Privacy policy
Last updated: September 5, 2026
Questa informativa sulla privacy è disponibile solo in inglese.
What data we collect
Cardheist collects only what's needed to run the site and provide you with a usable account.
- Account — email address, hashed password (if you set one), verification status, optional marketing consent, and an optional display name used in mail salutations.
- Social-login identities — if you sign in via Google or Facebook, we store the provider's user ID and the email + name they return. We never receive or store your social password. You can unlink any provider under Account → Connected accounts.
- Sessions — IP address and user-agent at login, session token cookie.
- Affiliate clicks — server-side log entry per click (timestamp + product), hashed IP, no personal data, no third-party cookies.
- Analytics — anonymised, aggregated page views. Only with your consent.
Where your data lives
- Postgres database — Hetzner Cloud, Falkenstein, Germany (EU).
- Email delivery — Brevo (sendinblue.com), France (EU). Used to send verification mails, password resets, and (if you opt in) deal alerts. Brevo signs an EU-standard DPA and processes only what's needed to deliver the email.
How long we keep it
- Account — until you delete it.
- Active sessions — until you sign out, or 30 days of inactivity.
- Server logs — 90 days, then auto-rotated.
- Affiliate clicks — 24 months for commission reconciliation.
Your rights
Under GDPR you can exercise the following rights from your account page (or by emailing us):
- Access — download a JSON export of everything we hold about you under Account → Download your data.
- Rectification — change name, email, password, or marketing consent under Account.
- Deletion — wipe your account and all associated data under Account → Delete account. Confirmation email sent.
- Objection / Withdrawal — turn off marketing emails any time under Account → Email preferences.
- Portability — the data export is in machine-readable JSON.
- Complaint — you can lodge a complaint with the Danish Data Protection Authority (Datatilsynet).
Cookies
Cardheist.com asks for your consent to statistics and advertising cookies via Google's
certified consent management platform (IAB TCF v2.2), shown on your first visit. Your choice
is stored in a cookie (FCCDCF) on cardheist.com. You can change or withdraw
your consent any time via the
button at the bottom of the page, which opens Google's consent dialog again.
- Strictly necessary — login session, CSRF protection, your consent choice. Always set; the site won't work without them. Affiliate clicks are logged anonymously server-side (hashed IP, no personal data) so retailer partners can attribute commissions correctly.
- Search history —
heist_recent_searches(first-party, 1 year) remembers your recent searches so they can be shown in the search field. Only set if you turn on "Save search history" in the search field yourself; contains only your search terms and can be cleared via "Clear history" or turned off again in the same place. When signed in, recent searches are stored on your account instead. - Statistics — Google Analytics 4 with Consent Mode v2 and anonymised IP. Only enabled if you give consent in the consent message.
- Advertising — Google AdSense and affiliate networks. Without consent, non-personalised ads are shown without cookies; with your consent in the consent message, Google and partners may set cookies for personalisation.
Affiliate links
When you click a link to a retailer, we may receive a small commission. The retailer knows you came from Cardheist.com but does not receive your identity. If you've accepted marketing cookies, affiliate networks and the retailer may set their own cookies on their domain to measure whether your click led to a purchase.
Contact
Questions about our privacy policy? Write to privacy@cardheist.com — we reply within 5 working days.