Privacy Policy
A plain-language explanation of what Purchase Ledger collects, why it is needed, and the choices you have.
Effective date: August 23, 2026
Version: 1.0
Purchase Ledger helps users understand item-level retail spending and identify lower-cost purchasing options.
Operator
Service name: Purchase Ledger
Company and service operator: Copper Pine Digital Holdings LLC
Privacy/support contact: support@mypurchaseledger.com
Copper Pine Digital Holdings LLC (“Copper Pine,” “we,” “us,” or “our”) operates Purchase Ledger and is responsible for the service described in this policy. Questions or privacy requests can be sent to the contact above.
Data categories
Account and security data
- email address and display name;
- Argon2id password hash (never plaintext password);
- hashed browser/OAuth/capture token identifiers and expiration/revocation metadata;
- security/audit events and privacy-minimized application-error records, including a request ID, route category, status, and signed-in account link when available;
- privacy-hashed IP value for security-event correlation.
Private purchase data
- retailer, store/location, purchase date/time and channel;
- private receipt/order identifiers;
- products, quantities, item prices, discounts, subtotal, tax, and total;
- retailer SKU, GTIN/UPC, brand, category, package size/unit;
- source confidence;
- private user-triggered current product-page price captures, including the user-approved product name, optional note, and a cleaned source-page link used to return to the item and group its price history;
- product watch targets, optional return and warranty dates, and in-app alert status;
- shopping optimization preferences.
Retailer authentication data
When an approved retailer integration requires it, Purchase Ledger may store the minimum OAuth/session token required to read the user's authorized retailer data. Such values are designed to be encrypted at rest. Purchase Ledger does not support storing retailer passwords.
Email confirmation
Every new account uses Purchase Ledger's own expiring, one-time email confirmation link to verify that the registrant controls the email address. This includes accounts created through Google or Microsoft; a provider's authenticated identity response does not replace Purchase Ledger confirmation. Only a hash of the confirmation token is stored.
Receipt and invoice scanning
When a user chooses receipt or invoice scanning, Purchase Ledger sends the uploaded image—or locally rendered pages from a PDF or TIFF of up to five pages—to Amazon Textract to identify dates, totals, and item lines. Purchase Ledger does not retain the original upload or the rendered pages. The user must review the extracted fields before they are saved to the private ledger. AWS may process service request data as described in its service terms and privacy materials.
Financial-transaction matching
Purchase Ledger does not require bank credentials. A read-only matching tool may receive a retailer, date, and amount from ChatGPT or another authorized caller to find likely receipts. Purchase Ledger uses those query values transiently and does not persist the supplied financial transaction.
Optional community price trends
Participation is off by default.
If the user explicitly enables future contribution, eligible observations may include:
- product identifier used to group matching items;
- retailer/store identifier;
- local date/time information used for aggregate time buckets;
- item price/currency and a comparable package-unit price when available;
- channel;
- promotion/membership metadata where known;
- evidence confidence.
Enabling future contribution does not automatically contribute older private receipts. Historical contribution is a separate explicit action.
The settings page shows separate On/Off controls for future prices and existing-receipt prices. Turning off existing-receipt sharing removes those historical contributions without changing the future-price choice. Turning off future sharing removes all of the user's active contributions and also turns off historical sharing.
The shared observation does not include the user's name, email, bank account, card number, full receipt, retailer order number, password, retailer authentication token, or ChatGPT conversation text.
A keyed contributor pseudonym is stored internally to enforce privacy thresholds, remove a user's contributed observations on opt-out/deletion, and prevent one account from dominating aggregates. It is not returned in analytics responses.
Cross-user analytics are suppressed below the configured distinct-contributor threshold. Public statistics use equal-contributor robust aggregation (one contributor-level median per contributor before group statistics) and do not expose raw shared observations.
Turning participation off deletes observations associated with that user's contributor pseudonym while leaving their private ledger intact.
