Privacy Policy
Last updated: July 11, 2026 · Effective date: July 11, 2026
The short version.
- We don't sell your data. Ever.
- The Vinegar browser extension has no advertising pixels, no ad SDKs, and no cross-site trackers. We don't put them on Amazon, Walmart, Target, or any other supported shopping page either.
- We don't see your shopping cart, your checkout, your receipts, your purchase history, or your payment card numbers.
- We don't build behavioral ad profiles about you, and we don't track you across other websites.
- We run ads to grow Vinegar, so our public marketing website (getvinegar.com) has standard analytics (PostHog) and ad-measurement pixels — only on the marketing site, never inside the extension or on shopping pages, and never fed data from your Vinegar account. Full details in Section 10.
- After you sign up, we measure funnel performance at the cohort level, not per user. We don't call PostHog's identify function on authenticated users, we don't use session replay, and we don't send your account details, Vinegar user ID, or hashed emails to PostHog or advertising platforms. A short campaign label (like “twitter-week14”) is attached to your account so we can look at retention by acquisition source in aggregate — details in §10.3.
- When we use device or IP signals for security, we hash and salt them — the goal is to stop spammers, not to identify or follow you. And we collect what's needed to run accounts, prevent abuse, and keep contributions trustworthy.
This policy explains what Folkward LLC (“Vinegar,” “we,” “us”) collects when you use the Vinegar browser extension, website, and related services (the “Service”), how we use it, and the choices you have.
1. Who we are (controller)
For the purposes of applicable data-protection law (including the EU General Data Protection Regulation (“GDPR”) and the UK GDPR where they apply), the controller of personal information processed under this policy is:
Representative (GDPR Article 27). We value your privacy and your rights as a data subject and have therefore appointed Prighter Group, with its local partners, as our privacy representative and your point of contact for the following regions:
- European Union (EU)
- United Kingdom (UK)
Prighter gives you an easy way to exercise your privacy-related rights (for example, requests to access or erase personal data). To contact us via our representative, or to make use of your data subject rights, please visit:
https://app.prighter.com/portal/15631874945
Data Protection Officer: Folkward LLC has not appointed a Data Protection Officer because the requirements of GDPR Article 37 are not met: we are not a public authority, our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and we do not process special-category personal data or criminal-conviction data on a large scale. If our processing activities materially change such that a DPO becomes required, we will appoint one and update this policy.
2. What we collect — at a glance
The table below summarizes the categories of personal information we process. The sections that follow give the detail.
| Category | Examples | Where it comes from | Why we process it | Recipients / vendors | Retention |
|---|---|---|---|---|---|
| Account identifiers | Email, username, optional profile image URL, email-verification timestamp | You, when you sign up | Operate your account; communicate with you | Hetzner, PlanetScale (hosting/DB) | While account is active; deleted on account deletion (subject to legal retention) |
| Authentication credentials | Password hash; OAuth provider IDs/tokens for "Sign in with Google" | You; Google (if you use Google sign-in) | Authenticate you securely | Google OAuth, Hetzner, PlanetScale | While account is active |
| Anti-abuse / security signals | Browser/device fingerprint or identifier derived from one; salted hash of IP address; truncated user-agent; submission and report metadata; rate-limit counters; contributor reputation; moderation history | Derived from your requests to our servers; submission activity | Detect and prevent spam, scraping, ban evasion, vote manipulation, account abuse | Hetzner, PlanetScale (for our own anti-abuse signals); Cloudflare Turnstile at signup and other abuse-sensitive checkpoints (browser signals processed by Cloudflare, not by us) | Generally months, not years; longer for accounts under active investigation or with repeated violations |
| Community contribution data | Submissions, votes, reports, edit history, comments/notes, avoid lists | You | Run the contribution system; display public contributions; enforce policies | Hetzner, PlanetScale; public contributions visible to other users | Public contributions retained as part of the community record; private contributions until you delete |
| Extension lookup data | Brand name, product identifier, or merchant identifier being looked up; minimal request metadata | The supported shopping page you're on | Return ownership data for the brand you're viewing | Hetzner, PlanetScale | Aggregated/short-lived; not tied to your identity by default |
