Privacy Policy
Last updated August 22, 2026
DTC Perks (“Perks,” “we,” “us”) is operated by Ecombrand LLC, a Delaware limited liability company. This policy describes, without exaggeration or omission, what personal information the site actually collects, why, how long it’s kept, who else can see it, and how to exercise your rights over it. Where a feature described elsewhere on the site isn’t fully built yet, this policy says so rather than describing something that doesn’t exist.
Information we collect
Information you give us directly
- Account information — when you register, we collect your email address and, if you provide one, your name. If you sign up with a password, we store a salted, PBKDF2-hashed version of it — never the password itself, and we cannot reverse the hash to recover it.
- Google sign-in — if you choose to sign in with Google (where enabled), Google shares your name, email address, and a Google account identifier with us. We do not receive your Google password.
- Optional profile fields — your Shopify store domain and a self-reported monthly revenue band, if you choose to provide them, used only to personalize which deals we show as most relevant to your brand’s stage.
- Payment information — if you purchase Premium or Lifetime access, payment is processed entirely by Stripe, Inc. We never receive or store your card number, CVV, or full billing details. We do store the Stripe-generated customer and subscription identifiers, and your subscription status, so we can grant access and handle renewals or cancellations.
- Deal redemptions — which deals you’ve redeemed, when, and any code issued to you, so we can prevent duplicate redemptions and show you your own redemption history.
- Newsletter signups — the footer signup form validates your email address and acknowledges the submission, but as of this policy’s last-updated date, we do not yet store submitted newsletter emails or send any newsletter. This feature is under construction; we’re disclosing that plainly rather than implying an active mailing list exists.
- Anything you send us directly — if you email us with a question, request, or correction, we keep that correspondence to respond to you and, if relevant, to improve the site.
Information collected automatically
- Session cookie — one first-party, HTTP-only cookie (
perks_session) that keeps you signed in. See our Cookie Policy for full detail. - IP address, transiently — when you submit a login, registration, redemption, or newsletter form, your IP address is used briefly to enforce rate limits (for example, capping login attempts to slow down credential-stuffing attacks). This is stored in Cloudflare KV against a rate-limit key, automatically expires within the hour in almost every case, and is never linked to your account profile or used for tracking.
- Standard server logs — our hosting infrastructure (Cloudflare) generates standard request logs (timestamp, path, response code) for operating and securing the service. We do not run any separate analytics, advertising-pixel, or cross-site tracking script on this site today.
We do not collect precise geolocation, biometric data, or any information from users we know to be under 18. This site is intended for business owners and operators, not consumers or minors.
How we use your information
- To create and maintain your account, and to keep you signed in between visits.
- To show you deals relevant to your business stage and to track which deals you’ve redeemed, so you don’t see a redeemed offer as unclaimed.
- To process payments for Premium or Lifetime membership, manage your subscription, and handle renewals, cancellations, or disputes through Stripe.
- To respond to support requests you send us directly.
- To detect and slow down abuse — automated account creation, credential-stuffing, and scraping — using rate limits keyed to IP address and account.
- To meet legal obligations, such as responding to a lawful request from a government authority or enforcing our Terms of Service.
Our legal basis for processing (EEA/UK visitors)
If you’re located in the European Economic Area or United Kingdom, our legal bases for the processing above are: performance of a contract (running your account, showing you deals, processing a purchase), legitimate interests (rate-limiting to prevent abuse, responding to your emails), and consent where the law requires it (for example, before a newsletter is ever actually sent once that feature exists). You can withdraw consent at any time by contacting us.
When you click through to a vendor
When you click “Get this deal” and are taken to a vendor’s own website to sign up, that vendor becomes an independent data controller for whatever information you provide them there — subject to their own privacy policy, not ours. We encourage you to review each vendor’s policy before signing up. As of this policy’s last-updated date, our outbound links to vendors are plain links, not tracked redirects — we don’t currently know which specific vendor link you clicked unless you separately tell us (for example, by redeeming a deal through your account, which we do record per the section above).
How long we keep your information
- Account data — kept while your account is active, and for a reasonable period after deletion in case you return, unless you request immediate erasure (see “Your rights” below).
- Session tokens — expire automatically after 7 days, or immediately on logout.
- Rate-limit records — expire automatically, typically within an hour.
- Redemption records — kept for as long as your account exists, since they’re how we prevent double-redeeming a deal and show your own history back to you.
- Payment/subscription identifiers — kept for as long as required to manage your subscription and to meet our own financial record-keeping obligations after cancellation.
Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated personal information (subject to what we’re required to retain for legal, tax, or fraud-prevention reasons).
- Export your data in a portable format.
- Object to or restrict certain processing.
- If you’re a California resident, rights under the CCPA/CPRA, including the right to know what categories of information we’ve collected and to opt out of “sale” or “sharing” — we don’t sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of today, but you can still request confirmation of that in writing.
To exercise any of these rights, email hello@dtcperks.com. We’ll respond within 30 days. We may need to verify your identity before acting on a request involving your account.
How we protect your information
- Passwords are never stored in plain text — only a PBKDF2 hash with a per-user random salt, run at 100,000 iterations.
- Session tokens are signed (JWT), short-lived (7 days), stored in an HTTP-only cookie inaccessible to page scripts, and can be individually revoked.
- Administrative routes are gated behind session verification at the server level, not hidden only by a lack of a visible link.
- All traffic to the site is served over HTTPS.
- No method of transmission or storage is 100% secure, and we can’t guarantee absolute security — but we design and review the system with these specific protections in place, not as an afterthought.
Children's privacy
DTC Perks is a business-to-business tool aimed at ecommerce brand owners and operators. It is not directed at, and we do not knowingly collect information from, anyone under 18. If we learn we’ve collected information from someone under 18, we’ll delete it.
International data transfers
Our infrastructure provider, Cloudflare, operates a global network. Your information may be processed in the United States or other countries where Cloudflare, Stripe, or Google operate infrastructure. Where required, we rely on those providers’ own standard contractual safeguards for cross-border transfer.
Changes to this policy
If we make a material change to this policy, we’ll update the “Last updated” date above and, for significant changes, notify account holders by email. We won’t make a material change retroactive without your consent.
Contact us
Ecombrand LLC (operating DTC Perks) — hello@dtcperks.com. We’re a Delaware LLC and don’t currently publish a physical mailing address; write to us electronically and we’ll respond directly.