
Privacy Policy
Last updated August 21, 2026
Introduction
This Privacy Policy explains how Echelon Dynamics Inc. (“we”, “us”, “our”) collects, uses, and protects your information when you use DealHunter, our real-time marketplace monitoring SaaS application (“Service”).
This policy applies to users located in the United States and is intended for individuals aged 18 and older. All data is processed and stored on servers located in the United States.
Information We Collect
a. Account Information
When you sign up using Google or Apple Single Sign-On (SSO) via Google Firebase Authentication, we collect the information shared by those providers. This may include:
- Full name
- Email address
- Profile photo (if available)
This is information Google or Apple sends to us when you choose to sign in with them. It is a different flow from the information we send to Google for advertising measurement, which is described under “Advertising, Analytics & Conversion Measurement” below.
b. User-Generated Data
We collect information you input while using the Service, including:
- Search terms and criteria for monitored marketplaces
- Alert preferences and notification settings
c. Payment Information
We use Stripe to process payments. Stripe collects and processes your payment details directly. We do not store credit card numbers on our servers. For Stripe’s privacy practices, visit: stripe.com/privacy
d. Device & Notification Data
If you enable push notifications, we collect a Firebase Cloud Messaging (FCM) device token to deliver marketplace alerts to your device. This token does not contain personal information and is used solely for notification delivery.
e. Technical, Location & Anti-Abuse Data
- IP address. We record the IP address your account is created from and store it with your account. We use it to stop one person taking more of a limited feature than one account allows: a sign-up is refused when an earlier account from the same network has already used up its free alert allowance, and no more than two accounts may be created from one network in any 24-hour period. Your IP address is also sent to the third parties named below — a location lookup provider, and, on some advertising conversion uploads, an advertising network.
- Location. Local marketplaces need a location. If you do not grant the browser location permission, we send your IP address to a location lookup provider to suggest an editable ZIP code. If you tap the location control and grant permission, your device’s exact latitude and longitude are sent to BigDataCloud — and, if that returns no postcode, to the OpenStreetMap Nominatim service — to be converted into a ZIP code. Those coordinates are also saved with the search you were creating, so nearby listings can be matched to you.
- Device and usage information. Your browser user-agent string, the pages you view, and the clicks, taps and scrolling you perform in the Service. See “Session Recording” below for how much of this is recorded and by whom.
How We Use Your Information
We use your data to:
- Operate and maintain your account
- Deliver marketplace alerts based on your saved searches
- Send push notifications to your device via Firebase Cloud Messaging
- Manage billing and process payments through Stripe
- Improve our service and infrastructure
- Communicate service updates, billing notices, and security alerts
- Detect and block abuse, including repeat sign-ups used to work around account limits — this is what the IP address recorded at sign-up is for
- Notify ourselves that a new account was created, so a one-person team knows the Service is being used
- Measure which advertisements produce sign-ups and subscriptions, which involves sending data to advertising companies as described below
Data Processors & Third-Party Services
We do not exchange your personal information for money. Whether some of the advertising transfers described below count as a “sale” or a “share” under California law is a separate question, addressed in the California Residents section at the end of this page.
Below is every third party we send personal information to, and what each one receives. Everything listed here is running in production today unless the entry says otherwise.
- Stripe — Payment processing and subscription management
- Google Firebase — Authentication (SSO) and push notification delivery (FCM)
- MongoDB Atlas — Cloud database hosting (data stored in the US)
- Cloudflare — Content delivery, bot protection on our contact and account-deletion forms, and first-party routing of analytics requests
- Twilio SendGrid — Delivery of account, billing and lifecycle email, and the mailing lists that drive it
- Anthropic — Powers AI Search Assist inside the app. The wording you type is sent to Anthropic to be turned into search criteria
- OpenAI — Powers the optional Searchsmith GPT assistant (only when you choose to use it)
- PostHog — Product analytics and session recording (US region)
- Sentry — Error monitoring
- Google — Google Analytics 4 usage analytics, and Google Ads conversion measurement by two separate routes: a tag in your browser, and an upload sent directly from our servers. Both are described in detail under “Advertising, Analytics & Conversion Measurement” below
- Microsoft Advertising — Conversion measurement through its UET tag. That tag also loads Microsoft Clarity, a session-recording product. The UET tag is live on this website today even though we are not currently buying Microsoft ads
- Reddit — Conversion measurement, both through an advertising pixel in your browser and through an upload sent from our servers. The pixel is live on this website today even though we are not currently buying Reddit ads
- Pushover — Operational alerting. Each time a new account is created, we send ourselves a phone notification containing the new account’s email address in plain text, the sign-in method used, and the advertising campaign, source and medium the visit arrived with. This is how a one-person team learns a sign-up happened
- Location lookup providers — FreeIPAPI, IPGeolocation.io and IPLocate.io. When we need to suggest a ZIP code and you have not granted the browser location permission, your IP address is sent to these providers in turn until one returns a US ZIP code
- BigDataCloud and the OpenStreetMap Nominatim service — Reverse geocoding. When you grant the browser location permission, your exact latitude and longitude are sent to BigDataCloud, and to Nominatim if BigDataCloud returns no postcode, to be turned into a ZIP code
Each of these companies handles what it receives under its own privacy policy and its own terms with us.
