Privacy Policy
Updated July 14, 2026This policy explains exactly what Couponly collects across the website and browser extension, why, who ever sees it, and the controls and rights you have — written to match what our code actually does.
On this page
Who we are
Couponly — this website and the Couponly browser extension — is operated by , a private limited company registered in the Estonian Commercial Register under registry code , registered address , , , , Estonia (VAT ). is the data controller for the personal data described in this policy.
The fastest way to reach us about privacy is email — [email protected] — or the contact page, where there is a dedicated account & privacy option. We have not appointed a data protection officer, because the scale and nature of our processing does not require one; and because we are established in the EU, no separate EU representative is needed.
What this policy covers
This policy covers the couponly.ai website, the Couponly browser extension for Chrome and Firefox (including the same extension package where it is listed for other Chromium-based browsers), our mobile apps for iOS and Android, and the emails we send. If an app's data practices ever differ from what this policy describes, we will update this policy before shipping the difference.
You can browse the website and use the extension without creating an account. An email address is required only if you create an account or subscribe to alerts — you are never under a statutory or contractual obligation to give us data, and the core service works without it.
Information we collect on the website
Account information. If you create an account, we store your email address, display name, and sign-in credentials. Passwords are stored only as salted hashes — we cannot read them.
Sessions. When you sign in, we create a session record that includes your IP address and browser user-agent string, used to keep the session secure and spot abuse. A session is valid for 7 days, and the session table is the only place our application database stores raw IP addresses.
Watched products and alerts. If you choose to watch a product, we store a record linking your account to that product (and optionally a specific variant) together with the alert threshold or target price you set. Watching is opt-in and signed-in only; you can remove a watch at any time.
Your savings. When the extension measurably lowers your total and you are signed in, we record the win — the merchant host, the code that worked, the measured savings amount, and the currency — so your lifetime savings total follows you across devices. This is only ever the real savings the extension measured; we never estimate or invent a figure. Signed out, your savings ledger stays in your browser; the only thing sent is the anonymous per-attempt outcome signal described in the extension section — which includes the measured amount — and it is not linked to you.
Store reviews. If you write a review, we publish it with your display name. If you later delete your account, the review text stays but is detached from you and your name is removed from it.
Deal alerts without an account. You can subscribe to a store's new-coupon digest with just an email address — no account needed. The subscription does nothing until you click the confirmation link we email you (double opt-in), and every digest carries a one-click unsubscribe that deletes it.
Store requests. When you ask us to support a store, we record the store's host and a request count. If you are signed in when you ask, we may associate your account so we can follow up.
Technical data. Like most sites, we process IP address, user agent, and basic request metadata to operate the service, prevent abuse, and keep sessions secure. Rate-limiting counters keyed by IP address live only in the server's memory and are never written to the database. Beyond that, our web server and CDN keep standard access logs — routine infrastructure records that include IP addresses, used only for operating, securing, and debugging the service, never to build a profile of you.
First-party traffic analytics. We keep our own traffic records to understand how the site is used and to keep it secure. For each page you open we store the page path, the referring website, your IP address, browser user-agent, and approximate country (derived by Cloudflare from your IP). We use these to understand how the site is used, see which sites refer visitors to us, keep the service secure, and measure our own campaigns — our legitimate interest in running, improving, and securing the service (Art. 6(1)(f)). We retain these records for up to 45 days. For a signed-out visitor they are not tied to any durable identifier — we use only a short-lived, strictly-necessary cookie (15 minutes) for security and abuse prevention; if you are signed in, they are linked to your account. Durable analytics identifiers — a 90-day first-touch cookie recording which site referred you, and an anonymous device fingerprint used only to count who is browsing right now — are set only if you accept on the cookie banner; see “Cookies and local storage” below.
Information the browser extension collects
Everything the extension collects goes to exactly one server — ours, at couponly.ai — and its background process refuses to send collected data anywhere else. The one other kind of request it can make is affiliate attribution: when you actively use one of our codes or click one of our links, the extension may load the merchant's affiliate-network link so the merchant knows Couponly sent you. That request is a normal web visit from your browser to the network and the merchant — your IP address and browser, none of your Couponly data — and it never happens from passive browsing. See “Who receives your data” below.
