Utforska Tillgängliga erbjudanden Nyheter Guider Om oss Önskelista Logga in

Privacy policy

Last updated: September 5, 2026

Denna integritetspolicy finns endast på engelska.

What data we collect

Cardheist collects only what's needed to run the site and provide you with a usable account.

  • Account — email address, hashed password (if you set one), verification status, optional marketing consent, and an optional display name used in mail salutations.
  • Social-login identities — if you sign in via Google or Facebook, we store the provider's user ID and the email + name they return. We never receive or store your social password. You can unlink any provider under Account → Connected accounts.
  • Sessions — IP address and user-agent at login, session token cookie.
  • Affiliate clicks — server-side log entry per click (timestamp + product), hashed IP, no personal data, no third-party cookies.
  • Analytics — anonymised, aggregated page views. Only with your consent.

Where your data lives

  • Postgres database — Hetzner Cloud, Falkenstein, Germany (EU).
  • Email delivery — Brevo (sendinblue.com), France (EU). Used to send verification mails, password resets, and (if you opt in) deal alerts. Brevo signs an EU-standard DPA and processes only what's needed to deliver the email.

How long we keep it

  • Account — until you delete it.
  • Active sessions — until you sign out, or 30 days of inactivity.
  • Server logs — 90 days, then auto-rotated.
  • Affiliate clicks — 24 months for commission reconciliation.

Your rights

Under GDPR you can exercise the following rights from your account page (or by emailing us):

  • Access — download a JSON export of everything we hold about you under Account → Download your data.
  • Rectification — change name, email, password, or marketing consent under Account.
  • Deletion — wipe your account and all associated data under Account → Delete account. Confirmation email sent.
  • Objection / Withdrawal — turn off marketing emails any time under Account → Email preferences.
  • Portability — the data export is in machine-readable JSON.
  • Complaint — you can lodge a complaint with the Danish Data Protection Authority (Datatilsynet).

Cookies

Cardheist.com asks for your consent to statistics and advertising cookies via Google's certified consent management platform (IAB TCF v2.2), shown on your first visit. Your choice is stored in a cookie (FCCDCF) on cardheist.com. You can change or withdraw your consent any time via the button at the bottom of the page, which opens Google's consent dialog again.

  • Strictly necessary — login session, CSRF protection, your consent choice. Always set; the site won't work without them. Affiliate clicks are logged anonymously server-side (hashed IP, no personal data) so retailer partners can attribute commissions correctly.
  • Search historyheist_recent_searches (first-party, 1 year) remembers your recent searches so they can be shown in the search field. Only set if you turn on "Save search history" in the search field yourself; contains only your search terms and can be cleared via "Clear history" or turned off again in the same place. When signed in, recent searches are stored on your account instead.
  • Statistics — Google Analytics 4 with Consent Mode v2 and anonymised IP. Only enabled if you give consent in the consent message.
  • Advertising — Google AdSense and affiliate networks. Without consent, non-personalised ads are shown without cookies; with your consent in the consent message, Google and partners may set cookies for personalisation.

Affiliate links

When you click a link to a retailer, we may receive a small commission. The retailer knows you came from Cardheist.com but does not receive your identity. If you've accepted marketing cookies, affiliate networks and the retailer may set their own cookies on their domain to measure whether your click led to a purchase.

Contact

Questions about our privacy policy? Write to privacy@cardheist.com — we reply within 5 working days.