Skip to content

Privacy Policy

Last updated June 2026

Short version: no accounts, no passwords, no third-party ad trackers, no data sales. Email is collected only when you explicitly ask for something email-shaped. Analytics are first-party, but they do use a persistent random session id and record campaign/ad-click tags (like UTM and gclid) when they're in the link you arrived on — so they aren't fully anonymous. We honor Global Privacy Control and Do Not Track; otherwise analytics are on by default and you can opt out anytime from the cookie banner. The data controller is Jupiter Coastal Media, operating Setup Gear Guide (201 N US Highway 1, STE D10 #1269, Jupiter, FL 33477).

What we collect

Email addresses — only when you set a price alert, save a build by email, or sign up for a deal digest. Every email use is double-opt-in: nothing sends until you click the verification link, and every email carries a one-click unsubscribe.

Corrections & contact — if you submit a correction or use the contact route, we receive what you send (which may include an email address you provide) so we can respond and fix the catalog.

Saved builds — stored under unguessable share tokens. A build link is a capability: anyone holding the link can view it. Builds are not public, not listed, and not indexed by default.

On-site searches — the text you type into the site search is recorded (with the number of results) so we can see what gear people look for and which searches return nothing. Don't type anything sensitive into the search box.

First-party analytics — a random session id, event names like 'builder started' or 'build saved', and the page path. No third-party analytics scripts, no advertising pixels, no fingerprinting.

Traffic attribution — when you arrive from a campaign or ad, we record the UTM tags, the gclid ad-click id (if present), the referring site's hostname, and the landing page, kept as a first-touch record for that browser. This is how we measure which sources send useful traffic.

API logs — public API calls log a salted hash of the caller IP for rate-limit enforcement; the raw IP is not stored.

Cookies, consent & your controls

We set one first-party cookie, sp_session: a random id (no name, email, or cross-site data) set on your first visit and kept for about 12 months. It links your page views to any outbound affiliate clicks in the same session so we can measure the content→click funnel.

We honor your browser's Global Privacy Control (GPC) and Do Not Track (DNT) signals — if either is on, no analytics cookie is set and nothing is tracked. Otherwise the sp_session cookie is set on your first visit and analytics are on by default; choose Decline on the cookie banner at any time to opt out.

To withdraw consent later, choose Decline on the cookie banner or clear cookies/site data for this site in your browser.

What we never collect

No passwords (there are no accounts). No payment data (purchases happen on retailer sites). No precise location. No data sales to anyone, ever.

Affiliate clicks

Outbound retailer clicks pass through our /go redirect, which records the offer clicked, the page type it came from, and the sp_session id (so a click can be tied to the browsing session that led to it). Retailers and affiliate networks have their own tracking once you arrive — their policies govern from there.

Business outreach

We sometimes contact creators and businesses (e.g. for partnerships or to flag catalog issues) using business contact details that are publicly listed. Our lawful basis is legitimate interest in B2B outreach; we store the contact, the source, and our correspondence, and we honor opt-outs immediately — every outreach email carries an unsubscribe link, and once you opt out we suppress future contact. This outreach is separate from the consumer email above.

Deletion

Unsubscribing removes you from sends immediately. To fully delete your email identity and alerts, use the contact route on the corrections page; deletion is processed manually in v1.