ALLR

Privacy Policy

Last updated: 2026-09-19

1. Who we are

ALLR is a motorcycle gear price-comparison service. The data controller responsible for your personal data is Some Company LTD. Registered address: 12 Direzze Court, Richmond Hill, ON L4C 5T8, Canada. To contact us about anything in this policy, email privacy@allr.io.

2. What we collect

We collect the minimum we need to run the site:

  • Account data: email address, hashed password (handled by AWS Cognito), and any optional fields you fill in your profile (riding history, sizes, preferred region).
  • Activity data: products you save, price alerts you create, items you add to your Fitting Room. Used to show you those products on subsequent visits.
  • Technical data: IP address, browser/device user-agent, request timestamps, and inferred country so we can show region-appropriate prices and pre-fill currency. Our server logs also record how the site is used — which product pages are opened, outbound Buy-link clicks (which product, which retailer, when — and, when the link came from our MCP connector, that it did and which assistant), sign-ups and subscriptions as counts, and JavaScript errors your browser reports so we can fix them. For requests to our public MCP connector at /mcp, those logs also record which tool an AI assistant called, the argument key names it passed and any country, category or brand among them, the protocol version, whether the call succeeded, how long it took and how many results it returned, plus the name the assistant’s client software reports for itself. Free-text arguments — a search query, a body measurement — are never written to a log line, and these connector lines carry no IP address and no identifier of a person (your request IP is still used for rate limiting and appears in our ordinary access logs, as it does for any request to any website). These lines carry no account identifier and no cookie is involved. These usage lines carry one further field: a short daily code, derived from your IP address and user-agent with a secret keyed hash, that lets us count visitors rather than only page views. It rotates at midnight UTC, it cannot be reversed to recover your IP address, nothing is written to your device, and it is never linked to an account. Which pages you opened, where you arrived from and which marketing link you followed (the utm parameters in a link, and whether a Reddit link carried Reddit’s own click id — the id itself is never recorded) are logged the same way. Logged for at most 30 days. Country is inferred by sending your IP address to ipapi.co, a third-party geolocation service — see §4 and §7.
  • Billing data (only if you subscribe to ALLR Pro): your subscription status, plan, currency, renewal date and the Stripe customer/subscription identifiers. Your card details are entered directly into Stripe and are never received or stored by ALLR — we hold no card numbers, expiry dates or security codes.
  • Images you upload (only if you use the Fitting Room or add a bike photo): the photographs you choose to upload, and the images generated from them. See §4 for who processes them.
  • Cookies: a session cookie for sign-in, a refresh cookie to keep you signed in, a CSRF cookie for form security, and a cookie recording your answer to the cookie banner. We set no advertising, analytics or affiliate cookies — see the Cookie Policy.

3. Why we collect it (lawful basis under GDPR)

  • Contract (Art. 6(1)(b) GDPR): account creation, saved gear, price alerts, Fitting Room generations, and taking payment for and providing an ALLR Pro subscription.
  • Legitimate interests (Art. 6(1)(f) GDPR): fraud / abuse prevention, security logging, keeping the service working, and understanding in aggregate how the site is used.
  • Legal obligation (Art. 6(1)(c) GDPR): keeping transaction records for tax and accounting where subscription payments are involved.
  • Consent (Art. 6(1)(a) GDPR): any non-essential cookie. We don't currently set one; if we introduce one, it will only be set after you accept.

4. Who we share it with

  • AWS hosts our infrastructure (Cognito for auth, DynamoDB for storage, S3 for uploaded images, SES for email, CloudFront for delivery). Data stays in our chosen AWS region except where CloudFront serves cached content from an edge location near you.
  • Stripe (Stripe, Inc. / Stripe Payments Europe) processes ALLR Pro payments. If you subscribe, Stripe receives your email address, payment details and billing country directly from you and tells us only whether the subscription is active. Stripe processes this as a controller in its own right for fraud prevention and regulatory purposes — see Stripe's own privacy policy.
  • ipapi.co receives your IP address when you first open the ALLR home page, so it can return the country used to pick your currency and duty rules. This happens automatically, before you interact with the site and before any cookie choice, because the page needs a region to show prices at all. We send nothing but the request itself and receive nothing back but a country code. Once you have chosen a region yourself, we stop sending your IP for geolocation.
  • Google (Google LLC, via the Gemini API) processes images you upload to the Fitting Room, together with the prompt describing the gear and bike, in order to generate the try-on image. This only happens for images you actively choose to upload. If you never use the Fitting Room or add a bike photo, no image of yours is ever sent to Google.
  • Retailers see whatever your browser sends to their site when you click through (referrer header, IP).
  • We do not sell your data, do not share it with advertisers, and run no third-party advertising or analytics trackers — no analytics script, tag or pixel from another company runs on ALLR. We do count anonymous events in our own server logs (page views, sign-ups, subscriptions and JavaScript errors); those records contain no account identifier and never leave our infrastructure. So that we can tell a hundred visits by one person from a hundred visits by a hundred people, a page-view record carries a short code derived from your IP address and browser by a keyed one-way hash. It changes every day, cannot be turned back into your IP address, is not stored on your device and is not linked to any account.

5. How long we keep it

  • Account data: until you delete your account.
  • Saved gear and alerts: until you remove them or delete your account.
  • Uploaded and generated images: until you delete them or delete your account.
  • Billing records: retained by Stripe under its own retention rules; we keep the subscription status and identifiers for as long as required for tax and accounting purposes.
  • Technical logs: 30 days.
  • Backups: rolling 7-day retention.

6. Your rights

If you are in the EU/UK, you can:

  • Request a copy of your data (Art. 15).
  • Correct inaccurate data (Art. 16).
  • Delete your account and associated data (Art. 17).
  • Object to or restrict processing (Art. 18 / 21).
  • Withdraw consent for non-essential cookies at any time — use the Cookie settings link in the footer of any page, which clears your stored choice and brings the banner straight back.
  • Lodge a complaint with your local data-protection authority.

Email privacy@allr.io to exercise any of these.

7. International transfers

Our hosting region is Canada (AWS ca-central-1, Montreal). If you are in the EU/EEA, your data is transferred to Canada on the basis of the European Commission's adequacy decision for Canada (Commercial Organizations) under PIPEDA. If you are in the UK, the equivalent UK adequacy regulations for Canada apply. No Standard Contractual Clauses are required for these transfers; we will adopt them and notify you on this page if either adequacy decision is revoked.

Canada is not the whole picture, and the following transfers also take place:

  • ipapi.co — your IP address is sent to this geolocation provider, which operates outside the EEA, when you first open the home page and have not yet chosen a region.
  • Google LLC (United States) — images you upload to the Fitting Room, and the accompanying prompt, are processed by the Gemini API in the US.
  • Stripe (United States / Ireland) — subscription payment data, if you subscribe to ALLR Pro.

Each of these is covered by the relevant provider's own transfer mechanism (Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework). If you would rather not have your IP sent for geolocation, pick your region from the selector in the header — once you have, we stop asking.

8. Children

ALLR is not directed to children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, email privacy@allr.io and we'll delete it.

9. Changes to this policy

We will update this page when our practices change. Material changes will be highlighted at the top of the page; the "Last updated" date will tell you when the most recent revision happened.