Privacy Policy
Last updated September 5, 2026
The short version
Fyndare is built to work without knowing who you are. There are no visitor accounts, no advertising, and no advertising profiles. The one place we ask for anything about you is the newsletter box, which is entirely optional and takes an email address and nothing else — skip it and the site never learns a thing about you. The little data we handle ourselves exists to keep the site fast, honest, and abuse-free — and none of it can single you out as a person. One thing we won’t leave in the fine print: our affiliate partners Impact and Sovrn Commerce have attribution tags that set cookies in your browser, so a purchase you make at a retailer can be credited back here — that is how the site is funded. We may also run Google Analytics, which sets cookies of its own to count visits and tells us nothing about you as a person. Those three are the only such technologies on the site, they answer to the same switch, and in the EEA and the UK none of them load until you say yes; everywhere else they load on arrival and you can switch them off from any page. The Cookies section below names exactly what they store.
Information we collect
Click events. When you click an outbound coupon, deal, or store link, we record an anonymous event: which offer was clicked, the page you came from, a one-way cryptographic hash (SHA-256) of your browser’s user-agent string, and your two-letter country code (derived at the network edge). We do not store your IP address, name, email address, or any identifier that could single you out. These events power the “popular right now” and success-rate features you see on the site.
Offer-view counters. When a coupon button scrolls into view, we count one anonymous view: which offer was shown and on which kind of page (a store page, the homepage, a category page). That is the entire record — no cookie, no hash, no identifier of any kind, nothing that could single you out. We use these counts only to measure which offer layouts people find useful. When we compare two versions of a button, your browser also remembers a coin flip (literally the word “control” or the name of the alternative, stored on your device) so you see the same version each visit; it is shared by roughly half of all visitors and identifies no one.
Newsletter signups. If you enter your email address in the newsletter box, we store the address, which page the form was on, and the handful of dates that describe where your subscription stands: when you submitted the form, when you confirmed it, when we last sent you something, and when you unsubscribed if you have. Nothing else — no name, no browsing history, and no link to the anonymous click and view data described above, which carries no identifier that could be joined to an address in the first place. We do not sell, rent, or share the list.
Confirming, and leaving. Signing up takes two steps on purpose. No address is ever sent the newsletter until it has confirmed, and the only email an unconfirmed address can receive is the one request to confirm it — ignore that request and you never hear from us again. Every newsletter we send carries a one-click unsubscribe link, both as a link you can click and in the message headers, so your mail app can remove you without your opening anything. You can also write to privacy@fyndare.com and we will delete your address by hand.
Abuse prevention. Your IP address is used transiently to enforce fair-use limits on things like voting, rating, and the AI assistant (so one person can’t stuff the ballot or flood a paid service). These rate-limit counters expire automatically — within 24 hours at most — and are never joined with click or browsing data. Separately, our hosting provider processes standard request data (including IP addresses) transiently to serve and secure the site, as virtually all web hosts do.
AI assistant questions. If you use the deal assistant, the question you type is sent to Anthropic (our AI provider) to generate the answer. We do not store your questions in our database, and Anthropic’s commercial API terms do not use them to train its models by default. Please don’t include personal information in your questions — the assistant only needs to know what kind of deal you’re after.
Community feedback. “Did this code work?” votes and store star ratings are stored only as anonymous aggregate counters (e.g. “42 people said this worked”). No vote or rating is linked to you.
Affiliate attribution. We work with an affiliate network called Impact, and it has a tracking tag. Its job is attribution: recording that a visit happened here, so that if you go on to buy something at a retailer, the retailer knows the referral came from Fyndare and pays the commission that pays for the site. To do that, it stores a few values in your browser and sends page-view events to Impact’s servers. We do not read those values, we get no personal information back from them, and they are not used to advertise to you — but they are tracking technology, and calling them anything else would be dishonest.
Where we ask first. If you are visiting from the European Economic Area or the United Kingdom, that tag — and the analytics described below, where enabled — does not load at all until you choose “Accept” on the banner. Not when the page loads, not while you decide, not if you ignore it — declining and ignoring have exactly the same effect, and neither sends so much as a request. Elsewhere they load on arrival, as the attribution tag has since the site opened. You can change your answer any time with “Cookie preferences” at the bottom of any page; if you turn it off after turning it on, we delete what was stored.
What we deliberately don’t collect
- No visitor accounts and no names — the optional newsletter box is the only place we ask for an email address, and it asks for nothing alongside it
- No IP addresses stored by us — not in our click data, not in our analytics
- No advertising or retargeting cookies, no ad pixels, and no fingerprinting
- No precise location — only a country code
- No selling or sharing of personal information, ever
The affiliate attribution tag and the analytics described below are the only tracking technologies on the site: one is limited to crediting purchases, the other to counting visits. We do not run advertising, and Google Analytics — where it is enabled — has its advertising features switched off in the tag itself, not merely unticked in a dashboard. Nothing here feeds an ad profile.
