Privacy Policy
Last updated: August 26, 2026
Privacy at a glance.
- We do not sell or share your Personal Information for advertising, ever.
- We use a small set of trusted service providers (Supabase, Stripe, PostHog, Pulsetic, Postmark, Slack, Apple, Google, Vultr, and Cloudflare) to run the Service. See Section 5.
- You can delete your account yourself at any time from Account settings (with a 30-day grace period to change your mind), or access, correct, or export your data by emailing hello@shouldirip.com.
- The Service is for users 18 and older. We do not knowingly collect data from anyone under 18.
- Disputes about this Policy are subject to the dispute-resolution provisions of our Terms of Service, including binding individual arbitration and a class-action waiver (with a 30-day opt-out).
This Privacy Policy describes how Triple Lloyd, LLC, an Alaska limited liability company ("Triple Lloyd," "we," "us," "our"), collects, uses, discloses, and protects information in connection with the "Should I Rip?" service available at https://shouldirip.com (the "Service" or "Site"). It applies to visitors to the Site and to registered users of the Free, Pro, and Founding Member tiers. By using the Service, you acknowledge the practices described in this Policy.
For purposes of this Policy, "Personal Information" means information that identifies you or could reasonably be linked to you. It does not include data we have aggregated or de-identified so that it can no longer reasonably be used to identify you.
Table of Contents
- Introduction
- Personal Information We Collect
- How We Use Your Information
- Your Email Choices (CAN-SPAM and CASL)
- Cookies and Similar Technologies
- How We Share Information
- Legal Bases for Processing (EU and UK Users)
- Your Rights
- How to Exercise Your Rights
- Data Retention
- Data Security and Breach Notification
- International Data Transfers
- Children's Privacy
- Do Not Track and Global Privacy Control
- California-Specific Disclosures
- Accessibility
- Communications Channels (SMS / Push)
- Changes to This Policy
- Contact Us
1. Introduction
Should I Rip? is a subscription analytics product. The Service ingests publicly available trading-card pack data from Arena Club (ArenaClub.com, Inc.), computes the Expected Value ("EV") of each pack, surfaces rankings and time-series charts, computes its "CS Trigger" statistic (an estimate of the share of pulls on which Arena Club's optional "Collect Safe" buyback floor would activate), and — for Pro subscribers (and Founding Members) — sends positive-EV email alerts. The Service does not facilitate gambling, wagering, the buying or selling of trading cards, or the trading of securities. It is purely an informational and analytical tool. You open ("rip") trading-card packs yourself at Arena Club's own site.
Triple Lloyd is independent of Arena Club and is not affiliated with, endorsed by, or sponsored by Arena Club. "Arena Club," "Slab Packs," and "Collect Safe" are trademarks or registered trademarks of ArenaClub.com, Inc., used only to identify the product and features the Service analyzes (sometimes called "nominative" use — that is, naming the product, not implying any sponsorship). Triple Lloyd has no affiliate, sponsorship, advertising, or data relationship with Arena Club and earns no commission on purchases you make there; outbound links to arenaclub.com are provided for your convenience only.
This Policy covers the Service only. It does not cover third-party websites or services that you access through the Service (including arenaclub.com), which are governed by their own privacy policies.
2. Personal Information We Collect
We collect information directly from you, automatically through your use of the Service, and from a limited set of service providers. The table below is a quick-reference; the sub-sections that follow have full detail.
| Category | Examples | Why we collect it | Source |
|---|---|---|---|
| Account | Email, Supabase UUID, OAuth identifier, display name, tier, founder number, signup source/date, onboarding state, alert mode, email preferences | Create and run your account | You; Apple/Google at sign-in |
| Billing | Stripe customer ID, subscription status, plan, billing cycle, card brand, last four digits | Process subscription payments | Stripe |
| User Content | Favorited pack IDs, feedback submissions, optional display name | Deliver features you use; respond to feedback | You |
| Arena Club activity | The Arena Club username you choose to tell us, and the public pack-opening records we match to it — card, pack, value at the time, and when the card left the pool | Show you a history and summary of your own pulls, on the Service and in your recap email | You (the username); Arena Club's public pack and card data (the pull records) |
| Analytics | PostHog distinct_id, IP address, user-agent, page views, clicks, feature usage, and masked session replays (a recording of on-site interactions; anything you type is masked, as are the parts of a page showing your email address or Arena Club username) | Understand product usage; debug; improve | Your browser via PostHog |
| Site performance | IP address, user-agent, the URL of the page you are viewing, and page-timing measurements (Core Web Vitals such as load speed, layout stability, and responsiveness) | Measure how fast pages actually load for real visitors; find and fix slow pages | Your browser via Pulsetic |
| Email engagement | Opens, clicks, timestamps, IP/user-agent at open or click, bounces, complaints | Deliverability; debug; honor opt-outs | Postmark |
| Server logs | IP, request URL, HTTP status, user-agent, timestamp | Security; debugging | Our servers |
| Coarse geolocation | Approximate region inferred from IP address | Security; abuse prevention; analytics | Your IP via our servers, PostHog, and Pulsetic |
2.1 Account Information
- What: Email address, Supabase user identifier (UUID), the identifier returned by your chosen authentication provider (Apple or Google) if you sign in with one, optional display name, the tier you are on (Free, Pro, or Founding Member), your assigned Founder Number (if applicable), the source that referred you to sign up, your signup date, your current onboarding state, your alert mode, and your email preferences.
