Legal
Privacy Policy
Last updated: July 29, 2026
LiftRadar is a price-comparison site for supplements and energy drinks. We do not sell the products we list; purchases happen on the retailer's own site. This policy explains what we collect, why, and what you can do about it.
What we collect
If you create an account: your email address, a salted hash of your password (we cannot read the password itself), your first and last name, and the date you created the account and accepted our terms. Your name is never shown publicly. It appears on your own account page, in email we send you, and to our administrators.
Your watchlist: the products you asked us to watch, any target price you set, and your alert preference.
Your lists and stack: if you use Collections, My Stack or the Shopping Planner, we store the products you added, any notes you wrote, and the servings and schedule figures you entered. None of this is a purchase record. LiftRadar cannot see what you buy, does not receive purchase data from retailers, and never infers a purchase from a click.
Your preferences: if you set interests or preferred retailers, we store those choices. They change which sections you are shown. They never change a price or a ranking, which are identical for everybody.
Saved comparisons: the products you compared and the priorities you selected.
Product interactions: we record which products are viewed, favourited, compared, added to a stack or collection, and which retailer links are followed, along with the part of the site the action came from and a coarse device category (phone, tablet or desktop). If you are signed in, the event is linked to your account; if you are not, it carries a random session identifier that is derived from nothing about you and disappears when your session cookie does. We do not store your IP address with these events (the table has no column for one) and we never store your browser's user-agent string, only the coarse category.
Sign-in activity: when you sign in, we record the time, the method (password or emailed link) and the IP address the request came from. This is the "recent sign-ins" list on your account page, and it exists so you can spot a sign-in you don't recognise.
Outbound clicks: when anyone follows a "View deal" link to a retailer, we record the product, store, price, category, which part of the site the click came from, and the time. If you are signed in, the click is linked to your account.
Server logs: like any website, our hosting provider records ordinary request logs, which include IP addresses. We also use IP addresses in memory, without storing them, to rate-limit abusive traffic.
Cookies and analytics
Our own cookie. We set one first-party cookie ourselves: the session cookie that keeps you signed in. It is HttpOnly and, in production, Secure. It also carries the random session identifier described above, which links a visit's product interactions to each other and to nothing else. When you make a choice about the analytics banner below, we also store that choice in a small first-party cookie so we do not ask again.
Google Analytics. We use Google Analytics 4 to understand which pages and categories people find useful, in aggregate. It loads on every page but starts in a consent-denied mode that sets no cookies and sends only anonymous, cookieless signals. The first time you visit, a banner asks whether you agree to analytics cookies:
- If you decline (or your browser sends a Global Privacy Control or Do Not Track signal), no analytics cookie is ever set.
- If you accept, Google Analytics sets its own cookies (named
_gaand_ga_<id>) to recognise a returning browser for up to 24 months. You can change this decision at any time from the "Cookie settings" link in the footer.
Google Analytics is configured with IP anonymisation. We have not enabled Google Signals, advertising features, or data sharing with other Google products, and Google acts as our service provider and may not use this data for its own purposes. We configure Google to retain this analytics data for 14 months. We use no other third-party analytics, advertising trackers, or cross-site tracking cookies.
Why we collect it
Your email address and watchlist exist to send the price alerts you asked for. Sign-in records exist so you can audit access to your own account. Click records tell us which deals and retailers are actually useful, and they are how affiliate commissions are attributed. We do not build advertising profiles.
Who else processes it
We use a small number of service providers, and they only handle what they need to do their job:
- Resend: sends our email, so it processes your email address and message contents.
- SendGrid (Twilio): our standby email provider, kept configured as a fallback; it processes the same email address and message contents whenever it is the one delivering.
- Our hosting provider: runs the site and stores the database, and keeps ordinary server logs.
- Sentry: receives technical error reports when something breaks, which can include request details. It is only enabled when configured.
- Google (Google Analytics): receives anonymised, aggregated usage data (pages visited, approximate location, device category) so we can see what is useful. It sets cookies only if you accept the analytics banner, and only ever acts on our instructions.
- Retailers and affiliate networks: when you follow an outbound link, they see that a visit came from LiftRadar. They do not receive your email address or your account identity from us.
We do not sell or rent your personal information. Using service providers like the ones above is not the same as selling data: they act on our instructions and are not permitted to use your information for their own purposes.
How long we keep it
Account information stays until you delete your account. Outbound-click records are deleted after 180 days, and product interaction events after 180 days.
Deleting your account removes your profile, watchlist, collections, stack, saved comparisons and preferences.
One exception worth stating plainly: our email delivery log keeps a record of messages we sent, including the address they went to, and that log is not erased when an account is deleted. We keep it so we can show that a message was or was not sent, and so that unsubscribe requests continue to be honoured.
Your choices
From your account page you can:
- download everything we hold about your account as a JSON file;
- change or pause which emails you receive;
- delete your account.
Deleting is immediate and permanent. Your account, watchlist and sign-in history (including the stored IP addresses) are erased, and your past clicks are unlinked from you so only anonymous totals remain. As noted above, the email delivery log is retained.
If you would like help with any of this, or want to ask what we hold, email us at [email protected] and we will respond as quickly as we reasonably can.
Price alerts, newsletters and digests are optional and every one of them carries a working unsubscribe link that does not require you to sign in. If you opt out, we stop sending that kind of email. Account emails (verification, password resets and security notices) are transactional: we send those regardless of your marketing preferences, because they are part of running your account.
Children
LiftRadar is intended for adults and is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will remove it.
Security
Passwords are stored only as salted hashes, sign-in tokens are stored hashed, the site is served over HTTPS in production, and access to the admin tools is restricted. No website can promise perfect security, and we do not. If we ever become aware of a breach affecting your information, we will act on it and notify affected users where the law requires it.
Changes
If we change this policy we will update the date at the top of this page.
How to reach us
LiftRadar · 323 Shepherd St, Jonestown, PA 17038 · [email protected]