| Brand History (Premium + opt-in only) | Record of brands you've looked up or searched while the feature is on | The supported shopping page you're on | Show you your own past lookups | Hetzner, PlanetScale | While the feature is enabled and you have Premium; on cancellation/opt-out, see Section 6 |
| Subscription / billing data | Stripe customer ID, subscription status, billing country, last 4/expiration of card (held by Stripe), invoice metadata | Stripe (we don't see your full card number) | Process Premium subscriptions | Stripe | As required by tax, accounting, and consumer-protection laws (typically several years) |
| Communications | Emails and messages to support, feedback and feature requests, correction or DMCA notices, arbitration opt-out requests, appeals; opt-in marketing/product-update emails if you've enabled them | You | Respond to you; handle feedback and support; send product updates only if you opted in; create legal records where applicable | Resend (transactional and opt-in marketing email), Featurebase (support, feedback, changelog), Google Workspace (inbound legal/DMCA) | Reasonable period after the issue is resolved; marketing consent records kept while you're subscribed and for a reasonable audit period after; legal records retained per Section 13 |
| Legal records | Arbitration opt-out attempts (including the original email and our confirmation), DMCA notices and counter-notices, formal legal correspondence | You; our systems | Maintain an evidentiary record for the duration of any potential dispute | Resend (intake/confirmation), Google Workspace, Hetzner, PlanetScale | Indefinite, or as required by applicable statutes of limitation, whichever is longer |
| Marketing-website analytics | Standard visit data collected when you visit our public marketing website (getvinegar.com): IP address, browser/device information, pages viewed, referrer, campaign source. Not collected inside the extension or on supported shopping pages. Not linked to your Vinegar account. | Visitors to our marketing website | Understand website traffic, measure whether our ads are working, improve the site | PostHog (product analytics, anonymous); advertising platforms via measurement pixels — marketing website only. See Section 10 | Aggregated and generally short-lived; anonymous (not tied to your Vinegar account). See Section 10 |
3. The data we collect — in detail
3.1 Account data
When you create an account, we collect:
- email address
- username
- password hash (we never see your plaintext password)
- optional profile image URL
- email-verification timestamp
- if you sign in with Google: the OAuth provider account ID and tokens needed to authenticate you
3.2 Anti-abuse and security data
To keep contributions trustworthy and stop spam, scraping, vote manipulation, and account abuse, we collect and store:
- a browser/device fingerprint or identifier derived from one - used only to detect duplicate accounts, ban evasion, and automated abuse;
- a salted hash of your IP address - we don't keep raw IPs in our regular records; the hash lets us recognize repeat abuse without retaining your address;
- truncated user-agent strings - enough to recognize browsers/platforms for compatibility and abuse signals, not enough to fingerprint you precisely;
- submission and report metadata (timestamps, what was submitted, what was reported);
- contributor reputation and tier;
- moderation history (warnings, removals, restrictions);
- rate-limit counters used to detect unusual activity.
See Section 4 for a fuller explanation of how fingerprinting works at Vinegar, what we don't do with it, and how to appeal a false positive.
3.3 Community and contribution data
When you contribute to the Service, we store:
- your submissions (claims, sources, edits)
- your votes
- reports you file
- edit history on entries you've touched
- moderation actions taken on your contributions
- comments or notes attached to contributions
- avoid lists (the companies you've chosen to flag for yourself)
Public contributions - like submitted ownership claims, sources, votes, and edit history - may be visible to other users alongside your username. Private contributions like avoid lists are visible only to you.
3.4 Extension and lookup data
To run the extension and our APIs, we use:
- short-lived JWT or session tokens for authentication;
- local storage in your browser (we prefer local-first where it makes sense);
- a local cache of ownership data so the extension can answer quickly without re-querying every time;
- the brand, product identifier, or merchant identifier being looked up on a supported shopping page, which is sent to our servers along with minimal auth/abuse metadata.
See Section 5 for what the extension does locally on your device versus on our servers, and what we don't transmit.
3.5 Payment data (Premium)
If you subscribe to Premium, payments are handled by Stripe. Stripe collects and processes your payment details directly under Stripe's privacy policy. We receive a customer ID, subscription status, billing country, and limited transaction metadata - we never see or store your full card number.