Coupon-apply signals. When the extension tries codes at checkout, it sends an anonymous outcome signal for each attempt: the merchant host, the coupon code itself, whether it worked, and the savings amount and currency it measured. A coupon code is the merchant's data, not yours — and to be precise, the code is sent as-is, not hashed. These signals have no separate off switch, but they fire only when you actively run the coupon-testing feature, and they are never linked to your account; see “Crowd signals” below for how we keep them unlinked.
Product-page data (Product Pulse). On a supported store's product-list and product-detail pages, the extension reads the catalog facts the page shows — product titles, prices and list prices, currency, brand, availability, the page's canonical product URL, and other structured facts the page publishes (identifiers such as GTIN, SKU, or MPN, plus category and spec attributes) — sends them to us to build price history: the data behind the price card, lowest-ever badges, and watch alerts. Raw page content is never sent and is discarded after the catalog facts are read. This sharing is on by default; you can turn it off at any time in the extension's options under Privacy & data (“Share product info from supported stores to power price tracking”).
Price-history lookups. Separately from Product Pulse, when “Show price history on product pages” is enabled in options (on by default) and you open a page that looks like a product page — on any store, supported or not — the extension asks our server whether we already know that product. That lookup sends the product's identity: the store host, product title, canonical URL, brand, and GTIN/MPN/SKU where the page publishes them. This is how the price badge and the popup sparkline work. Turning “Show price history on product pages” off stops these lookups entirely — the on-page badge and the popup's price chart simply don't load — and dismissing the badge on a store silences it there for a week.
Store-interest beacon. On stores we do not yet support, the extension may send a beacon containing that store's hostname and nothing else — no URL, page title, or product — at most once per store per day. This is how the stores you actually shop at get supported next: the beacon feeds the same demand ledger as the popup's “request this store” button, and enough distinct shoppers on one store moves it up our onboarding queue. It obeys the same cart/checkout gates and never fires in private windows. It has no separate off switch — it is the one switchless signal that can fire from ordinary browsing — and it carries only the hostname.
Signing in. If you sign in from the extension, it authenticates with your email and password and keeps a session token in the extension's local storage. Signed-in features send only what they need, as described in this policy; the extension checks your watches in the background roughly every 30 minutes, and sends nothing at all for these features while you are signed out.
Crash reports — on by default, with an off switch. The extension reports its own errors so we can fix them: the error message (truncated), up to three stack frames with web addresses stripped out, the site's registrable domain, the extension version, and the browser family — never page content, full URLs, or anything that identifies you. Reports go to error-monitoring software we host on our own servers — no third-party crash service ever sees them — and are capped at five per hour. Turn the toggle off in options (Privacy & data) and reporting stops immediately.
On-device storage. Codes you save, your preferences, caches of the supported-store list and codes, and your running savings total live locally in the browser's extension storage. Nothing there syncs through your browser vendor's account. The options page has one-click buttons to clear your savings history, watch-state cache, and requested-store list; uninstalling the extension deletes all of it.
Our commitment for extension data. Everything the extension collects is used solely for its single purpose — finding and applying coupons and tracking prices for you — consistent with the Chrome Web Store's Limited Use policy. All of it travels over HTTPS to couponly.ai only. In the Chrome Web Store's vocabulary, the collection above is declared as “website content” (the catalog facts the extension reads from product pages) and “user activity” (the anonymous coupon-apply outcomes); we do not collect “web history”. On Firefox, we will declare the same collection in the add-on's install-time data dialog: website content and the anonymous coupon-apply outcomes as required for the features above — not a history of your browsing — and technical/error data as optional — on by default, with the off switch in the extension's options.
What we never collect
These are commitments we intend to keep ahead of the code: if a change would break one of them, we update this policy before shipping it, not after.
- No payment details — ever.
- No raw page content: the extension reads catalog facts out of a page and discards the rest.