- Source: Provided by you when you create an account; in part returned by Apple or Google when you use Sign in with Apple or Sign in with Google.
2.2 Subscription and Billing Information
- What: Your Stripe customer identifier, current subscription status, plan, billing cycle, and limited card metadata such as the last four digits of your payment card and card brand. We do not receive or store full payment card numbers, CVC, or expiration dates — these are held by Stripe.
- Wallet payments: If you choose to pay using Stripe Link, Apple Pay, Google Pay, or another wallet-based payment method (if available at checkout), the wallet provider transmits a payment token to Stripe. Triple Lloyd does not receive your underlying card details in any case.
- Source: Stripe, Inc. at checkout and via Stripe webhooks.
2.3 Preferences and User Content
- What: Your alert mode and email preferences, your list of favorited packs (pack IDs), and any free-form feedback you submit to us through the Service. See Section 2.1 — preferences are also part of your profile.
- Source: Provided by you.
2.4 Usage and Analytics Information
- What: A pseudonymous PostHog distinct identifier, IP address, user-agent, device and browser characteristics, referring URL, pages viewed, buttons clicked, and features used. Before you sign in this information is pseudonymous; after you sign in it is associated with your account so that we can understand product usage.
- Session replays: A reconstruction of your interactions with the Site — pages viewed, clicks, scrolling, and pointer movement — recorded via PostHog's session replay. The recording includes the text of the pages you view, so that we can tell which pack, price, or figure was on screen when you did something. Anything you type into a form is masked in your browser before any data is transmitted — including your email address at sign-in and your payment details, which in any case are entered on Stripe's own pages and never on ours. We also mask, in the same way, the specific parts of a page that display your own account details: your email address, and your Arena Club username if you have given us one. We do not record replays of our internal administration pages at all. Session replays use the same ph_<key>_posthog identifier and are subject to the same consent and opt-out controls as our other PostHog analytics (see Section 4). We do not record session replays for visitors who have not consented where consent is required, or for anyone who has opted out or sent a Global Privacy Control signal.
- Site performance (Pulsetic). We measure how fast pages actually load for real visitors using Pulsetic's Real User Monitoring script. It records page-timing measurements — the Core Web Vitals (largest contentful paint, cumulative layout shift, interaction to next paint, first contentful paint) and related load timings — for the page you are viewing, together with that page's URL and the IP address and user-agent your browser sends with any request. It does not set a cookie, does not write anything to your browser's storage, and does not assign you a visitor identifier, so it cannot follow you from page to page or from visit to visit. Because the measurement is nonetheless transmitted to a provider outside our systems, we load the Pulsetic script under the same consent controls as our PostHog analytics (see Section 4): it is not loaded for EEA, UK, or Swiss visitors unless they consent, and not for anyone who has opted out or sent a Global Privacy Control signal.
- Source: Automatically through your browser via the PostHog JavaScript SDK, the Pulsetic Real User Monitoring script, and our application servers.
2.5 Email Engagement Information
- What: Whether you opened an email we sent, which links you clicked, the timestamp, and the IP address and user-agent at the time of the open or click. Postmark also notifies us of bounces and spam complaints associated with your address.
- Source: Postmark via a 1×1 tracking pixel and link rewriting in our outbound email.
- How to opt out of email tracking and email marketing: Every commercial email we send includes a one-click unsubscribe link in the footer; you may also email hello@shouldirip.com with the subject "Unsubscribe" or "Disable Email Tracking" and we will honor the request within ten (10) business days as required by the U.S. CAN-SPAM Act. For visitors located in the EEA, UK, or Switzerland, we do not send commercial email or enable open-tracking pixels without your prior consent.
2.6 Server Log Information
- What: IP address, request URL, HTTP status, user-agent, and timestamp.
- Source: Automatically generated by our application servers.
2.7 Cookies and Local Storage
We and our service providers set a small number of cookies. See Section 4 for the full list. We do not set advertising cookies, retargeting pixels, or social-tracking pixels.
2.8 Arena Club Activity Information
- What: If you choose to tell us your Arena Club username, we store it on your account and use it to match publicly visible pack-opening ("pull") records to you — the card, the pack it came from, the card's value at the time, and when it left the pool. We show you the resulting history and summaries on the Service, and may include a summary of them in your recap email.
- It is optional and unverified. Providing your username is entirely optional and the Service works without it. We do not verify that a username you enter belongs to you, and we match only records that Arena Club already makes publicly visible. You can change or remove the username at any time from your account, which stops the matching.
- We never publish it. We do not display your Arena Club username, or attribute any pull to you, on any public page or to any other user. This information is shown to you, and used by us in aggregate for analytics and product development.
- It is incomplete by design. We only see a pull if our polling observes the card while it is attributed to your showroom, so our records are a partial view of your activity, not a complete one.
