Skip to content

Legal

Privacy Policy

Last updated August 2026

This policy explains what The Coupon Hub (“we”, “us”) collects when you use our website and browser extension, why we collect it, and what control you have over it.

What we collect

Account information

When you create an account we store your email address, your name if you provide one, and an identifier from PayPal, our payment processor, so we can match your subscription to your account. We never see or store your card number — that stays with PayPal.

Licence and device information

We store your API key twice: as a one-way hash, which is what we match against when the extension activates, and as an encrypted copy, which is what lets your dashboard show you the key again instead of forcing you to generate a new one. We also store a randomly generated device identifier so we can enforce the 1 device limit on your key. That identifier is generated by the extension and is not derived from your hardware, browser fingerprint, or any advertising ID.

Activating or re-checking a licence also records your IP address and your browser's user-agent string against that device. We use them for two things only: enforcing the device limit, and showing you a recognisable list of your own devices on the dashboard (“Chrome on macOS”). We do not use them to build a profile, and we do not share them.

Extension usage data

The extension reports a small, aggregate health signal after each run so we can detect when a grocery site changes its layout and breaks coupon loading. That signal contains:

  • the store domain (for example kroger.com)
  • how many coupons were found and how many were clipped
  • how long the run took, and the extension version
  • your licence session token, which identifies the subscription the run belongs to — not you personally, and not tied to anything you did outside the extension
  • which matching method succeeded, so we can tell a healthy store from one limping along on a fallback

It does not contain URLs you visit, page content, coupon details, product or purchase history, your name, or your email address.

What we never collect

  • Your grocery store password. The extension never asks for, reads, stores or transmits your store credentials. It operates on pages you are already signed in to.
  • Your browsing history. The extension only runs on the specific grocery store coupon pages listed in its manifest, and it does not report which pages you visit.
  • Your card details. Payment is handled entirely by PayPal on their own pages. Your card number never reaches our servers.

How we use it

  • To operate your subscription and validate your licence key
  • To enforce the device limit on your key
  • To detect and fix broken store integrations
  • To respond when you contact support
  • To contact you about your subscription if something needs your attention

Who we share it with

We do not sell your data and we do not share it for advertising. We use a small number of service providers strictly to run the service: PayPal for billing and subscription management, and Google Firebase for authentication and database hosting. Each processes data only on our instructions.

We may disclose information if required by law, or to protect our rights or the safety of our users.

How long we keep it

Account and licence records are kept while your account is open and for up to 24 months afterwards, so we can handle billing disputes and comply with tax obligations. Aggregate health data is retained for 90 days. Support emails are kept for 24 months.

Your rights

You can at any time:

  • access the personal data we hold about you
  • correct anything inaccurate
  • delete your account and the data attached to it
  • export your data in a portable format
  • object to processing, or withdraw consent where we rely on it

Email contact@thecouponhub.com and we will action any of these within 30 days. Deleting your account cancels your subscription and permanently revokes your key.

Security

Data is encrypted in transit using TLS and at rest by our hosting provider. API keys are never stored in plain text: the copy we match against is a one-way hash, and the copy your dashboard displays is encrypted with a key held outside the database, so a breach of the database alone would not expose usable keys. Access to production data is limited to staff who need it.

Children

The service is not intended for anyone under 18 and we do not knowingly collect data from children.

Changes

If we make a material change we will email active subscribers and update the date at the top of this page before the change takes effect.

Contact

Questions about this policy? Email contact@thecouponhub.com.