Separately from that list: running a saved search means sending your search terms to the marketplaces we monitor, the way any search on those sites does. Those requests carry your keywords and, where the search is local, a ZIP or coordinates — never your name, email address or DealHunter account identifier.
We intend this list to be complete. If you find a data flow that is not described here, tell us at [email protected] and we will correct this page.
Searchsmith GPT (Optional AI Assistant)
“DealHunter Searchsmith” is an optional custom GPT that helps you craft search criteria. It runs on your own ChatGPT account, so your conversation with it is handled by OpenAI under OpenAI’s privacy policy, not by DealHunter. Using it is entirely voluntary.
If you choose to send a drafted search from the GPT into your DealHunter account, the only data transmitted to us is:
- The search criteria you co-authored (title, keywords, exclusions, marketplaces, price range)
- A short, single-use pairing code you generate in the DealHunter app
We do not receive your ChatGPT conversation, your OpenAI account details, your name, or your location through this flow. The pairing code carries no personal information and only links the draft to your already-authenticated DealHunter account.
A search sent this way is stored only as a temporary draft for your review. The pairing code and the draft both expire automatically (the code within minutes, the draft within roughly thirty minutes) and are deleted. We keep a minimal audit record of the transfer for security and abuse-prevention purposes. No search is created or activated until you review it and tap “Create” within your signed-in DealHunter session. All of this data is processed and stored in the United States.
Cookies & Tracking Technologies
We use the following technologies:
- Essential cookies for session management and authentication
- Error tracking (Sentry) to diagnose and resolve performance issues
- Product analytics (Google Analytics 4 and PostHog) to understand how the Service is used
- Advertising and conversion measurement (Google Ads, the Microsoft Advertising UET tag, and the Reddit pixel) to measure which advertisements lead to sign-ups and subscriptions
Exactly what those advertising and measurement technologies send, in which direction, and to whom, is set out in the next section.
We use Google Analytics 4 to collect usage data, including page views, session duration, and user interactions. This data helps us understand how the Service is used and improve it over time. Google Analytics may set cookies or use similar technologies. You can opt out by installing the Google Analytics Opt-out Browser Add-on. You can also control cookie behavior in your browser settings.
Advertising, Analytics & Conversion Measurement
We buy advertising to find new users, and we measure which advertisements produce sign-ups and subscriptions. That measurement moves data out of DealHunter to advertising companies. This section describes every such flow.
Tags that run in your browser
Three advertising tags load on this website: the Google Ads tag, the Microsoft Advertising UET tag (which also loads Microsoft Clarity, described under “Session Recording” below), and the Reddit pixel. All three are live today. We currently buy advertising only on Google, but the Microsoft and Reddit tags still load and still report page views and conversions to those companies.
None of these three tags are included in the DealHunter iOS or Android app.
What we send to Google, and in which direction
Signing in with Google is an inbound flow: Google sends us your name and email address so we can create your account. The flows below are the opposite direction — we send data to Google.
- Enhanced conversions, from your browser. When you complete checkout, your email address and your first and last name are handed to Google’s tag as an “enhanced conversion” so the subscription can be matched to the advertisement that brought you here. The tag applies a SHA-256 hash to those values in your browser before anything is transmitted, so Google receives irreversible hashes rather than your address and name in readable form. Our Google Ads account has accepted Google’s customer-data terms and has enhanced conversions enabled, so this is live rather than theoretical. The tag is given those values only for that single conversion and they are cleared immediately afterwards, so they do not accompany any other Google tag event sent from the same page.
- Offline conversion upload, from our servers. Separately, when your first paid invoice is charged, our server sends Google Ads a conversion record directly. It contains the Google click identifier (“gclid”) stored when you first arrived from a Google ad, the SHA-256 hash of your email address, the Stripe invoice identifier for that payment, the amount, and the time of payment. This is how a subscription that begins days after the click is still attributed to the advertisement.
- Google Analytics 4. Usage analytics for the website and app. Where a sign-up or payment completes away from the browser, our server sends Analytics a matching event containing the Analytics client identifier, your DealHunter account identifier, your IP address and your browser user-agent.
We also report other milestones to Google Ads as conversions — creating an account, creating a saved search, and reaching the subscription prompt. Those carry no email address or name, only the fact that the milestone happened and which advertisement click it belongs to. The Microsoft and Reddit tags in your browser receive the same kinds of milestone events.