3.6 Brand History (Premium + opt-in only)
Brand History is a Premium feature that is off by default. We only store a Brand History record when both of the following are true:
- You have an active Vinegar Premium subscription, and
- You have explicitly opted in to Brand History from your settings.
When both are true, we log the brands you look up or search for through the extension so you can review your own history later.
If either condition stops being true - you cancel Premium, or you opt out of Brand History - we stop logging new lookups immediately.
See Section 6 for what happens to your existing Brand History entries when Premium ends.
We don't use Brand History for advertising, recommendations to other users, or any purpose other than showing you your own history.
3.7 Communications
If you email us, file a report, submit a correction, send a DMCA notice, request support, or share feedback or a feature request, we keep that correspondence so we can respond and improve the Service. Support, feedback, feature requests, and changelog communications are handled through Featurebase. Legal and DMCA correspondence is handled through Google Workspace. Transactional and (with your consent) product-update emails are sent via Resend.
3.8 Marketing communications (opt-in only)
We may send occasional marketing and product-update emails — things like changelogs, feature announcements, product news, and important updates about Vinegar. These are separate from transactional and service emails, which we send regardless (billing confirmations, security notices, legal notices, and similar).
At signup, you can opt in to marketing emails via a clearly labeled checkbox. The checkbox is unchecked by default.
Existing users are opted out by default. If you had an account before we introduced this feature, we will not enroll you automatically. You can opt in at any time from Settings → Notifications.
You can opt in or out at any time from Settings → Notifications, or by clicking the unsubscribe link at the bottom of any marketing email. Unsubscribing stops all marketing categories, not just one.
Unsubscribing takes effect promptly — typically within a few business days at the outside, and usually within minutes.
We keep a record of your consent (whether you opted in, when, and where) so we can honor your choices and demonstrate compliance if asked.
We don't use data from your Vinegar account, your extension activity, your Brand History, or your avoid list to target marketing emails — the content is the same for everyone who opts in.
4. Fingerprinting and device identifiers — in plain English
What we collect. A “fingerprint” or device identifier in this context means a value we derive from a small set of signals visible to your browser when you connect to our servers - for example, a salted hash of your IP address, a truncated user-agent string, and selected browser characteristics that are stable enough to recognize repeat abuse but not granular enough to single out individuals across the web. We may also assign a server-side identifier to a session that we cluster with these signals.
Why we use it. Strictly for security and abuse prevention:
- detecting accounts that are being mass-created;
- detecting users banned for serious violations who are trying to come back under a new account;
- detecting vote manipulation, spam submissions, and scraping;
- protecting the integrity of community contributions and reputation systems.
What we don't do. We do not use fingerprints, IP hashes, or user-agent strings to:
- show you ads;
- build advertising or behavioral profiles;
- share with ad networks, data brokers, or marketing partners;
- follow you across other websites.
Vendors. We perform most anti-abuse fingerprinting in-house, on infrastructure operated by Hetzner and PlanetScale. We use Cloudflare Turnstile at specific abuse-sensitive moments — currently signup, and potentially other high-risk actions like rapid-sequence contribution submissions — to distinguish humans from automated traffic. Turnstile performs its check in the user's browser and returns a pass/fail token to us; the browser signals it uses to make that decision (things like screen size, canvas rendering, and TLS handshake patterns) are processed by Cloudflare, not by us. We do not use Turnstile for advertising, cross-site tracking, or profiling.
Aside from Turnstile at those specific checkpoints, we do not use a third-party fingerprinting, fraud-prevention, or device-intelligence vendor. If we ever introduce another one, we will update this policy and the subprocessor list before doing so.
Retention. Anti-abuse signals are retained only for as long as we reasonably need them - generally measured in months, not years - and longer only when tied to an active investigation, a repeat-violator profile, or a legal obligation.
Appeals (false positives). Anti-abuse systems are imperfect. If you believe you were incorrectly flagged, restricted, or banned, you can appeal at [email protected]. Tell us what happened and any context that would help us review. We can't always disclose the exact signals that led to a decision (because that would help bad actors evade them), but we will reconsider the outcome.
