Privacy
What we store, who sees it, how to get it deleted.
Last updated: 2026-07-25
Controller
CurlShip is run by Marcin Dudek, an indie developer (marcindudek.dev). Contact for privacy requests, access, erasure, and takedowns: [email protected].
What we collect
When you submit a listing (via POST /api/submit or the web form), we store:
- Email — the only personal datum. Required so you can prove ownership of the listing and so we can contact you about it.
- Product URL and scraped Open Graph fields (title, description, image).
- Listing metadata — tier, badge status, status, timestamps, and (for paid tiers) a DodoPayments subscription id.
Your email is never shown publicly. It does not appear on the directory, listing pages, API responses, or feeds.
IP addresses are held in memory only, in per-IP rate-limiter dictionaries, for at most one hour. They are never written to disk and never stored in the database.
What we do not collect
CurlShip sets zero cookies. We do not run advertising pixels, social trackers, or fingerprinting scripts. Card and payment details never touch our servers — they go straight to the Merchant of Record.
Why we process your data
- Contract — to create and keep your listing live, and to deliver a paid-tier subscription you bought.
- Legitimate interest — to operate the directory, fight spam/abuse, and apply per-IP rate limits.
Who else sees the data
- DodoPayments — Merchant of Record for paid tiers. They process card data; we only keep a
dodo_subscription_idand pass your email as the checkout customer. - Umami analytics — self-hosted at
mws03-52117.wykr.es. Cookieless, no cross-site tracking, no personal data. - Cloudflare — CDN and reverse proxy in front of the origin.
- Outsider (mikr.us) — mail host for
[email protected]. Used when you write to us; we do not send automated transactional email.
Retention
Active listings (and their email) stay for as long as the listing is active. On an erasure request to [email protected], we delete the listing and the email. Subscription records may be retained by the Merchant of Record for as long as tax and accounting rules require. In-memory rate-limit data expires within one hour.
Your rights
Under GDPR (Arts. 15–21) you can request: access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. You also have the right to lodge a complaint with a supervisory authority in your country of residence. Write to [email protected] — no form, no ticket queue.
Changes
If this notice changes in a material way, we will update the date at the top of this page. Continued use of CurlShip after that date means you accept the updated notice.
Questions? [email protected]