Privacy Policy — getdeal.am
Version 1.0 · Effective date: 20 September 2026
This is the English version. If the English and Armenian versions differ, the Armenian version applies.
1. Who we are
getdeal.am ("getdeal", "we", "us") is a price comparison website for products sold by shops in Armenia. Who runs it:
getdeal.am is operated by a private individual (ֆիզիկական անձ) based in Yerevan, Republic of Armenia.
The operator's full name and postal address are provided on request by email and are included in every reply to a request about your data.
Email: [email protected]
Under the Law of the Republic of Armenia "On Protection of Personal Data" (adopted 18 May 2015, HO-49-N, as amended), we are the processor ("մշակող") of the personal data described in this policy. In plain words: we decide why and how your data is used, and we are responsible for it.
2. What this policy covers
This policy explains what personal data we collect when you use getdeal.am, why we collect it, who can see it, how long we keep it, and what rights you have.
"Personal data" means any information that identifies you or could identify you, directly or indirectly (Article 3 of the Law).
getdeal.am is made for people in Armenia. Prices are shown in Armenian drams and the shops we compare are Armenian shops.
3. What getdeal does, in one paragraph
We automatically visit the public pages of Armenian online shops, read the product name, price, availability and similar facts, and show them side by side so you can find the best price. We do not sell anything. When you click "Go to store", you leave getdeal and buy on the shop's own website, under the shop's own terms and privacy policy.
We collect no personal data from the shops. We do not read or store customer reviews, reviewer names or any other information about the shops' customers.
4. The data we collect, and why
4.1 If you only browse (no account)
| Data | Why we use it | Legal basis |
|---|---|---|
| Your IP address and basic request details (page requested, time, browser type) | To deliver pages, protect the site from abuse and overload, and fix errors | Necessary to provide the service you asked for (Article 9(4)(2) of the Law); security duty (Article 19) |
The cookie gd_consent (your cookie choice: accepted or declined) | To remember whether you allowed on-device storage | Your choice, recorded when you click Accept or Decline |
With your consent only: the products you recently viewed, saved in your browser's storage (keys starting with getdeal:) | To show you a "Recently viewed" list | Your consent (Article 9(7)). You can withdraw it at any time in Account → Privacy or by clicking Decline; the stored data is then deleted from your device |
| Your display theme (light/dark) and language, saved in your browser | To show the site the way you set it | Necessary to provide the service you asked for |
We do not currently use third-party analytics, advertising or tracking cookies. If we start, we will update this policy first and ask for your consent where the law requires it.
4.2 If you create an account
| Data | Required? | Why we use it |
|---|---|---|
| Email address | Required | To identify your account, send verification and password-reset emails, and answer your requests |
| Password (stored only as a one-way hash, never in readable form) | Required for email sign-up; not needed for Google/Apple sign-in | To let you sign in securely |
| First name and last name | Required | To address you and personalise your account |
| Gender | Required at sign-up | Used only to address you correctly in the interface and in emails |
| Phone number, date of birth | Optional | Only if you choose to add them to your profile |
| Interface language and theme | Set automatically from your choices | To keep your settings on every device |
| Email verification status, last sign-in time, password-change time | Created by us | Account security |
Session identifier (in the gd_session cookie and on our server) | Created by us | To keep you signed in for up to 30 days and to let you sign out of all devices |
| For each sign-in: the browser description your device reports, your IP address, the time you signed in and the time you last used that session | Created by us | To show you the list of devices you are signed in on, so you can recognise one that is not yours and sign it out |
Legal basis: creating an account means entering into the agreement described in our Terms of Use. Processing the data needed for that agreement is lawful under Article 9(4)(2) of the Law. Optional fields are processed on the basis of your consent (Article 9(7)).
4.3 If you sign in with Google or Apple
When you choose "Continue with Google" or "Continue with Apple", the sign-in itself happens with Google or Apple through Google's Firebase Authentication service. We receive a signed token that contains your email address, your name (if the provider shares it), whether the provider has verified your email, and a provider user ID. We store the provider user ID and the Firebase ID so we can recognise you next time. We do not receive your Google or Apple password.
Google and Apple process your data under their own privacy policies. We only use Firebase for authentication, not for analytics or advertising.
We use the information received from Google or Apple only to create your getdeal account and keep you signed in. We do not share it with third parties, sell it, or use it for advertising or profiling. You can revoke getdeal's access at any time in your Google Account permissions (myaccount.google.com/permissions) or your Apple ID settings; deleting your getdeal account deletes this data on our side. getdeal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
4.4 If you contact us
The contact form sends your name, email address, chosen topic, message and interface language to our support mailbox and sends you an acknowledgement email. We keep the email conversation for as long as needed to resolve your request and for up to 12 months after that. Contact messages are not stored in the website database.
4.5 If you report a problem with an offer
Signed-in users can report that a price or offer looks wrong. We record the offer, shop and product concerned, your answer (correct / not correct), the reason, an optional comment of up to 500 characters, the price we showed, the time we last checked that price, and your account. We use this only to fix our data and to prevent abuse of the reporting feature. Please do not include other people's personal data in your comment.
4.6 Emails we send
We send only service emails: account verification, password reset, confirmation of a contact request, and security notices. We do not send marketing emails. If we later add price alerts or newsletters, they will be opt-in and you will be able to unsubscribe in one click.
4.7 Features that are not live yet
Price alerts and a paid "Pro" plan are planned. When they launch, this policy will be updated to describe the extra data involved (for example the products you follow and the alert channel you choose). Payments, if introduced, will be handled by a licensed payment provider; we will not store your card details.
5. Where we do not collect data
- We do not collect personal data about the shops' customers or staff.
- We do not collect reviews, reviewer names or user-generated content from the shops.
