Privacy, plainly.
This is Spur's full privacy policy — everything we collect, why, who touches it, how long we keep it, and how you delete it. Written in plain English on purpose; it is still the binding version.
What we don't do.
- We don't ask for your card numbers. You tell us which cards you carry, like "Chase Sapphire Reserve", not the actual 16-digit numbers. Those stay between you and your bank.
- We don't take a cut of your points or cashback. Your rewards go straight from your bank to you, like they always have. We never touch them.
- We don't sell, share, rent, or trade your data. Not to advertisers, not to data brokers, not to anyone. Full stop.
- We don't track you around the internet. No Facebook pixels, no Google ads scripts, no cross-site trackers following you off our site. Our website analytics (PostHog) are cookieless — nothing is stored on your device and nothing follows you anywhere.
- We don't spam. One email when there's a beta spot for you. No marketing blasts, no newsletter unless you ask for it.
What we collect in the app.
- Account details you give us. Your name, email, date of birth (once, to confirm you're 18 or older — it can't be edited afterwards), and phone number. If you use email sign-in, your password is stored only as a salted bcrypt hash — we can't read it. If you use Sign in with Apple, Apple shares your name and email (or a private relay address) and we store those; Apple never shares a photo or anything else.
- Your profile photo, if you add one. A photo you pick from your library stays on your device — we have no upload endpoint for it. If you tap "Find my picture", we look up your email's Gravatar and store that image URL on your profile. Both are optional; the default is your initial.
- Your cards and activity. Which cards you carry (the product, like "Chase Sapphire Reserve" — never a card number), your points goals, sign-up-bonus progress, and any spending you log by hand. This is the data the recommendations run on.
- App analytics — first-party first. Events like "recommendation shown", "alert tapped", or "error occurred" go to our own servers, where sensitive values are stripped. We use them to fix bugs and see which features matter. A pseudonymous copy of these cleaned events (a random ID — never your email, name, or device identifiers, and never any location-related event) is processed for us by PostHog, our analytics provider. The app itself contains no third-party analytics code.
- Crash reports. If the app crashes, a crash diagnostic (stack trace, device model, OS version) may be sent via Sentry. Crash reports carry no name, email, location, or card data.
- A push token, if you allow notifications. It's the address Apple gives us to deliver your alerts. Turn off notifications and it goes unused.
Location — only if you turn it on.
Smart location alerts are off until you enable them. When they're on, your iPhone watches for place visits on-device. When you arrive somewhere, the app sends that coordinate to our servers to work out which merchant you're at (we use Foursquare's places database for this — Foursquare receives coordinates and a search query, not your name or account). You get the alert; iOS shows the blue location indicator the whole time we're watching.
- We keep no map of your movements. Our servers store aggregate counters only — how many alerts fired, how fast venue lookups were — never a per-person location history. This is enforced in code and checked in CI.
- Sensitive places never alert. Medical, legal, religious, and similar categories are filtered on-device and never trigger anything.
- One switch kills it all. Turning smart alerts off stops the monitoring itself, not just the notifications. You can also ask for the best card manually — that uses your location once, at the moment you ask.
How we use what we collect.
- To run Spur — match your cards to bonuses, track your goals, and recommend the right card at the right moment.
- To deliver the alerts you asked for — and nothing you didn't.
- To keep your account secure — sign-in, token refresh, fraud prevention.
- To fix what breaks — crash reports and product analytics (collected first-party, processed with PostHog's help).
- To answer you — when you email contact@spur.cards.
- To meet legal obligations — and that's the whole list. No advertising, no profiling for ads, no selling.
Who touches your data.
We use a small set of service providers to run Spur. They process data for us, under contract, and can't use it for their own purposes:
- Apple — Sign in with Apple and push notification delivery.
- Google Cloud — our servers and database (hosted in the United States).
- Foursquare — venue lookup for location alerts (coordinates and query only, no account identity).
- Plaid — only if you choose to connect a bank (details below).
