Privacy Policy
Last updated 2 September 2026
This policy explains what IPOCheckr does with the information you give it. “IPOCheckr” is a working product name; no separate legal entity is named here yet.
Your PAN
A PAN you type in is sent to our server, which forwards it to the registrar handling the issue you selected in order to look up your application. It is used for that lookup and nothing else.
- Your PAN is never placed in a web address.
- Your PAN is never written to your browser’s local storage, session storage, or cookies.
- Your PAN is masked (for example ABCDE****F) everywhere it is displayed back to you.
- Raw PANs are removed from our server logs by an automatic redaction filter.
If you are not signed in, your PAN exists only in the memory of the browser tab you are using and is discarded when you close or reload it. Nothing is stored.
Saved PANs
If you create an account and choose to save a PAN, it is stored in our database against your account so you do not have to retype it. Saved PANs are only ever returned to your browser in masked form — the full value stays on the server, and the application resolves it there when you run a check.
You can delete a saved PAN at any time from the My PANs page. Deleting your account removes its saved PANs along with it.
You may optionally give a saved PAN a name so you can tell them apart (for example “Mom” or “Dad”). If you leave this blank, and a registrar returns the applicant’s name while you check an allotment, we save that name against the PAN so it is shown the same way next time. This never happens if you have already given the PAN a name yourself, and this name is shown only to you.
Accounts
Accounts are handled by Supabase Auth. Your email address and password are submitted directly to Supabase; we do not store your password, and we hold no password hashes or reset tokens of our own. We can see the email address associated with your account.
Allotment queries
We keep a record of allotment checks for operational purposes such as rate limiting and diagnosing failures. PANs in these records are stored as a one-way cryptographic fingerprint rather than the PAN itself, so a check can be counted without the PAN being recoverable from the record.
Third parties
To answer a query, the application communicates with the registrar that holds the issue you selected. Those registrars operate their own systems and their own privacy practices, which we do not control. We also use Supabase for accounts and data storage, and Upstash Redis for caching and rate limiting.
Analytics
The application does not send your PAN to any analytics service. Pages that handle PANs are marked so that search engines do not index them.
Contact
For questions about this policy or to request deletion of your data, use the contact route published alongside the deployed application. A dedicated contact address will be listed here once it is available.