Privacy Policy
Kitlist compares football shirt prices across shops. You can browse without an account and without being tracked. We only hold personal data when you ask us to do something with it: watch a shirt, send us a message or suggest a shop.
Who runs Kitlist
Kitlist is run personally by José Roberto Coccorese Mello da Silva, Lisbon, Portugal, who is the controller of the personal data described here. For anything about your data, write to privacy@kitlist.club.
Browsing
Looking at shirts needs no account, sets no cookies and involves no analytics, advertising or tracking. Like any website, our servers receive technical request information: your IP address, browser (user agent), the page requested and the time. Kitlist doesn’t store it. Our hosting provider keeps short-lived request and error logs to run and secure the service (legitimate interest).
When you search, your words are turned into filters (club, size, price…) on our server. We don’t store your searches. Searches are handled by our own rules; they are not sent to an AI provider.
Product images come from the shops
Shirt photos are loaded straight from the shops’ own servers or image services. Your browser sends those servers the usual request information, such as your IP address and user agent, as it would when visiting the shop. We ask browsers not to tell them which Kitlist page you were on. The shops’ own privacy policies apply to what they receive.
Shop links
When you follow a link to a shop, you leave Kitlist. What you do there, including buying, is between you and the shop, under its terms and privacy policy.
Watches and price alerts
To watch a shirt, you tell us how to reach you: Telegram or email. That’s the only sign-in Kitlist has. There are no passwords.
- Email. We send a one-time confirmation link (valid for 30 minutes). Once you confirm, we store your email address.
- Telegram. You send a one-time code to the Kitlist bot. We store the numeric Telegram chat ID the bot replies to. We don’t store your Telegram name, username or phone number.
- Each watch. The shirt (including sleeve length and version), your size, your target price or percentage, the price when you started watching, the latest price we checked, the shop, and when the watch was created, reached or stopped.
- Alerts. When a shirt hits your price, we record the alert (price, shop, link, time) and whether each message was delivered, including the provider’s message reference.
- Your devices. A random sign-in code is kept in a cookie in your browser (see Cookies below). We store only a scrambled (hashed) version of it, plus when it was created, last used and signed out.
We use this to run the alerts you asked for (performance of our agreement with you). Alerts are transactional only. We don’t use your email address or Telegram chat for newsletters, promotions or unrelated marketing.
You’re in control: switch Telegram or email alerts off in Watching → Settings, use the unsubscribe link in any alert email, send /stop to the bot, stop individual watches, or delete everything with Delete my data.
Contact
The Contact form asks for your email address and message, and optionally your name. We store your message and forward a copy to our inbox so we can reply (legitimate interest in answering you).
Suggest a shop
Suggest a shop asks for the shop’s web address and an optional note. No name or email is needed. We store the suggestion and forward a copy to our inbox so we can review it (legitimate interest).
Spam and abuse protection
To limit each form to a few submissions a day without storing IP addresses, we keep a keyed, one-way code derived from your IP address and the date next to each Contact message or shop suggestion. It is pseudonymous, not anonymous, so we treat it as personal data and remove it after 48 hours. Confirmation emails are also limited to one every 30 seconds per browser. We do this to keep the service working and protect it from abuse (legitimate interest).
Cookies and local storage
Kitlist uses no analytics, advertising or third-party cookies, so there’s no cookie banner. What we use is strictly necessary for things you ask for:
kl_session(cookie, first-party). Keeps you signed in for your watches and alerts. It is set only when you choose Telegram or email to watch a shirt; browsing alone never sets it. It can’t be read by page scripts (HttpOnly), is sent only over HTTPS and lasts up to 400 days. Sign out on this device removes it.kitlist-theme(your browser’s local storage). Remembers light or dark mode if you pick one. It never leaves your browser.
If we ever add analytics or advertising, we’ll ask for your consent first wherever the law requires it.
Who helps us run Kitlist
These providers process data for us, only to provide their service to Kitlist:
- Vercel (hosting; a US company, running Kitlist’s server code in Frankfurt, Germany, with pages delivered from the server nearest you): every page request and the data you send through Kitlist passes through it. Also keeps short-lived request and error logs.
- Supabase (database; Frankfurt, Germany): stores the data described above.
- Resend (email delivery; United States): confirmation and alert emails, and the copies of Contact messages and shop suggestions sent to our inbox.
- GitHub (United States): runs the scheduled job that checks prices and sends alerts, so it handles the email addresses and Telegram chat IDs needed to deliver them.
- Telegram: delivers Telegram alerts and bot messages. If you use Telegram, Telegram’s own privacy policy also applies to your use of it.
- Our email inbox provider, which receives Contact messages, shop suggestions and emails to privacy@kitlist.club.
We don’t sell personal data or share it with advertisers.
Transfers outside the EU
Some of these providers are based in, or process data in, the United States or other countries outside the European Economic Area. Vercel is a US company even though Kitlist’s server code runs in Frankfurt, and its content delivery network serves pages from locations around the world. Where they do, we rely on the safeguards they provide under their data processing terms, such as the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses. Write to privacy@kitlist.club for details.
How long we keep it
- Sign-in attempts, including an email address that was never confirmed: 24 hours.
- Anonymous records from a sign-in that was never finished: 30 days.
- Signed-out devices: 30 days after signing out.
- Stopped watches: 90 days after you stop them. Watches that hit your price: 90 days after the alert.
- Alert and delivery history: 90 days.
- Your email address, Telegram chat ID and settings: while you use Kitlist. If you have no active watch and haven’t used Kitlist for 24 months, we delete them. Active watches are kept while they’re active.
- Contact messages and shop suggestions: 12 months. Their anti-abuse code: 48 hours.
Deletion runs automatically several times a day. Copies can remain in our providers’ logs and backups for a limited time before they’re overwritten.
Delete my data
In Watching → Settings, Delete my data permanently deletes your watches, your email address and Telegram connection, your alert history and every signed-in device, straight away, after you confirm. You’re signed out everywhere. Messages you sent through Contact aren’t linked to your alerts. Write to privacy@kitlist.club and we’ll delete those too.
Your rights
Under the GDPR you can ask to access, correct or delete your personal data, to restrict or object to how we use it, and to receive the data you gave us in a portable format. Write to privacy@kitlist.club. We may need to check that the request is yours, for example by replying from the Telegram chat or email address concerned. We answer within one month.
You can also complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt), or to the authority where you live or work.
Security
Sign-in codes, confirmation links and session secrets are stored only as hashes. The database can’t be reached from browsers; only our server can reach it. Unsubscribe links are signed, and everything is served over HTTPS. No system is completely secure, but we work to keep your data safe and keep as little of it as we can.
Children
Kitlist is not directed at children under 16.
Changes
If what we collect or how we use it changes, we’ll update this page and the date at the top.