Privacy policy
Last updated: August 25, 2026This policy explains the personal data Benchmark Maker uses, why we use it, how long certain code-managed data lasts, and the choices available to you.
1.Controller and scope
Vincent Quesada, a sole trader operating as Benchmark Maker, is the controller. Contact help@benchmarkmaker.com. Postal contact details are in the legal notice.
This policy covers the site, accounts, comparisons, Premium, optional analytics and advertising, feedback, translation, AI features, and the browser extension. Linked websites have their own privacy practices.
2.Data we process
2.1Account and community data
We process account identifiers, email address, password or passkey authentication data, Google OAuth account information returned within the scopes you approve, security events, optional profile and social data, and comparison content: titles, descriptions, items, criteria, scores, notes, images, links, sharing settings, versions, favorites, shares, notifications, reports, and moderation information.
2.2Payment, technical, and feedback data
For Premium, we receive Stripe customer, payment, and subscription identifiers, not card numbers. Technical data can include IP address used for rate limits, browser and request data, consent choices, rate-limit keys, media provenance, source URLs, preview IDs, and selected-image rights confirmations. UserJot feedback can include feedback text, votes, comments, and an email address you supply.
2.3Translation, AI, and extension inputs
Google Cloud Translation receives eligible benchmark titles, descriptions, items, criteria, and notes when automatic translation is used. AI prompts can include comparison context, item names, criteria, your instructions, and extension-supplied page information. On your explicit extension action, it reads the current page's canonical URL, title, up to five descriptions, and up to eight image candidates. It does not collect page text in the current implementation.
3.Why we use data
| Activity | Purpose and data | Legal basis | Retention logic | Recipients and transfers |
|---|---|---|---|---|
| Account, security, and Google OAuth | Create and secure an account, authenticate with email, passkeys, or Google OAuth, and prevent abuse. Google OAuth uses account information returned within the scopes you approve. | Performance of the account service and legitimate interests in security. | A one-year sliding session is configured and refreshed on activity, with a one-day fresh-authentication age. Account data has no single code-configured deletion schedule. | Benchmark Maker, Supabase, Vercel, and Google for Google OAuth. |
| Stripe customer creation and Premium | The Stripe integration creates a Stripe customer record at each signup, then uses customer and subscription identifiers to offer, administer, and support Premium. Card details stay with Stripe. | Legitimate interest in preparing the account billing capability; performance of the Premium contract when you purchase it; legal obligations for billing records. | The code does not set a general Stripe-record deletion schedule. Stripe and legal accounting, fraud, and dispute requirements can apply. | Stripe. |
| Comparisons and community | Store, display, share, moderate, and notify about comparisons and optional profiles, follows, favorites, shares, reports, and preferences. | Performance of the feature you choose and legitimate interests in keeping the community safe. | While the relevant account or content remains available. Account deletion cascades several account-linked records, but the code does not prove an unscheduled cleanup of every provider copy. | Benchmark Maker, Supabase, Vercel, Resend, and people allowed by the sharing setting. |
| Media search, previews, and rate limiting | Search or import selected images, preserve provenance, prevent abuse, and protect remote preview access. Upstash keys can contain an IP address plus endpoint, or an email address plus email type. Product-page preview records contain a user ID, preview ID, original URL, and source-page URL. | Performance of the requested feature and legitimate interests in security, traceability, and rights protection. | Preview records expire after at most 15 minutes. Image-search cache records expire after one day. Rate-limit counters expire at their configured bounded windows, from one minute to 24 hours depending on the endpoint. | Upstash Redis for configured production rate limits, preview records, and image-search cache; Supabase, Vercel, and the selected source provider or website. |
| Optional analytics | After you opt in, PostHog records an anonymous or pseudonymous distinct ID, pageviews, pageleaves, autocapture interactions, and sanitized application error events to understand and improve the product. Sensitive fields and email-like strings are redacted before logger events are sent. | Consent. | PostHog loads and captures only after you accept analytics. It stops optional capture after you withdraw, including opt-out and reset of its optional analytics state. Provider-side event retention follows the configured PostHog service setting. | PostHog. |
| Feedback, roadmap, and Recent Updates | After an explicit Feedback, Roadmap, or Recent Updates action, UserJot provides the requested interface and processes feedback, votes, comments, and any email address you supply. | Performance of the feedback feature you request and legitimate interests in managing product feedback. | The code does not configure a general UserJot deletion schedule. Feedback remains subject to provider configuration and applicable obligations. | UserJot. |
| Translation | Translate eligible benchmark titles, descriptions, items, criteria, and notes when automatic translation is enabled for display. | Performance of the optional translation feature you request. | For the request and the provider's technical lifecycle. The code does not establish a general provider deletion schedule. | Google Cloud Translation. |