- Source: The username is provided by you; the pull records come from Arena Club's public pack and card data.
2.9 What We Do Not Collect
We do not knowingly collect:
- Special categories of personal data under GDPR Article 9 — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation;
- The following categories of California "sensitive personal information" beyond what is identified in Section 14 — government-issued identifiers (SSN, driver's license, passport), precise geolocation (within 1,850 feet), genetic or biometric information, health information, citizenship or immigration status, or the contents of mail, email, or text messages not directed to us; or
- Information from anyone under 18 (see Section 12).
We may infer your approximate region from your IP address for security and analytics (see Sections 2.4, 2.6, and 14); we do not collect precise geolocation. Account credentials (such as authentication tokens received from Apple, Google, or magic-link sign-in) are classified as "sensitive personal information" under California law. We use them only to authenticate you and secure your account, not to infer characteristics about you.
3. How We Use Your Information
We use the information described above for the following purposes:
- Provide the Service. Create and maintain your account, authenticate you, display EV calculations, rankings, charts, CS Trigger figures, and favorites, and operate the features of your tier.
- Process payments. Through Stripe, charge your subscription, manage renewals and cancellations, prevent fraud, and meet tax and accounting obligations.
- Communicate with you (transactional). Send sign-in links, billing receipts, security notices, sold-out notifications for packs you have favorited, cancellation confirmations, annual (and any monthly) renewal reminders required by our Terms of Service, and other account-related messages. These messages are required to operate your account.
- Communicate with you (commercial / optional). If you have opted in or not opted out, send positive-EV alerts, weekly recaps, and product announcements. You may unsubscribe at any time (see Section 3A).
- Improve the Service. Understand which features are used, debug problems, measure performance, and develop new functionality.
- Secure the Service. Detect and prevent abuse, scraping, fraud, and other unauthorized activity, and enforce our Terms of Service.
- Comply with law. Meet legal obligations, respond to lawful requests, and exercise or defend legal claims.
We do not use your information to make automated decisions that produce legal or similarly significant effects about you. EV calculations and rankings are product features; they do not determine your access to credit, insurance, employment, housing, or any other consequential service.
3A. Your Email Choices (CAN-SPAM and CASL)
Every commercial email we send includes a one-click unsubscribe link and our postal address, as required by the U.S. CAN-SPAM Act (15 U.S.C. § 7701 et seq.) and Canada's Anti-Spam Legislation (CASL) where applicable. You may also adjust your email choices at any time in Account → Email Preferences. We will honor opt-out requests within ten (10) business days, as required by 15 U.S.C. § 7704(a)(4).
Transactional emails (sign-in links, billing receipts, security notices, renewal reminders required by law, and cancellation confirmations) are required for the operation of your account and cannot be turned off while your account remains active. To stop transactional email, close your account (see Section 7).
For users in Canada (CASL) and the EEA, UK, and Switzerland (GDPR/ePrivacy), we send commercial email only with your express consent or where a recognized exemption applies. Email open tracking via the Postmark pixel is disabled for these users unless you have consented; click tracking via link rewriting may be used for deliverability debugging and may be turned off in your email preferences.
4. Cookies and Similar Technologies
The following cookies and local-storage items may be set when you use the Service:
| Name | Purpose | Type | Expiration | Party |
|---|---|---|---|---|
| sb-<project>-auth-token | Maintains your authenticated session so you stay signed in. | Strictly necessary | Session / refresh-token lifetime (sliding; the actual duration matches our Supabase project configuration — please contact us for the current value) | Supabase (first-party; HttpOnly, Secure, SameSite=Lax) |
| sb-<project>-auth-token-code-verifier | PKCE (a security check used during sign-in) code verifier. | Strictly necessary | Cleared after sign-in completes | Supabase (first-party; HttpOnly, Secure, SameSite=Lax) |
| ph_<key>_posthog | Stores a pseudonymous distinct_id for product analytics and feature-flag bootstrapping. | Analytics | 365 days (rolling) | PostHog (first-party on shouldirip.com; data transmitted to and processed by PostHog in the US) |
| perf | Optional internal diagnostic that enables verbose client-side performance logging when set to "1." Not used for advertising or cross-site tracking. | Functional (diagnostic) | 7 days | Triple Lloyd (first-party) |
| (none — Pulsetic Real User Monitoring stores nothing in your browser) | Measures how fast the page you are viewing actually loads (Core Web Vitals and related page timings). Loaded only where the consent rules below allow it. It sets no cookie, writes no local-storage item, and assigns you no visitor identifier. | Analytics (performance) — storage-less | Not applicable — nothing is stored | Pulsetic (script loaded from cdn.pulsetic.com; measurements transmitted to and processed by Pulsetic — see Section 5) |
Consent and opt-out. The strictly necessary Supabase authentication cookies are required for the Service to function. The optional perf diagnostic cookie is set only when you yourself enable it by visiting a URL with ?perf=1; you can disable it by visiting ?perf=0 or by clearing cookies for shouldirip.com. For visitors located in the European Economic Area, the United Kingdom, and Switzerland, we present a consent banner on first visit and do not load the PostHog analytics cookie until you affirmatively consent. For visitors elsewhere, PostHog is loaded by default; you can opt out at any time using the Cookie Preferences link in the site footer, by emailing hello@shouldirip.com, or by sending a Global Privacy Control signal from your browser (we honor GPC — see Section 13). You can withdraw consent and have analytics data deleted from your account by emailing the same address. The ph_<key>_posthog cookie is set in the first-party context on shouldirip.com; the underlying analytics data is transmitted to and processed by PostHog Inc. on us.i.posthog.com in the United States. PostHog analytics includes session replay — a recording of on-site interactions, with anything you type, and the parts of a page showing your own account details, masked in your browser (see Section 2.4). Session replay relies on the same ph_<key>_posthog identifier and is governed by the same consent and opt-out controls described here: it is not recorded for EEA, UK, or Swiss visitors unless they consent, or for anyone who opts out or sends a Global Privacy Control signal. We also load Pulsetic Real User Monitoring — a page-performance script — under exactly these same controls: it is not loaded for EEA, UK, or Swiss visitors unless they consent, and not for anyone who opts out or sends a Global Privacy Control signal. We gate it on consent even though it sets no cookie and stores nothing in your browser, because the measurement it sends still includes your IP address and user-agent.