- Gravatar — only if you tap "Find my picture".
- Sentry — crash diagnostics.
- Vercel — hosts this website and its cookieless analytics.
- PostHog — product analytics: cookieless page counts on this website, and pseudonymous app events (random ID only; sensitive values stripped before forwarding; location events never leave our servers).
Beyond that: we disclose data only if the law compels us, or as part of a merger or acquisition — and if that ever happens, this policy still binds whoever takes over, and we'll tell you first.
How we count visits.
We use Vercel Web Analytics and Vercel Speed Insights on this site; on our interactive pages, PostHog counts page views the same cookieless way. All of it is cookieless — nothing is stored on your device, and there are no Facebook pixels, no Google ads scripts, nothing that follows you off our site. PostHog is a third-party service that processes these anonymous counts for us; it never receives your name, email, or anything typed into a form, and it is not loaded at all when your browser sends the Global Privacy Control signal.
What we count, in plain English:
- Page views — which pages were loaded, by region and device class (not who you are).
- Clicks on the waitlist or beta button — so we know which page convinced you.
- Whether the form was submitted, errored, or duplicate — never the email you typed.
- Whether you shared a referral link — never who you shared it with.
We honor the Global Privacy Control signal — if your browser sends it, we don't count your visit.
If you connect Plaid (totally optional).
Spur works either way. If you want better, personalized recommendations, you can optionally connect your accounts via Plaid, a regulated financial-data provider used by most of the apps you already trust. Plaid lets Spur see which categories you actually spend in, so we recommend the card that earns most for your real life, not a generic one.
- It's opt-in. Skip Plaid and Spur still works. You just won't get the personalized layer on top of category-bonus matching.
- Disconnect anytime. You can revoke the connection from inside the app or directly through Plaid's portal. Once you do, the spending data goes with it.
- We don't sell what Plaid gives us. It powers your recommendations. That's the only thing it does.
How long we keep it, and how you delete it.
- While your account exists. Your profile, cards, goals, and activity stay as long as your account does — that's what makes the app work across devices.
- Delete your account in the app, right now. Profile → Delete account. The deletion runs on our servers first — if it fails, we tell you honestly and nothing is half-deleted. Signing out alone does not delete anything.
- Or email us. contact@spur.cards, subject "delete my data". We action it within 30 days, usually within 48 hours.
- What survives deletion. Aggregate statistics that never identified you (like alert counts), and records we're legally required to keep. Encrypted backups age out on a rolling schedule.
Your rights.
Wherever you live, we honor these on request — and for GDPR (EU/UK) and CCPA (California) they're the law:
- Access & portability — get a copy of what we hold about you.
- Correction — fix anything that's wrong (name is editable in the app; email us for the rest).
- Deletion — see above; the in-app button is the fastest path.
- Objection & restriction — tell us to stop a particular use.
- No sale, no "sharing". We do not sell personal information or share it for cross-context behavioral advertising, so there's nothing to opt out of. This site honors the Global Privacy Control signal.
- No discrimination — exercising a right never costs you features.
Requests go to contact@spur.cards. If you're in the EU/UK and we don't resolve something, you can complain to your local data-protection authority.
How we protect it.
- Encrypted in transit — TLS on every connection, app and site.
- Passwords hashed — salted bcrypt; we can't read them and never store them in plain text.
- Bank tokens encrypted at rest — Plaid access tokens are AES-256-GCM encrypted before they touch the database.
- Your session lives in the Keychain — iOS's secure storage, wiped on sign-out, with optional Face ID on top.
- Least access — admin surfaces see aggregates, not individual location or spending data.
Age, changes, and contact.
Spur is for adults. You must be 18 or older — we ask your date of birth at signup and enforce it server-side. We don't knowingly collect data from anyone under 18; if we learn we have, we delete it.
If this policy changes materially, we'll tell you in the app or by email before the change takes effect, not after. The date at the top always reflects the current version.
Questions, concerns, or doubts? Email contact@spur.cards. A human answers.