Privacy Policy
What we collect, where it lives, who else sees it, and what you can make us do about it. Written from the actual code, not from a template.
This document has not been reviewed by an attorney. It is a working draft prepared so that a lawyer has something complete to mark up. Do not rely on it as a statement of your rights or of ours, and do not treat it as legal advice.
Drafted 2026-09-29.
1. The short version
You can use almost all of this site without telling us anything. There is no tracking, there are no advertising pixels, there are no analytics, and we set no cookies of our own — which is why you have never seen a cookie banner here.
If you make an account, we hold your email address and the lists you save. If you subscribe, we hold your email address. If you report a wrong price, we hold what you told us. That is close to all of it.
Your birthday month never reaches us at all. It stays in your browser. There is no column for it in our database, deliberately.
We have never sold anyone’s personal data, we do not do it now, and the site has no mechanism for doing it.
2. Who we are
Spend Elevated is a product of Vocally Yours LLC, a New Jersey limited liability company. Spend Elevated is a product name rather than a company, so the organisation responsible for your information is Vocally Yours LLC. It is the controller of the information described here: the one who decides what is collected and why, and the one you complain to.
Privacy questions go to privacy@spendelevated.com.
3. What we collect, and why
This is the whole list. Each row names the table or the file it was checked against on 2026-09-29, so you can hold us to it rather than take our word for it.
| What | Why | Where it lives | How long |
|---|---|---|---|
| Your email address, if you create an account | It is the whole of your account. Sign-in is a one-time link emailed to you, so the address is both your identifier and the way you prove it is you. | Supabase Auth (auth.users), mirrored to public.profiles.email | Until you ask us to delete the account. Deleting the auth user cascades to profiles, saved lists and saved items. |
| Your saved lists and the items on them | So a list you make on your phone is there on your laptop. | public.saved_lists, public.saved_items | Until you delete the list, the item, or the account. |
| Which loyalty and birthday programmes you have ticked as joined or claimed | So the site stops suggesting a programme you already joined, and can tell you whether you have collected this year's birthday reward. | public.program_enrollments | Until you delete the account. |
| Your email address, if you subscribe to the newsletter | To send you the weekly email you asked for. | Resend audience (api.resend.com) | Until you unsubscribe. Unsubscribing is honoured for good, not just for a while. |
| A correction you report on a deal — and your email address only if you choose to add it | A reader spotting a wrong price is the most useful thing that happens on this site. The email is only so we can come back to you, and the form works fine without it. | public.deal_reports (reporter_email is nullable and optional) | Kept as a quality record. No deletion schedule is set yet — see the note below. |
| A takedown or rights complaint you submit | A legal notice has to be recorded, actioned and kept — including your contact details and your statements, because those are part of the notice. | public.takedown_requests | Kept as a legal record, including after the complaint is resolved. This is one place where a deletion request may have to be refused. |
| A ZIP code you type into the deal or trip search | Weekly circulars are local. Without a ZIP there is nothing to show you. | Sent as a `zip` query-string parameter and used for that request only. Not written to any table and not tied to your account. | Not stored by us. It appears in the URL, so it will be in Vercel's request logs for as long as Vercel keeps those. |
Beyond that, our host keeps ordinary server logs — your IP address, which page you asked for, the time, and what your browser said it was. Every website has these. We use them to keep the site up and to notice when something is being attacked, and we do not use them to build a picture of you.
