Privacy policy
Effective ; last updated .
This policy covers flexidealshq.com. It is written to cover the accounts, price alerts, browser extension and apps we intend to offer as well, so that it does not have to be rewritten when they arrive; today none of them exists, the site sets no cookie for a signed-out visitor, and the only personal data we hold about most readers is a short-lived server log. The controller is Ahsan Khan, who operates FlexiDealsHQ personally while the U.S. company that will run it is being formed; that company becomes the controller on registration and this policy will be updated with its registered name and address. Privacy questions: [email protected].
What we collect
- Without an account: server logs (IP address, user agent, requested page) kept briefly for security, and cookieless, aggregated analytics. We do not set cookies for visitors who are not signed in; the country notice and its dismissal are stored in your browser only.
- With an account: email address, a hashed password or passkey, watchlists and alert preferences, and optionally a U.S. ZIP code (used only for sales-tax and shipping estimates) and the names of payment cards you tell us you hold (never card numbers).
- Affiliate clicks: when you follow a "Go to retailer" link we record the click with a pseudonymous identifier so we can reconcile commissions; retailers and networks may set their own cookies on their sites.
Why, and on what basis
- To run the site and keep it secure (legitimate interest; contract for account holders).
- To send alerts you asked for (contract / consent, withdrawable at any time).
- To measure and improve the site with cookieless analytics (legitimate interest).
- To be paid commissions on purchases you choose to make (legitimate interest).
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we run no third-party advertising trackers.
Global Privacy Control
We treat a browser's Global Privacy Control (GPC) signal as a valid request to opt out of sale or sharing of personal data, automatically and without further action on your part. Because we do not sell or share personal data in the first place, the signal changes nothing about how we process your information, but we record it and honour it. You can also use the Do Not Sell or Share My Personal Information page.
Your rights: United States
If you live in a U.S. state with a comprehensive privacy law (including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland), you have the right to:
- know and access the personal data we hold about you
- delete it
- correct it
- opt out of sale or sharing and of targeted advertising
- limit the use of sensitive personal data
- receive a portable copy
We respond within 45 days (extendable once where the law allows) and never discriminate for exercising a right. You may appeal a decision by replying to our response; we will explain the outcome and, where required, how to contact your state attorney general. California residents: we do not sell or share personal information, we do not use sensitive personal information for inferences, and we have not done so in the preceding 12 months. Authorised agents may submit requests with proof of authority.
Your rights: EU/EEA (GDPR)
If you are in the European Economic Area you have the right to:
- know and access the personal data we hold about you
- have it erased
- have it rectified
- receive a portable copy
- restrict processing
- object to processing
We respond within 30 days. You may withdraw consent at any time and lodge a complaint with your supervisory authority. We have not appointed representatives under Article 27 of the GDPR or the UK GDPR, and we do not claim to have. Until we do, people in the EEA and the UK should use the privacy mailbox or the privacy request form: we answer on the GDPR and UK GDPR clocks either way, and the representatives' names and addresses will be published here when they are appointed. We notify the relevant authority of a personal-data breach within 72 hours where required.
Your rights: United Kingdom (UK GDPR)
UK residents have the same rights listed above and we respond within 30 days. Complaints may be raised with the Information Commissioner's Office. Our Article 27 representative for the UK is not appointed yet either; the note above applies to UK residents in the same way.
Other regimes
Residents of Canada (PIPEDA and Quebec Law 25), Brazil (LGPD), Australia (Privacy Act) and India (DPDP Act) have the same universal rights flow; we apply the shortest response window that applies to you. We review our practices whenever a country exceeds 5% of our visits.
How to exercise your rights
Use the privacy request form (one form for every right and every regime), email [email protected] from the address on your account, or ask us for a postal route on the contact page. One set of endpoints serves every regime; we verify identity proportionately and never ask for more data than the request needs.
Processors and international transfers
- Hetzner Online GmbH (origin hosting and backups, Germany)
- Cloudflare, Inc. (edge network, DNS, affiliate-link redirect, image delivery)
- Anthropic, PBC (language-model API used to draft explanation text from non-personal price data)
- Transactional email provider (magic links and price alerts)
- Affiliate networks and retailer programs (click attribution for links you choose to follow)
We are putting a data processing agreement in place with each processor before it handles personal data; that work is in progress and not yet complete. Our origin servers and backups are in Germany (Hetzner Online GmbH, Falkenstein, Germany); the edge network is global. Transfers to U.S. processors rely on data privacy framework or standard contractual clauses.
Cookies and similar technologies
Analytics run cookieless by default and set no cookie. Signed-in users receive a strictly necessary session cookie. A consent prompt is shown only where the law requires it (EU, EEA, UK, CH) and only if a non-essential cookie would be set, which today is never. Third-party advertising trackers: none.
Retention
- Affiliate click records: 26 months.
- Search performance data: 5 years (non-personal).
- Price observations: indefinitely (non-personal).
- Accounts: until deletion, plus 30 days for backups.
- Server logs: up to 30 days.
Children
Accounts are for people aged 13 and over (16 where EU law sets a higher age of digital consent). We do not knowingly collect data from children below those ages.
Changes
We post changes here with a new "last updated" date and, for material changes, notify account holders by email.