Legal · privacy
Privacy policy
Product Outbid limits personal data to what is needed for accounts, ownership, safety, payments, and trustworthy click measurement.
Effective August 24, 2026
Information we process
- Account name, email address, login and security records.
- Product submissions, ownership proofs, claims, and moderation history.
- Billing customer, checkout, payment, tax, refund, and dispute references associated with your account.
- A signed random visitor identifier and one-way derived value used to count qualified unique clicks, plus bounded operational logs needed for security and reliability.
- On production public pages only and after explicit consent, sanitized Google Analytics 4 page views and a small set of coarse funnel events without account, product URL, payer, checkout, payment, free-text, query-string, or referrer identifiers.
Product Outbid does not receive or store full payment-card numbers. Dodo Payments collects payment and billing details on its hosted checkout under its own privacy terms.
Why we use it
We use this information to authenticate users, verify ownership, moderate destinations, create and reconcile checkouts, fulfill verified placement, prevent duplicate or abusive credit, measure qualified clicks, answer support requests, and meet legal, tax, accounting, and security obligations.
Service providers and transfers
Data may be processed by Dodo Payments for checkout and merchant-of-record functions, AWS for application and email infrastructure, Neon for the primary database, and Upstash for bounded cache and rate-limit state. After explicit consent, the production public site may also use Google Analytics 4 and cookie-free Ahrefs Web Analytics for optional product analytics. Ahrefs may also crawl canonical public pages for manual search-engine audits. Neither service supplies ranking, payment, ownership, moderation, or exact-click records. These providers may process data in countries different from yours, subject to their contracts and applicable safeguards.
Retention and security
Account and operational data is retained only as long as needed for the purposes above. Financial, refund, dispute, ownership, moderation, and audit records may need longer retention for integrity or legal duties. Secrets remain server-side, payment payloads stored locally are reduced to attribution and amount fields, and browser responses must not contain provider credentials.
Optional public analytics and SEO audit
When explicitly enabled for productoutbid.com, Product Outbid uses Google Analytics 4 and Ahrefs Web Analytics only after an explicit Analytics opt-in. Rejecting analytics does not restrict the service. The consent choice is stored in first-party local storage and can be changed through the Analytics preferences control in the public footer. A previous GA-only or retired analytics-provider preference is not reused for this expanded provider set.
Google Analytics may set first-party analytics cookies only after acceptance. Advertising storage, advertising personalization, Google signals, automatic page views, query strings, and referrers are disabled by Product Outbid. We send only sanitized public paths, enumerated funnel names, and coarse allowlisted properties. Analytics is disabled in local, test, preview, staging, login, dashboard, checkout-status, admin, API, outbound-redirect, and known-crawler surfaces.
Ahrefs Web Analytics is cookie-free by default. Ahrefs documents that it processes page URLs, referrers, browser/device information derived from user agents, language, approximate country/city derived from IP, and automatic page-view, outbound-link, and eligible form-submission events. Ahrefs states that raw IP addresses are discarded rather than stored. Product Outbid loads no Ahrefs script on URLs containing query strings or fragments, private routes, noncanonical hosts, or known crawlers, and sends no custom Ahrefs event properties.
The production Google Analytics property and its reviewed retention setting must be recorded before analytics is enabled. Withdrawing consent records the rejected preference, clears Product Outbid's pending analytics queue, and reloads the page so both optional browser scripts are no longer present. Ahrefs Site Audit separately performs bounded manual crawling of public canonical URLs and does not change browser consent or product behavior.
Your choices
You can request access, correction, or deletion where applicable by using the Support page. Some records cannot be deleted immediately when retention is required for financial, security, dispute, or legal reasons. The visitor cookie is used for integrity-focused click counting and does not create payment credit.