Spend Elevated

Pay less. Live bigger.

Privacy Policy

What we collect, where it lives, who else sees it, and what you can make us do about it. Written from the actual code, not from a template.

DRAFT — PENDING LEGAL REVIEW

This document has not been reviewed by an attorney. It is a working draft prepared so that a lawyer has something complete to mark up. Do not rely on it as a statement of your rights or of ours, and do not treat it as legal advice.

Drafted 2026-09-29.

1. The short version

You can use almost all of this site without telling us anything. There is no tracking, there are no advertising pixels, there are no analytics, and we set no cookies of our own — which is why you have never seen a cookie banner here.

If you make an account, we hold your email address and the lists you save. If you subscribe, we hold your email address. If you report a wrong price, we hold what you told us. That is close to all of it.

Your birthday month never reaches us at all. It stays in your browser. There is no column for it in our database, deliberately.

We have never sold anyone’s personal data, we do not do it now, and the site has no mechanism for doing it.

2. Who we are

Spend Elevated is a product of Vocally Yours LLC, a New Jersey limited liability company. Spend Elevated is a product name rather than a company, so the organisation responsible for your information is Vocally Yours LLC. It is the controller of the information described here: the one who decides what is collected and why, and the one you complain to.

Privacy questions go to privacy@spendelevated.com.

3. What we collect, and why

This is the whole list. Each row names the table or the file it was checked against on 2026-09-29, so you can hold us to it rather than take our word for it.

Information that reaches our servers or a service working for us.
WhatWhyWhere it livesHow long
Your email address, if you create an accountIt is the whole of your account. Sign-in is a one-time link emailed to you, so the address is both your identifier and the way you prove it is you.Supabase Auth (auth.users), mirrored to public.profiles.emailUntil you ask us to delete the account. Deleting the auth user cascades to profiles, saved lists and saved items.
Your saved lists and the items on themSo a list you make on your phone is there on your laptop.public.saved_lists, public.saved_itemsUntil you delete the list, the item, or the account.
Which loyalty and birthday programmes you have ticked as joined or claimedSo the site stops suggesting a programme you already joined, and can tell you whether you have collected this year's birthday reward.public.program_enrollmentsUntil you delete the account.
Your email address, if you subscribe to the newsletterTo send you the weekly email you asked for.Resend audience (api.resend.com)Until you unsubscribe. Unsubscribing is honoured for good, not just for a while.
A correction you report on a deal — and your email address only if you choose to add itA reader spotting a wrong price is the most useful thing that happens on this site. The email is only so we can come back to you, and the form works fine without it.public.deal_reports (reporter_email is nullable and optional)Kept as a quality record. No deletion schedule is set yet — see the note below.
A takedown or rights complaint you submitA legal notice has to be recorded, actioned and kept — including your contact details and your statements, because those are part of the notice.public.takedown_requestsKept as a legal record, including after the complaint is resolved. This is one place where a deletion request may have to be refused.
A ZIP code you type into the deal or trip searchWeekly circulars are local. Without a ZIP there is nothing to show you.Sent as a `zip` query-string parameter and used for that request only. Not written to any table and not tied to your account.Not stored by us. It appears in the URL, so it will be in Vercel's request logs for as long as Vercel keeps those.

Beyond that, our host keeps ordinary server logs — your IP address, which page you asked for, the time, and what your browser said it was. Every website has these. We use them to keep the site up and to notice when something is being attacked, and we do not use them to build a picture of you.

4. What never leaves your browser

This is the genuinely unusual part of this policy and it is worth reading. Some of what the site remembers about you is stored only in your own browser. It is not sent to us, we cannot see it, it is not in our backups, and it cannot be handed over in response to a support request or a subpoena, because we do not have it.

Stored in your browser, and nowhere else.
WhatWhy it is here and not thereWhere in your browser
Your birthday monthIt filters the birthday-rewards page to the month you care about. There is no column for it anywhere in our database and it is never sent to us — a month kept in one browser cannot leak from an account, a backup or a support query.localStorage key "spendelevated.birthmonth.v1"
Saved lists, when you are signed outSo you can save things without making an account at all.localStorage key "spendelevated.lists.v1"
Programme ticks, when you are signed outSame reason: no account needed to tick a box.localStorage key "spendelevated.programs.v1"
A marker recording that the copy-up above has already happenedSo signing in twice does not redo the copy.localStorage key "spendelevated.programsmerged.<your user id>"
Your sign-in session, if you have an accountSo you stay signed in between pages and visits.localStorage key "sb-<project>-auth-token", set by the Supabase client library

To clear any of it, clear this site’s data in your browser settings. You do not need to ask us and we cannot do it for you.

One consequence worth being straight about: because these live in one browser, they do not follow you to another device, and clearing your browsing data will lose them. That is the trade-off we chose on purpose.

5. What we don’t do

Stated as flatly as we can, because these are the things people assume:

One honest exception to “no third parties in your browser”: the site loads its two typefaces from Google Fonts, so your browser makes a request to Google on each page load and Google sees your IP address. See the table below. Self-hosting those fonts would remove it, and that is on our list.