Cookies and local storage
Fyndare writes no cookies of its own on the public site, apart from the one that remembers your answer to the banner. Everything else below is set by a third-party tag running on the page, and each is worth naming plainly:
- Affiliate attribution (Impact). The tag described above sets first-party cookies — at the time of writing,
IR_gbdandIR_MPS— and stores animpact-referralvalue in your browser’s local storage. They exist to connect a purchase you make at a retailer back to the referral from this site. Their lifetime is set by Impact, not by us, and what Impact does with them is governed by Impact’s own privacy policy. In the EEA and the UK, none of this is set unless you accept it first. - Affiliate attribution (Sovrn Commerce). Sovrn’s Commerce tag sets first-party cookies whose names begin with
vglnk.and reports the page it ran on to Sovrn. It does the same job as the Impact tag above — connecting a purchase back to the referral from this site — for the retailers Sovrn represents. Their lifetime is set by Sovrn, not by us, and what Sovrn does with them is governed by Sovrn’s own privacy policy. In the EEA and the UK, none of this is set unless you accept it first, and the same “Cookie preferences” switch deletes them. - Analytics (Google), if enabled. Google Analytics 4 sets first-party cookies named
_gaand_ga_-plus-a-stream-id. They hold a randomly generated number that lets Google tell one browser from another, so that ten page views by you are not counted as ten visitors. They carry no name, no email, and nothing you typed. In the EEA and the UK they are not set unless you accept first, and the same “Cookie preferences” switch deletes them. - Your cookie choice. When you answer the banner, we store that answer in a cookie named
fyndare_consentfor about six months. It holds one word — whether you accepted or declined — and exists only so we don’t ask again. It is what makes “no” stick. - Administrator login. Authentication cookies are set only inside the administration area (
/admin) and only for the site’s administrators — they are strictly necessary for that login to function and are never set on public pages.
“Cookie preferences” at the bottom of any page turns these tags on or off whenever you like, wherever you are in the world — and switching them off deletes what they already stored. Your browser settings work too. Either way it costs you nothing: every page, every code, and every outbound link keeps working exactly the same. It only means a purchase you make may not be credited to us, and your visit won’t appear in our counts.
Analytics
We may use two analytics tools, and the difference between them matters enough to spell out.
Plausible Analytics is a privacy-first, cookieless service. It collects only aggregate statistics (page views, referral sources, country) without cookies, without persistent identifiers, and without tracking you across sites — which is why Plausible itself needs no consent banner and loads for everyone.
Google Analytics 4 is the ordinary one, and we treat it as such. It sets the cookies named in the Cookies section above, so it does not load for anyone who declined or ignored the banner in the EEA or the UK — the same rule as the affiliate tag, for the same reason. We use it for aggregate measurement only: the advertising features are switched off in the tag itself on every page load, Google Signals is off, the property is not linked to any advertising account, and we send Google no identifier of our own — no email, no account, no hashed anything, because we don’t have those to send. Google receives your IP address as part of the request, as every server you contact does, and uses it to derive an approximate location; Google states it does not log or store that address in GA4, and it is not available to us in any report. What we actually look at is which pages people land on from search and which ones they leave immediately.
If we ever switch on an analytics feature that does more than this — advertising integrations, cross-device identity, anything that profiles you — we will update this policy before it goes live, not after.
When you leave this site
Coupon and deal links lead to retailers via affiliate networks (Awin, CJ, Rakuten Advertising, Impact, and Sovrn Commerce). Impact and Sovrn Commerce are the two networks whose tags also run while you are still here, as described above; the rest come into play only once you leave. Once you follow an outbound link, those networks and retailers may set their own cookies to attribute any purchase you make — that attribution is how this site earns commissions (see our Affiliate Disclosure). Their processing is governed by their own privacy policies, and we encourage you to review them.
The browser extension
Fyndare Companion is an optional browser extension, separate from this site. You do not need it to use Fyndare, and everything below applies only if you install it.
It does not tell us which sites you visit. The extension carries its own copy of the list of stores we cover and checks the site you are on against that list on your device. If you are on a site we do not carry — which is most of the web — the extension makes no request to us at all. Nothing about that visit reaches us, because nothing is sent. There is no record for us to keep, hand over, or lose.
The two requests it does make. Once a day the extension downloads the store list itself: a single file, identical for every user, that says nothing about you. And when the list says you are on a store we cover, it asks us for that store’s current offers — a request that names the store, not your address bar and not the page you are reading.