- No keystrokes, form contents, or clipboard reading.
- No advertising, social-media, or analytics cookies on the website without your explicit consent on the cookie banner.
Cart, checkout, and private browsing
Product-page reading is deliberately fenced off from anything cart-like. Before sending product data, the extension applies several independent safety gates and stays silent if any of them trips: it refuses to report when the page is classified as a cart or checkout, when it detects cart line-item rows, when a promo-code field appears alongside those rows, or when the URL looks like a cart/checkout page. A page that looks at all like a cart never reports.
URLs are cleaned before they leave your browser: tracking parameters (such as utm_ and analytics tails) are stripped. Parameters that select a product variant — a size, a color — are kept, because price history attached to the wrong variant would be dishonest data.
How we use information, and our legal bases
Under the GDPR, every use of personal data needs a legal basis. Here are ours, in plain language:
- Running your account, watches, and the alerts you set up — necessary to provide the service you asked for (contract, Art. 6(1)(b)).
- Deal-alert digest emails — your consent, given by double opt-in and withdrawable any time with one click (Art. 6(1)(a)).
- Weekly watch summary — your consent, given by turning the summary on next to your watch list and withdrawable any time with one click (Art. 6(1)(a)); it never sends unless you switched it on.
- Crowd signals — coupon-apply outcomes, Product Pulse, price-history lookups, and store-interest beacons rest on our legitimate interest in keeping the coupon and price catalog accurate and deciding which stores to support next (Art. 6(1)(f)). You can object via the extension's switches where one exists, or by contacting us.
- Security — sessions, rate limiting, server logs, and abuse prevention rest on our legitimate interest in keeping the service secure (Art. 6(1)(f)).
- Crash reports — our legitimate interest in finding and fixing extension bugs (Art. 6(1)(f)): the payload is heavily sanitized, never leaves infrastructure we control, and the options toggle is your objection switch — off means off, immediately.
- Usage analytics and any advertising or marketing cookies — your consent, given on the cookie banner and withdrawable any time via Cookie settings in the footer (Art. 6(1)(a)); nothing in this category runs without it, and declining changes nothing about how the site works.
- Building the merchant catalog — stores, coupons, products, and prices rest on our legitimate interest in operating a useful public catalog; this is overwhelmingly data about merchants, not people (Art. 6(1)(f)).
Wherever we rely on legitimate interest, you have the right to object — see “Your rights and how to use them”. You can also ask us for more detail on how we balanced any of these interests against your privacy.
Emails we send, and your choices
Account emails. Verification codes, sign-in codes, and password-reset messages — sent only when you trigger them.
Deal-alert digests. Sent only after you confirm the double opt-in. Each digest lists a store's recently found codes. We keep the confirmation timestamp as the record of your consent, and the one-click unsubscribe in every message deletes the subscription.
Price-drop and back-in-stock alerts. Sent only for watches where you set a drop threshold or target price, and only to a verified email address. Our checks run hourly, so an alert arrives within about an hour of us observing the change. One-click unsubscribe turns off alert emails for all your watches at once.
Weekly watch summary. A short weekly roundup of your watched products' prices — sent only if you turn it on, with the toggle next to your watch list on the account page. It is off by default; creating a watch never enrolls you by itself. The one-click unsubscribe in every summary turns it off again, without touching your price-drop alerts.
Every alert and digest supports one-click unsubscribe (RFC 8058) that works even when you are signed out.
Who receives your data
We use a small set of providers, each receiving only what its job requires:
- Mailgun — delivers our email, so it receives the recipient address and message content of everything in the section above.
- Cloudflare — sits in front of the website as our CDN and security layer, so it sees visitor traffic, including IP addresses, in order to serve and protect the site.
- Analytics provider — only if you accept cookies on the banner. It then receives usage events — pages viewed, device and browser information, and a random cookie identifier — and processes them for us. We disable ad features and ad personalization, so this feeds statistics, not advertising. Decline (or enable Global Privacy Control) and it receives nothing.