6. Who else touches it

We use a small number of companies to run the site. They act on our instructions, for our purposes — they are processors, not people we sell to.

The column that matters most is the last one. Where it says our server, your own browser never contacts that company at all: we fetch the data on the server and send you the result, so visiting a page does not expose you to them.

Companies that handle information on our behalf.
WhoWhat forWhat reaches themContacted by
SupabaseDatabase and sign-inYour email address, your saved lists and items, your programme ticks, deal reports and takedown notices.both
VercelHostingWhatever any web host sees: your IP address, the page you asked for and your browser's user-agent, in server logs.your browser
ResendNewsletter deliveryYour email address, and only if you subscribed.our server
Google FontsThe two typefaces the site is set inYour browser requests the font files directly from Google, which means Google sees your IP address and user-agent on every page load. We do not control that request beyond choosing to make it, and self-hosting the fonts would remove it.your browser

Where our price, product and benefit data comes from is listed in the terms. Those are all fetched by our server. Your browser never talks to them, and they are never told anything about you.

Beyond those, we disclose personal information only where the law requires it, or to protect someone’s safety or our legal rights. If the business is ever sold or merged, this information may transfer with it, and we will say so here before it does.

7. The newsletter

If you subscribe, your address goes to Resend, the service that sends the email, and it is used for the weekly email and nothing else. We do not sell, rent, lend or swap the list, and we will not add you to it because you did something else on the site — making an account does not subscribe you.

Every email carries a one-click unsubscribe link. You never have to email anyone, log in, or explain yourself — the law is specific that an opt-out may not cost you a fee, ask for anything beyond your address, or take more than one reply or one web page, and we have no interest in being the kind of site that makes you fight for it.

CAN-SPAM Act, 15 U.S.C. § 7704 sets the rules we follow: honest sender information, honest subject lines, a working opt-out, and a real postal address in every message. Two of its deadlines are worth stating, because they are promises you can hold us to. An opt-out must be honoured within 10 business days — in practice ours is immediate. And the unsubscribe link must keep working for at least 30 days after an email goes out, so an old email in your archive is still a way out.

8. Why we’re allowed to hold it

US state privacy law mostly asks us to be clear about purposes rather than to name a legal basis the way European law does. For completeness, here is the reasoning for each thing:

9. How long we keep it

Account data lasts as long as the account. Delete the account and the profile row, the lists, the saved items and the programme ticks go with it — that cascade is built into the database, not a manual process someone has to remember.

Newsletter addresses last until you unsubscribe. An unsubscribed address is kept as a suppression record so that we cannot accidentally add you back, which is the one situation where keeping an address is the privacy-protective choice.

Takedown notices are kept as a legal record, including after they are resolved.

An honest gap. Deal reports have no deletion schedule. They are kept as a quality record, and nothing in the code deletes them. Setting a real retention period for these is an open item rather than something this policy is going to pretend is already decided.

10. How it’s protected

Three things that are actually true, rather than a paragraph about how seriously we take security:

Not overselling it. Row-level security is a real boundary between accounts, and it is the right one, but it is not encryption of the data at rest by us and it is not a guarantee. Our database and hosting providers hold the data on their infrastructure under their own security arrangements. No system is perfectly secure, and anyone who tells you otherwise is selling something.

11. Your rights, and how to use them

We give everyone the same rights, wherever you live. Sorting people by state so that some get fewer rights is not a thing we want to build.

How to ask

Email privacy@spendelevated.com from the address you signed up with, and say what you want. Sending from the address on the account is how we know it is you — we will not ask you for a document, and we will not create a new record about you in order to verify a request about your records.

We reply within 45 days. If something genuinely needs longer we will tell you inside that first 45 days, explain why, and take up to 45 more. There is no charge for the first request in any twelve-month period.

If we say no

We will tell you why, in writing, and you can appeal by replying and saying so. We will answer an appeal within 45 days, in writing, with our reasoning.

If you are still unhappy, you can complain to the New Jersey Division of Consumer Affairs in the Department of Law and Public Safety. We are required to tell you that, and we would rather you knew it than found it out.

12. New Jersey

We are a New Jersey company writing mostly for New Jersey readers, so this is the law that matters most here.

Whether it applies to us

The New Jersey Data Privacy Act, P.L. 2023, c. 266 (S332), N.J.S.A. 56:8-166.4 et seq. applies to a business that, in a calendar year, either controls or processes the personal data of at least 100,000 New Jersey consumers, or at least 25,000 while deriving revenue or a discount from selling personal data.

This site is well below both, and the second cannot ever be met, because we do not sell personal data at all. So the Act’s main obligations do not currently bind us.

We follow it anyway. The rights in section 11 above are the NJDPA’s rights, the 45-day deadline is its deadline, and the appeal route with the referral to the Division of Consumer Affairs is what it requires. Building the site to comply now means nothing has to change if it grows, and it is the way we would want to be treated.

