YOUR COLLECTION. YOUR SPACE.
Privacy Policy
A clear look at the information behind your good finds.
Last updated:
1. Who we are and what this policy covers
ShopBoard is operated by Aymen Hachicha. This policy covers the ShopBoard website, web application, Chrome extension, and the API that supports them. ShopBoard helps you save products you choose, organize your collection, ask questions about saved products, and keep notes with your finds.
For privacy questions or requests, contact aymen.hachicha@icloud.com.
2. Information we handle
- Account information. Google sign-in supplies your Google account identifier, verified email address, name, and profile picture. We also store your account creation date and language preference. We do not request access to your Gmail, Google Drive, contacts, or other Google account content.
- Products you save. We collect the product URL and available page text, metadata, structured product data, images or image URLs, title, price, retailer, and other product details. We store saving and update times, your notes, and bought or archived status.
- Product conversations. We store questions you submit about a saved product and the AI responses, associated with your account and that product.
- Authentication and local settings. The web application uses an essential session cookie. The extension stores its ShopBoard session token, temporary pairing information in Chrome’s local extension storage. These support sign-in and connecting your account.
- Technical information. Requests to our service expose technical information such as IP address, requested URL, time, and browser or device information to our server infrastructure. Technical logs and rate-limit information support service operation, troubleshooting, and security.
Automatic product detection happens locally in your browser. With access to HTTP and HTTPS websites, the extension inspects the page URL, product metadata, and purchase controls to recognize single product pages and display a ShopBoard save button. This detection makes no network requests and sends no page content or browsing history to ShopBoard. Opening the popup also reads the current tab’s URL locally to fill the save field. A product page snapshot is sent to ShopBoard when you explicitly choose to save it using the page button or popup. We receive the URLs you save, not a record of your full browsing history. If you paste a product link into the web app, our server attempts to read that public page.
3. How we use information
We use this information to authenticate you, connect the extension to your account, save and display your collection, extract product details, answer your product questions, and apply your settings. We also use necessary technical information to operate and secure the service, prevent abuse, and investigate errors.
We do not sell user data. We do not use or transfer it for purposes unrelated to ShopBoard’s single purpose, for creditworthiness or lending decisions, or for personalized advertising.
5. Storage, security, and retention
Your collection and account records are stored in ShopBoard’s server-hosted database, not solely on your computer. Production connections to ShopBoard use HTTPS. The web session cookie is HTTP-only and secure in production, and the server stores session-token hashes rather than the raw tokens. Account-scoped access controls limit collection access to the signed-in account. No internet service can guarantee absolute security.
Account and collection records remain available until you delete the relevant products or your account. Deleting a product removes its associated conversations and notifications from the active application database. Deleting your account removes its profile, saved products, notes, conversations, pairing records, notifications, and sessions from that database.
Reminders are currently unavailable. Previously saved reminder dates, notes, and notification records may remain stored until you delete the relevant product or your account. We no longer process these dates or deliver reminder notifications.
Sessions expire after 30 days; temporary account-pairing codes expire after five minutes. Expired server records are cleaned up automatically. Signing out in the extension disconnects it and clears its session token. Signing out of the web app ends that web session, not other connected sessions. Infrastructure logs, backups, and third-party provider records are separate from the active application database and may follow their own retention periods. Contact us with questions about these records or a deletion request.
6. Your choices and privacy requests
You choose which products to save, which questions to submit, and what notes to keep. You can edit or delete products, change your language preference, sign out, disconnect or uninstall the extension, and use Settings → Delete account in the web app to delete your account. Uninstalling the extension alone does not delete server-side account records.
For access, correction, export, deletion, or objections concerning your personal information, email aymen.hachicha@icloud.com. We may need to verify account ownership before acting on a request. Depending on applicable law, you may also have rights to restrict processing, portability, or to complain to your local data-protection authority.
7. Changes to this policy
We will update this page when our data practices change and show the latest revision date above. For questions about a change, please contact us before continuing to use the affected feature.