Legal

Privacy policy

This policy explains what FindIt collects, why, and your rights under the GDPR.

01

What we collect

  • Click data: when you click through to a merchant we record the event, a hashed (pseudonymised) IP address for fraud prevention, and a coarse session identifier. We do not store your raw IP address.
  • Cookies: a consent cookie and, if you accept, a session cookie used for click attribution. See our cookie policy.
  • Price alerts: if you ask us to watch a price, we store the email address you gave, the listing, and the target you set. Nothing else about you is attached to it.
02

Why we process it

Click and fraud data are processed under legitimate interest (operating and protecting the service). Optional analytics cookies are processed only with your consent. Price alerts are processed on your consent alone: we confirm the address before sending anything, and every alert email carries a one-click unsubscribe link.

03

Retention

Raw click rows are kept for 90 days, then moved to an anonymised archive. Fraud salts are rotated regularly so old hashes cannot be re-linked.

A price alert lasts until you unsubscribe or the listing is removed. An alert that is never confirmed is deleted after 7 days, and an unsubscribed one is kept for 30 days as a record of your withdrawal — so nobody can re-subscribe you without a fresh confirmation — and then erased.

04

Your rights

You may request access, correction or deletion of your data by emailing info@find-it.es.