Overview
Cardstock is a browser extension that monitors product availability at retail websites and sends you notifications when items come back in stock.
The short version: We collect only what's necessary to make the extension work. We don't sell your data, we don't track your browsing, and we don't use third-party analytics.
Information We Collect
| Data | Purpose | Storage |
|---|---|---|
| Email address | Account authentication | Stored only as a salted SHA-256 hash (plaintext not retained) |
| API key | Authenticating your connection to our server | Stored securely on our server; prefix stored locally in extension |
| User preferences | Filtering alerts by retailer, brand, etc. | Chrome sync storage (syncs across your devices) |
Information We Don't Collect
- Browsing history - We don't track what websites you visit
- Personal information - No name, address, phone number, or payment info
- Analytics or tracking - No Google Analytics, no third-party trackers, no ads
- Retailer account credentials - We never ask for your Target, Best Buy, or Amazon login
How We Use Your Information
- Email hash - Used solely to verify your identity when you authenticate. We cannot recover your email from the hash.
- API key - Validates your connection to receive real-time stock alerts via WebSocket.
- Preferences - Applied locally in the extension to filter which alerts you see and how they're displayed.
Extension Permissions
The extension requests the following Chrome permissions:
- tabs - To open product pages when alerts arrive, prevent duplicate tabs, and clean up stale tabs
- notifications - To show desktop notifications when products restock
- storage - To save your preferences and sync them across devices
- Host permission (cardstock.cc) - To connect to our server for real-time alerts and fetch the product catalog
Data Security
We take reasonable measures to protect your information:
- Email addresses are hashed with SHA-256 before storage - we cannot see or recover your plaintext email
- API keys are generated with cryptographically secure random values
- All connections use HTTPS/WSS encryption
- We don't store any data we don't need
Third-Party Services
The extension connects only to our own server (cardstock.cc). We do not share your data with any third parties.
When you click on product links, you'll be directed to retailer websites (Target, Best Buy, Amazon). These retailers have their own privacy policies that apply when you visit their sites.
Affiliate Links
Product links in the extension may include affiliate codes. If you make a purchase after clicking one of these links, we may receive a commission from the retailer.
When you use an affiliate link, the retailer (e.g., Amazon) tracks purchases made through that link and provides us with aggregate sales data such as products purchased and commission earned. This data cannot be tied back to individual users or your extension activity - we have no way of knowing who made a purchase, only that a purchase was made.
Currently, Amazon links include affiliate codes. We may add affiliate relationships with other retailers in the future.
Data Retention
- Account data - Retained while your account is active. You can request deletion at any time.
- Local preferences - Stored in Chrome until you uninstall the extension or clear the data.
Your Rights
You can:
- Request a copy of any data we have associated with your account
- Request deletion of your account and associated data
- Uninstall the extension at any time to remove all locally stored data
To make a request, contact us at the email below.
Changes to This Policy
If we make significant changes to this privacy policy, we'll update the "Last updated" date at the top and may notify users through the extension.
Contact
Questions or concerns about this privacy policy? Contact us at:
Email: privacy@grimnoire.com