Trying codes at checkout. If you click “Try codes at checkout”, the extension reads the promo-code box and the order total on that page so it can enter each code and see whether the total moved. That reading happens inside your browser and is never transmitted — we never receive your basket, its contents, or its value. It only runs when you click; the extension does not read the pages you browse.
Activating a deal. Clicking “Activate deal” sends you to a retailer through the same redirect the website uses, and records the same anonymous click event described above, tagged so we can tell extension traffic from site traffic. One difference: the referring page recorded is the store’s address only — for example https://www.example.com — never the full URL of the page you were on. As on the site, nothing in that event identifies you.
What stays on your device. Your settings, the stores you have hidden, the store list, and short-lived caches of offers all live in your browser’s extension storage. We cannot read them. Removing the extension removes them with it.
The extension has no account, no login, and no identifier of any kind. It does not read your history, your bookmarks, your passwords, or the contents of pages you visit, and we do not sell or share anything it produces.
Service providers
We rely on a small set of infrastructure providers to run the site:
- Vercel — hosting and content delivery (processes request data, including IP addresses, transiently; derives the country code we store)
- Supabase — database and image storage (holds the anonymous data described above)
- Upstash — short-lived rate-limit counters for abuse prevention
- Anthropic — processes AI assistant questions to generate answers
- Plausible — cookieless aggregate analytics, if enabled
- Google — Google Analytics 4, if enabled; sets the cookies described above and processes visit data on servers in the United States and elsewhere, under Google’s own privacy policy and the EU–US Data Privacy Framework
- Impact — affiliate attribution; its tag runs on public pages and sets the cookies described above
- Sovrn — affiliate attribution; its Commerce tag runs on public pages and sets the cookies described above
- Resend — sends administrator password-reset emails only; it never touches visitor data
Each provider processes data on our behalf and under its own security and privacy commitments. We do not sell, rent, or share data with advertisers or data brokers.
Data retention
Anonymous click events and aggregate feedback counters are retained for as long as they remain useful for the statistics they power; they contain no personal identifiers. Newsletter addresses are kept until you ask us to remove yours, or until we abandon the newsletter — if we decide to stop, we delete the list rather than sit on it. An address that was asked to confirm and never did is deleted about a month after its confirmation link expires; there is no point holding an address that has given us no usable consent. If you unsubscribe we keep the address itself, and nothing more, so that a later signup form submission can’t quietly put you back on a list you left — tell us and we will delete that record too. Rate-limit counters expire automatically within at most 24 hours. Administrator password reset tokens are single-use, stored only as hashes, and expire within one hour. Where Google Analytics is enabled, the visit data it collects is held by Google for 14 months and then deleted automatically — the shortest retention that still allows a year-over-year comparison, which for a site whose traffic is seasonal is the whole point of keeping it at all. The affiliate and analytics cookies live in your browser, not our database — their lifetimes are Impact’s and Google’s to set, and clearing your browser storage removes them.
Your rights
Depending on where you live (for example under the GDPR in Europe or the CCPA/CPRA in California), you may have rights to access, correct, delete, or port personal data, and to opt out of its sale or sharing. Two honest notes on how those rights apply here: first, we do not sell or share personal information as those laws define it, so there is nothing to opt out of; second, because the rest of the data we keep cannot identify you, we are generally unable to link any of it back to a specific person who asks (a situation the GDPR anticipates in Article 11). The newsletter list is the one exception, and the simple one: it is keyed by your email address, so if you write to us from that address we can confirm, correct, or delete your entry directly. You can contact us with any other request or question and we will do our best to help.
Do Not Track and Global Privacy Control
We run no advertising, build no ad profiles, and do not sell or share personal information — so most of what a Do Not Track or Global Privacy Control signal asks for is already the default here for everyone, with nothing to switch off. The honest caveat is affiliate attribution: connecting a click here to a purchase at a retailer is a cross-site measurement by nature, and it is what funds the site. Analytics, where enabled, is the smaller cousin of the same caveat. If you would rather neither happened, “Cookie preferences” at the bottom of any page turns both off in one click, and costs you nothing else. In the EEA and the UK they are off until you turn them on.
Children
Fyndare is not directed at children under 13, and we do not knowingly collect personal information from anyone — children included.
International visitors
The site is operated from the United States and data is processed on servers in the United States. By using the site, you understand that the minimal data described above is processed there.
Changes to this policy
If our practices change — for example, when the newsletter starts sending, or if we add new analytics — we will update this policy before the change takes effect and revise the “last updated” date above. Material changes will be flagged prominently on this page.
Contact
Questions about this policy — or any privacy request — can be sent to privacy@fyndare.com.