Privacy Policy
We collect as little as the service needs, we show no advertising, and sellers never learn who you are.
Who is responsible
Chaffery is operated by Chaffery, 34800, Istanbul, Türkiye. We are the controller of the personal data described on this page.
For anything about your data, write to legal@chaffery.com. We answer within 30 days.
What we collect
Only what you give us and what running the service produces:
- Account: your e-mail address, the name you choose to give, your language and your alert settings.
- Targets: the products you named a price for, the price, and when you set, changed, renewed or withdrew it.
- Alerts: the notifications and e-mails we sent you, and whether an e-mail could not be delivered.
- Sign-in and security: one-time codes (stored only as a hash), your signed-in sessions with IP address and browser type, the IP address used when the account was opened and when a target was set, and the version of the terms you accepted.
- Messages: what you send us through “Report a problem” or by e-mail.
- Sellers, in addition: the store’s address and platform, the access keys the platform gives us (stored encrypted), the store’s product data, the notes and cost figures you enter, and the state of your subscription. Card and bank details never reach us — payments are handled by Polar.
We do not buy data about you, we do not build advertising profiles, and we use no analytics or tracking tools.
Why we use it
- To run your account, keep your targets and tell you when a price is met — the service you asked for (performance of a contract, Art. 6(1)(b) GDPR).
- To send the e-mails you have switched on: price met, target about to expire, a seller’s note. Each kind can be switched off under Account → Alerts, and every such e-mail has a one-click unsubscribe link. Sign-in codes and essential notices about your account or these terms are always sent.
- To keep the service safe: limiting sign-in attempts, detecting fake accounts and manipulation, blocking abuse (our legitimate interest, Art. 6(1)(f) GDPR).
- To show sellers anonymous demand for their products (our and their legitimate interest; see the next section).
- To meet legal obligations, such as answering lawful requests from authorities (Art. 6(1)(c) GDPR).
We send no marketing e-mail. Nothing is decided about you by automated means with a legal or similarly significant effect.
What sellers see
A seller sees, for their own products only: the prices shoppers named, the day each was set and whether it is still open — next to a random-looking code that is different for every product, so that targets cannot be linked across products or back to a person.
Sellers never see your name, your e-mail address, your IP address or anything else about you, and we never sell or hand over your contact details. If you go to a store and buy there, the store learns what any online shop learns from its customers — under the store’s own privacy policy, not this one.
Links to stores carry a tag such as “utm_source=chaffery” so that the store can see a visit came from Chaffery. The tag says nothing about you.
Who else handles data
We use a small number of service providers, each only for its task:
- Hetzner Online GmbH, Germany — the servers that the site, the database and our e-mail run on.
- Polar Software Inc., United States — sells the seller subscription as merchant of record and processes sellers’ payment and invoice data under its own privacy policy. Shoppers’ data never goes to Polar.
- The store platforms (Shopify, WooCommerce sites, Google Merchant Center) — we read sellers’ product data from them and send them nothing about shoppers.
Our e-mail is sent from our own server, not through a marketing service. We do not sell personal data, and we disclose it to authorities only when the law requires it.
Where your data is
Our servers are in Germany, inside the European Union. If you use Chaffery from another country — for example Türkiye, the United Kingdom or the United States — your data is therefore transferred to and stored in Germany.
Polar, which handles sellers’ payments, is based in the United States and relies on the safeguards described in its own privacy policy.
How long we keep it
- Your account and open targets: until you delete the account. An open target expires after 90 days unless you renew it.
- Met, withdrawn and expired targets: 365 days, then they are erased. They stop counting for sellers immediately.
- Notifications in your account: 365 days.
- IP addresses stored with an account or a target: 90 days. Signed-in sessions are deleted when you sign out or when they expire (30 days).
- Copies of automatic e-mails we sent: 90 days; sign-in code e-mails: 2 days.
- Messages you sent us and our replies: up to 730 days.
- Reports: 730 days after they are closed.
- Anonymous counts of visits to a store: 400 days.
- Security and administration logs: up to 730 days.
- Backups: 14 days. Erased data disappears from the backups within that time.
- A deleted seller account: the product data of its stores is removed after 30 days. Invoices are kept by Polar for as long as tax law requires.
When you delete your account, your personal data is erased from the live system at once.
Your rights
You can ask for access to your data, for a copy of it, for correction, erasure or restriction, and you can object to processing that rests on our legitimate interests. Where processing rests on consent, you can withdraw it at any time.
Most of this needs no request: under Account → Privacy (sellers: Settings → Your data) you can download everything we hold as a file and delete your account immediately.
For anything else write to legal@chaffery.com. We may ask you to write from the e-mail address of your account, so that we know the request is yours. You also have the right to complain to the data protection authority where you live.
Cookies
We only use the cookies the site cannot work without: one that keeps you signed in and one that remembers your language. There are no advertising, analytics or social-media cookies, which is why you see no cookie banner. Details are in the Cookie Policy.
Our pages load nothing from other companies. Even product photos are delivered through our own servers, so a store or its image host does not see your IP address unless you decide to visit the store.
Children
Chaffery is for adults. You must be at least 18 years old to open an account, and we do not knowingly collect data from anyone younger. If you believe a minor has given us personal data, write to legal@chaffery.com and we will delete it.
Security
All traffic is encrypted (HTTPS). There are no passwords to steal: you sign in with one-time codes, and session keys are stored only as hashes. Stores’ access keys are encrypted at rest, our administration tools cannot be reached from the internet, and the database is backed up daily.
No system is perfectly secure. If a breach ever puts your data at risk, we will tell you and the competent authority as the law requires.
Information for users in Türkiye (KVKK)
Under the Turkish Personal Data Protection Law No. 6698 (KVKK), the data controller is Chaffery. Your data is processed for the purposes listed above, because it is necessary for setting up and performing a contract, for the controller’s legal obligations and for its legitimate interests (KVKK Art. 5(2)(c), (ç) and (f)). It is collected electronically through the website and stored on servers in Germany.
Under KVKK Art. 11 you may learn whether your data is processed, request information about it, learn the purpose of the processing and the recipients, ask for correction or erasure, and object to a result that arises from automated analysis. Send requests to legal@chaffery.com; we answer free of charge within 30 days. You may also complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
Changes to this policy
When we change this policy we update the date at the top. If a change matters for how your data is used, we tell you by e-mail at least 15 days before it takes effect.