Most browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies will prevent you from signing in or using the Service. If you click through to arenaclub.com, Arena Club may set cookies in your browser; those cookies are governed by Arena Club's own privacy and cookie practices.
Outbound link tracking. Links from the Service to arenaclub.com — on our pages and in our emails — pass through a first-party redirect on shouldirip.com (a /go/ link) before sending you on to Arena Club. We record each outbound click in a first-party log: the date and time, which pack you clicked, whether the click came from our website or an email, and your account identifier when we can determine it. We keep this record to understand which packs members find worth opening and to evidence that we refer traffic to Arena Club. We also append a standard utm_source=shouldirip.com attribution parameter to the destination URL; this is ordinary referral attribution, not an affiliate or commission code — we have no paid relationship with Arena Club and earn nothing on your click (see our Terms, Section 10). The analytics event associated with a click is subject to the same consent controls as the rest of our PostHog analytics described above.
5. How We Share Information
We do not sell your Personal Information. We do not "share" your Personal Information for cross-context behavioral advertising (a California-law term that means tracking you across other businesses' sites or apps to show you targeted ads). We have not done so in the preceding twelve months and have no plans to do so.
We share Personal Information only with the categories of recipients listed below:
- Service providers (sub-processors) — companies we hire that handle some of your data on our behalf under contractual confidentiality and security obligations. The full list is in the table below.
- Identity providers that you choose to use to sign in (Apple or Google).
- Legal and safety recipients. We may disclose information when we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or governmental request; to protect the rights, property, or safety of Triple Lloyd, our users, or others; or to investigate fraud or abuse.
- Business transfers. If Triple Lloyd is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred to the successor entity, subject to this Policy.
- With your direction. When you choose to share information through the Service (for example, by clicking an outbound link), we transmit that information consistent with your instructions.
Sub-Processor Table
| Provider | Purpose | Data Received | Location | Link |
|---|---|---|---|---|
| Supabase, Inc. | Database (Postgres) and authentication infrastructure. | Email, Supabase UUID, optional display name, tier, founder number, signup source and date, alert mode, onboarding state, email preferences, favorites, feedback submissions, hashed session tokens. | United States | https://supabase.com/privacy |
| Stripe, Inc. | Payment processing, subscription billing, and invoicing. | Email, billing address, full payment card details (held by Stripe); Triple Lloyd receives only the Stripe customer ID, subscription status, billing cycle, card brand, and last four digits. | United States (with global payment infrastructure under SCC-compliant frameworks) | https://stripe.com/privacy |
| PostHog Inc. (US Cloud) | Product analytics and feature-usage measurement. | Pseudonymous distinct_id, IP address, user-agent, device and browser characteristics, page views, button clicks, feature interactions; aliased to your Supabase UUID after sign-in. | United States (us.i.posthog.com) | https://posthog.com/privacy |
| Designmodo Inc. (Pulsetic) | Website uptime monitoring and browser-side Real User Monitoring (page-performance measurement). | For uptime monitoring: automated requests from Pulsetic to our public health endpoint — no user data. For Real User Monitoring: IP address, user-agent, the URL of the page viewed, and page-timing measurements (Core Web Vitals). No cookie, no browser-storage item, and no visitor identifier is set, and the measurements are not linked to your account. | United States (Designmodo Inc., New York); hosting and cloud-storage sub-processors engaged under its Data Processing Agreement are located in both the United States and the European Union | https://pulsetic.com/privacy/ |
| Wildbit, LLC (Postmark) | Transactional and notification email delivery, open and click tracking, bounce and complaint webhooks. | Email address, message content, delivery metadata, open and click events, IP and user-agent at the time of open or click. | United States | https://postmarkapp.com/privacy-policy |
| Salesforce, Inc. (Slack) | Internal team communication and operational notifications (e.g., error alerts, signup events, payment events). | Automated operational notifications that may include user identifiers such as email address, subscription tier, and event type. | United States | https://slack.com/trust/privacy/privacy-policy |
| Apple Inc. (Sign in with Apple) | OAuth identity provider used when you choose Apple sign-in. | Email address (real or Apple-relayed private alias), Apple user identifier, authentication tokens. Apple may independently retain sign-in event metadata under Apple's own privacy policy. | United States | https://www.apple.com/legal/privacy/ |
| Google LLC (Sign in with Google) | OAuth identity provider used when you choose Google sign-in. | Email address, Google account identifier, basic profile (name where granted), authentication tokens. Google may independently retain sign-in event metadata under Google's own privacy policy. | United States | https://policies.google.com/privacy |
| The Constant Company, LLC (Vultr) | Cloud hosting infrastructure for application servers and databases. | Request traffic to the Service, including IP address, user-agent, request URLs, and any data submitted to the Service. | United States | https://www.vultr.com/legal/privacy/ |
| Cloudflare, Inc. | CDN, DDoS protection, DNS, and edge caching. | Request traffic to the Service, including IP address, user-agent, request URLs, TLS metadata, and cached content. | United States (with global edge network) | https://www.cloudflare.com/privacypolicy/ |
We will maintain a current sub-processor list and will use reasonable efforts to notify users in advance of material changes.
