Skip to content

Privacy policy

Last updated: 2026-10-09

Information we use

When you sign in, Supabase Auth processes your email address to send and verify a magic sign-in link. Account and listing activity may also be associated with your account email and profile.

If you subscribe to updates, we process your email address, where you signed up, and subscription or unsubscribe status. You can unsubscribe using the link in an email; unsubscribing changes the subscription status and does not itself erase the subscription record.

Forms may collect the fields you submit. A free listing or paid listing intake can include your name and email, tool website and backlink URLs, tool name and descriptions, categories, logo and screenshot URLs, social-profile and location details, primary keyword, and affiliate-program information. A listing claim uses your email and the listing being claimed. A report uses your email, the listing, issue type, and any message you provide. A contact message uses your name, email, subject, and message. Contact submissions can also include the referring page, browser user-agent, and security-check results. We use these details to review submissions and claims, respond to messages, and operate listings.

Stripe processes checkout and payment details for paid listing upgrades in Stripe Checkout. Yo.directory receives checkout, payment-status, customer-email, and listing-related transaction details; the site does not ask you to enter card details into a Yo.directory form.

When you upvote a tool, the site sets a random voter identifier in a cookie and stores a hash of that identifier with the vote so it can recognize the same voter. Cloudflare Turnstile processes security-check tokens and verification signals, including the request IP address sent for verification. Vercel, as the site host, may process request and diagnostic information such as IP address, user-agent, requested path, and error details in hosting logs.

Google Analytics 4 is used to understand site use only after you accept analytics. The site uses Google Consent Mode with analytics storage denied by default. While denied, Google may still receive limited cookieless consent signals; analytics cookies and storage are not enabled unless you accept. The site does not run advertising tags, and advertising-related consent signals remain denied.

Why we use information

Transactional emails are sent through Resend. Where the code records mail events, it stores details such as delivery status and provider event identifiers for operational and delivery tracking.

We use these details to provide sign-in and account features, handle listing submissions and claims, complete paid listing checkout, send requested service and newsletter emails, answer contact requests, count upvotes, prevent abuse, protect the site, and (if you accept) measure how the site is used.

In plain terms, we use information needed to provide a service or take steps you request; we rely on your consent for newsletter subscriptions and optional analytics; and we rely on our legitimate interests in answering inquiries and operating, protecting, and preventing abuse of the site. You can withdraw consent at any time for future processing that depends on it.

Service providers

We use these providers to support the functions described above:

  • Supabase for authentication and application data.
  • Stripe for paid listing checkout and payment processing.
  • Resend for transactional and newsletter email delivery.
  • Google Analytics for optional site-usage measurement under your analytics choice.
  • Cloudflare Turnstile for automated-abuse and form security checks.
  • Vercel for hosting and related operational logs.

Cookies and local storage

The site uses the following cookies for the purposes shown:

  • dang_upvote_voter identifies an upvote voter; it is HttpOnly and expires after one year.
  • dang_sidebar_state remembers the dashboard sidebar preference for seven days.
  • dang_dashboard_zone remembers a dashboard view preference for one year.
  • Supabase Auth session cookies, normally named sb-<project-ref>-auth-token and possibly numbered chunks, maintain sign-in state; Supabase manages their values and session lifetime.
  • After analytics consent, Google Analytics may use cookies such as _ga and a measurement-specific _ga_… cookie.

The consent choice is stored separately from cookies in browser local storage under yo-consent-v1, with the choice and time it was made. You can change it using Privacy settings in the footer. Your browser also lets you clear cookies and local storage; clearing them may reset preferences or sign you out.

Retention

The application does not enforce a general deletion schedule for account, listing, contact, newsletter, or payment records. Unless a specific expiry is stated above, information is kept while the relevant account or listing is active, or until you ask us to delete it. Unsubscribing changes newsletter status but does not delete that record. Google Analytics and provider-side records follow settings or retention rules managed by those providers, which are not specified in this site's code.

Your choices and rights

Depending on where you live, you may have the right to ask for access to or correction or deletion of your information, object to or restrict certain processing, and withdraw consent. You can decline analytics or later change your choice with Privacy settings in the footer. To exercise a privacy right or ask a question, email info@yo.directory.