Privacy Policy
Last updated: September 6, 2026
1. Overview
PC Parts Lens ("we", "us", or "our") tracks historical prices for computer components and lets you watch parts for price drops and restocks. This Privacy Policy explains what information we collect, why, who we share it with, and the choices you have.
You can browse price history, charts, and part pages without an account. Creating an account, setting up alerts, and subscribing to our paid plan each involve additional information, described below.
2. Information We Collect
Account information. When you register, we collect your email address and a password. Authentication is handled by Amazon Cognito; your password is stored and verified by Cognito and is never visible to us. We also store the account identifier Cognito issues, which is what links your alerts and subscription to you.
Alerts and notification history. When you create a price-drop or back-in-stock alert, we store the part you are watching, your target price, the email address to notify, and whether the alert is still active. When an alert fires we keep a record of it — the part, the triggering price, the marketplace, and the time — so you can see your alert history in the app.
Billing information. If you subscribe to Pro, payments are processed by Stripe. Your card number never reaches our servers. We store the Stripe customer and subscription identifiers, your plan and billing interval, your subscription status and renewal date, and the brand and last four digits of your card so we can show you which card is on file.
Usage and device information. Our servers keep basic request logs: the path requested, the response status, the time, and the network address the request arrived from. Behind our load balancer that address is usually the balancer's own rather than yours. We do not log your browser, operating system, or referring page. If you consent to analytics (see section 4), Google Analytics collects device and usage information via cookies, and that data is held by Google.
Error reports. When something breaks, we send diagnostic information — the error, the page it happened on, and browser details — to Sentry so we can fix it. We do not record your screen or your session, and we have disabled Sentry's automatic collection of personally identifying request data.
Product recommendations. If you suggest a part for us to track, we store the suggestion and link it to your account, so we can tell you what happened to it.
Export records. If you export price history on a paid plan, we record which parts you exported and in which month, so we can apply your monthly allowance.
Local storage. Your signed-in state, your analytics choice, and — if you arrived from one of our ads — the click identifier that ad appended to the link are stored in your browser's local storage, not sent to us as cookies. See section 4.
Advertising attribution. If you arrived from one of our ads and then create an account or subscribe, Google receives the click identifier above — with the date and amount of that first payment, in the case of a subscription — so we can tell which ads pay for themselves. When you create an account we also send a one-way hash of your email address, which is what lets Google match that signup to the click: Google receives the hash, never the address itself. We do not send your name or account identifier.
3. How We Use Your Information
- Provide the Service: render price history, run your alerts, and deliver the notifications you asked for.
- Authenticate you and keep your account secure.
- Process subscription payments, renewals, and cancellations, and grant or revoke Pro features accordingly.
- Diagnose errors, monitor reliability, and prevent abuse.
- With your consent, understand which parts and pages people use so we know what to build next.
- Measure whether our advertising works — which ads lead to sign-ups and subscriptions — so we do not keep paying for ones that do not.
- Respond to support and privacy requests.
Why we are allowed to. If you are in the European Economic Area, the United Kingdom or Switzerland, the law asks us to name a basis for each use. Running your account, your alerts and your subscription is performance of a contract with you. Keeping request logs, monitoring errors, and protecting the Service against abuse is our legitimate interest in it staying up and working. Keeping billing records for seven years, and keeping an unsubscribed address on the suppression list, are legal obligations. Analytics and advertising, including the ad click identifier, rest on your consent, which you give through the banner and can withdraw at any time from your settings.
We do not sell your personal information. The only third party that receives any of it for advertising is Google, for one purpose: telling us which of our ads produced a sign-up or a subscription. What we send is described in section 2 — the click identifier from the ad, the date and amount of a first payment, and a one-way hash of your email address on sign-up. We run no remarketing lists and no audience targeting, so nothing we send is used to follow you around other sites, and we ask Google to handle it under its restricted data processing terms, which limit it to measuring our own campaigns.
4. Cookies, Local Storage, and Your Choices
We do not set any advertising or tracking cookies of our own. What the site stores in your browser falls into three categories:
- Strictly necessary. When you sign in, Amazon Cognito stores session tokens in your browser's local storage so you stay signed in. We also store a small cached copy of your signed-in state so pages render without a flash of logged-out content, your analytics choice so we do not ask again on every visit, and a two-letter country code our content delivery network works out from your network address, which is how we know which privacy rules apply to you. That code identifies a country and nothing else — no identifier for you or your device — and it is what decides whether the choices below are on or off by default. These are required for the site to work and are not used for tracking.
- Analytics and advertising, and your choice about them. Google's tag is present on every page, and what it does before you answer depends on where you are. In the European Economic Area, the United Kingdom and Switzerland it starts with every storage type denied: it sets no cookies and builds no profile of you across pages or visits until you accept. Everywhere else these are on by default and you can turn them off — from the notice on your first visit, or at any time from the Data & privacy section of your settings. If your browser sends a Global Privacy Control signal we treat that as turning them off, wherever you are. Where these are on by default, the tag also sends the ad click identifier described below whichever way you answer; where consent comes first, it sends nothing until you accept. Declining leaves the site behaving identically.
- Ad attribution. When you follow one of our ads, Google appends a click identifier to the link. We store that identifier in your browser's local storage so that if you later subscribe, we can tell Google which ad earned the sale — a click and a subscription are often days apart, and there is no other way to connect them. In the European Economic Area, the United Kingdom and Switzerland we store nothing until you accept, and turning the setting off afterwards erases it; elsewhere it is stored whichever way you answer, and turning the setting off leaves it in place. It is stored on our own site, and it identifies the ad rather than you. We report it to Google when that click leads to a signup or a paid subscription, whichever way you answered the banner — measuring that is the only reason we keep it. It is discarded after 90 days, which is the longest Google will accept it. Clearing your site data removes it.
