Privacy Policy

Effective date: [EFFECTIVE DATE] · Document version: 2026-10-02-draft

This Privacy Policy explains what [COMPANY LEGAL NAME] (“we”, “us”) collects and does with information when you use Dealvyx. It describes how the app works today. Questions: [CONTACT EMAIL].

1. What we collect

Numbers you type into the analyzer are sent to our server to be calculated, then returned to you. They are stored only if you click save (or if you export a report, which is generated and sent back to your browser). Free-plan and logged-out analysis is not saved.

2. Payments (Stripe)

Subscriptions are handled by Stripe Checkout and the Stripe customer portal. Your card number and billing details are entered on Stripe’s pages and are processed by Stripe under Stripe’s own privacy policy; they never reach our servers or database. We send Stripe your email address to create your customer record. Stripe tells us your subscription status.

3. Cookies and similar technology

We set one cookie, bb_sid: a strictly necessary, HttpOnly, SameSite=Lax session cookie (marked Secure in production) that keeps you logged in for up to 30 days or until you log out. We do not use advertising, analytics or tracking cookies, and the site loads no third-party scripts. Stripe may set its own cookies on its hosted checkout and portal pages.

4. Email

We send only account emails (verify your address, reset your password). They go out through a transactional email provider we configure (for example Resend or Postmark) using SMTP, so that provider processes your email address and the message. We do not send marketing email.

5. We do not sell your data

We do not sell or rent your personal information, and we do not share it for advertising. We share data only with service providers needed to run the Service (hosting, our email provider, Stripe), when you direct us to, to comply with law or protect rights, or in a business transfer, with notice.

6. Storage, security and retention

Data is stored in a SQLite database on a persistent disk at our hosting provider, and backups of that database may be kept. Passwords are hashed; session and email tokens are stored only as hashes; connections use HTTPS in production. No system is perfectly secure. Expired sessions and tokens are purged automatically. We keep your account and saved deals until you ask us to delete them or we close the account; billing-related records may be kept as required for tax, accounting and legal purposes and by Stripe. Backups may retain deleted data for a limited time.

7. Your choices and rights

There is currently no self-service delete button. To access, correct, export or delete your data, or to close your account, email [CONTACT EMAIL]. Depending on where you live (for example under certain U.S. state privacy laws), you may have additional rights; we will honor valid requests as required by law. Cancel a subscription any time in the billing portal.

8. Children

The Service is not for anyone under 18, and we do not knowingly collect data from children.

9. Changes and contact

We will post changes here and update the effective date; for material changes we will notify you in the app or by email. Contact: [COMPANY LEGAL NAME], [CONTACT EMAIL], [STATE].