Legal

Privacy for the
pretend purchase.

This policy explains the data KindaBought collects and, just as importantly, the data it never collects from simulated shopping.

Data we collect

We collect account data you provide, such as email address, display name, authentication state, 18+ confirmation, theme preference, and account settings. We also collect simulated cart, order, product-interaction, report, and receipt-sharing records needed to run the product.

For brand owners, we process submitted product text, images, variants, moderation decisions, storage usage, and simulated analytics. Security logs and rate-limit events may also be retained to protect the service.

If you contact a published KindaBought inbox, our email provider processes and retains the message, routing metadata, and any attachments so an authorized operator can review and respond. Do not send unrelated sensitive information.

Public catalog pages use a pseudonymous browser identifier to record product impressions and detail views for simulated brand analytics. It contains no name, email, address, payment data, or authentication cookie, and the browser request omits account credentials.

Data we do not collect in simulated checkout

We do not request, transmit, or store a real shopper card number, CVV, billing address, shipping address, fulfillment preference, or delivery instruction. The address and Kinda Card shown in a simulated order are fictional.

Brand membership billing is different: Stripe processes real membership payments. KindaBought stores only the identifiers and subscription status needed to provide the membership, not raw payment credentials.

How we use information

We use data to operate accounts, simulate orders, display order history, publish approved catalog content, calculate simulated intent metrics, moderate submissions, respond to reports, prevent abuse, and send account or membership messages.

Sharing and public information

Approved brand and product information appears in the public catalog. A receipt becomes public only when you explicitly create a share link; its generated image is designed to contain product summaries, simulated total, KindaBought branding, and Roast copy—not personal information. You can revoke a share link.

Retention and choices

When a brand subscription ends, recoverable data is retained for 30 days, then uploaded assets and product working data are deleted while only anonymized aggregate metrics may be retained. You can manage your account, theme preference, receipts, and brand membership in product settings.

You can delete your account in Account settings. Deletion revokes public receipt shares, removes or anonymizes readable account data, and starts the applicable asset cleanup. An active real brand membership must be canceled in Stripe before account deletion can finish.

For privacy questions and available request routes, visit the Contact page.