4. What never leaves your browser
This is the genuinely unusual part of this policy and it is worth reading. Some of what the site remembers about you is stored only in your own browser. It is not sent to us, we cannot see it, it is not in our backups, and it cannot be handed over in response to a support request or a subpoena, because we do not have it.
| What | Why it is here and not there | Where in your browser |
|---|---|---|
| Your birthday month | It filters the birthday-rewards page to the month you care about. There is no column for it anywhere in our database and it is never sent to us — a month kept in one browser cannot leak from an account, a backup or a support query. | localStorage key "spendelevated.birthmonth.v1" |
| Saved lists, when you are signed out | So you can save things without making an account at all. | localStorage key "spendelevated.lists.v1" |
| Programme ticks, when you are signed out | Same reason: no account needed to tick a box. | localStorage key "spendelevated.programs.v1" |
| A marker recording that the copy-up above has already happened | So signing in twice does not redo the copy. | localStorage key "spendelevated.programsmerged.<your user id>" |
| Your sign-in session, if you have an account | So you stay signed in between pages and visits. | localStorage key "sb-<project>-auth-token", set by the Supabase client library |
To clear any of it, clear this site’s data in your browser settings. You do not need to ask us and we cannot do it for you.
One consequence worth being straight about: because these live in one browser, they do not follow you to another device, and clearing your browsing data will lose them. That is the trade-off we chose on purpose.
5. What we don’t do
Stated as flatly as we can, because these are the things people assume:
- We do not sell your personal data. Not for money, and not for anything else of value.
- We do not share it for advertising. There is no ad network here and no audience being built out of you.
- We run no analytics. No Google Analytics, no Plausible, no first-party event tracking. We genuinely do not know which pages you looked at.
- We set no cookies of our own. Your sign-in session is kept in your browser’s local storage, not in a cookie.
- We do not profile you or make automated decisions about you.
- We do not track you across other sites. There is no pixel, no tag and no remarketing.
One honest exception to “no third parties in your browser”: the site loads its two typefaces from Google Fonts, so your browser makes a request to Google on each page load and Google sees your IP address. See the table below. Self-hosting those fonts would remove it, and that is on our list.
6. Who else touches it
We use a small number of companies to run the site. They act on our instructions, for our purposes — they are processors, not people we sell to.
The column that matters most is the last one. Where it says our server, your own browser never contacts that company at all: we fetch the data on the server and send you the result, so visiting a page does not expose you to them.
| Who | What for | What reaches them | Contacted by |
|---|---|---|---|
| Supabase | Database and sign-in | Your email address, your saved lists and items, your programme ticks, deal reports and takedown notices. | both |
| Vercel | Hosting | Whatever any web host sees: your IP address, the page you asked for and your browser's user-agent, in server logs. | your browser |
| Resend | Newsletter delivery | Your email address, and only if you subscribed. | our server |
| Google Fonts | The two typefaces the site is set in | Your browser requests the font files directly from Google, which means Google sees your IP address and user-agent on every page load. We do not control that request beyond choosing to make it, and self-hosting the fonts would remove it. | your browser |
Where our price, product and benefit data comes from is listed in the terms. Those are all fetched by our server. Your browser never talks to them, and they are never told anything about you.
Beyond those, we disclose personal information only where the law requires it, or to protect someone’s safety or our legal rights. If the business is ever sold or merged, this information may transfer with it, and we will say so here before it does.
7. The newsletter
If you subscribe, your address goes to Resend, the service that sends the email, and it is used for the weekly email and nothing else. We do not sell, rent, lend or swap the list, and we will not add you to it because you did something else on the site — making an account does not subscribe you.
Every email carries a one-click unsubscribe link. You never have to email anyone, log in, or explain yourself — the law is specific that an opt-out may not cost you a fee, ask for anything beyond your address, or take more than one reply or one web page, and we have no interest in being the kind of site that makes you fight for it.
CAN-SPAM Act, 15 U.S.C. § 7704 sets the rules we follow: honest sender information, honest subject lines, a working opt-out, and a real postal address in every message. Two of its deadlines are worth stating, because they are promises you can hold us to. An opt-out must be honoured within 10 business days — in practice ours is immediate. And the unsubscribe link must keep working for at least 30 days after an email goes out, so an old email in your archive is still a way out.
8. Why we’re allowed to hold it
US state privacy law mostly asks us to be clear about purposes rather than to name a legal basis the way European law does. For completeness, here is the reasoning for each thing:
- Your account. You asked for it. We cannot give you an account without holding the address you sign in with.
