This page explains what information ProductMoat collects, why, and how it's handled — whether you're just browsing, applying to be featured, or recommending someone else.
Last updated: August 27, 2026
ProductMoat (productmoat.com) is an interview series run by Martin Knapic. This policy covers the information collected through the website — browsing the directory and map, applying to be featured, recommending someone else, signing up for a profile, and signing in with LinkedIn to verify an application.
Depending on how you use the site, we collect:
We use the information above to:
We don't use your information for anything beyond running and improving ProductMoat.
Signing in with LinkedIn on the Apply, Recommend, or Put yourself on the map forms does two things. First, it's an identity check: LinkedIn's authorization server sends the confirmation back to a short-lived, server-side function, which reads your name, email, and photo from the token and stores them in a signed, HttpOnly cookie for a few minutes — just long enough to pre-fill the form. Second, it signs you in site-wide: the same function also sets a longer-lived (30-day) signed, HttpOnly session cookie, which is what shows your avatar and a "My profile" / "Log out" menu in the nav afterward, on any page. You can end that session at any time via "Log out." Either way, we don't use this to post to LinkedIn on your behalf or access your connections.
Clicking "Sign up" in the nav takes you to a page that explains, before anything happens, that signing in with LinkedIn there creates a private profile record (name, email, photo) and automatically subscribes you to the newsletter — you choose whether to opt out on that same page, before you sign in. This is separate from the identity-check sign-in on Apply/Recommend/Put yourself on the map: those set the same session cookie so you show up as signed in, but don't create a profile record or touch your newsletter subscription. If you'd like your profile record deleted or your newsletter preference changed later, contact us using the details in section 13.
We don't sell or rent your information. We don't share application or recommendation details with third parties except:
ProductMoat doesn't run third-party analytics or advertising trackers. We set two cookies, both described above: the short-lived LinkedIn verification cookie, which expires automatically a few minutes after it's created, and the 30-day sign-in session cookie, which you can clear early with "Log out." We also use your browser's local storage to remember your theme preference — this stays on your device and is never sent to us.
We keep application and recommendation details for as long as needed to review them and, if you're featured, to keep your published profile accurate. If you signed up, we keep your profile record and newsletter preference until you ask us to delete it. If you'd like your application, recommendation, or profile data deleted, contact us and we'll remove it.
You can ask us at any time to tell you what information we hold about you, correct it, or delete it — including withdrawing a published interview, unsubscribing from the newsletter, or deleting your profile record entirely. Reach out using the contact details below and we'll handle it directly.
We take reasonable steps to protect the information you share with us, including keeping the LinkedIn verification exchange server-side and never exposing credentials or tokens to the browser. No method of transmission or storage is ever fully secure, so we can't guarantee absolute security.
ProductMoat is intended for working professionals and isn't directed at children. We don't knowingly collect information from anyone under 16.
We may update this policy as the site evolves. If we make a material change, we'll update the "Last updated" date at the top of this page.
Questions about this policy, or a request to access, correct, or delete your information? Reach out via [ LinkedIn ].