5. The extension — what's processed where
Permissions. The extension requests only the permissions necessary to do its job: scripting/host permissions limited to supported shopping domains, local storage, and the ability to make network requests to Vinegar's APIs. We do not request permission to read your full browsing history, your tabs on unrelated sites, your cookies on unrelated sites, or your downloads.
Supported pages. The extension activates on Amazon (free tier) and, with Premium, on Walmart and Target. Supported sites may expand over time; the current list is shown in the extension. The extension is designed not to run on pages outside that list except as needed for installation, sign-in, and update flows.
Local on your device:
- the page context the extension reads on a supported site (just enough to identify the brand or merchant being viewed);
- your settings and preferences;
- your avoid list;
- a cache of ownership data so the extension can answer quickly without re-querying;
- your session/auth tokens.
Sent to our servers:
- the brand, product identifier, or merchant identifier that needs to be looked up;
- minimal account/auth signals needed to authenticate the request and prevent abuse (token, anti-abuse signals as described in Section 4);
- if Brand History is enabled and you have Premium, an entry recording that lookup so you can review it later (Section 3.6 / Section 6).
What we do not transmit or store:
- your full URL bar contents (we transmit identifiers extracted from supported pages, not the full URL);
- the full HTML or text content of pages you visit;
- your shopping cart, checkout, receipts, order history, or purchase history;
- your payment card number, CVC, or banking details (Stripe handles payment data; we never see card numbers);
- pages on websites we don't support.
Local storage on your device. The extension stores data in your browser using local storage and similar mechanisms. Clearing extension storage from your browser clears it. Some functionality won't work without local storage.
6. What happens to Brand History when Premium ends
If your Premium subscription ends - whether by cancellation, non-payment, or termination - and you previously had Brand History enabled:
- New lookups stop being recorded immediately.
- Existing entries are handled as follows: Deleted after 7 days unless you resubscribe. We will state and follow the policy in effect at the time your subscription ends; if we change this policy, the change will not retroactively erase data you previously trusted us to keep without notice.
You can clear your Brand History at any time from your settings. Clearing deletes the records.
7. AI and automation in our processing
We may use automated systems, including machine-learning and large-language-model–based systems, to support operation of the Service. Current or anticipated uses:
- Entity matching - linking brand names, product identifiers, and merchant pages to underlying company entities in our index.
- Spam, fraud, and abuse detection - finding patterns in submissions, votes, and reports that suggest manipulation or automation.
- Moderation support - flagging contributions that may violate the Community Guidelines for human review.
- Source-quality analysis - scoring or summarizing public sources, and clustering corroborating sources around a claim.
These systems are decision support. They can be wrong. Where automated output is the basis of a moderation action that meaningfully restricts your account or contributions, you can appeal - see Section 4 (false-positive appeals) and the Terms of Service.
We do not currently use automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Article 22.
Use of contributions for training. We may use User Contributions, in aggregate or de-identified form, to develop and improve our own internal models. We do not sell or license User Contributions to third parties for the purpose of training their AI/ML models, and we do not provide them to third-party model developers for that purpose, except with your express permission or as required by law.
8. How we use data
We use the data described above to:
- run the Service and the features you ask for (authentication, contributions, search, Premium);
- protect the Service, our users, and the community against fraud, abuse, spam, and manipulation;
- moderate User Contributions and enforce our Terms and Community Guidelines;
- process payments and manage subscriptions;
- communicate with you about your account, your contributions, and meaningful product changes;
- diagnose and fix problems, monitor performance, and improve the Service;
- comply with legal obligations and respond to lawful requests.
Legal bases (GDPR / UK GDPR). Where GDPR or UK GDPR applies, our legal bases are:
- Performance of a contract (Article 6(1)(b)): operating your account, providing Premium features you've subscribed to, processing payments.
- Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing fraud and abuse, moderating content, improving the Service, communicating service-related messages. We balance these against your rights and interests; you can object as described in Section 12.
- Consent (Article 6(1)(a)): for Brand History, optional analytics if and when offered, and any feature we describe as opt-in. You can withdraw consent at any time.