Data Processing Addendum (DPA). Where a sub-processor processes Personal Information of EEA, UK, or Swiss data subjects on our behalf, we rely on that sub-processor's standard Data Processing Addendum, which typically incorporates the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) where applicable. Controllers and qualifying data subjects may request information about the DPA applicable to a specific sub-processor by emailing hello@shouldirip.com.
6. Legal Bases for Processing (EU and UK Users)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your Personal Information on the following legal bases under the GDPR and UK GDPR. The table maps each processing purpose to its legal basis:
| Purpose | Legal basis |
|---|---|
| Create your account; authenticate you; deliver tier features | Contract performance (Art. 6(1)(b)) |
| Subscription billing and renewals | Contract performance and legal obligation (Art. 6(1)(b), (c)) |
| Transactional email (receipts, security notices, renewal reminders required by law) | Contract performance (Art. 6(1)(b)) |
| Marketing email (+EV alerts, weekly recap, product announcements) | Consent (Art. 6(1)(a)) where required; legitimate interests with opt-out elsewhere |
| Product analytics (PostHog) | Legitimate interests (Art. 6(1)(f)) where permitted; consent in jurisdictions that require it (for example, Germany under TTDSG) |
| Session replay (PostHog) | Consent (Art. 6(1)(a)) — for EEA, UK, and Swiss visitors we record session replays only after affirmative consent |
| Page-performance measurement / real user monitoring (Pulsetic) | Consent (Art. 6(1)(a)) — for EEA, UK, and Swiss visitors we load the Pulsetic script only after affirmative consent |
| Email open and click tracking | Consent (Art. 6(1)(a)) for EU/UK/Swiss visitors; legitimate interests elsewhere |
| Security, fraud and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Tax and accounting recordkeeping | Legal obligation (Art. 6(1)(c)) |
You have the right to object at any time to processing based on legitimate interests, as described in Section 7.3. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. We do not carry out automated decision-making producing legal or similarly significant effects about you.
7. Your Rights
Depending on where you live, you may have the rights described below. Some rights apply only to residents of specific jurisdictions; we extend the core rights of access, correction, and deletion to all U.S. residents regardless of state of residence.
7.1 California Residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what categories and specific pieces of Personal Information we have collected about you, the sources, the purposes, and the categories of recipients (see Section 14).
- Delete Personal Information we hold about you, subject to exceptions permitted by law (such as completing a transaction, complying with a legal obligation, or detecting security incidents).
- Correct inaccurate Personal Information we maintain about you.
- Opt out of the sale or sharing of your Personal Information. As stated above, we do not sell or share your Personal Information for cross-context behavioral advertising.
- Limit the use and disclosure of Sensitive Personal Information. We only use sensitive info (your sign-in tokens) to log you in and keep your account secure. We do not use it to infer things about you. California gives you the right to ask us to limit this — but since we already limit it to those purposes, exercising the right will not change anything in practice. You can still ask, and we will confirm our practices in writing.
- Non-discrimination. We will not deny you the Service, charge you different prices, or provide a different level of quality because you exercised any right under the CCPA.
"Do Not Sell or Share" request. Although we do not sell or share Personal Information for cross-context behavioral advertising, California regulations require us to offer a clear method to submit a "Do Not Sell or Share" request. You may submit such a request — which we will confirm and record — by emailing hello@shouldirip.com with the subject line "Do Not Sell/Share." A signal received via the Global Privacy Control (see Section 13) is also recorded as an opt-out preference.
Financial Incentive Notice. Triple Lloyd offers Pro and Founding Member subscription tiers at the prices presented at checkout. The value of these tiers reflects the additional features and access we provide and is unrelated to the value of any Personal Information we collect. You may sign up for, decline, or cancel a paid tier at any time without giving up any privacy right.
