DealsAndBobs – Swipe the best deals & community

Privacy Policy

Last updated:

This policy explains what personal data DealsAndBobs collects, why, how long we keep it, and your rights. We have kept it short and plain on purpose. If anything is unclear, email .

In short

  • We only collect what we need to run your account and the community.
  • We don't sell your data, send marketing emails, or use advertising or analytics cookies.
  • We use one essential cookie to keep you logged in.
  • You can delete your account – and the content you posted – yourself, at any time.

1. Who is responsible for your data

The "controller" of your personal data is , registered in (company number ), registered office: . For anything about your data, contact us at .

2. What we collect and why

Data Why we use it Lawful basis (UK GDPR)
Account details: username, email address, password (stored only as a secure, one-way hash), date you joined and accepted our terms To create your account, log you in, and contact you about your account or legal matters Contract – needed to provide the service you signed up for
What you post: deals, comments, edits, and when you posted them To publish them on the site. Your username and posts are public. Contract
Votes (hot / not) To calculate a deal's temperature and make sure each member votes only once. Other members cannot see how you voted. Contract
Reports and moderation records: reports you send, reports about your content, moderator decisions and notes, account suspensions To keep the community safe, deal with illegal content, handle complaints and appeals, and show we meet our legal duties Legal obligation (Online Safety Act 2023) and legitimate interests (a safe, spam-free community)
Login session: a random session token in a cookie; we store only a scrambled (hashed) copy To keep you logged in securely Contract
Technical data: IP address, browser type, and the pages requested Processed by our hosting provider to deliver the site, protect it from attacks, and help us fix errors. We do not store IP addresses in our own database, except in scrambled form for security (see the next row). Legitimate interests (security and keeping the site working)
Security records: when you log in, sign up, change your password or ask for a password reset, we record a scrambled (hashed) version of the email address used and of your IP address, and the time To limit repeated attempts, so nobody can guess passwords or flood the site with fake accounts. Deleted automatically after 24 hours. Legitimate interests (keeping accounts secure)
Account emails: your email address and the emails we send you (for example password reset links and "your password was changed" alerts) To let you recover your account and warn you about important changes to it. We do not send marketing emails. Contract
Messages you send us by email To reply, handle reports, complaints and data protection requests Legitimate interests, or legal obligation where the law requires us to respond

Where we rely on legitimate interests, those interests are running a safe, reliable community site. You can object – see Your rights. Giving us an email address and password is required to create an account; everything else you post is up to you. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The only automatic rules are simple limits (for example, how many deals an account can post per day) to stop spam.

3. Who we share it with

We do not sell your data or share it with advertisers. When you click a link to a retailer (including an affiliate link), you leave our site: the retailer and any affiliate network may set their own cookies under their own privacy policies. We do not send them your account details.

Deal images are shown directly from the retailer's own website (for example Amazon or Argos). To display them, your browser connects to that retailer, which – as with any image on the web – receives your IP address and browser type. We only allow images from a list of known retailers.

4. International transfers

Cloudflare runs a global network, so some technical data (like your IP address) may be processed outside the UK, including in the United States. Resend, our email delivery service, is also based in the United States. Where this happens, it is protected by UK-approved safeguards such as the UK–US data bridge or the UK International Data Transfer Addendum to standard contractual clauses.

5. How long we keep it

6. Cookies

We use one cookie, and it is strictly necessary for the site to work, so we don't need to ask for consent:

Name Purpose Lasts
dab_session Keeps you logged in. Only set when you log in or sign up. 30 days, or until you log out

We don't use analytics, advertising or social media tracking cookies. If we ever do, we will ask for your consent first.

7. Your rights

Under UK data protection law, you have the right to:

To use any of these rights, email from the address linked to your account. We will reply within one month (this can be extended in complex cases – we'll tell you if so). It's free.

8. Complaints

If you're unhappy with how we use your personal data, please complain to us first at with the subject "Data protection complaint". We will acknowledge your complaint within 30 days, look into it without undue delay, keep you updated, and tell you the outcome.

You also have the right to complain to the UK regulator, the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, helpline 0303 123 1113.

9. Children

DealsAndBobs is not for children. You must be at least to create an account. If you believe a child has created an account, tell us and we will delete it.

10. Security

Passwords are stored as strong, salted one-way hashes, so nobody – including us – can read them. The site only works over an encrypted connection (HTTPS), and the login cookie can't be read by scripts on the page. After several wrong passwords, logging in to that account is paused for a short time, and we email you whenever your password is changed. No system is perfectly secure, but if we ever had a data breach that put you at risk, we would tell you and the ICO as the law requires.

11. Changes to this policy

We will update this policy if the way we use data changes – for example, if we start sending emails or use analytics. The date at the top shows the latest version, and we will tell members on the site about important changes.