- Your lists and programme ticks. Same — they are the service you asked for.
- The newsletter. You consented, by typing your address into the box. You can withdraw that at any time and it is as easy as giving it was.
- Deal reports. You chose to send one. The email address is optional and the form works without it.
- Takedown notices. We have to keep a record of a legal claim made against us, and this is the one place a deletion request may be refused.
- Server logs. Our legitimate interest in keeping the site running and defending it from attack.
9. How long we keep it
Account data lasts as long as the account. Delete the account and the profile row, the lists, the saved items and the programme ticks go with it — that cascade is built into the database, not a manual process someone has to remember.
Newsletter addresses last until you unsubscribe. An unsubscribed address is kept as a suppression record so that we cannot accidentally add you back, which is the one situation where keeping an address is the privacy-protective choice.
Takedown notices are kept as a legal record, including after they are resolved.
An honest gap. Deal reports have no deletion schedule. They are kept as a quality record, and nothing in the code deletes them. Setting a real retention period for these is an open item rather than something this policy is going to pretend is already decided.
10. How it’s protected
Three things that are actually true, rather than a paragraph about how seriously we take security:
- There are no passwords to steal. Sign-in is a one-time emailed link. We hold no password, no password hash and no security answers, so none of those can leak from us or be reused against you somewhere else.
- Row-level security in the database. Every table holding personal data has policies that let a signed-in person read and write only their own rows. The subscriber list and the takedown queue go further: they accept new entries and have no read policy at all, so the key that ships in your browser cannot read a single row back out of either.
- Everything travels over HTTPS.
Not overselling it. Row-level security is a real boundary between accounts, and it is the right one, but it is not encryption of the data at rest by us and it is not a guarantee. Our database and hosting providers hold the data on their infrastructure under their own security arrangements. No system is perfectly secure, and anyone who tells you otherwise is selling something.
11. Your rights, and how to use them
We give everyone the same rights, wherever you live. Sorting people by state so that some get fewer rights is not a thing we want to build.
- Know and access. Ask what we hold about you and get a copy.
- Correct. Tell us something is wrong and we will fix it.
- Delete. Ask us to delete your account and what is attached to it.
- Take it with you. Get your lists in a portable, readable format.
- Opt out of sale, targeted advertising and profiling. Already done: we do none of the three, for anybody.
- No retaliation. Using any of these changes nothing about the service you get. There is nothing to take away.
How to ask
Email privacy@spendelevated.com from the address you signed up with, and say what you want. Sending from the address on the account is how we know it is you — we will not ask you for a document, and we will not create a new record about you in order to verify a request about your records.
We reply within 45 days. If something genuinely needs longer we will tell you inside that first 45 days, explain why, and take up to 45 more. There is no charge for the first request in any twelve-month period.
If we say no
We will tell you why, in writing, and you can appeal by replying and saying so. We will answer an appeal within 45 days, in writing, with our reasoning.
If you are still unhappy, you can complain to the New Jersey Division of Consumer Affairs in the Department of Law and Public Safety. We are required to tell you that, and we would rather you knew it than found it out.
12. New Jersey
We are a New Jersey company writing mostly for New Jersey readers, so this is the law that matters most here.
Whether it applies to us
The New Jersey Data Privacy Act, P.L. 2023, c. 266 (S332), N.J.S.A. 56:8-166.4 et seq. applies to a business that, in a calendar year, either controls or processes the personal data of at least 100,000 New Jersey consumers, or at least 25,000 while deriving revenue or a discount from selling personal data.
This site is well below both, and the second cannot ever be met, because we do not sell personal data at all. So the Act’s main obligations do not currently bind us.
We follow it anyway. The rights in section 11 above are the NJDPA’s rights, the 45-day deadline is its deadline, and the appeal route with the referral to the Division of Consumer Affairs is what it requires. Building the site to comply now means nothing has to change if it grows, and it is the way we would want to be treated.