7.2 Other U.S. State Residents
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, or Delaware (and any other state whose comprehensive privacy law extends similar rights), you may have the right to:
- Confirm whether we process your Personal Information and access it;
- Correct inaccuracies in your Personal Information;
- Delete Personal Information we have collected or maintained about you;
- Obtain a portable copy of Personal Information you provided to us;
- Opt out of the sale of your Personal Information, of targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects.
We do not sell your Personal Information, do not engage in targeted advertising, and do not profile you in furtherance of decisions producing legal or similarly significant effects.
If we decline a request, you may appeal our decision as described in Section 8.
7.3 EU, UK, and Swiss Residents
If you are located in the EEA, UK, or Switzerland, you have the right to:
- Access the Personal Information we hold about you;
- Rectify inaccurate or incomplete Personal Information;
- Request erasure ("right to be forgotten") subject to applicable exceptions;
- Restrict processing in certain circumstances;
- Object to processing carried out on the basis of our legitimate interests (including direct marketing);
- Receive a copy of certain Personal Information in a portable format;
- Withdraw consent at any time where processing is based on consent;
- Lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office at https://ico.org.uk).
Article 27 Representative. We currently rely on the position that the Service is directed primarily at U.S. users and that incidental access by EU/UK visitors is at their own initiative. If you are an EU/UK supervisory authority or data subject and wish to contact us, please email hello@shouldirip.com. We will appoint an Article 27 Representative if and when our processing activity in the EU or UK requires one, and we will identify the Representative in this Policy at that time.
7.4 Canadian and Brazilian Residents
If you are located in Canada, you may exercise rights under PIPEDA (and, where applicable, Quebec's Law 25). If you are located in Brazil, you may exercise rights under the LGPD. In either case, contact us at hello@shouldirip.com.
8. How to Exercise Your Rights
To exercise any right described in Section 7, email hello@shouldirip.com from the email address on file with your account, or use any in-app privacy request form we make available. Please describe the right you wish to exercise and provide enough information for us to locate your account.
Verification (account-holders). Before fulfilling a request, we will take reasonable steps to verify your identity. For account-holders this typically means confirming control of the email address on file or your ability to sign in. For requests involving particularly sensitive information we may ask for additional verification proportionate to the request.
Verification (non-account-holders). If you have never signed in but have visited the Site, we may match your request to the pseudonymous identifier(s) associated with your IP address and/or PostHog distinct_id. We may ask you to provide the distinct_id from your browser or other device information so we can locate the records. Where we cannot verify a request to a reasonable degree of certainty, we will decline and explain.
Response time. For requests subject to the CCPA we will respond within 45 days, extendable by an additional 45 days where reasonably necessary with notice to you. For requests subject to the GDPR or UK GDPR we will respond within one month, extendable by up to two additional months for complex requests with notice to you. For requests under other state laws we will respond within the period prescribed by the applicable law (typically 45 days).
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may require you to verify your own identity directly with us.
Appeals. If we deny your request and you reside in a U.S. state that provides for an appeal, you may appeal our decision by replying to our response email within a reasonable period. We will respond to your appeal within the time required by the applicable state law (generally 60 days) and, if we deny the appeal, will provide information about how to contact your state attorney general or supervisory authority.
9. Data Retention
We retain Personal Information for as long as your account is active and for a period thereafter to satisfy legal, accounting, fraud-prevention, and operational obligations. Specific retention windows are estimates and may vary based on the category of information and our legal obligations:
- Account, profile, preferences, and favorites: For the life of your account, plus up to 90 days thereafter for backup-rotation cycles before complete deletion. Inactive accounts (no sign-in for 24 months) will receive a 30-day deletion-warning email to the address on file; if there is no sign-in within those 30 days, the account is deleted.
- Billing records (Stripe customer ID, subscription status, billing cycle, last-four digits): Up to 7 years from the last transaction to satisfy U.S. tax and accounting recordkeeping.
- Feedback submissions: Up to 24 months from submission, then deleted or anonymized (the identifier is replaced by a random ID and retained for product analysis as permitted by the Terms of Service).
- Product-analytics events (PostHog): Approximately 12 to 24 months from capture; aggregated, non-identifying metrics may be retained longer. When you delete your account, we instruct PostHog to delete the alias mapping your distinct_id to your account; pseudonymous event data captured before that mapping may remain in PostHog within its analytics retention period in non-identifying form.
- Session replays (PostHog): Retained for the session-replay retention period configured with our analytics provider (currently approximately 30 days from capture) and then deleted. Associated replays are deleted on the same basis as your other PostHog data when you delete your account.
- Page-performance measurements (Pulsetic): Under our Data Processing Agreement with this provider, these measurements are retained for as long as our service contract with it remains in force, unless applicable law requires otherwise, and are deleted or returned to us when that contract ends. There is no shorter fixed window. These measurements carry no visitor identifier and are not linked to your account, so they cannot be located or deleted by reference to you individually. If you would prefer they not be collected at all, decline analytics using the Cookie Preferences link in the site footer or send a Global Privacy Control signal (see Section 13).