- We do not sell, rent or trade your personal data.
- We do not use your data for automated decisions that have legal effects on you (Article 16 of the Law).
6. Cookies and on-device storage
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
gd_session | Cookie, HTTP-only, secure | Keeps you signed in | 30 days or until you sign out |
gd_consent | Cookie | Remembers your Accept/Decline choice for on-device storage | 1 year |
getdeal:* | Browser storage (localStorage) | Recently viewed products; only if you accepted | Until you decline, delete your account or clear your browser |
| Theme setting | Browser storage | Light/dark mode | Until you change it or clear your browser |
| Firebase Authentication storage | Browser storage set by Google Firebase | Only used during Google/Apple sign-in | Managed by Firebase |
You can delete cookies and site storage at any time in your browser settings. The site works without the optional storage; you will simply not see the "Recently viewed" list.
7. Who can see your data
We share personal data only with the service providers we need to run the site. They act on our written instructions as "authorised persons" under Article 14 of the Law and may not use your data for their own purposes.
| Provider | What they do for us | Data involved | Location |
|---|---|---|---|
| Hetzner Online GmbH | Provides the server that runs the website, our application (API), the PostgreSQL database and the Redis session store | All account data, sessions, reports, request logs | Germany (EU) |
| Cloudflare, Inc. | DNS, website proxy/CDN and network protection; stores and serves product images (Cloudflare R2); routes incoming email to our mailbox | IP address and request logs; emails you send us | United States (organisation) / global network |
| Google LLC (Firebase Authentication) | Verifies Google/Apple sign-in tokens | Email, name, provider IDs | United States (organisation) / EU |
| Brevo (Sendinblue SAS) | Sends our service emails | Email address, name, email content | France (EU) |
We may also disclose data when Armenian law requires it, for example to a court or to a state body acting within its legal powers, or to protect our legal rights.
The shops do not receive your personal data from us. When you click "Go to store", the link opens the shop's website in a new tab and is set not to pass on the page you came from. From that moment the shop's own privacy policy applies.
8. Transfers outside Armenia
Our servers are in Germany (Hetzner) and our email provider is in France (Brevo), both in the European Union; Cloudflare and Google are United States organisations with global networks, so some data is stored outside Armenia. Article 27 of the Law allows such transfers when the receiving country provides an adequate level of protection. The Personal Data Protection Agency's list of such countries (Decision N ԱՏՊՊ-001/24 of 8 July 2024) includes all EU member states, the United Kingdom, Switzerland and organisations in the United States, among others. Where a transfer is needed to run the service you asked for, it is also allowed under Article 27(1). By creating an account you also give your consent to these transfers.
9. How long we keep data
| Data | Kept for |
|---|---|
| Account data | Until you delete your account. The account is then marked deleted immediately and permanently erased within 30 days, except data we must keep by law |
| Sign-in sessions, and the device details shown next to them | 30 days, or until you sign out, sign out of all devices, or change your password — the record is deleted with the session, not kept as a history |
| Email verification links | 24 hours; password reset links: 30 minutes |
| Consent cookie | 1 year |
| Offer reports | 24 months; after account deletion they are kept without the link to you |
| Contact emails | Up to 12 months after the request is closed |
| Server and API logs | 90 days |
When data is no longer needed for its purpose we delete it or make it anonymous (Articles 5 and 19(1) of the Law).
10. How we protect your data
- All traffic between your browser and getdeal is encrypted (HTTPS/TLS).
- Passwords are stored only as bcrypt hashes. We cannot read them.
- Sign-in tokens are cryptographically signed and tied to a server-side session that we can revoke at any time. Changing your password signs out every other device, and you can sign out one device, or all of them, from your account at any time.
- The browser and IP address shown next to a session are what your device reported when it signed in. We show them so you can recognise your own sign-ins; we never use them to decide whether a sign-in is allowed.
- Access to production systems is limited to the operator and protected by strong authentication.
- If personal data ever leaks from our systems, we will publish a notice on the site and notify the Police and the Personal Data Protection Agency immediately, as Article 21(4) of the Law requires, and tell affected users what happened and what to do.
11. Your rights
Under Articles 15–17 and 20–21 of the Law you have the right to:
- Know whether we process your data and get a copy of it, with the purpose, legal basis, recipients and retention period.
- Correct data that is wrong or out of date.
- Block or delete data that is incomplete, inaccurate, obtained unlawfully or no longer needed.
- Withdraw consent at any time for anything we do on the basis of consent. We will then stop and delete that data within 10 working days and confirm to you within 3 working days after deletion.
- Delete your account yourself in Account → Privacy → Delete account.
- Complain to the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia (https://www.pdpa.am, [email protected], +374 10 594 194) or to a court.
To exercise a right, email [email protected] from the address linked to your account, or use the tools in your account area. We answer within 5 days of receiving a written request, and we correct, block or delete data within 3 working days of confirming the problem (Article 20 of the Law). We may ask you to confirm your identity so that we do not disclose your data to someone else. Requests are free of charge.
If we refuse a request, we will tell you why in writing and name the legal provision we rely on. You can then appeal to the Agency or to a court.
12. Children
getdeal is not intended for children under 16. Under Article 9(9) of the Law, personal data of a person under 16 may be processed only with the consent of a parent or legal guardian. We do not knowingly register users under 16. If you believe a child has created an account, contact us and we will delete it.
13. Changes to this policy
We may update this policy when the service or the law changes. The current version and its effective date are always shown at the top of this page. If a change materially affects account holders, we will notify them by email or by a notice in the account area before it takes effect.
14. Contact
Questions about privacy: [email protected]
Postal address: available on request by email (see Section 1)
Supervisory authority: Personal Data Protection Agency, Ministry of Justice of the Republic of Armenia — https://www.pdpa.am