The one part that binds us regardless of size
An amendment in P.L. 2026, c. 25 (A5328), approved June 30, 2026, amending N.J.S.A. 56:8-166.12 added a prohibition on selling sensitive data that applies, in its own words, regardless of how many consumers a business handles. There is no threshold and no consent exception.
We comply with it completely and easily: we sell no data of any kind, sensitive or otherwise. Nor do we knowingly collect most of what New Jersey counts as sensitive — no health data, no precise location, no biometrics, no immigration status, no financial account credentials.
The nearest thing is your birthday month, and we deliberately arranged for that never to reach us at all. See section 4.
Enforcement
The New Jersey Attorney General enforces the Act. It gives individuals no private right of action, which is a fact about the law and not a limitation we are imposing — you can still complain to the Division of Consumer Affairs, and you should.
13. California
The California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (as amended by the CPRA) applies to a business that meets at least one of three tests: annual gross revenue above a threshold that is adjusted for inflation and currently stands at $26,625,000; buying, selling or sharing the personal information of 100,000 or more consumers or households a year; or deriving 50% or more of its revenue from selling or sharing personal information.
This site meets none of them, so the CCPA does not currently apply to us.
California visitors get the same rights as everyone else under section 11 regardless. On the two things Californians usually look for:
- There is no “Do Not Sell or Share My Personal Information” link on this site. That requirement attaches to businesses that sell or share personal information, and we do neither. A link offering to stop something we never started would be theatre.
- We honour the Global Privacy Control signal by construction: there is no selling, sharing or targeted advertising for it to switch off.
If we ever start selling or sharing — we have no plan to — this policy changes first, and the link goes up with it.
14. Europe, the UK and everywhere else
The site is written for people shopping in the United States. Prices are in dollars, the content is US circulars and US benefit programmes, there is no other-language version, we do not advertise anywhere in Europe or the UK, and we do not ship anything anywhere.
On that basis we have assessed that the Regulation (EU) 2016/679 (GDPR), Article 3 and Recital 23 does not apply to this site. Article 3(2) reaches a company outside the EU only where it is offering goods or services to people in the Union or monitoring their behaviour there, and Recital 23 says in terms that a website merely being reachable from the Union is not enough to show that intention. The EDPB, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), version 2.1, 12 November 2019 puts it directly: where a service reaches someone in the Union incidentally, the processing is outside the GDPR’s scope. The UK’s equivalent test works the same way.
The second limb — monitoring behaviour — is the one that catches most US sites that pass the first. It does not catch us, because there is nothing here doing any monitoring: no analytics, no advertising pixels, no profiling. See section 5.
We have therefore not appointed a representative in the EU or the UK, since that obligation only arises where Article 3(2) does.
This is a decision, not an assumption, and it has a trigger list. It gets re-examined if any of these change: prices or payments in euros or pounds; an EU- or UK-language version of the site; advertising or search spend targeted at an EU or UK audience; EU or UK customer testimonials, or naming EU or UK users; any analytics, ad pixel, remarketing tag or profiling that tracks visitors.
If you are in Europe or the UK and you want to know what we hold about you, or want it deleted, just ask. We are not going to argue about jurisdiction with somebody who wants their data out of a database.
15. Children
This site is not for children and is not designed to appeal to them. There is no child-directed content here: it is grocery prices, benefit eligibility and coupon rules, written for adults doing the shopping. You must be at least 13 to use it, and at least 18 to agree to the terms.
We do not knowingly collect personal information from anyone under 13. We do not ask anyone’s age — the rule does not require us to, and asking would mean collecting one more thing about everybody in order to protect a few. So we will not discover it unless someone tells us. If we do learn that an account or a newsletter address belongs to someone under 13, we delete it and the data with it, without asking for anything in return. Children's Online Privacy Protection Rule, 16 C.F.R. Part 312 (as amended, 90 FR 16918, 22 April 2025; compliance date 22 April 2026) is the rule behind this.