The one part that binds us regardless of size

An amendment in P.L. 2026, c. 25 (A5328), approved June 30, 2026, amending N.J.S.A. 56:8-166.12 added a prohibition on selling sensitive data that applies, in its own words, regardless of how many consumers a business handles. There is no threshold and no consent exception.

We comply with it completely and easily: we sell no data of any kind, sensitive or otherwise. Nor do we knowingly collect most of what New Jersey counts as sensitive — no health data, no precise location, no biometrics, no immigration status, no financial account credentials.

The nearest thing is your birthday month, and we deliberately arranged for that never to reach us at all. See section 4.

Enforcement

The New Jersey Attorney General enforces the Act. It gives individuals no private right of action, which is a fact about the law and not a limitation we are imposing — you can still complain to the Division of Consumer Affairs, and you should.

13. California

The California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (as amended by the CPRA) applies to a business that meets at least one of three tests: annual gross revenue above a threshold that is adjusted for inflation and currently stands at $26,625,000; buying, selling or sharing the personal information of 100,000 or more consumers or households a year; or deriving 50% or more of its revenue from selling or sharing personal information.

This site meets none of them, so the CCPA does not currently apply to us.

California visitors get the same rights as everyone else under section 11 regardless. On the two things Californians usually look for:

If we ever start selling or sharing — we have no plan to — this policy changes first, and the link goes up with it.

14. Europe, the UK and everywhere else

The site is written for people shopping in the United States. Prices are in dollars, the content is US circulars and US benefit programmes, there is no other-language version, we do not advertise anywhere in Europe or the UK, and we do not ship anything anywhere.

On that basis we have assessed that the Regulation (EU) 2016/679 (GDPR), Article 3 and Recital 23 does not apply to this site. Article 3(2) reaches a company outside the EU only where it is offering goods or services to people in the Union or monitoring their behaviour there, and Recital 23 says in terms that a website merely being reachable from the Union is not enough to show that intention. The EDPB, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), version 2.1, 12 November 2019 puts it directly: where a service reaches someone in the Union incidentally, the processing is outside the GDPR’s scope. The UK’s equivalent test works the same way.

The second limb — monitoring behaviour — is the one that catches most US sites that pass the first. It does not catch us, because there is nothing here doing any monitoring: no analytics, no advertising pixels, no profiling. See section 5.

We have therefore not appointed a representative in the EU or the UK, since that obligation only arises where Article 3(2) does.

This is a decision, not an assumption, and it has a trigger list. It gets re-examined if any of these change: prices or payments in euros or pounds; an EU- or UK-language version of the site; advertising or search spend targeted at an EU or UK audience; EU or UK customer testimonials, or naming EU or UK users; any analytics, ad pixel, remarketing tag or profiling that tracks visitors.

If you are in Europe or the UK and you want to know what we hold about you, or want it deleted, just ask. We are not going to argue about jurisdiction with somebody who wants their data out of a database.

15. Children

This site is not for children and is not designed to appeal to them. There is no child-directed content here: it is grocery prices, benefit eligibility and coupon rules, written for adults doing the shopping. You must be at least 13 to use it, and at least 18 to agree to the terms.

We do not knowingly collect personal information from anyone under 13. We do not ask anyone’s age — the rule does not require us to, and asking would mean collecting one more thing about everybody in order to protect a few. So we will not discover it unless someone tells us. If we do learn that an account or a newsletter address belongs to someone under 13, we delete it and the data with it, without asking for anything in return. Children's Online Privacy Protection Rule, 16 C.F.R. Part 312 (as amended, 90 FR 16918, 22 April 2025; compliance date 22 April 2026) is the rule behind this.

If you are a parent or guardian and you think your child has given us something, email privacy@spendelevated.com and we will deal with it straight away.

New Jersey separately requires a teenager’s own consent before their data is used for targeted advertising, sale or profiling, between 13 and 16. We do none of those things to anybody, at any age.

16. Changes

When this policy changes, the date at the top changes with it. If a change is significant — new information collected, a new company handling it, a new purpose — we will say so plainly on the site, and email account holders and subscribers before it takes effect rather than after.

We will not apply a materially different use to data we already hold without asking you first.

17. Contact

Privacy, and any request under section 11: privacy@spendelevated.com
Anything else: hello@spendelevated.com

Vocally Yours LLC, a New Jersey limited liability company, operator of Spend Elevated.

Sources

Every statement of law on this page was read from a primary source on the date shown. Nothing here is written from memory, which is the same rule the rest of the site follows for prices and programme rules.

Thresholds move. The California figure is adjusted for inflation in odd-numbered years, and New Jersey’s Act has already been amended twice in 2026. Every applicability verdict on this page is as at 2026-09-29 and has to be rechecked, not assumed to hold.

Draft of 2026-09-29. Not reviewed by an attorney, and not legal advice. Assessed as at that date: GDPR does not apply — US-only audience and content, USD only, English only, no EU targeting, and no behavioural tracking to engage the monitoring limb.

California threshold figure verified against the CPPA’s own inflation-adjustment notice on 2026-09-29.