Purposes
Data is processed to:
- search and explain item-level purchases;
- classify spending;
- match financial transactions to likely receipts;
- compare the user's historical/current prices;
- identify possible duplicates, incomplete imports, recurring purchases, and recorded price increases;
- evaluate user-created price targets against legitimately received observations, without claiming universal live price or stock data;
- remind users about return and warranty dates they enter;
- compare exact product UPC/GTIN values with official U.S. Consumer Product Safety Commission recall data;
- compute privacy-preserving aggregate price patterns;
- compare verified equivalent products on compatible package bases;
- optimize shopping baskets according to user preferences;
- secure, audit, export, and maintain the service.
Copper Pine does not sell a user's private Purchase Ledger data and does not expose one tenant's private ledger to another tenant.
Administrative access and corrections
Authorized Copper Pine administration may access private account and purchase information when reasonably necessary to provide support, diagnose problems, correct records, protect the service, maintain data integrity, fulfill user requests, or comply with law. Administrative access is limited to those purposes, and important access and modifications are recorded for accountability. Administrator correction does not transfer ownership of user data or permit unrelated use.
Recipients / disclosures
Copper Pine currently uses Amazon Web Services for Purchase Ledger hosting, encrypted volumes, container images, systems management, email delivery, content delivery, and user-requested receipt/invoice analysis. Google and Microsoft process identity data when a user chooses those sign-in methods. An enabled retailer connection sends the minimum authorized requests to that retailer. An authorized ChatGPT or other MCP client receives only tool results requested for the signed-in user. DNS and domain registration providers process ordinary domain/network records.
The service retrieves public recall records from the U.S. Consumer Product Safety Commission. It sends no user or purchase data to the CPSC API.
The service does not intentionally send private purchase data to advertising networks. If analytics, advertising, support, database, monitoring, or other subprocessors are added, this policy must be updated before that processing begins.
Retention
- private ledger: retained until the user deletes purchase data or the account, subject to backup retention;
- shared contribution: retained while contributed, and removed from the active shared table after opt-out/account deletion;
- security/audit and account-linked application-error data: retained for account security and service reliability, and removed with account deletion unless law or a security investigation requires limited preservation;
- encrypted production backups: generated daily and retained for 14 days. A deletion is removed from the active database promptly but may remain in an encrypted backup until that backup expires or is overwritten. Restoring a backup requires re-applying deletions made after that backup.
User controls
The control panel provides:
- future community-price sharing opt-in/out;
- separate historical contribution action;
- OAuth/MCP authorization revocation;
- browser-session revocation;
- extension capture-token revocation;
- individual browser, extension, and connected-app revocation;
- password change with credential revocation;
- notification settings, with product recalls on by default and all other alert types off by default;
- product watchlist, return-date, and warranty-date controls;
- data export;
- deletion of purchase data without deleting the account;
- deletion of an individual saved-price record;
- retailer-connection disconnect/removal; and
- account deletion.
Saved source links are never fetched by the server. Credentials, fragments, common tracking parameters, and links outside the selected retailer's domain are discarded before storage. Source links and private notes are not copied into shared price observations.
The export contains only the account email, purchases, private saved-price snapshots, and shared price contributions. It excludes service preferences, consent and audit records, password hashes, live retailer secrets, browser-session tokens, capture tokens, and OAuth bearer tokens.
Deleting purchase data without deleting the account removes the same three purchase-data collections included in the export: purchases, private saved-price snapshots, and shared price contributions. The account email, settings, sign-in methods, security records, and retailer connections remain. Account deletion removes the remaining account-linked data, subject to the backup and legal-retention limits above.
Security
Copper Pine uses Argon2id, hashed opaque session/bearer/capture credentials, AES-256-GCM for approved retailer secrets, encrypted volumes and backups, tenant-scoped private reads, CSRF/security headers, and privacy-thresholded shared analytics to protect Purchase Ledger. No service can promise absolute security; we maintain patches, monitoring, access control, incident response, and security testing.
Children / regulated data
Purchase Ledger is not designed to intentionally collect government identifiers, payment-card security data, protected health information, or other regulated data beyond ordinary retail purchase records. Registration is limited to adults in the United States under the current Terms.
Changes
Material privacy changes should be reflected in this policy before data handling changes are deployed. Changes that expand shared-data use should require appropriate user notice/consent rather than silently broadening an existing choice.
Contact
Copper Pine Digital Holdings LLC
support@mypurchaseledger.com