- Legal obligation (Article 6(1)(c)): tax, accounting, and similar requirements; responding to lawful legal process.
9. What we don't do
We want this part to be unambiguous:
Our business practices
- We don't sell or rent personal information. Not to advertisers, not to data brokers, not to anyone.
- We don't build advertising or behavioral profiles about you.
- We don't track you across other websites.
Inside the extension and on shopping pages
- We don't put advertising pixels, trackers, or behavioral ad SDKs inside the Vinegar browser extension. (The web sign-in flow lives on getvinegar.com, which is our marketing website — see §10.2 for what runs there.)
- We don't put advertising pixels, trackers, or behavioral ad SDKs on supported shopping pages. The extension doesn't inject them; we don't add them to Amazon, Walmart, Target, or any other supported page.
- We don't see your shopping carts, checkout pages, receipts, order history, or payment card numbers.
- We don't log your purchase history.
Data flow to third parties
- We don't send data from the extension to advertising platforms. Your brand lookups, your Brand History, your avoid list, your account data, your shopping activity — none of it is shared with X, Meta, Google Ads, or any other ad platform.
- We don't use your contributions to train third-party AI models without your permission.
One thing we do do, transparently: we run ads to promote Vinegar to potential new users, and to measure whether those ads work, we use limited advertising measurement pixels on our public marketing website (getvinegar.com). These pixels are only on the marketing website — they are not in the extension, not on supported shopping pages, and not used to gather data from Vinegar users. See Section 10 for the full details.
If we ever change any of these in the future, we'll tell you in advance and update this policy.
10. Cookies, analytics, and marketing
10.1 In the extension and product (Vinegar app and supported shopping pages)
We use a small number of cookies and local-storage entries to keep you signed in, remember your preferences, cache ownership data, and support abuse prevention. We do not use third-party advertising cookies, marketing pixels, behavioral ad SDKs, or cross-site trackers inside the extension or on the shopping pages it supports. You can clear extension storage and cookies through your browser at any time; some functionality may not work without them.
Note: signing in to Vinegar happens on getvinegar.com — see §10.2 for what runs there.
10.2 On our marketing website (getvinegar.com)
Our marketing website is where we describe Vinegar to people who don't have it yet — for example, someone who clicked an ad. On this website only, we use two categories of third-party services:
Product analytics — PostHog. We use PostHog to understand traffic, page performance, feature interest, and conversion rates on the marketing website and the pre-signup funnel. PostHog helps us learn things like: what percentage of visitors click “install,” which pages perform well, and where the site is confusing. PostHog is a service provider that processes this data on our behalf under a data processing agreement; we do not use PostHog to build advertising profiles or to sell data.
Advertising measurement pixels. When we run ads on advertising platforms (currently including X, TikTok, and potentially platforms like Google Ads and Meta in the future), those platforms provide a measurement pixel that we place on our marketing website. Its purpose is to tell the advertising platform when a visitor arrived from one of our ads and whether they took an action we care about (like installing the extension or signing up). This is conversion measurement, not surveillance — it's how anyone running online ads learns whether the ads are worth paying for.
Where pixels are placed. Advertising pixels are placed only on marketing pages that need to measure conversions — the home page, ad landing pages, the pricing page, and the moment you complete the sign-up form. They are not placed on account settings pages, the sign-in page for existing users, dashboard pages, or any authenticated area of getvinegar.com after you sign in.
Technical note. These pixels work the way advertising pixels generally work. When they fire, the advertising platform receives your IP address, browser user-agent, the URL of the page you're on, and — if you arrived from one of our ads — a click identifier that the ad platform assigned to that ad click. They do not receive your email, your username, your Vinegar account details, or any content from the extension. Conversion events are fired client-side (from your browser), not server-side; we do not send hashed emails or user IDs to advertising platforms.
What these services never receive:
- your Vinegar account information (email, username, account ID);
- your brand lookups or search history;
- your Brand History;
- your avoid list;
- your extension activity;
- any content of pages you visit on Amazon, Walmart, Target, or any other supported shopping page;
- anything about your shopping carts, checkouts, receipts, or purchases;
- any data transmitted from our servers to an advertising platform after you sign up.
