Privacy policy

Last updated: August 25, 2026

Customer Blacklist is a private claim file for shops. It is not a public directory. This policy describes how we handle information in the United States. It is operator-written product documentation, not legal advice. Use of Customer Blacklist is also subject to our terms of use. Background on how the product is structured lives on /legal.

Who we are

Customer Blacklist is operated for merchants who file and look up written claims about customers (chargebacks, no-shows, disputes, and similar incidents). Requests about this policy go through our contact form. We do not publish a street address on this page.

Information we collect

We collect information you provide and information created by using the service:

  • Accounts. Email, name if you give one, password hash, email verification status, and database session records when you sign in. Shop accounts can also store a business name, membership plan, and Stripe billing identifiers.
  • Claims. Subject first and last name, one or more subject emails (the lookup keys), incident type, a written description, evidence notes, optional evidence files, who filed, and later contest messages.
  • Lookups. The name and email a paying member searches, whether it hit a claim, and when.
  • Contact. Name, email, message, and requester IP address stored with the inquiry (and used for rate limiting) when you write us at /contact.
  • Technical. IP addresses and similar request metadata used to send OTP codes, enforce rate limits, and keep the site running. Signed-in use relies on session cookies. The site also loads Vercel Analytics and Speed Insights for aggregated traffic and performance measurement.

Information we do not collect

We do not run a public people-search. We do not ask for Social Security numbers, government ID numbers, or full payment card numbers on this site (Stripe handles card entry on its checkout). We do not want photos of people as evidence. We do not send marketing blasts to named customers, and we do not treat browsing the marketing pages as a claim file.

How we use information

We use information to:

  • Create and secure shop accounts and sessions.
  • Verify the shop/filer inbox with a 6-digit OTP before a claim is filed.
  • Store claim files and show them to people who are allowed to see them.
  • Run email lookups for members and keep a lookup history on the account.
  • Process membership payments and manage billing with Stripe.
  • Answer contact messages and operate, secure, and debug the service.

Who can see a claim file

A claim is not listed for the open internet. Other shops see a file only after they sign in and, for lookup, pay membership. Typical access:

  • The shop that filed the claim (the filer).
  • The named subject, if they sign in with a verified email that matches a subject email on the claim, via /file.
  • Paying members who look up a matching subject email. Lookup is session-gated and costs $10/month.
  • Operators who need access to run, secure, or review the service.

Filing a claim does not notify the named customer. We do not publish names, emails, or evidence as a public directory.

Emails, OTP, and the named customer

On /submit, the shop/filer email receives the 6-digit OTP. The customer/subject email is the claim key and never gets the code. Additional subject emails, if added, are extra lookup keys only — they also never receive the OTP. We skip the shop code only when the signed-in shop email is already verified (OTP sign-in or an already-verified member). Unverified password sessions still get a shop code.

Membership, lookups, and payments

Filing a claim is free. Looking someone up requires a signed-in shop account and a $10/month membership billed through Stripe. We store Stripe customer and subscription identifiers on the merchant record so we can confirm membership, open the billing portal, and record lookup activity. We do not store full card numbers.

Evidence files

Evidence should be a processor notice, chargeback letter, booking log, or similar document — PDF, text, or a scan of the letter. No photos of people. Claim evidence is stored privately with the claim in Neon Postgres (or Neon object storage when that backend is configured), not on a public CDN. It is available to the same people who can see the claim file, not to anonymous visitors.

Retention

We keep claim files, evidence, lookup history, contest messages, and account records for as long as they are needed to run Customer Blacklist and to show a file to filers, named subjects, and paying members. Contact inquiries are kept to handle the request and related follow-up. Sessions last while you remain signed in. Billing records follow Stripe and ordinary operating needs. If you ask us to delete or correct information, we will review the request against the need to keep an accurate private file.

Service providers

We use processors to host and operate the product. Named vendors today include Neon (Postgres and, when configured, private object storage for claim evidence), Vercel (hosting, Analytics, and Speed Insights), Stripe (membership payments), Resend (transactional email, including OTP and contact delivery), and Vercel Blob (CMS/media library storage when configured — not claim evidence). They process information on our instructions, not as a public bulletin board.

Children

Customer Blacklist is for merchants and adult customers in a commercial setting. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). If you believe a child under 13 was named or created an account, use /contact so we can review and delete the data.

Your choices and requests

You can sign in to manage your account, membership, and (if you are the named subject) view claims on /file. Named subjects and the filing shop can contest an open claim in writing from that file. For access, correction, or deletion requests, use /contact. This policy is US-focused; we do not appoint a data protection officer on this page.

Changes

We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Continued use after an update means the revised policy applies to later use of Customer Blacklist.

Contact

Privacy questions and requests: /contact. Named customers who want to contest a claim: sign in and open /file. Related pages: terms of use and /legal.