spycart
Sign in
Spy Search

Security & Data Practices

spycart, a Canadian company · Last updated: 1 September 2026

We never see your card details

Subscription payments are handled end-to-end by Stripe. Card numbers are entered on Stripe's own payment surface and are never sent to or stored on spycart servers. We keep only the subscription status we need to know whether your searches are unlimited.

Encrypted in transit, access-controlled at rest

All traffic to spycart runs over HTTPS. Our database enforces row-level access rules, so your saved searches, alerts and account row are readable only by your signed-in session — not by other users, and not by the browser of anyone else.

Check-ins are anonymous by design

Store check-ins record a store and a coarse coordinate so other shoppers can see how busy a place is. They are never shown with your name, they expire automatically after a short window, and you can delete your own check-in at any time.

Data minimisation

We ask for as little as possible: an email address, an optional display name and postal code, and the searches you run. We do not sell personal data, we do not run ad networks, and we do not build shopper profiles for third parties. See the Privacy Policy for the full list.

Deleting your account

Email us from your account address and we delete your profile, alerts and check-ins. Cancelled subscription records are kept only as long as Canadian bookkeeping rules require.

Reporting a vulnerability

Found a hole? Email Sales@gdcs.me with “security” in the subject and enough detail to reproduce it. Please give us a reasonable window to fix it before publishing, and do not access other people's data while testing. We acknowledge reports within 2 business days and we will not pursue good-faith researchers.

See also Support and Refunds.