Why: because these services are not present in the extension or on shopping pages, and they are not fed data from our servers after you sign up. They only run on our marketing website — which is where potential new users learn about Vinegar. The extension itself is a separate technical surface with a separate privacy posture.
10.3 Anonymous funnel measurement (signup and Premium checkout)
After you sign up, we still want to understand how the product funnel is working — for example, what percentage of users visit the Premium page, how many start a checkout, and how many complete it. This helps us improve pricing, messaging, and the checkout experience.
All analytics described in this section only run if you have accepted analytics cookies via our cookie banner, or you are in a region where non-essential cookies are accepted by default. If you have declined or your browser sends Global Privacy Control, none of this loads (see §10.4).
We do not identify you individually to our analytics tools. Specifically:
- We do not call
posthog.identify()on authenticated users. To PostHog, the sequence “someone visited the Premium page → someone started checkout → someone completed checkout” is an anonymous event stream, not a per-user timeline tied to your account. - We do not send your account email, username, name, or Vinegar account ID to PostHog. PostHog assigns your browser an anonymous ID (stored in its own ph_*_posthog cookie, configured to expire after 180 days) to link funnel steps within your session. That ID is a browser identifier — not a user identifier — and we never link it to your account record. It stays with the browser until it expires, you clear cookies, or you opt out via the “Cookie preferences” link in the site footer.
- We do not use PostHog session replay. No recording of your interactions.
- We do not build persistent person profiles in PostHog for anonymous visitors.
Stripe knows who paid (it has to — that's how billing works). PostHog only knows “a checkout completed” as an anonymous event. To make that possible, when you start a Premium checkout we attach the anonymous PostHog browser ID to the Stripe subscription metadata for that transaction only. When Stripe's webhook confirms the purchase, our server reads the ID, fires the anonymous PostHog event, and removes the ID from the subscription metadata. It is not stored on your Stripe customer object, and it is never linked to your account in PostHog.
Events we track (all anonymous):
- initial page views and page leave events
- install button clicked (split by browser store: Chrome, Firefox, Safari, Edge)
- signup completed
- email verified
- extension connected
- extension connection failed
- Premium page viewed
- Premium checkout started
- Premium purchased
UTM tags (like utm_source=twitter) that arrive with your ad click are captured with these events so we can measure which campaigns drive signups and conversions. They are attached to the anonymous events; they are not stored as persistent per-user advertising history on your account.
Cohort attribution on your account (first-party, our database only). So we can measure things like “do users from twitter ads retain better than users from google ads,” we write a lightweight cohort label to your user record at signup (for example, “twitter, week 14”). This label lives in our own database, is not sent to PostHog or any advertising platform, and is used only for cohort-level analysis of retention and engagement. We do not use it for individual advertising, and we do not use it to change your product experience.
The overall tradeoff is intentional: we get less granular product insight than a company that identifies every user in analytics, and in exchange your in-product activity is not tied to your identity in a third-party analytics database.
10.4 Cookies, consent, and Global Privacy Control
We take a region-aware approach to consent, matching the rules that apply to each visitor.
How we detect your region. We use Cloudflare's CF-IPCountry header (a signal Cloudflare adds based on your IP address) to determine which consent rules apply to you. This is a coarse country-level signal used only to pick the right banner behavior; we don't build a profile from it.
EU/UK and other consent-required regions. If you visit the marketing website from the EU, UK, or another jurisdiction that requires consent for non-essential cookies and similar technologies, you will see a cookie consent banner the first time you visit. Analytics and advertising measurement pixels do not load until you provide consent, and you can withdraw consent at any time via the “Cookie preferences” link in the site footer. Essential cookies (needed to make the site work) load regardless.
US and other regions. In the US, non-essential cookies currently load without a pre-consent banner, which is standard practice. You can opt out at any time via the “Cookie preferences” link in the site footer.
Global Privacy Control. Regardless of region, we honor Global Privacy Control (GPC) signals sent by your browser as an opt-out. If your browser sends the Sec-GPC: 1 header, all non-essential analytics and advertising pixels are blocked entirely — the consent banner is not needed, and nothing loads.