If you are a parent or guardian and you think your child has given us something, email privacy@spendelevated.com and we will deal with it straight away.
New Jersey separately requires a teenager’s own consent before their data is used for targeted advertising, sale or profiling, between 13 and 16. We do none of those things to anybody, at any age.
16. Changes
When this policy changes, the date at the top changes with it. If a change is significant — new information collected, a new company handling it, a new purpose — we will say so plainly on the site, and email account holders and subscribers before it takes effect rather than after.
We will not apply a materially different use to data we already hold without asking you first.
17. Contact
Privacy, and any request under section 11: privacy@spendelevated.com
Anything else: hello@spendelevated.com
Vocally Yours LLC, a New Jersey limited liability company, operator of Spend Elevated.
Sources
Every statement of law on this page was read from a primary source on the date shown. Nothing here is written from memory, which is the same rule the rest of the site follows for prices and programme rules.
- New Jersey Data Privacy Act, P.L. 2023, c. 266 (S332), N.J.S.A. 56:8-166.4 et seq.https://pub.njleg.state.nj.us/Bills/2022/PL23/266_.PDFApplicability thresholds (N.J.S.A. 56:8-166.5), the definitions of 'consumer' and 'sale' (56:8-166.4), consumer rights (56:8-166.10), the 45-day response deadline and the appeal process (56:8-166.7), sensitive-data opt-in consent (56:8-166.12), and enforcement with no private right of action (56:8-166.19).Read 2026-09-29.
- P.L. 2026, c. 25 (A5328), approved June 30, 2026, amending N.J.S.A. 56:8-166.12https://pub.njleg.state.nj.us/Bills/2026/AL26/25_.HTMThe new N.J.S.A. 56:8-166.12(a)(6) ban on SELLING sensitive data, which by its own terms applies 'regardless of the number of consumers' — i.e. it binds this site today, below every threshold, and has no consent exception. Also the data broker / data collector registration regime at 56:8-166.20 to -166.24.Read 2026-09-29.
- P.L. 2025, c. 367 (A5017), approved January 20, 2026, amending N.J.S.A. 56:8-166.13https://pub.njleg.state.nj.us/Bills/2024/AL25/367_.PDFConfirming that the 2026 exemption amendments did not move the applicability thresholds.Read 2026-09-29.
- New Jersey Division of Consumer Affairs — proposed NJDPA rules, N.J.A.C. 13:45L, 57 N.J.R. 1101(a)https://www.njoag.gov/murphy-administration-announces-proposed-rules-establishing-comprehensive-consumer-data-privacy-protections/Enforcement authority and rulemaking status. The rules were proposed 2 June 2025 and have NOT been adopted; this policy is drafted to the statute, not to the proposal.Read 2026-09-29.
- California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (as amended by the CPRA)https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140Applicability thresholds in § 1798.140(d): gross revenue, 100,000 consumers or households bought/sold/shared, or 50% of revenue from selling or sharing.Read 2026-09-29.
- California Privacy Protection Agency — CCPA inflation adjustment (Cal. Civ. Code § 1798.199.95(d))https://cppa.ca.gov/regulations/cpi_adjustment.htmlThe current adjusted revenue threshold of $26,625,000, effective 1 January 2025. Adjusted in odd-numbered years; re-check before January 2027.Read 2026-09-29.
- CAN-SPAM Act, 15 U.S.C. § 7704https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title15-section7704&num=0&edition=prelimHonest headers (§ 7704(a)(1)) and subject lines (§ 7704(a)(2)); identification as an advertisement (§ 7704(a)(5)(A)(i)); a valid physical postal address (§ 7704(a)(5)(A)(iii)); a clear and conspicuous opt-out (§ 7704(a)(3)(A)) that stays live for at least 30 days (§ 7704(a)(3)(A)(ii)) and is honoured within 10 business days (§ 7704(a)(4)(A)(i)). There is no small-business exemption.Read 2026-09-29.
