✨ Memorial Day Mega Sale is LIVE — Up to 70% off across 200+ brands. Shop the deals →
🔒 Legal & Compliance GDPR · CCPA Compliant · 📅 Last updated May 9, 2026

Privacy Policy

Full transparency on what data Price & Pick collects, how we use it, your rights under GDPR and CCPA, and how to manage your privacy preferences. Cross-reference our affiliate disclosure, terms of use, or cookie policy.

⚡ TL;DR

The short version

  • We collect minimal data — just what's needed for the site to work and to send you our newsletter (if you subscribe).
  • We don't sell your data to advertisers or data brokers. Period.
  • You can delete your data any time by emailing us via the contact page. We respond within 30 days.
  • We use cookies for analytics, affiliate tracking, and personalization. You can manage these via the cookie banner or our cookie policy.
  • Compliant with GDPR (EU), CCPA (California), and other major privacy regulations.

01 Who we are

Price & Pick is an independent product review website operated by our 14-person editorial team. We test products, publish reviews, and help readers make better purchasing decisions. Read our about page for full company background or our testing methodology for editorial standards.

For the purposes of this policy, "we," "us," and "our" refer to Price & Pick. "You" refers to anyone who visits our site, subscribes to our newsletter, or interacts with us in any way. Our data controller is reachable via the contact page for any privacy-related questions.

02 What we collect

We collect only the data needed for the site to function and to provide the services you request. We've structured our data collection to be minimal — if we don't need it, we don't collect it.

Data CategoryWhat's CollectedWhen
Account dataEmail, hashed password, display name (optional)If you create an account
Newsletter dataEmail address, subscription preferencesIf you subscribe
Usage dataPages viewed, click events, session durationWhenever you visit
Device dataBrowser, OS, screen size, IP address (anonymized)Whenever you visit
CookiesSession identifiers, preferences, analyticsPer cookie policy
Contact form dataName, email, message contentWhen you contact us

What we do NOT collect

  • Payment information — we don't sell anything directly, so we never see your credit card details
  • Sensitive personal data — health, biometric, religious, political affiliations, etc.
  • Precise location data — we don't track your GPS coordinates
  • Phone numbers — we never ask for them
  • Social security or government IDs — never relevant for what we do

03 How we use your data

We use the data we collect for specific, limited purposes — all related to running the site and delivering content you've asked for.

  • Provide our services — show you reviews, awards, deals, and recommendations across our reviews, 2026 awards, and blog
  • Send communications — newsletter emails (if you subscribe), product updates, responses to your inquiries via the contact page
  • Improve the site — understand what content readers find useful, what pages fail to load, what's slow, what's confusing
  • Maintain security — detect and prevent fraud, spam, and abuse of our systems
  • Comply with the law — respond to lawful requests from regulators, law enforcement, or courts when required

What we never do: We never sell your data to advertisers or data brokers. We never use your data for unrelated marketing purposes. We never share your reading habits with brands you might be researching. Your data isn't a product we sell — it's a responsibility we carry.

04 Cookies & tracking

We use cookies and similar technologies (web beacons, local storage, pixel tags) to make the site work, remember your preferences, measure traffic, and track affiliate referrals. Read our complete cookie policy for full detail.

Categories of cookies we use

  • Strictly necessary — required for the site to function (login sessions, security, basic navigation). Cannot be disabled.
  • Analytics — Google Analytics 4, internal logging. Helps us understand what works. You can opt out via cookie banner.
  • Affiliate tracking — required to attribute purchases that support our editorial work. See our affiliate disclosure. You can opt out.
  • Preferences — remembers your dark/light mode, font size, dismissed banners. You can clear these via your browser settings.

How to manage cookies: Use the cookie banner that appears on your first visit, your browser's privacy settings, or our cookie policy page. You can clear cookies any time, though some site features may not work properly without strictly necessary cookies.

05 Third parties we work with

We use a small number of third-party service providers to help run the site. Each one is bound by privacy agreements that prevent misuse of your data. We choose providers based on their privacy track record, not just price.

Service providers

  • Google Analytics 4 — anonymized site analytics. IP addresses are masked before they reach Google.
  • Cloudflare — security, DDoS protection, content delivery network
  • SendGrid / Postmark — newsletter and transactional email delivery
  • Stripe / Payment processors — only used for paid services (e.g., partnership inquiries); never for reader-facing transactions
  • Affiliate networks — Amazon Associates, Skimlinks, Impact, Awin, Commission Junction. Used to track affiliate referrals (see our disclosure)

What these providers see

Each provider only sees the minimum data needed for their function. Analytics providers see anonymized usage patterns. Email providers see your email address and the messages we send you. Affiliate networks see referral clicks, not your identity. We've reviewed each provider's privacy policy and only work with those meeting our standards.