- Advertising and marketing platforms — only if you accept cookies on the banner. Platforms that measure our advertising campaigns then receive campaign events — for example, that an ad brought you to couponly.ai — and process them for us. Decline (or enable Global Privacy Control) and they receive nothing.
- OpenAI — our AI provider. It receives store, coupon, and product content only — never data about you: no account data, no telemetry, nothing from your browsing (details, including one narrow merchant-contact caveat, in the sections below).
- Error monitoring (Sentry, self-hosted) — runs on our own infrastructure, so server errors and extension crash reports never leave systems we control.
Each of these providers acts as our processor under a data-processing agreement: it may use the data only on our instructions and must protect it to the same standard we do.
Merchants and affiliate networks. When you click out to a store — or when the extension applies one of our codes and claims the attribution — the link may be an affiliate link that routes through an affiliate network on its way to the merchant. The network and the merchant then see a normal web visit from you (your IP address and browser) and may set attribution cookies on their domains so the merchant knows Couponly sent you — that is how commissions work. We do not send them your Couponly account details. Which affiliate is ultimately credited is decided by the network's own attribution rules (commonly last-click) — those cookies live on the network's and merchant's domains, so we cannot see whether another party already holds an attribution, and we never read or delete anyone's cookies. Those cookies are governed by the network's and merchant's own policies, and blocking them does not affect anything on Couponly. Our Terms of Service explain how we make money.
We disclose personal data to authorities only where the law requires it. We honor Global Privacy Control: with GPC enabled, non-essential cookies are treated as declined automatically, without showing you the banner.
AI processing and automated decisions
We use a third-party AI provider (OpenAI) to work on merchant and catalog content: extracting coupon codes and normalizing their conditions from store pages, building store profiles and classifying stores into categories, summarizing a store's own shipping and returns pages into guides, composing product descriptions from merchant spec sheets, naming product variant options, and recognizing when two stores sell the same product. Every one of these requests carries store, product, or coupon content — never your account data, your telemetry, or anything else about you. These features also fail closed: if the provider is not configured, they simply do not run.
Automated decision-making. We make no automated decisions about you that have legal or similarly significant effects, and none of our AI processing profiles users — it works on merchants and products.
Data about merchants
Our systems automatically collect publicly available pages — store frontpages, policy pages, product pages, sitemaps — and publicly available coupon sources to build the catalog. A merchant's public pages occasionally include personal data the merchant chose to publish, such as a named contact person or a business email address; because merchant pages are processed as published, such business contact details can be included in the content sent to our AI provider. We process this under our legitimate interest in maintaining an accurate public catalog, and this section is our notice to the people it may concern (GDPR Art. 14).
If you are a merchant — or a person named on a merchant's site — and want data corrected or removed, use the contact page. The same channel handles logo-removal and other crawl-related requests.
International transfers
We are established in Estonia and serve users worldwide. Some of our providers process data outside the European Economic Area. Where that happens, we rely on the GDPR's recognized safeguards: where a provider is certified under the EU–U.S. Data Privacy Framework, we rely on that adequacy decision; otherwise, on standard contractual clauses in our data-processing agreements. Our AI provider, OpenAI, is not certified under the Data Privacy Framework — it never receives data about you in the first place: the only personal data that can reach it is the merchant-published business contact detail described under “Data about merchants”, and those transfers travel under the same safeguards. Analytics data (only if you consented) is processed by our analytics provider under the same recognized safeguards — our current provider's US entity participates in the EU–U.S. Data Privacy Framework. Our error monitoring is self-hosted on our own infrastructure, so no transfer arises there at all.
How long we keep data
Account data — kept until you delete your account. Deletion is self-service from your account page and cascades immediately: sessions, watches, alert settings, and your savings ledger are removed; your reviews are detached and de-named; and deal-alert subscriptions for your verified email are deleted.
Sessions — a session is valid for 7 days; after that it stops working immediately, and the stored record is removed the next time that session is presented or when you delete your account.
Consent records — we keep double-opt-in confirmation timestamps as proof of consent for as long as the subscription exists.