- CAN-SPAM Rule, 16 C.F.R. Part 316https://www.ecfr.gov/current/title-16/part-316The primary-purpose test (§ 316.3); what counts as a 'valid physical postal address' — a street address, a USPS-registered PO box, or a CMRA private mailbox (§ 316.2(p)); and the limits on what an opt-out may demand (§ 316.5).Read 2026-09-29.
- FTC Guides Concerning the Use of Endorsements and Testimonials in Advertising, 16 C.F.R. Part 255 (2023 revision, 88 FR 48092)https://www.ecfr.gov/current/title-16/part-255Material-connection disclosure (§ 255.5(a)) and the affiliate-link example (§ 255.5(b)(11)); the definition of 'clear and conspicuous', which requires a disclosure online to be 'unavoidable' (§ 255.0(f)); and § 255.4(b)(3) Example 3, which holds that paid-for rankings are deceptive whether or not they are disclosed.Read 2026-09-29.
- N.J.S.A. 9:17B-3 (age of majority; no disaffirmance because of minority)https://www.nj.gov/dca/codes/publications/pdf_lti/legal_age_req.pdfWhy the Terms ask for 18 to agree: below it, a person's assent to a contract may be disaffirmed. Read from a NJ state-agency reproduction of the statute rather than the Legislature's own database, which could not be queried — flagged in the attorney memo.Read 2026-09-29.
- Digital Millennium Copyright Act, 17 U.S.C. § 512https://www.law.cornell.edu/uscode/text/17/512Notice-and-takedown elements, counter-notice, misrepresentation liability.Read 2026-09-29.
- Designation of agent to receive notification of claimed infringement, 37 C.F.R. § 201.38https://www.ecfr.gov/current/title-37/chapter-II/subchapter-A/part-201/section-201.38That registration is electronic-only (§ 201.38(c)), expires after three years (§ 201.38(c)(4)), and needs a physical street address (§ 201.38(b)(1)(i)).Read 2026-09-29.
- Copyright Office fee schedule, 37 C.F.R. § 201.3(c)(25)https://www.ecfr.gov/current/title-37/chapter-II/subchapter-A/part-201/section-201.3The $6 fee to designate an agent, or to amend or resubmit a designation. Corroborated by https://www.copyright.gov/about/fees.html, read the same day.Read 2026-09-29.
- EDPB, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), version 2.1, 12 November 2019https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdfThat a service inadvertently or incidentally reaching someone in the Union is outside the GDPR's territorial scope, and the factor list for deciding whether a site targets the Union.Read 2026-09-29.
- Children's Online Privacy Protection Rule, 16 C.F.R. Part 312 (as amended, 90 FR 16918, 22 April 2025; compliance date 22 April 2026)https://www.ecfr.gov/current/title-16/part-312That 'child' means under 13 (§ 312.2) and that the Rule reaches a general-audience site only on actual knowledge (§ 312.3), plus the requirement in § 312.10 that children's data not be kept indefinitely.Read 2026-09-29.
- Regulation (EU) 2016/679 (GDPR), Article 3 and Recital 23https://eur-lex.europa.eu/eli/reg/2016/679/ojWhether the GDPR reaches a US-only site that happens to be reachable from the EU.Read 2026-09-29.
Thresholds move. The California figure is adjusted for inflation in odd-numbered years, and New Jersey’s Act has already been amended twice in 2026. Every applicability verdict on this page is as at 2026-09-29 and has to be rechecked, not assumed to hold.
Draft of 2026-09-29. Not reviewed by an attorney, and not legal advice. Assessed as at that date: GDPR does not apply — US-only audience and content, USD only, English only, no EU targeting, and no behavioural tracking to engage the monitoring limb.
California threshold figure verified against the CPPA’s own inflation-adjustment notice on 2026-09-29.