The cookies we set on the marketing website:
| Cookie | What it stores | How long |
|---|---|---|
| vg_consent | Your cookie/analytics choice (accepted, declined, or specific preferences) | ~1 year |
| vg_geo_gate | Your Cloudflare-detected region (e.g., "EU", "US"), used to apply the right consent rules | ~24 hours |
| ph_*_posthog (PostHog) | An anonymous browser identifier used to link funnel steps together within your session | 180 days (configured shorter than PostHog's 365-day default; refreshed when you visit) |
| Ad-platform pixels | Cookies or identifiers set by advertising platforms (e.g., X) for conversion measurement, when consented | Set by the platform; see their privacy policies |
vg_consent and vg_geo_gate are essential to running the consent system itself and load regardless of your choice — they exist specifically to remember and apply your preference. The others only load if consent is given (and never load if GPC is sent).
10.5 Marketing email suppression list
If you unsubscribe from marketing emails, we keep your email on a suppression list — specifically so that we don't accidentally email you again if your address re-enters our systems from a different source (a re-signup, a support conversation import, and so on). This is a privacy-protective retention, not a marketing one. If you want your email removed from the suppression list as well, contact [email protected].
10.6 Managing your preferences
In your browser. You can block, clear, or restrict cookies at any time through your browser settings. Most browsers also honor a “Do Not Track” signal and Global Privacy Control; where required by law, we treat GPC as an opt-out signal.
On the marketing site. Use the “Cookie preferences” link in the footer to update your consent.
In the extension. Clear extension storage from your browser's extension management page.
11. Sharing data with service providers
We use a short list of vendors to operate the Service. They process data on our behalf, under contract, only for the purposes we tell them.
| Vendor | What they do | Where to learn more |
|---|---|---|
| Stripe | Subscription billing and payments | stripe.com/privacy |
| Google OAuth | "Sign in with Google" authentication | policies.google.com/privacy |
| Google Workspace | Email and document infrastructure for our team (e.g., handling legal and DMCA correspondence) | policies.google.com/privacy |
| Resend | Transactional email (account, subscription, and legal confirmations; inbound parsing for arbitration opt-out requests) and, with your consent, marketing/product-update emails | resend.com/legal/privacy-policy |
| Featurebase | Customer support, feedback, feature requests, changelog, and product-update communications | featurebase.app/privacy |
| PostHog | Product analytics, A/B testing, and conversion tracking — used to understand product and website performance. Used anonymously — we don't identify individual users to PostHog and we don't use session replay. See §10.3. | posthog.com/privacy |
| Advertising platforms (marketing website only) | Measurement of ad performance and conversions on our public marketing website (getvinegar.com) via advertising pixels — currently including X, potentially including platforms like Google Ads or Meta in the future. Not used inside the extension or on supported shopping pages. See Section 10 | Privacy policies of the platform running the ad (e.g., X, Google, Meta) |
| Hetzner | Hosting and infrastructure | hetzner.com/legal/privacy-policy |
| Cloudflare | CDN, DDoS protection, coarse country-level geolocation (CF-IPCountry) used to apply the correct consent rules to your visit, and Turnstile bot-detection at signup and other abuse-sensitive checkpoints | cloudflare.com/privacypolicy |
| PlanetScale | Database infrastructure | planetscale.com/legal/privacy |
We may add or change vendors over time. When we do, we'll update this list. Material changes will be communicated as described in Section 17.
We may also share information when:
- You ask us to - for example, by publicly posting a contribution.
- A law or legal process requires it - for example, a valid subpoena or court order. We'll push back on overbroad requests and, where we can, notify you.
- It's necessary to protect rights or safety - to investigate fraud, enforce our Terms, or protect users or the public.
- A business transaction occurs - like a merger or acquisition. If that happens, we'll tell you, and the data will remain subject to a privacy policy at least as protective as this one.
12. Your choices and rights
You can:
- Access and update your account information from your settings.
- Delete your account. Email [email protected] or use the in-app deletion flow. We'll delete or de-identify account data within a reasonable period, subject to legal retention requirements and the contribution-record practice described in Section 13.
- Turn Brand History on or off, and clear it.
- Manage your avoid list.
- Cancel Premium at any time from your settings.