5. Service Providers and Third Parties
We share information with the following providers only as needed to run the Service. Each processes it under its own privacy policy.
- Amazon Web Services — hosting, databases, and Amazon Cognito for account sign-up and authentication.
- Amazon Simple Email Service (SES) — delivery of alert emails to the address you provided.
- Stripe — payment processing and card storage for Pro subscriptions.
- Google Analytics — usage analytics. Present on every page, but stores nothing and sends no identifier unless you consent.
- Google Ads — advertising measurement. Receives the ad click identifier described in section 4, and the date and amount of a first subscription payment, so we can tell which ads are worth running.
- Sentry — error and performance monitoring. Sentry receives no session recordings from us.
We may also disclose information where required by law, or to protect our rights, safety, or the integrity of the Service.
Affiliate links. Some links to marketplaces are affiliate links. Following one tells that marketplace we referred you, so it can attribute a purchase to us. We do not receive your order details or any personal information back from those marketplaces — only aggregate commission reporting. See our affiliate disclosure for how this does and does not affect what we show you.
Where your information is held. We operate from the United States and our servers are in the AWS US East region. Every provider above processes information in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, using the Service means your information is transferred there, which is a country without an adequacy decision covering all of these transfers. We rely on the European Commission's Standard Contractual Clauses, which each of the providers above offers as part of its data processing terms, and on the UK Addendum where the UK GDPR applies.
6. Alert Emails and Unsubscribing
We only email you about alerts you created, plus transactional messages about your account or subscription. We do not send marketing email.
Every alert email carries a one-click unsubscribe link. Using it adds your address to a suppression list, which stops all alert email to that address regardless of which alert fires or which account it belongs to. You can also turn alert emails off, and back on, from the Price alerts section of your settings — it writes to the same suppression list. In-app notifications continue either way, unless you pause or delete the alerts themselves.
7. Data Retention
- Account data — kept while your account is active. Deleting your account removes it from our live systems immediately; residual copies may persist in backups for up to 12 months.
- Alerts and notification history — kept alongside your account, on the same schedule, and deleted with it.
- Product recommendations — if you suggest a part for us to track, we keep the suggestion, but deleting your account detaches it from you. An approved suggestion has already become a tracked part that other people rely on.
- Billing records — kept for 7 years, as tax and accounting rules require, and therefore not removed when you delete your account. What we keep is the record that ties a payment to an account: Stripe identifiers, plan, status, and dates. The card brand and last four digits are cleared on deletion, since they existed only to show you which card was on file. Card details themselves are held by Stripe, not by us.
- Suppressed email addresses — kept indefinitely. This is the record that stops us emailing an address that asked us not to, so deleting it would undo the unsubscribe.
- Export records — kept alongside your account and deleted with it.
- Server request logs — retained for 30 days, then deleted automatically.
- Analytics data — held by Google under its own retention settings, if you consented. We keep no copy, and it is not stored against your account in a form we can look up, so we cannot retrieve or delete your browsing history from Google for you. Withdrawing consent and clearing your cookies is what stops and removes it. The conversion recorded when an ad leads to a signup or subscription is different: deleting your account withdraws it from Google, and clears the click identifier from our own records.
- Ad click identifiers — kept in your browser for 90 days, and on our side only on the billing record of a subscription that resulted from one. Deleting your account clears ours immediately, even though the billing record itself is retained for the seven years tax rules require.
- Locally stored preferences — kept in your browser until you clear them.
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Request correction or deletion of your personal information.
- Object to or restrict certain processing of your data.
- Withdraw consent where processing is based on consent, such as analytics.
- Receive a copy of your data in a portable format.
- Complain to a data protection authority. If you are in the European Economic Area, the United Kingdom or Switzerland, you can raise a concern with the supervisory authority where you live or work without contacting us first — though we would rather you gave us the chance to put it right.
If you are a California resident, the CCPA and CPRA give you these rights along with the right not to be discriminated against for exercising them. We do not sell personal information for money, and we do not engage in cross-context behavioral advertising — we run no remarketing lists and no audience targeting — which is what “sharing” means under those laws. The advertising data described in section 3 goes to Google solely to measure our own campaigns.
Opt-out signals. If your browser sends a Global Privacy Control signal we treat it as an opt-out without you having to do anything: analytics and advertising cookies stay off, and we neither store nor report the identifier from an ad you followed. Turning the setting on yourself, from the Data & privacy section of your settings, overrides the signal for that browser.
Deleting your account. You can do this yourself, at any time, from the Delete account section of your settings. It takes effect immediately and cannot be undone: it removes your profile and sign-in credentials, your alerts and their targets, your notification history, and cancels any active Pro subscription at once. There is no recovery period. Billing records are retained as described in section 7, and an unsubscribed email address stays on the suppression list so we do not start emailing it again.
Getting a copy of your data. The Data & privacy section of your settings downloads a JSON file of what we hold about you in this app: your alerts, your notification history, your export allowance, and your billing record. It does not include data held by our processors, and the file lists those omissions so you know what it does not cover. We can retrieve your Stripe billing history on request. We cannot retrieve your analytics or error-diagnostic data, or single you out in our server logs: none of it is linked to your account — we never send Google or Sentry an identifier for you — so there is nothing for us to look up.
To exercise any other right above — correction, objection, or anything the download does not cover — email us at privacy@pcpartslens.com. We will verify your request against the email address on your account and respond within 30 days.
9. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
10. Security
We take reasonable technical and organizational measures to protect your information: traffic is encrypted in transit, passwords are handled by Amazon Cognito rather than stored by us, and card details are held by Stripe. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
12. Contact
If you have any questions or concerns about this Privacy Policy, please contact us at privacy@pcpartslens.com.