What we send to Reddit
When a visit arrives with a Reddit click identifier, our server reports the resulting sign-up to Reddit’s Conversions API, and reports the first paid invoice the same way. That upload contains the SHA-256 hash of your email address, the SHA-256 hash of your DealHunter account identifier, the Reddit click identifier, the amount for a payment — and, on the sign-up event, your IP address and browser user-agent in readable form, which Reddit hashes on its side. Sign-ups made inside the iOS or Android app are excluded from this upload.
What we do not do
We show no cookie or consent banner, and these tags load without asking you first. We do not currently detect or honor “Do Not Track” or Global Privacy Control signals, and there is no switch inside DealHunter that turns this measurement off. The controls that do exist are the browser-level ones described under “Session Recording” below, and writing to us.
Session Recording
We use session-recording tools, which reconstruct what happened on screen: the pages you viewed, your clicks, taps, scrolling and pointer movement, and the text the page displayed to you. Which tools run depends on where you are using DealHunter.
On this website and in the installed web app, two providers record, including on the sign-up page and on the subscription and checkout pages:
- PostHog — product session replay, used to see where people get stuck. It records across the Service with one exception: it does not start on the home page or on blog articles. Even on those two pages it will begin recording if you navigate further into the site, or if you click rapidly and repeatedly on the same control
- Microsoft Clarity — loaded automatically by the Microsoft Advertising UET tag described above, and governed by Microsoft’s privacy statement. It records every page it loads on
In the DealHunter iOS and Android app, only PostHog records, and it records the whole session. Microsoft Clarity cannot run there because the Microsoft Advertising tag that loads it is not included in the app build.
Payment card details are never part of a recording. Your card number, expiry date and security code are typed into fields hosted by Stripe on Stripe’s own domain, which these tools cannot see. Values you type into DealHunter’s own form fields, including passwords, are masked by the PostHog recorder before the recording leaves your browser.
We use recordings to diagnose errors and to understand where the product is confusing. They are retained for a limited period under each provider’s retention settings. We do not sell recordings, and we do not use the PostHog recordings for advertising targeting. Microsoft Clarity is different: it is delivered by an advertising tag, and what it collects is held by Microsoft under Microsoft’s own terms, which we do not control and which permit Microsoft to use that data for its own purposes, including advertising.
Your choices on the website. These tools are supplied by third parties and load as scripts in your browser, so they can be stopped there. A browser or extension that blocks analytics and advertising scripts, or blocking third-party scripts in your browser settings, prevents them from loading; the Google Analytics Opt-out Browser Add-on covers Google Analytics specifically. DealHunter continues to work normally when these scripts are blocked.
Your choices in the app. Script blocking is not available inside the iOS and Android app, and DealHunter does not currently offer a setting there to turn recording off. If you do not want your app sessions recorded, write to us: we will delete the recordings we hold for your account on request. If you have questions about recording, contact [email protected].
Data Retention
We retain your data as long as your account is active or as necessary to provide the Service. Upon account deletion, we will remove your personal data within 30 calendar days, except where retention is required for legal, audit, or security purposes.
Data Security
We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest
- Secure credential and token storage
- Access controls and audit logging
Despite these efforts, no system can guarantee 100% security. We will notify affected users within 72 hours of discovering a confirmed data breach.
Your Rights & Choices
You may request:
- Access to the personal data we store about you
- A portable copy of your data
- Correction of inaccuracies in your data
- Deletion of your account and associated data
Account deletion is processed within 30 calendar days of a verified request submitted via email to [email protected].
California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: You may request details about the personal information we collect and how it is used.
- Right to delete: You may request deletion of your personal information.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, email [email protected] with “CCPA Request” in the subject line.
Sale and sharing. We do not exchange your personal information for money. We do send hashed identifiers, and in one case your IP address and browser user-agent, to Google, Microsoft and Reddit so those companies can match a sign-up or a subscription back to an advertisement — the flows set out under “Advertising, Analytics & Conversion Measurement” above. Under the CCPA as amended by the CPRA, transfers of that kind can amount to “sharing” for cross-context behavioral advertising, and on some readings to a “sale”, even where no money changes hands. We have not concluded that question and are taking advice on it; we will state the answer on this page rather than leave it implied. In the meantime, if you want to opt out of those transfers, email the address above with “Do Not Sell or Share My Personal Information” in the subject line. There is no automated toggle in the product today, and we do not currently detect Global Privacy Control signals, so an email is the only route.
Children’s Privacy
DealHunter is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have inadvertently collected data from a minor, we will promptly delete it. If you believe a minor has provided us with personal information, please contact us at [email protected].
Data Processing Location
All data is processed and stored on servers located in the United States. By using the Service, you consent to your data being processed in the US in accordance with this Privacy Policy.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Continued use after changes take effect constitutes acceptance of the revised policy.
Contact Us
For any privacy-related inquiries, please contact:
Echelon Dynamics Inc.
30 N Gould St, Sheridan, WY 82801
Email: [email protected]
Phone: +1 (820) 444-6469