- Email engagement events (Postmark): Approximately 12 to 24 months from capture.
- Server logs: Approximately 30 days, except where retained longer for an active security investigation.
- OAuth refresh tokens. Authentication tokens received from Apple, Google, or magic-link sign-in are stored in encrypted form by Supabase Auth and are rotated automatically. We delete refresh tokens promptly upon account deletion, sign-out, or revocation by you.
- Email suppression list. To comply with CAN-SPAM and protect users from receiving email at bounced or complained addresses, we maintain a suppression list of such email addresses indefinitely. The list contains email addresses only — no other Personal Information.
- Backups. Database backups containing Personal Information are retained on a rolling cycle of up to 90 days and are then permanently deleted in the normal backup-rotation cycle.
You can delete your account yourself from Account settings. Deletion is scheduled with a 30-day grace period during which you may sign back in and restore your account; once that period elapses, your account is permanently deleted and any active subscription is cancelled. When you delete your account, we will delete or de-identify your Personal Information within a reasonable period (typically within 90 days), except where we are required or permitted by law to retain it (for example, de-identified feedback you submitted, which is retained without your identifier).
10. Data Security and Breach Notification
Our security program includes encryption of data in transit using TLS 1.2 or higher; encryption at rest for our primary application database; role-based access controls; audit logging of administrative actions; separation of production and non-production environments; regular dependency and vulnerability scanning; and contractual security obligations on our sub-processors. We never receive or store full payment card numbers — Stripe is responsible for handling and securing that data.
Multi-factor authentication. Multi-factor authentication is available through your chosen identity provider (Sign in with Apple, Sign in with Google) where you have enabled it on that account. Magic-link sign-in is bound to your verified email address and uses one-time, time-limited links.
No method of transmission over the internet and no method of electronic storage is completely secure. We cannot guarantee absolute security. If you believe your account or any information has been compromised, please contact us immediately at hello@shouldirip.com.
10.1 Breach Notification
In the event of a confirmed Personal Information breach that creates a risk to your rights or property, we will notify affected users without undue delay and in accordance with applicable law. For EU/UK users, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required by Article 33 of the GDPR, and we will notify affected data subjects without undue delay where required by Article 34. For U.S. residents, we will provide notification consistent with the breach-notification laws of your state of residence (including Alaska Stat. § 45.48.010 et seq. and California Civ. Code § 1798.82), including the methods, content, and timing prescribed by those laws.
11. International Data Transfers
The Service is operated from the United States. Each sub-processor listed in Section 5 processes Personal Information in the location stated in that table. All of our sub-processors are headquartered in the United States. Two of them use infrastructure outside it: Stripe operates global payment infrastructure under SCC-compliant frameworks, and Designmodo Inc. (Pulsetic) engages hosting providers located in both the United States and the European Union. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, which may have data-protection laws that differ from those in your country.
If your data leaves the EEA, UK, or Switzerland for the United States, we use legal protections required by GDPR/UK GDPR. In particular:
- We rely on the European Commission's Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, Module 2 (controller-to-processor), with each US sub-processor that does not itself self-certify under an adequacy framework.
- For UK transfers, we use the UK International Data Transfer Addendum issued by the Information Commissioner's Office.
- For sub-processors that maintain a current self-certification under the EU-U.S. Data Privacy Framework (and the UK Extension and Swiss-U.S. DPF, where applicable), we may rely on that certification as an additional transfer mechanism. You may verify the current DPF status of any sub-processor at https://www.dataprivacyframework.gov.
- We apply supplementary measures including encryption in transit and at rest, role-based access controls, and contractual commitments with our sub-processors to challenge over-broad government-access requests. We periodically review the legal landscape applicable to international transfers and our sub-processors' transfer safeguards; you may request additional information about a specific transfer mechanism by emailing hello@shouldirip.com.
You may obtain a copy of the transfer mechanism applicable to a specific sub-processor by emailing hello@shouldirip.com.
12. Children's Privacy
The Service is for users 18 years of age or older. We do not knowingly collect Personal Information from anyone under 18. Consistent with the U.S. Children's Online Privacy Protection Act ("COPPA"), we do not knowingly collect, use, or disclose Personal Information from children under 13. If we learn that we have collected Personal Information from a person under 18, we will suspend the account, delete the information from our systems and instruct our sub-processors to do the same, cancel any active subscription, and — where requested in writing by a parent or legal guardian — refund unused subscription fees notwithstanding the standard no-refund policy in our Terms of Service. Parents or guardians who believe a minor has registered may contact us at hello@shouldirip.com.
13. Do Not Track and Global Privacy Control
Most modern browsers offer a "Do Not Track" ("DNT") setting. Because there is no industry-wide consensus on how to interpret DNT signals, we do not currently respond to them.
We recognize the Global Privacy Control ("GPC") signal as a valid opt-out under California, Colorado, Connecticut, and other state laws that require us to honor it. Because we do not sell Personal Information or share it for cross-context behavioral advertising, the GPC signal does not change our existing processing — but we record receipt of the signal as confirmation of your opt-out preference in case our practices change in the future. To submit a separate, account-level Do Not Sell or Share request, email hello@shouldirip.com.
