Privacy

HasTrust is built to be privacy-respecting, and this page is written to be checkable rather than reassuring. We collect no personal data — with one clearly-marked exception you control: an email address, and only if you choose to set a price alert (see below). The browser extension does record which domains it looked up; that is described in full under “What we store”, because we would rather explain it plainly than call it nothing.

The browser extension

By default the extension looks up the domain of every page you open (e.g. example.com), so it can show a trust pill without you having to ask. It reads only that bare domain — never the full URL, page contents, your cart, form fields, or any personal data — and the only network request it makes is to our API. You can switch the on-page pill off entirely in its settings.

One exception, and only when you ask for it: on a product page you can click “Check this product”. That sends the product's URL (with tracking parameters stripped) to our API so we can fetch its price and find cheaper or better alternatives. Nothing is sent until you click; we never read your cart, account, or form fields.

On marketplace product pages (Amazon, bol.com, eBay) sold by a third-party seller, that same explicit product check also includes the seller's name as shown in the page's own "sold by" block — so we can warn about the actual counterparty, not just the platform. It is never sent without the product check.

On search-engine result pages (Google, Bing, DuckDuckGo) the extension looks up the domains of the results in one batched request so it can show a trust badge next to shops we already know. Only those result domains are sent — never your search query. This can be turned off in the extension's settings ("Badges on search results").

The right-click "Scan selection for scams" action sends the text you selected to our API for scam analysis — only when you explicitly choose it from the menu, never automatically. To time its checkout warning the extension also checks locally whether a payment-card field is present on the page; the field's contents are never read or transmitted.

Sites we never look up

The extension never sends work or internal addresses. Private and local names (an IP address, anything ending .local or .internal, a single-word intranet name), hosts behind an access gate, and common internal subdomains such as jira., sonarqube. or staging. are all skipped before any request is made. Because no rule can know every company's naming scheme, the extension's settings also have “Never check these domains”: add your employer's domain once and nothing under it is ever looked up.

Price alerts (optional email)

If — and only if — you tap “Watch price” and enter your email, we store that address to send the price-drop alert you asked for. It is double opt-in: we email a confirmation link and send nothing until you click it. We use your address for that alert alone — we never sell it, share it, or send marketing. Every alert has an unsubscribe link, and unsubscribing deletes your address.

What we store

Usage events (the domain looked up, the event type, and a random per-install id) and community trust votes. We never store your name, your IP, or which pages you viewed within a site — but a random id sitting next to a list of domains is pseudonymous, not anonymous, so we will not pretend otherwise: after 30 days both the domain and the id are erased, leaving only aggregate counts. Votes store a one-way hash of your IP solely for rate-limiting. We do not sell data.

In your browser

We store your extension settings (theme, quiet and auto-open toggles, sites you have muted, your never-check list, and the pill's position) and a random per-install id in your browser's local storage. The website sets at most two cookies. “hv” lasts two days, is tied to your IP, cannot be read by scripts, and exists only to tell a real browser from an automated one. “hs” is a random id that lets us count how many people read a page and which page they came from; in the EEA, the UK and Switzerland it is only set if you accept it, it expires after 30 days, it never leaves our server, and it is never used for advertising — refuse, or withdraw later from the link in the footer, and it is deleted. There are no advertising cookies and no third-party cookies.

The scam checker

When you paste a message, link or screenshot text into the scam checker, we keep it together with the result for 90 days, visible only to us, to check how well the checker works; after that it is deleted automatically. To analyse the message we send it to Anthropic (Claude). We also send a copy with email addresses, phone and account numbers, codes and link parameters removed to TypeSafe (directly, or through Vercel's AI Gateway if TypeSafe is unreachable) to work out which kind of scam it resembles and show you the matching guide. Please don't paste passwords or one-time codes.

Ask about this shop

When you type a question in “Ask about this shop” (on a check page or in the extension), we remove email addresses, phone and account numbers and codes from it, then send it with the shop's name to TypeSafe, which only tells us which topic it is about (returns, contact, payment…). The answer you see is our own text, filled from the check. To learn what shoppers need, we also keep the cleaned question text with its topic, the page it was asked on and whether we could answer, visible only to us; the text is deleted after 30 days, the counts stay. No IP address, id or anything else that could link a question to you is stored.

Third parties

Assessments cite public web sources you can visit. Site and brand logos load from Google's public favicon service (which sees the domain, not you). When the extension asks about a domain we have never assessed, our server looks up its registration date at rdap.org — so that domain, and nothing else about you, reaches them. Building an assessment also queries public sources about the site being checked: Exa, YouTube, the Internet Archive, Tranco, and the Dutch (KVK) and French (INSEE) company registers. If you choose to click a “Buy” or seller link, it opens through our affiliate partner (Amazon Associates or Awin), which may record the click to attribute a purchase — a commission that never changes your price. We disclose this next to every such link.

Your data, and how to reach us

You can ask what we hold about you, ask for it to be deleted, or object to it — email [email protected] and we will answer within 30 days. In practice there is usually nothing to send: unless you set a price alert we hold no email address, and the extension's per-install id is generated in your browser, so clearing its storage or reinstalling detaches you from every past event. HasTrust is run from the Netherlands; this page follows the GDPR.

Last updated 27 September 2026.