Privacy Policy
Last updated September 24, 2026.
Harbor provides an API that lets apps ("developers") buy from stores on behalf of their users. This policy explains what we collect from developers and, on their behalf, about their users.
Developers
- Account: your email address and sign-in details. Passwords are handled by our authentication provider; Harbor never sees them.
- Usage: API requests, keys (stored only as hashes), webhook endpoints, and billing usage.
Your users (processed for developers)
- The developer's own id for the user, the spending limits they choose, and which stores they connect.
- The offers, checkouts and orders the developer's app creates: products, prices, totals, order numbers and status.
- A shipping address or email only when the developer sends one for a checkout.
- With Harbor for Chrome: only what's needed to prepare an order the user's app asked for (the product, cart and total), on the retailer's pages involved in that order.
We don't collect store passwords or payment card numbers, and we don't sell personal information.
Why we use it
To run Harbor: look up offers, prepare and place orders within users' limits, report order status to developers, prevent abuse, and bill for usage.
Who processes it
- Vercel (hosting), in the United States.
- Supabase (database and authentication), in the United States.
- The stores involved in an order, which receive what's needed to place it.
- Google Fonts, which serves the site's typefaces.
Cookies and storage
We use your browser's storage for your sign-in session and preferences like light or dark mode. We don't use advertising trackers.
Retention and deletion
We keep data while the developer's account is active and delete it on request or when the account closes, except where we must keep records by law. Users can ask the developer who built their app, or us, to delete their data.
Security
See Security for how keys, tokens and data are protected.
Contact
Privacy questions or requests: hello@useharbor.io.