Introduction

This Privacy Policy (the "Policy") describes how VRAMGlass ("VRAMGlass", "we", "our", or "us") collects, uses, and discloses information about you in connection with your access to and use of the website at vramglass.com and related widgets and APIs (collectively, the "Service"). This Policy forms part of our Terms of Service.

All browsing features of the Service are available without signing in. We store information associated with your account only when you sign in and use features such as the watchlist and price alerts.

Information We Collect

  • Account information: Your email address, interface language, and the dates and times you registered and last signed in. If you sign in with Google, we also receive the unique account identifier, display name, and profile picture URL provided by Google. Source: you, or the Google account you choose to use.
  • Watchlist and alert settings: The GPUs you follow, the platforms for which you set alerts, your target prices and currencies, and whether each alert is enabled. Source: you.
  • Email delivery records: The time each verification code email and price alert email is sent, the price that triggered each alert, and delivery status. Source: the Service and our email service provider.
  • Sign-in security data: Email verification codes are stored only as cryptographic hashes and expire after 10 minutes. To prevent abuse, we count the number of codes sent per cryptographically hashed email address and IP address. Source: generated automatically by the Service.
  • Technical and access information: IP address, browser type and version, operating system, referring page, and language preference. Source: processed automatically through Cloudflare.
  • Usage statistics: Page views, traffic sources, country or region, clicks and scrolling, and Microsoft Clarity session replays. Source: your browser, collected through the analytics services listed under "Service Providers" below.

We do not collect payment information, and we do not ask you to provide your real name, phone number, or address.

How We Use Information

We use the information described above to:

  • provide and operate the Service, including verifying your identity, saving your watchlist and alerts, and determining whether prices have reached the target prices you set;
  • send emails you have requested, namely sign-in verification codes and price alerts;
  • detect, prevent, and respond to fraud, abuse, bulk account registration, or violations of our Terms of Service;
  • communicate with you about account matters, service announcements, and material updates to our policies;
  • analyze usage in aggregate to improve the Service; and
  • comply with applicable legal obligations.

We do not send marketing emails, we do not use your personal information for behaviorally targeted advertising, and we do not sell your personal information to any third party.

Cookies and Local Storage

The Service uses the following cookies and local browser storage items:

  • __Host-vg_session (HTTP cookie): Maintains your session after you sign in. Retained for 30 days and renewed when used; deleted when you sign out.
  • __Host-vg_oauth (HTTP cookie): Protects against request forgery while you sign in with Google. Expires after 10 minutes and is deleted once sign-in is complete.
  • __Host-vg_challenge (HTTP cookie): Records the current verification attempt while you sign in with an email verification code. Expires after 10 minutes.
  • vg-theme, vg-currency (local storage): Remember your selected light or dark theme and display currency. Retained until you clear them manually.
  • vg-price-navigation (session storage): Restores your scroll position when you return from a price page. Cleared when you close the tab.
  • _ga, _ga_* (first-party cookies): Used by Google Analytics 4 to distinguish browsers and sessions and to measure overall traffic. Retained for up to 2 years.
  • _clck, _clsk, and similar (first-party cookies): Used by Microsoft Clarity to measure clicks and scrolling and to provide session replays. Retained for up to 1 year.
  • Cloudflare may set cookies for security purposes (such as __cf_bm), which are typically retained for 30 minutes.

The first three items and Cloudflare's security cookies are strictly necessary to operate the Service. Ahrefs Web Analytics does not use cookies. You can clear cookies and local storage at any time through your browser settings; doing so will sign you out. You can also block analytics scripts using your browser's privacy settings or a content-blocking extension; this will not affect any functionality of the Service.

Service Providers

We engage the following service providers to operate the Service. Each receives only the data necessary for the function described:

  • Cloudflare: Website hosting, database, content delivery, DNS, and abuse prevention. Account, watchlist, and alert data are stored in a database hosted by Cloudflare. Cloudflare also processes request metadata (IP address and User-Agent).
  • Resend: Sends verification code and price alert emails. Receives recipient email addresses and email content.
  • Google: Google sign-in (only if you choose to sign in with Google), which receives the sign-in request and returns your account identifier, email address, display name, and profile picture to us; and Google Analytics for traffic analytics.
  • Microsoft: Microsoft Clarity for usage analytics and session replay.
  • Ahrefs: Ahrefs Web Analytics for traffic analytics; and Ahrefs Bot Analytics, to which basic request metadata (such as the request URL, IP address, user agent, referrer, and response status) is shared server-side so we can understand how search engines and other crawlers access the Service.

These service providers process data in accordance with their own privacy policies: Cloudflare, Resend, Google, Microsoft, Ahrefs.

Disclosure of Information

Other than to the service providers listed under "Service Providers" above, we disclose your information only: when required by law, regulation, or a competent authority; when necessary to protect the rights, property, or safety of the Service, our users, or the public; or in connection with a merger or transfer of the Service, in which case the successor will continue to process your information in accordance with this Policy.

Data Retention

  • Account, watchlist, and alerts: Retained until your account is deleted.
  • Sessions: Expire after 30 days without use; expired records are purged periodically.
  • Verification code records: Deleted within 24 hours.
  • Abuse-prevention counters: Reset within 1 hour.
  • Alert email records: Email bodies are deleted once sending is complete; records used to prevent duplicate sends (time, price, and status) are retained for 90 days.
  • Database backups: Rollback copies of our Cloudflare-hosted database are retained for up to 30 days, after which they are automatically overwritten.
  • Usage statistics: Retained in accordance with each analytics service's retention settings.

When we process your request to delete your account, we also delete your account information, sessions, watchlist, alerts, and email delivery records; copies in database backups are overwritten within 30 days.

Your Rights

Depending on the laws where you live, you may have the right to access, correct, delete, or export your personal information, to restrict or object to certain processing by us, and to withdraw your consent. You can:

  • view and edit your watchlist and alerts on your account page;
  • stop receiving alert emails by clicking the unsubscribe link at the bottom of any alert email; or
  • email hello@vramglass.com to request deletion of your account or make any other request, and we will respond within 30 days.

You also have the right to lodge a complaint with the data protection supervisory authority where you live.

International Data Transfers

We and our service providers process data in multiple countries and regions, including the United States. Your information may be transferred to locations outside your jurisdiction, and we will implement appropriate safeguards in accordance with applicable law.

Children's Privacy

The Service is not directed to children under the age of 13 (or under the minimum age of digital consent in your jurisdiction). If we learn that we have unknowingly collected such information, we will delete it.

Security

We take reasonable technical measures to protect your information, including: HTTPS across the entire site; session cookies that are restricted to HTTPS and cannot be read by scripts; storing only hashes of session tokens and verification codes in our database, never plaintext; and rate limiting of sign-in requests. No system can guarantee absolute security.

Changes to This Policy

We may revise this Policy from time to time, and we will update the date at the top of this page when we do. If we make material changes, we will post a notice on the website or notify registered users by email.

Contact Us

If you have any questions about this Policy, please contact us at hello@vramglass.com.

This Policy is available in several languages. If the versions differ, the English version governs.