Legal
Privacy Policy
Last updated: July 29, 2026
LiftRadar is a price-comparison site for supplements and energy drinks. We do not sell the products we list; purchases happen on the retailer's own site. This policy explains what we collect, why, and what you can do about it.
What we collect
If you create an account: your email address, a salted hash of your password (we cannot read the password itself), your first and last name, and the date you created the account and accepted our terms. Your name is never shown publicly. It appears on your own account page, in email we send you, and to our administrators.
Your watchlist: the products you asked us to watch, any target price you set, and your alert preference.
Your lists and stack: if you use Collections, My Stack or the Shopping Planner, we store the products you added, any notes you wrote, and the servings and schedule figures you entered. None of this is a purchase record. LiftRadar cannot see what you buy, does not receive purchase data from retailers, and never infers a purchase from a click.
Your preferences: if you set interests or preferred retailers, we store those choices. They change which sections you are shown. They never change a price or a ranking, which are identical for everybody.
Saved comparisons: the products you compared and the priorities you selected.
Product interactions: we record which products are viewed, favourited, compared, added to a stack or collection, and which retailer links are followed, along with the part of the site the action came from and a coarse device category (phone, tablet or desktop). If you are signed in, the event is linked to your account; if you are not, it carries a random session identifier that is derived from nothing about you and disappears when your session cookie does. We do not store your IP address with these events (the table has no column for one) and we never store your browser's user-agent string, only the coarse category.
Sign-in activity: when you sign in, we record the time, the method (password or emailed link) and the IP address the request came from. This is the "recent sign-ins" list on your account page, and it exists so you can spot a sign-in you don't recognise.
Outbound clicks: when anyone follows a "View deal" link to a retailer, we record the product, store, price, category, which part of the site the click came from, and the time. If you are signed in, the click is linked to your account.
Server logs: like any website, our hosting provider records ordinary request logs, which include IP addresses. We also use IP addresses in memory, without storing them, to rate-limit abusive traffic.
Cookies
We set one first-party cookie: the session cookie that keeps you signed in. It is HttpOnly and, in production, Secure. It also carries the random session identifier described above, which links a visit's product interactions to each other and to nothing else. We do not use third-party analytics, advertising trackers, or cross-site tracking cookies, which is why you are not seeing a cookie consent banner.
Why we collect it
Your email address and watchlist exist to send the price alerts you asked for. Sign-in records exist so you can audit access to your own account. Click records tell us which deals and retailers are actually useful, and they are how affiliate commissions are attributed. We do not build advertising profiles.
Who else processes it
We use a small number of service providers, and they only handle what they need to do their job:
- Resend: sends our email, so it processes your email address and message contents.
- SendGrid (Twilio): our standby email provider, kept configured as a fallback; it processes the same email address and message contents whenever it is the one delivering.
- Our hosting provider: runs the site and stores the database, and keeps ordinary server logs.
- Sentry: receives technical error reports when something breaks, which can include request details. It is only enabled when configured.
- Retailers and affiliate networks: when you follow an outbound link, they see that a visit came from LiftRadar. They do not receive your email address or your account identity from us.
We do not sell or rent your personal information. Using service providers like the ones above is not the same as selling data: they act on our instructions and are not permitted to use your information for their own purposes.
How long we keep it
Account information stays until you delete your account. Outbound-click records are deleted after 180 days, and product interaction events after 180 days.
Deleting your account removes your profile, watchlist, collections, stack, saved comparisons and preferences.
One exception worth stating plainly: our email delivery log keeps a record of messages we sent, including the address they went to, and that log is not erased when an account is deleted. We keep it so we can show that a message was or was not sent, and so that unsubscribe requests continue to be honoured.
Your choices
From your account page you can:
- download everything we hold about your account as a JSON file;
- change or pause which emails you receive;
- delete your account.
Deleting is immediate and permanent. Your account, watchlist and sign-in history (including the stored IP addresses) are erased, and your past clicks are unlinked from you so only anonymous totals remain. As noted above, the email delivery log is retained.
If you would like help with any of this, or want to ask what we hold, email us at [email protected] and we will respond as quickly as we reasonably can.
Price alerts, newsletters and digests are optional and every one of them carries a working unsubscribe link that does not require you to sign in. If you opt out, we stop sending that kind of email. Account emails (verification, password resets and security notices) are transactional: we send those regardless of your marketing preferences, because they are part of running your account.
Children
LiftRadar is intended for adults and is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will remove it.
Security
Passwords are stored only as salted hashes, sign-in tokens are stored hashed, the site is served over HTTPS in production, and access to the admin tools is restricted. No website can promise perfect security, and we do not. If we ever become aware of a breach affecting your information, we will act on it and notify affected users where the law requires it.
Changes
If we change this policy we will update the date at the top of this page.
How to reach us
LiftRadar · 323 Shepherd St, Jonestown, PA 17038 · [email protected]