, which questions to submit, and what notes to keep. You can edit or delete products, change your language preference, sign out, disconnect or uninstall the extension, and use Settings → Delete account in the web app to delete your account. Uninstalling the extension alone does not delete server-side account records.

For access, correction, export, deletion, or objections concerning your personal information, email aymen.hachicha@icloud.com. We may need to verify account ownership before acting on a request. Depending on applicable law, you may also have rights to restrict processing, portability, or to complain to your local data-protection authority.

7. Changes to this policy

We will update this page when our data practices change and show the latest revision date above. For questions about a change, please contact us before continuing to use the affected feature.