Skip to content

01Legal

Privacy Policy

Two audiences read this page: merchants who have an account with us, and the people who visit a site running one of our banners. Both are covered below, separately, because the two are handled differently.

Last updated 2026-08-27

This policy describes how OfferBanner (“we”) handles personal data at offerbanner.com and through the banner script we serve. Questions, requests and complaints: the form at offerbanner.com/help — a person reads every submission.

1. If you have an OfferBanner account

What we store

  • Identity. Your email address, your name and your profile picture URL if Google supplied one. Sign-in is Google OAuth or an emailed magic link — there are no passwords, so we never hold one.
  • Sessions. A session record with its expiry, plus the IP address and browser user-agent it was created from. This is how staying signed in works, and how a stolen session can be told apart from yours.
  • Your content. The sites you add, the banners you design, their schedules, and the discount offers attached to them.
  • Billing. Your Stripe customer id, which plan you bought and whether the licence is active. We never receive or store card numbers — Stripe Checkout collects those directly.
  • Your Stripe restricted key, if you connect one. It is encrypted (AES-GCM) before it is written to the database, is never sent back to a browser, and only the last four characters are shown in the dashboard so you can recognise it.
  • API keys you create for agents, stored as hashes.

Account data lives in a Cloudflare D1 database. We keep it while your account exists; ask on the help page to have the account and everything under it deleted, and we will confirm when it is done.

Cookies on offerbanner.com

One kind: the session cookie set when you sign in. It is strictly necessary — without it there is no signed-in state — and it is not used for advertising or cross-site tracking. We set no marketing cookies and run no ad pixels on this site.

Site screenshots

When you type a website address into the banner editor we take a screenshot of that public page to use as the backdrop behind your bar and to read its colours. The image and a small record of the palette are cached for seven days and then expire.

2. On your visitors’ site

This is the section to read before you paste our tag. Our script runs on your website, in your visitors’ browsers, so what it does there is something your own privacy notice has to be able to describe.

What it does

  • It asks our edge for your banner’s current design and renders it. The request carries what any web request carries — IP address, user-agent, and the address of the page it was loaded from.
  • It sends up to four one-way signals as the visitor interacts with the bar: view, click, dismiss and code copied. Each one increments a counter and a per-day total for your banner. That is the whole record: a counter increased by one.
  • It reads the visitor’s country, as reported by our CDN, so a banner you targeted at one country is shown in that country and the hit is credited to the right campaign.
  • It writes one value into the browser’s localStorage: a timestamp recording that this person closed the bar, so it stays closed for thirty days. It is stored under your own domain, is not readable by us, and is not an identifier: it records that the bar was dismissed, not who dismissed it.

What it does not do

  • No cookies, no fingerprinting, no advertising or analytics identifier of any kind.
  • No per-visitor profile. The counters are aggregate totals per banner per day; there is no row anywhere that represents a person, so there is nothing to join across your visits or across our customers’ sites.
  • No reading of your page. The banner renders inside a shadow root and does not inspect your DOM, your forms or your cart.

The referer check

Because an embed code is visible in your HTML, anybody can paste it into their own page and distort your numbers. So when a counting signal arrives we compare the browser-set Referer against the host the site is registered under: if a browser tells us the page lives on a different host, the signal is dropped and nothing is recorded. Requests with no referer at all are allowed through, because a strict referrer policy is a normal browser setting and blocking real visitors would cost more than the abuse it prevents. The referer is used for this check and to log a refusal; it is not stored alongside your statistics.

Legal basis, and who is responsible

For visitor interactions we act as a processor for the merchant whose banner is being shown: it is their site, their campaign and their statistics, and we do not use the counts for anything except showing them to that merchant. Because the counts are aggregate and no identifier is set, our view is that the script does not require consent under the ePrivacy rules on device storage — the one localStorage value exists only to keep the bar closed after a visitor closes it. If your own counsel reads it differently for your jurisdiction, the banner works with that key blocked; it will simply reappear on the next page load.

3. Analytics on our own website

offerbanner.com uses Plausible Analytics, self-hosted by us. It is cookie-free, records no personal data and does not follow visitors across sites; we use it to see which pages people read.

4. Who else processes data

  • Cloudflare — hosting, database, storage, CDN and browser rendering. Everything above runs here.
  • Stripe — payments, and the API that creates coupons in your own Stripe account. Card details go straight to Stripe and never touch our servers.
  • Google — only if you choose to sign in with Google, which tells us your email, name and picture.
  • Resend — delivery of the transactional emails we send: magic links and account notices.

We do not sell personal data, and we do not share it with anyone for advertising.

5. Your rights

You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it and close your account. Ask on the help page, giving the address on the account, and we will answer within thirty days. If you are in the UK or the EU you may also complain to your local data protection authority.

6. Changes

We will update this page when what we do changes, and the date at the top always reflects the current version. Material changes are emailed to account holders.