← Back to directory

Privacy

What we store, who sees it, how to get it deleted.

Last updated: 2026-08-11


Controller

CurlShip is run by Marcin Dudek, an indie developer (marcindudek.dev). Contact for privacy requests, access, erasure, and takedowns: [email protected].

What we collect

When you submit a listing (via POST /api/submit or the web form), we store:

  • Email — the only personal datum. Required so you can prove ownership of the listing and so we can contact you about it.
  • Product URL and scraped Open Graph fields (title, description, image).
  • Listing metadata — tier, badge status, status, timestamps, and (for paid tiers) a DodoPayments subscription id.

Your email is never shown publicly. It does not appear on the directory, listing pages, API responses, or feeds.

IP addresses used for rate limiting are held in memory only, in per-IP dictionaries, for at most one hour, and are never written to disk.

One exception: if you use the self-service edit flow, the IP that asked for the change is stored with the edit record (legitimate interest — an edit to someone else's listing has to be traceable). Everything else about that flow is listed under Edit records below.

What we do not collect

CurlShip sets zero cookies. We do not run advertising pixels, social trackers, or fingerprinting scripts. Card and payment details never touch our servers — they go straight to the Merchant of Record.

Why we process your data

  • Contract — to create and keep your listing live, and to deliver a paid-tier subscription you bought.
  • Legitimate interest — to operate the directory, fight spam/abuse, and apply per-IP rate limits.

Who else sees the data

  • DodoPayments — Merchant of Record for paid tiers. They process card data; we only keep a dodo_subscription_id and pass your email as the checkout customer.
  • Umami analytics — self-hosted at mws03-52117.wykr.es. Cookieless, no cross-site tracking, no personal data.
  • Cloudflare — CDN and reverse proxy in front of the origin.
  • Outsider (mikr.us) — mail host for [email protected]. Used when you write to us, and to send the confirmation and change-notice emails of the self-service edit flow. We send no marketing email and run no mailing list.

Edit records

Changing a listing through the self-service flow writes two things: a pending request (listing id, what you asked to change, a one-time token, your IP) and, once applied, an audit row per changed field with the old and new value. Both are kept for as long as the listing exists — they are what makes an unwanted change provable and reversible. Erasing the listing erases them too.

Retention

Active listings (and their email) stay for as long as the listing is active. On an erasure request to [email protected], we delete the listing and the email. Subscription records may be retained by the Merchant of Record for as long as tax and accounting rules require. In-memory rate-limit data expires within one hour.

Your rights

Under GDPR (Arts. 15–21) you can request: access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. You also have the right to lodge a complaint with a supervisory authority in your country of residence. Write to [email protected] — no form, no ticket queue.

Changes

If this notice changes in a material way, we will update the date at the top of this page. Continued use of CurlShip after that date means you accept the updated notice.


Questions? [email protected]

← Back to directory