Skip to content

Privacy Policy

Last updated: August 1, 2026

OptimalCardSetup, operated by Fortesen LLC ("we", "us", "our"), operates the website at optimalcardsetup.com. This Privacy Policy explains what information we collect, how we use it, and the choices available to you. We aim to collect what is reasonably needed to operate, secure, and support the Service.

1. Information We Collect

  • Account information — email, optional display name, authentication method, account timestamps, and the versioned signup-consent record. Consent records include the time, authentication method, a one-way email hash, request ID, user-agent, and IP address used for the request.
  • Authentication information — email/password accounts store a one-way password hash, never the original password. OAuth accounts store the provider and provider account ID needed for future sign-ins.
  • Optimization information — monthly spending assumptions, selected cards and preferences, job inputs, result data, and the catalog snapshot used by a saved scenario.
  • Optional planning information — saved-scenario names and descriptions, custom card details, application timeline entries, and email-digest preferences you choose to create.
  • Billing information — subscription tier and interval, Stripe customer and subscription IDs, and billing state. Stripe, not OptimalCardSetup, handles payment-card details.
  • Information you submit — feedback messages, category, page address, and optional contact email; newsletter email, source, consent date, and subscription status.
  • Limited technical measurement — cookieless aggregate page-view and product-event metrics, selected performance measurements, and technical error-monitoring events. Error monitoring is configured to scrub user identifiers, credentials, request bodies, cookies, query strings, and other sensitive fields before events are sent to Sentry.

2. Information We Do Not Request

The Service does not ask for bank credentials, credit card numbers, CVVs, expiration dates, Social Security numbers, government IDs, contacts, or address-book information. Spending amounts are user-entered assumptions; they are not read from a bank or card account.

3. How We Use Information

  • Run the optimization engine and return modeled card setups.
  • Save, reload, compare, and share scenarios when you use those features.
  • Authenticate and secure accounts, process password resets, and provide support.
  • Manage Premium access, subscriptions, and billing reconciliation.
  • Send transactional messages and optional newsletters or digests you request.
  • Measure aggregate usage and reliability without building user-level advertising profiles.
  • Detect, investigate, and correct errors, abuse, and security incidents.

4. Cookies and Local Storage

We do not use first-party advertising or tracking cookies. Limited analytics is designed to be cookieless. The theme preference, authentication tokens, and small interface state are stored in browser localStorage, not in a cookie. See the Cookie Policyfor the current storage details.

5. Service Providers and Sharing

We use service providers to host and operate the Service, including Railway for backend infrastructure, Cloudflare for delivery, Stripe for billing, Google and Microsoft for OAuth when you choose it, Resend for email, and Sentry for scrubbed error monitoring. Providers process information under their own terms and privacy practices. We may disclose information when reasonably necessary to provide the Service, prevent fraud or security harm, comply with a legal obligation, or protect rights. We do not sell personal information for advertising.

6. Shared Scenarios

A shared scenario link is a public, read-only link. Anyone who has the link can view the spending assumptions, selected cards, and saved result. Shared pages are marked noindex and are not cached by the API, but noindex is not a security boundary. Revoke a link from the scenario controls when you no longer want it available. Do not share assumptions you want to keep private.

7. Retention and Account Deletion

We retain account and scenario information while needed to provide the Service. You can request self-service account deletion from Account settings after resolving active billing. Deletion removes the local account, saved scenarios, custom cards, application entries, jobs, digest settings, and referral records. Feedback may remain in anonymized form. Versioned policy-consent evidence may be retained with the account relationship removed; billing, email, OAuth, hosting, security, legal, and fraud-prevention providers may retain records under their own policies. Encrypted backups may age out on their ordinary cycle and may not disappear immediately. Account deletion does not cancel a Stripe subscription; cancel billing in Account settings first.

8. Your Choices and Requests

You can update your display name, manage email preferences, export account data, revoke shared scenarios, and request account deletion through the Service where those controls are available. You can unsubscribe from a newsletter through its one-click link or confirmation page. For privacy questions or a request not covered by an available control, email [email protected]. We will handle requests according to applicable law and may need to verify identity.

9. Children and Age

Accounts are intended for adults and you must be at least 18 to create one. The Service is not directed to children under 13, and we do not knowingly request personal information from a child under 13. If you believe a child has provided information, contact us so we can investigate and remove it where appropriate.

10. Security

We use reasonable administrative, technical, and organizational safeguards, including hashed passwords, access controls, encrypted transport, and scrubbing for error-monitoring events. No internet service can guarantee absolute security. Do not submit bank credentials, card numbers, or other sensitive information in free-text fields.

11. Changes and Contact

We may update this policy and will update the date above. Material changes that require fresh signup acknowledgment will use a new version at the account-creation boundary. For questions or accessibility feedback, email [email protected]. We welcome accessibility reports and do not represent that the site conforms to any particular accessibility standard.