Privacy
This notice describes what the current build actually does. It needs legal review before launch.
Spotnup stores the email you enter at checkout, a hashed session cookie, and hashed single-use login links. Passwords are not used for customers.
To preview a link, the server fetches that public URL. It does not run JavaScript from the page and does not send your cookies to it. Google Web Risk may receive the URL for malware and phishing checks when that provider is enabled.
Payments are handled by the configured payment provider. Card details are entered on the provider page, not stored here.
If analytics is enabled, PostHog receives product events such as board views and claim steps. Card fields are not recorded. Email is sent through Resend when that provider is enabled, otherwise it is printed to the server log in development.