- Opt out of arbitration within 30 days of first accepting our Terms, via Settings → Legal or by emailing [email protected] from your account address. See Section 21 of the Terms of Service.
- Opt in or out of marketing emails (product updates, changelogs, feature announcements, and Vinegar news) at any time from Settings → Notifications, or by clicking the unsubscribe link at the bottom of any marketing email. Marketing emails are off by default and are always separate from transactional and service emails (billing, security, legal notices), which we send regardless.
- Manage cookies and analytics on our marketing website via the “Cookie preferences” link in the site footer. If you're in the EU, UK, or another consent-required jurisdiction, non-essential analytics and advertising measurement pixels will not load until you consent. See Section 10.
- Appeal moderation or anti-abuse decisions at [email protected].
Depending on where you live, you may have additional rights. To exercise these, email [email protected]. We may need to verify your identity before responding. We won't discriminate against you for exercising privacy rights.
EEA / UK rights. Under GDPR and UK GDPR, you have the right to access, rectify, erase, restrict processing, object to processing, and receive a portable copy of your personal data; to withdraw consent (without affecting the lawfulness of processing before withdrawal); and to lodge a complaint with your local supervisory authority (in the UK, the ICO; in the EU, your member-state authority).
California rights (CCPA/CPRA). You may request to know, delete, and correct the personal information we hold about you, and to limit the use and disclosure of sensitive personal information. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
Texas rights (TDPSA). As a Texas-based company, we respond to rights requests from Texas residents under the Texas Data Privacy and Security Act on the same terms.
Other states. Residents of other U.S. states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Utah, Oregon) can exercise comparable rights provided by those laws.
13. How long we keep data
We keep data for as long as we need it for the purpose we collected it for, then we delete or de-identify it. Rough guidelines:
- Account data: while your account is active.
- Public contributions, votes, edit history: generally retained as part of the community record, even if you delete your account, because they're part of how the data was sourced. We can disassociate a contribution from your username on request, subject to limitations.
- Anti-abuse signals (fingerprints, IP hashes, rate-limit data): typically months rather than years, unless tied to an active investigation or repeat offender.
- Moderation history: retained as long as needed to enforce our policies fairly.
- Brand History: while the feature is enabled and you have Premium; on cancellation/opt-out, see Section 6.
- Payment records: as required by tax, accounting, and consumer-protection laws (typically several years).
- Support communications: generally retained for a reasonable period after the issue is resolved.
- Legal records (arbitration opt-out attempts, DMCA notices and counter-notices, formal legal correspondence): retained indefinitely or as required by applicable statutes of limitation, whichever is longer.
14. International transfers
We're based in the United States, and our infrastructure providers may process data in the United States and Europe. If you use the Service from another country, your information may be transferred to and processed in those locations, which may have different data-protection laws than yours.
Transfer safeguards (EEA/UK). Where we transfer personal data out of the EEA or UK to a country that the European Commission or UK government has not deemed to provide an adequate level of protection, we rely on appropriate safeguards under GDPR/UK GDPR, including the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum or IDTA where applicable) with our vendors. You can request a description of these safeguards at [email protected].
15. Children
The Service is not directed to children under 13, and we don't knowingly collect personal information from them. If you believe a child has given us information, contact [email protected] and we'll delete it. Account creation is generally limited to users 16 and older outside the United States.
16. Security
We take reasonable technical and organizational measures to protect data - encryption in transit, hashing of sensitive identifiers, restricted access, and ongoing monitoring. No system is perfectly secure, and we can't promise that data is invulnerable. If we discover a security incident affecting your data, we'll notify you and, where required, regulators.
17. Changes to this policy
We may update this policy as the Service evolves. If we make material changes, we'll provide reasonable notice - for example, through the extension, by email, or by posting a notice on our website - before the changes take effect. Continuing to use the Service after the effective date means you accept the updated policy.
18. Third-party sites
The Service references third-party sources (registries, news outlets, company sites). When you click a source link, you leave Vinegar; their privacy practices govern from that point on, and we have no control over them.
19. Contact
Privacy questions or requests: [email protected]
Folkward LLC 5900 Balcones Drive, STE 100 Austin, TX 78731