First-party traffic records — the per-page visit records described under “First-party traffic analytics” are deleted automatically after 45 days; the aggregate counts we derive from them are kept longer but hold no IP addresses.
Analytics — if you accepted analytics, event data is retained by our analytics provider for 14 months, after which it is deleted automatically; your consent choice itself is remembered for 12 months in the consent cookie.
Provider-side email logs — our email provider keeps delivery logs, which include recipient addresses and message content, for about 30 days on its side.
Backups — we take nightly database backups with rolling retention, so deleted data can persist in backups for up to about eight weeks before aging out. Backups are used only for disaster recovery, never to resurrect deleted accounts.
An account stays yours until you close it — we do not delete accounts just because they go quiet. If you want anything removed that the self-service tools do not cover, ask via the contact page and we will action it.
Your rights and how to use them
You have the full set of GDPR rights, and we honor them for everyone, wherever you live — without you needing to qualify under any particular statute. Residents of US states with privacy laws (such as California) additionally have the specific rights those laws provide, including opting out of “sales” or “sharing” as those laws define them; we honor Global Privacy Control as such an opt-out signal:
- Access & portability. Download a machine-readable JSON export of your data — profile, reviews, watches, subscriptions, savings — from your account page, any time.
- Rectification. Fix your details in account settings, or ask us.
- Erasure. Delete your account yourself from the account page, or ask us to delete specific data.
- Objection. Object to any processing we base on legitimate interest — the extension's switches are the fastest route (below), or contact us.
- Restriction. Ask us to freeze processing of your data while a dispute is resolved.
- Withdrawing consent. Every consent has an off switch as easy as the on switch: one-click unsubscribe links in every alert and digest, and Cookie settings for analytics. Withdrawal never affects what was lawfully done before it.
How the extension's switches map to these rights. “Share product info from supported stores” is your objection to Product Pulse. “Show price history on product pages” stops the product-identity lookups everywhere, popup included. The crash-report toggle is your objection to crash reporting — flip it off and reports stop immediately. The options page's Clear buttons erase on-device data.
For anything else, email [email protected] or use the contact page. We respond within one month, as the GDPR requires — usually much faster.
Complaints. If you believe we are handling your data unlawfully, you can complain to the Estonian Data Protection Inspectorate or to the supervisory authority in your own EU/EEA country. We would appreciate the chance to fix things first, but that is your call.
Cookies and local storage
Our own cookies are: two strictly necessary sign-in cookies (a session cookie that keeps you logged in for up to 7 days, and a short-lived five-minute signed cache cookie that saves a database lookup); a strictly necessary, short-lived visit cookie (15 minutes) used for security and abuse prevention; a consent cookie that remembers your cookie-banner answer for 12 months; and — only after you say yes on the banner — analytics statistics cookies, a 90-day first-touch cookie that records which site referred you, and advertising or campaign-measurement (marketing) cookies. A visitor who never signs in gets at most two cookies from us before answering the banner — the consent cookie and that short-lived visit cookie — and no analytics, marketing, or durable-identifier cookie before they answer or when browsing with Global Privacy Control enabled. Cloudflare, our CDN, may additionally set its own security cookies at the edge.
The website keeps a few small preferences on your device in localStorage — your light/dark theme, your display currency, and, for staff accounts, an admin sidebar setting — which never leave your browser. Any non-essential cookie or storage — analytics, marketing, anything else — is set only after you say yes on the banner, with an equally easy no, and you can change your answer any time via Cookie settings in the footer. See also our Cookie Policy.
Children
Couponly is not directed at children. You must be at least 13 to create an account or use consent-based features — Estonia's digital-consent age — and where your country sets a higher age (up to 16 in some EU countries), that age applies. We do not knowingly collect personal data from children under 13 anywhere, including under the US COPPA rules, and we deliberately never ask for a birthdate. If you believe a child has given us personal data, contact us and we will delete it promptly.
Changes to this policy
We update this policy as the product evolves, and the date at the top always reflects the current version. We also hold ourselves to the substance: we commit to updating this policy before shipping any change to what the extension sends — not afterwards.