| Advertising and Speed Insights | Fund the free service with Google AdSense where permitted. Vercel Speed Insights measures anonymous performance data such as Core Web Vitals, route or page, device or browser information, and country-level location. | Consent where required for advertising; legitimate interests in anonymous service-performance measurement for Speed Insights. | Advertising follows the applicable Google and consent-management lifecycle. The application code does not set a Speed Insights retention period. | Google AdSense and Vercel Speed Insights. |
| AI-assisted features | Generate suggestions, research items, and proposed comparison data from the prompt and context you submit. | Performance of the AI feature you request. | For the request and the technical lifecycle needed to deliver, secure, and troubleshoot it. No general provider cleanup run is configured in the code. | Google Gemini and Perplexity. |
| Browser extension | On your explicit extension action, prepare a comparison draft from the current page's limited metadata and image candidates. Drafts are kept in chrome.storage.session for the browser session. | Performance of the extension feature you request. | The current extension uses browser-session storage; it does not configure persistent page-text collection or a server-side extension-data retention schedule. | Benchmark Maker only when you send the draft to the service; otherwise Chrome session storage on your device. |
4.Service providers and recipients
| Provider | Role |
|---|---|
| Vercel and Vercel Speed Insights | Hosting, delivery, and anonymous performance measurement. |
| Supabase | Database and storage services. |
| Stripe | A customer record is created on signup; Stripe also processes Premium subscriptions and payment data. |
| Google OAuth and Google Cloud Translation | Optional sign-in and translation of eligible benchmark text. |
| Upstash | Configured Redis rate limits, short-lived media previews, and image-search cache. |
| PostHog | Consent-gated product analytics with in-memory browser persistence and sanitized logger events. |
| UserJot | Feedback, roadmap, and Recent Updates interface loaded only after the corresponding explicit action. |
| Resend | Transactional email delivery. |
| Google AdSense | Advertising and Google's consent-management flow where it applies. |
| Google Gemini and Perplexity | AI-assisted comparison and research requests. |
6.Retention
Benchmark Maker-controlled retention is configured as follows: a one-year sliding session refreshed on activity, a 15-minute maximum for protected media previews, a one-day image-search cache, and rate-limit windows from one minute to 24 hours. Unused media is eligible for a daily scheduled cleanup after 30 days without use. Translation cache rows are checked daily and removed when the source changes or is no longer eligible, or when failed for seven days. These technical expiry periods do not promise simultaneous erasure of every provider log.
For provider-held payment, analytics, feedback, AI, advertising, and hosting records, Benchmark Maker does not control the provider retention setting. Their period is determined by the service agreement, provider dashboard setting, backup and security needs, and legal obligations. For Resend email data specifically, its DPA says it processes customer data while the agreement is active and deletes user or customer data within 90 days of Benchmark Maker terminating its Resend account. Account deletion can cascade several application records, but does not prove immediate deletion of every backup or provider copy.
7.International processing
The deployment configuration pins Vercel server execution to cle1. The repository does not reveal the production Supabase project region, deployed PostHog host, Upstash database region, UserJot workspace location, Google Cloud data-residency setting, Perplexity location, or accepted provider agreements. We therefore do not describe an unverified production destination for those services.
Stripe documents transfer of customer data to Stripe, LLC in the United States and its Data Processing Agreement and Data Transfers Addendum provide the EU-US Data Privacy Framework, with the EU Standard Contractual Clauses as the documented fallback. Resend documents that its primary processing operations take place in the United States, an EU-US Data Privacy Framework certification, and a DPA containing SCCs. For Vercel, Supabase, PostHog, Google, Upstash, UserJot, Perplexity, and Google AdSense, the applicable destination and safeguard must be verified against the configured account and accepted DPA before relying on them. Email help@benchmarkmaker.com for the available provider agreement, destination, or transfer details.
8.Your rights and complaints
Depending on the circumstances, you can request access, rectification, erasure, restriction, portability, or object to processing. You can withdraw optional consent at any time without affecting processing already carried out before withdrawal. We normally respond within one month, subject to the conditions and extensions allowed by the GDPR.
Send requests to help@benchmarkmaker.com. You may also lodge a complaint with the French supervisory authority through the CNIL's complaint service, or with the authority in your usual place of residence, work, or the place of the alleged infringement. CM2C is the consumer mediator for eligible consumer disputes after a prior written complaint. It is not the data-protection authority.
9.Security and policy updates
We use access controls, authenticated service providers, and technical measures appropriate to the service. No online service can guarantee absolute security.
We may update this policy when processing changes. The version published on this page is the current version.