06 How long we keep your data

We keep your data only as long as needed to provide our services, comply with legal obligations, or maintain editorial records. Different data types have different retention periods.

  • Account data — until you delete your account (then deleted within 30 days)
  • Newsletter data — until you unsubscribe (then deleted within 7 days)
  • Usage and analytics data — 26 months, then automatically deleted by Google Analytics
  • Contact form messages — 24 months for support history, then deleted
  • Server logs — 90 days for security and debugging purposes
  • Cookies — varies by type, typically 1-24 months (see cookie policy)

To request immediate deletion of any data we hold about you, contact our team. We respond to data deletion requests within 30 days as required by law.

07 Your rights

Regardless of where you live, you have rights regarding the data we hold about you. We honor these rights for all readers, not just those in jurisdictions that legally require it.

  • Right to access — request a copy of all data we hold about you
  • Right to correction — request that we fix inaccurate data
  • Right to deletion — request that we delete your data ("right to be forgotten")
  • Right to portability — request your data in a machine-readable format
  • Right to object — opt out of specific data uses (analytics, affiliate tracking, marketing)
  • Right to restrict processing — pause certain data uses while a dispute is being resolved

To exercise any of these rights, contact our team with the specific request. We'll respond within 30 days. There is no fee for these requests, and we don't ask for justification.

08 GDPR (EU/UK readers)

If you're in the European Union or United Kingdom, the General Data Protection Regulation (GDPR) gives you specific rights over your personal data. Price & Pick complies with GDPR for all EU/UK visitors.

Legal basis for processing

  • Consent — for analytics, affiliate tracking, and marketing cookies (you control via cookie banner)
  • Contract — to provide newsletter or account services you've signed up for
  • Legitimate interest — to maintain site security and improve our content (balanced against your privacy rights)
  • Legal obligation — to comply with regulatory or law enforcement requirements

International data transfers

Some of our service providers (e.g., Google Analytics, Cloudflare) are based in the United States. When we transfer EU/UK data to the US, we use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data remains protected. You can request a copy of these clauses by emailing us via the contact page.

Your right to lodge a complaint

If you believe we've violated your GDPR rights, you can file a complaint with your local data protection authority. We encourage you to contact us first — we'd rather fix issues directly than have them go through regulators. We respond to GDPR-related complaints within 7 days.

09 CCPA (California readers)

If you're a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you specific rights over your personal information. Price & Pick complies with both.

Your CCPA rights

  • Right to know — what personal information we collect, sources, uses, and third-party disclosures
  • Right to delete — request deletion of your personal information
  • Right to correct — request that we fix inaccurate information
  • Right to opt out of sale — we don't sell data, so this is automatic. You're opted out by default.
  • Right to limit use of sensitive PI — we don't collect sensitive personal information, so this also doesn't apply
  • Right to non-discrimination — exercising your rights won't result in different service or higher prices

"Do Not Sell My Personal Information": Price & Pick does not sell your personal information to anyone, period. This means there's nothing to opt out of — but if you'd like written confirmation of this, contact our team and we'll provide it.

To exercise CCPA rights, contact our team. We verify your identity through your registered email address and respond within 45 days (extendable by 45 days if needed, with notice).

10 Children's privacy

Price & Pick is not directed at children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. Our reviews cover consumer products that are sometimes used by children (toys, kids' tech), but our audience and account holders must be adults.

If you're a parent or guardian and believe your child has provided us with personal information, please contact our team immediately. We will delete the information within 7 days and confirm the deletion with you.

11 Security

We take reasonable technical and organizational measures to protect your data from unauthorized access, alteration, disclosure, or destruction. Specific measures include:

  • Encryption in transit — TLS 1.3 for all site traffic, ensuring data sent between your browser and our servers can't be intercepted
  • Encryption at rest — data stored on our servers is encrypted using AES-256
  • Access controls — only authorized team members can access user data, with audit logs of every access
  • Regular security audits — third-party penetration testing performed annually
  • Incident response plan — if a breach occurs, we notify affected users within 72 hours as required by GDPR

No system is perfectly secure — but we've structured our practices to minimize risk. If you discover a security vulnerability, please report it via our contact page. We respond within 24 hours and credit responsible disclosure researchers in our security acknowledgments.

12 Changes to this policy

We may update this privacy policy occasionally to reflect changes in our practices, services, or legal requirements. When we make material changes, we'll:

  • Update the "Last updated" date at the top of this page
  • Notify subscribers via email if you've signed up for our newsletter
  • Display a banner on the site for 30 days after significant changes
  • Maintain a changelog on this page (available via the contact page on request)

Material changes will not be applied retroactively without your explicit consent. We'll never reduce your rights or expand our data collection without notifying you first and giving you the option to opt out.

Questions about your privacy?

Whether you want to access, correct, or delete your data — or just understand our policies better — get in touch. We respond to all privacy inquiries within 30 days, often within 24 hours.