14. California-Specific Disclosures
This section supplements the information above and is intended to satisfy the additional disclosure requirements of the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").
In the preceding twelve months, we have collected the following categories of Personal Information enumerated in Cal. Civ. Code § 1798.140:
| CCPA Category | Examples Actually Collected | Sources | Business Purposes | Categories of Recipients | Retention |
|---|---|---|---|---|---|
| Identifiers | Email address, Supabase UUID, OAuth subject identifier (Apple/Google), IP address, PostHog distinct_id. | Directly from you; automatically from your device; from Apple, Google, and Stripe. | Provide and secure the Service; authenticate users; communicate; analytics; comply with law. | Supabase, Stripe, PostHog, Pulsetic, Postmark, Slack, Apple, Google, Vultr, Cloudflare. | Life of account + up to 90 days for backups; logs ~30 days. |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Email address, optional display name, billing details processed by Stripe. | Directly from you; from Stripe. | Provide the Service; bill subscriptions; communicate. | Supabase, Stripe, Postmark. | Life of account + up to 90 days; billing records up to 7 years. |
| Commercial information | Subscription tier, Founder Number, billing cycle, subscription status, favorited pack IDs. | Directly from you; from Stripe webhooks. | Operate paid features; tax/accounting compliance. | Supabase, Stripe. | Life of account + up to 90 days; billing records up to 7 years. |
| Internet or network activity | Page views, button clicks, feature usage, referring URL, device/browser, email opens and clicks, masked session replays, page-performance measurements (Core Web Vitals). | Automatically through PostHog, Pulsetic, and Postmark; from our application servers. | Analytics, product improvement, deliverability, security. | PostHog, Pulsetic, Postmark, Vultr, Cloudflare. | ~12-24 months; Pulsetic page-performance measurements for the term of our service contract with that provider. |
| Geolocation data (coarse, IP-derived) | Approximate region inferred from IP address. | Automatically from your device. | Security, abuse prevention, analytics; we do not collect precise geolocation. | PostHog, Pulsetic, Vultr, Cloudflare. | ~12-24 months; logs ~30 days. |
| Inferences | Derived preferences from feature usage (for example, which pack categories you favor based on viewing patterns). | Automatically from PostHog analytics. | Product improvement and personalization of the Service. | PostHog. | ~12-24 months. |
| Sensitive Personal Information | Account credentials (authentication tokens from Apple, Google, or magic-link sign-in). | From Supabase Auth and OAuth providers. | Authenticate you and secure your account only. Not used to infer characteristics about you. | Supabase, Apple, Google. | Life of session/account; deleted on account deletion or revocation. |
Sale and Sharing. In the preceding twelve months, we have not sold Personal Information and have not shared Personal Information for cross-context behavioral advertising. We have disclosed Personal Information for the business purposes described above to the categories of recipients listed above.
Sensitive Personal Information. We use Sensitive Personal Information only for purposes permitted by California regulations (such as performing the services you requested and securing your account) and not for inferring characteristics about you. As a result, the "right to limit" the use of Sensitive Personal Information does not change how we use it in practice; you may still submit a request and we will confirm our practices.
Financial Incentive Notice. Our Pro and Founding Member tiers are paid subscriptions. The price reflects the value of the additional product features and access we provide and is unrelated to the value of any Personal Information you provide. You may decline or cancel a paid tier without losing any privacy right.
"Shine the Light" (Cal. Civ. Code § 1798.83). California residents may request information about disclosures of Personal Information to third parties for those parties' direct marketing purposes. We do not disclose Personal Information to third parties for their direct marketing purposes.
15. Accessibility
Triple Lloyd is committed to making the Service accessible to users with disabilities. We strive to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. If you encounter an accessibility barrier or need an accommodation to access or exercise the rights described in this Policy, contact us at hello@shouldirip.com with the subject line "Accessibility," and we will respond within a reasonable time and work with you to provide the information or feature in an accessible format.
16. Communications Channels (SMS / Push)
We currently communicate with you only by email and in-app notice. We do not send SMS/text messages or push notifications. If we add such channels, we will obtain your prior express consent in compliance with the Telephone Consumer Protection Act (TCPA), CAN-SPAM, CASL, and other applicable laws, and you will be able to opt out at any time.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will provide reasonable advance notice — generally at least thirty (30) days — by posting the updated Policy at this URL, updating the "Last updated" date at the top, and notifying you by email to the address on file or via in-app notice. We may provide a shorter notice period (and may make non-material changes effective immediately when posted) where a shorter period is required by law, regulation, or to address a security or legal-compliance issue, in which case we will provide as much advance notice as is reasonably practicable. Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of it.
18. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, contact us at:
Triple Lloyd, LLC
Attn: Privacy
821 N St Ste 102
Anchorage, AK 99501
Email: hello@shouldirip.com
Disputes about this Policy are subject to the dispute-resolution provisions of our Terms of Service, including binding individual arbitration and a class-action waiver (with a 30-day opt-out). See Section 17 of the Terms of Service.