Privacy Policy
Effective 2026-08-19 · Last updated 2026-09-26
Who we are. Cashbackproof is operated by Easily Software LLC, 1441 Woodmont Ln NW #1453, Atlanta, GA 30318, US. Contact: hello@cashbackproof.com.
What this site collects. One thing: form submissions. If you join the waitlist or contact us, we store the email address you give us, an optional message (contact form), a source tag (so we know which community sent you), the page the form was on, and a timestamp. That's the complete list. Storage is Cloudflare D1, processed under Cloudflare's data processing terms.
What this site does NOT do. No analytics. No tracking pixels. No advertising cookies. No third-party scripts. The only cookies, if any, are Cloudflare's functional security cookies.
How we use your email. Waitlist: launch announcements and beta invitations — nothing else. Contact: replying to you. We never sell, share, or enrich your data.
Deletion. Email hello@cashbackproof.com and we delete your submissions, usually within 7 days.
The extension. The Cashbackproof browser extension has its own privacy terms, set out in full below.
The extension
Cashbackproof browser extension · privacy disclosures
What the extension stores (locally only)
Evidence bundles (redirect hops, click IDs, timestamps, session-continuity events, order number/total, a locally redacted screenshot, SHA-256 hashes), portal snapshots for decline monitoring, when each portal was last checked and whether that check succeeded, which locale of a multi-domain portal you use (inferred from your own portal visits and click-outs, so the monitor checks the site you actually log into), settings, and — on Pro — the license key with its signed validation certificate.
All of it lives in the browser's local storage on the device. There is no cloud copy, no sync, no account, and no telemetry of any kind.
What the extension observes (locally, never transmitted)
During a purchase you started from a supported portal, the extension watches the affiliate tracking cookies on that portal's affiliate networks — and, if you enable auto-capture, on the retailer — to detect when a coupon extension, ad-blocker, or other party overwrites or clears the cookie carrying your cashback attribution. This is read-only: the extension never sets or removes a cookie, and the cookie's value is never stored or transmitted. The only things it records are the network name, the cookie name, a timestamp, and whether the cookie matched your own click. Reading happens entirely on your device; nothing about it goes over the network, and it adds no new network destinations — the complete network surface below is unchanged. You can turn the attribution radar off in the vault's settings; when it is off, nothing is read from the retailer, and nothing is recorded, classified, or acted on.
The optional conflicting-extension scan runs only when you click "Scan for conflicting extensions" in the vault's settings. It reads the installed-extension list Chrome reports (each extension's name, id and on/off state) once, on this device, keeps only the matches against a list of known coupon and cashback extensions bundled with the extension, and drops the permission it asked for right after. Nothing about it goes over the network. Erasing everything in the vault also clears the stored result.
The complete network surface
- 01
Your portal pages — the extension reads cashback activity pages on the four supported portals using your own logged-in browser session. No credentials are collected or stored.
- 02
license.cashbackproof.com (Pro only) — about once a week the extension sends your license key and its activation instance id to validate the subscription with the payment provider. The license server is stateless: it stores no records of any kind. If it is unreachable, Pro keeps working for 14 days (fail-open; it retries about daily while it is unreachable) — outages never lock your data.
- 03
OpenTimestamps calendars (Pro, opt-in, OFF by default) — if you enable timestamp anchoring, the extension sends the 64-character SHA-256 fingerprint of a new evidence bundle to an OpenTimestamps calendar (a.pool.opentimestamps.org or b.pool.opentimestamps.org). The fingerprint reveals nothing about the bundle's contents; it lets you prove later that the evidence existed by that date.
Nothing else. No analytics, no error reporting, no content servers.
Payments
Pro is sold by Lemon Squeezy as merchant of record; payment details never touch Cashbackproof. The license key Lemon Squeezy issues is the only purchase artifact the extension ever sees.
Your controls
Export everything as JSON, erase everything, deactivate the license on a device, and toggle every feature — all from the vault's settings. "Erase everything" wipes evidence; it leaves the license untouched (it isn't evidence). Uninstalling the extension deletes all local data.