Last updated: July 12, 2026
This policy describes how the operator of this site handles personal data. Privacy questions and rights requests can be sent to the contact email published in the site footer.
Public browsing and offline cache
Browsing does not require an account. The progressive web app may cache public pages and static assets on your device for offline navigation. It excludes admin, checkout, and authenticated API responses. You can remove this cache through your browser's site-data controls.
When analytics is enabled, it processes page views and usage events under the analytics provider's own controls. The operator does not use matchup voter identifiers or Push subscription identifiers for cross-site advertising.
Directory submissions
The submission form stores the product facts you enter and an optional contact email so the editorial team can review the candidate and communicate a decision. Unpromoted candidates receive an expiry date; archived public facts are retained for audit and provenance rather than silently rewritten.
Daily matchup votes
Voting requires abuse-prevention verification. The server combines Site, matchup, IP address, and a bounded user-agent string into a keyed HMAC. The raw IP and user agent are not stored with the vote. The key rotates monthly, so the pseudonymous identifier cannot remain stable across months. Vote identifiers are removed after 90 days while aggregate counts remain. Results describe a self-selected directional preference sample, not a representative ranking.
Web Push
Push is opt-in and uses two separate actions: a contextual prompt and the browser's own permission dialog. The Push endpoint and keys are encrypted at rest. The site stores selected interests, consent proof, delivery status, and a frequency limit of at most one notification per subscription per day.
You can revoke Push from /notifications or your browser. Revocation deletes the usable encrypted endpoint and interests. Terminal provider responses also expire the subscription.
Admin accounts and audit
Operators with an admin account provide identity and authentication data. Site membership, security events, review decisions, API key metadata, and business actions are recorded for access control and accountability. API key plaintext is shown once and is not stored.
Purchases and downloads
A merchant of record handles checkout for the source-template purchase. Card and billing details are entered with the payment provider and governed by its privacy policy. This site stores the order identity, product, amount, currency, buyer email reported by the payment provider, entitlement, fulfillment state, artifact reference, and bounded download grants. It never stores card details.
Refunds revoke entitlements and outstanding download grants. Accounting records may be retained for legal and tax obligations.
Service providers and transfers
Depending on enabled features, data may be processed by the CDN and security provider (TLS, bot protection, object storage), the payment provider, browser Push providers, the configured analytics service, and infrastructure or monitoring providers. External directory links are governed by their own privacy policies.
Your choices
You may disable analytics with browser controls, decline Push, revoke an existing Push subscription, avoid optional submission email, and request access, correction, or deletion where applicable. Some ledger, fraud-prevention, licensing, and accounting records may need to be retained when law or security requires it.