Privacy Policy
This policy describes the data Merchant Debugger currently processes when you use the website, run a check, buy a batch or contact support.
1. Controller
The controller for Merchant Debugger service data is Daria Fokina, sole trader, Veilchenweg 16, 88046 Friedrichshafen, Germany. Privacy requests can be sent to merchantdebugger.support@gmail.com.
2. Data used for checks
For a single or batch check, we process the public product-page URL and the price, currency or availability value you submit. A batch upload also contains the CSV file needed to run the selected check. The service visits the product page and creates a diagnostic result.
CSV contents, product URLs, submitted product values and batch results are processed in memory and are not written to the persistent payment database. Temporary batch results are removed after your browser receives them or within two minutes after completion. Temporary browser-process files are deleted after processing.
3. Payment, job and recovery state
The SQLite database stores a limited technical record: opaque identifiers, hashed claim/access identifiers, hashed Paddle transaction and event identifiers, the selected SKU/module/tier, product limit, base offer snapshot, entitlement and job states, and queue/recovery timestamps. It does not store CSV contents, product URLs, submitted product values, results, buyer names, email addresses, postal addresses or card details.
An unfinished paid check can be recovered for up to seven days. Minimal technical payment, job and idempotency state is retained for up to 30 days, then deleted by automated cleanup.
4. Browser storage and cookies
Merchant Debugger does not create user accounts and does not use analytics or advertising trackers. It does not set its own cookies. The batch page stores only an opaque recovery code in your browser’s localStorage so the same paid check can be restored. CSV data and results are not stored in localStorage or sessionStorage. You can remove the recovery code by starting a new check or clearing this site’s browser storage.
The batch page loads Paddle.js and Paddle may use its own technologies when providing checkout, fraud prevention and payment services. Paddle describes that processing in its Privacy Notice. A live checkout is not currently enabled.
5. Hosting and technical logs
Merchant Debugger is hosted on Railway. The application does not create a separate access-log database and does not intentionally log CSV content, product values, recovery secrets or raw Paddle webhook bodies. Railway may process IP addresses, request metadata, deployment logs and security events to deliver and protect the hosting service. Infrastructure-log retention follows the active Railway configuration and Railway’s policies; Merchant Debugger does not maintain a separate archive of those logs.
6. Support correspondence
If you email support, we process your email address, message, headers and any information or attachments you choose to send. Support correspondence is kept only as long as reasonably necessary to answer the request, manage a related transaction or dispute, and meet legal obligations.
7. Purposes and legal bases
- Contract and pre-contract steps (Article 6(1)(b) GDPR): provide requested checks, validate purchases, maintain recovery and answer service-related support requests.
- Legitimate interests (Article 6(1)(f) GDPR): operate and secure the service, prevent abuse and duplicate fulfilment, troubleshoot failures and keep minimal technical records. These interests are balanced against user rights and the service is designed to minimize stored data.
- Legal obligations (Article 6(1)(c) GDPR): retain or disclose information where German or EU law requires it. Consent is used only where a specific optional activity requires it.
8. Recipients and service providers
- Railway provides application hosting, network delivery and persistent volume storage.
- Paddle independently handles checkout, payments, applicable sales taxes/VAT, billing documents, fraud controls and buyer support as Merchant of Record. Merchant Debugger does not receive your full card details.
- Google provides the Gmail mailbox used for support correspondence.
- The public product websites you ask us to check receive automated requests from the service. Their operators and embedded resources may receive the service’s IP address and ordinary request metadata under their own policies.
9. International transfers
Railway, Paddle, Google or product-page operators may process data outside Germany or the EEA. Where GDPR transfer rules apply to our service-provider relationships, transfers must use an applicable adequacy decision or appropriate safeguards such as standard contractual clauses. Paddle acts under its own Privacy Notice for buyer payment and billing data.
10. Your rights
Subject to the GDPR and any applicable limits, you may request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent for future processing where consent is the basis. You may also lodge a complaint with a data-protection supervisory authority, including the authority responsible for Baden-Württemberg.
To exercise a right, email merchantdebugger.support@gmail.com. We may need enough information to identify the relevant support message or technical record, but the service cannot search completed checks by email because it does not link them to an account.