Legal
Privacy policy
As of 7 September 2026. This notice describes what BuyProof actually processes. It does not replace legal review; open points are named at the end rather than filled in silently. In case of doubt, the German version at /legal/privacy?lang=de prevails.
Controller
Lars Becker
Am Sportplatz 23a
38176 Wendeburg
Germany
info@beckerbytegames.com
In short
- No external analytics services, no advertising or tracking scripts, no profiling. Aggregated campaign figures are evaluated on our own server – see “Beta application”.
- No cookies. The sign-in token lives in your browser's local storage, not in a cookie.
- No IP addresses in our database — not for sessions, not for clicks on offers.
- One external script is loaded: Cloudflare's bot protection, and only on the forms it is switched on for – registration, password reset and, when enabled, the beta application.
What is processed
| Account | E-mail address and a password hash (Argon2id). The password itself is never stored and cannot be derived from the hash. |
|---|---|
| Sessions | Per signed-in device: device type, client name, client version, creation and last-access time. No IP address, no full user agent, no fingerprinting data. |
| Watchlist and alerts | The products you saved yourself and the price alerts you created, including their thresholds. |
| Product checks | The link or search term you paste, and the result. What is learned about products is stored permanently and is not personal data. |
| Price observations | Measured prices for offers. Product-related, not personal. |
| Security log | Sign-in attempts as a timestamp with a non-reversible hash of the e-mail address. Kept for 90 days. |
| Usage counters | Event counters under a pseudonym that changes daily. Within a day it is possible to count how often something happened; across days the same person cannot be recognised. That is deliberate and cannot be undone after the fact. |
| Clicks on offers | Counted without any personal reference: shop, network, time. There is no column for an account and none for an IP address. |
| E-mail delivery | Recipient, subject, delivery status and time of messages sent. Transactional mail contains no tracking pixels. |
Beta application
If you apply for the closed beta at /beta, we process what you enter in the application form. An application creates no account, admits nobody and triggers no automatic decision; a person decides about admission.
| Required | Your e-mail address. Without it we cannot invite you. |
|---|---|
| Optional | First name, product categories, condition of the offers you look at, how you compare prices today, the browser you use, whether you are willing to give feedback, and your motivation. Every one of these may be left empty; the application is accepted either way. |
| Where the application came from | If you arrive through a link carrying campaign tags, we store the four
values utm_source, utm_medium,
utm_campaign and utm_content from the
address bar. That tells us which route led to applications. No cookie
is set, no tracking pixel is loaded and nothing is reported back to an
advertising network; the values stay in our own database. Open
/beta without such parameters and the four fields
stay empty. |
| Page views | We count how often /beta is opened – one
number per day, per event and per campaign tag, increased by one.
Individual visits are not stored – only these
daily totals. An entry consists of the date, the kind of event, the
campaign tag and the number itself; there is no column for an IP
address, an identifier, a timestamp or any browser characteristic.
The campaign tag does not come from your address
bar: the server matches the parameters against its own list of known
campaigns and writes only a tag from that list. If nothing matches,
the visit is counted under sonstige (“other”)
and the submitted text is stored nowhere. Here too: no cookie, no pixel, no outside service. Your
browser's user agent is read to leave automated requests uncounted,
and discarded afterwards.
Since 11 September 2026 there is a second event: we count whether the start of the application form came into view at all. That lets us tell a page that is too long from a form that puts people off – without it, any improvement would only tell us that “something” got better. Your browser sends this report, at most once per page view; it contains only the kind of event and the same campaign tag the server gave the page in the first place. Nothing is stored in your browser for it – no cookie, no local storage – and the number goes into the same daily total described above. Reload the page and the count starts over for that view. |
| Not stored | No IP address, no cookie, no browser fingerprint. |
Purpose: receiving, selecting and organising the tester places, and understanding which route applications arrived through.
Legal bases
Draft mapping. Each row names the purpose the basis follows from; the final assessment is still outstanding.
| Account, sessions, watchlist, alerts | Art. 6(1)(b) GDPR — performance of the user agreement. |
|---|---|
| Beta application | Art. 6(1)(b) GDPR — steps taken at your own request before a contract: you ask to be admitted to the test phase. Evaluating the campaign tag rests on Art. 6(1)(f) GDPR — legitimate interest in understanding what the search for testers costs. |
| Price alerts by e-mail | Art. 6(1)(b) GDPR — the notification is the service ordered. |
| Security log, bot protection, rate limiting | Art. 6(1)(f) GDPR — legitimate interest in protection against account takeover and automated abuse. |
| Usage counters | Art. 6(1)(f) GDPR — legitimate interest in operating the service. The daily pseudonym keeps the intrusion at the necessary minimum. |
| Click counting | Art. 6(1)(f) GDPR — evidence for settlement with partner networks, without personal reference. |
Cloudflare bot protection (Turnstile)
On the forms the bot protection is switched on for, your browser loads a
script from challenges.cloudflare.com. Those are
registration and password reset; it can
also be switched on for the beta application at
/beta. While it is off there, no Cloudflare script is
loaded on that page and the form is protected by a honeypot, a timing check
and a daily limit instead. As a
technically unavoidable consequence of that request, Cloudflare learns your
IP address and details about your browser. Without this check, the forms
concerned would stand open to automated requests: accounts could be created in
bulk and strangers' addresses buried in reset mail.
No Cloudflare script is loaded on any other page. Cloudflare Inc. is based
in the USA; the transfer rests on the adequacy decision or an appropriate
safeguard — [REVIEW REQUIRED: name the basis for the third-country
transfer].
Storage in your browser
BuyProof sets no cookies. Two values live in your own browser's storage and are never transmitted to us except as proof of sign-in with a request:
| Sign-in token | localStorage — so you stay signed
in. Removed when you sign out. |
|---|---|
| Invite code | sessionStorage — so the code
survives a switch between sign-in and registration. Gone when the tab
closes. |
Browser extension
The extension reads only the page you click it on. It reads no history, watches no other tabs and transmits no page you did not hand over for checking yourself. What it transmits is product information from the open page and the offers visible there — not your session with that shop.
Recipients
| Hosting | IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. Operates the servers, processing on our behalf under Art. 28 GDPR. |
|---|---|
| E-mail delivery | Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) — confirmation, alert and password-reset messages. Processing on our behalf under Art. 28 GDPR; the data processing agreement forms part of Resend's terms. The transfer to the USA relies on the EU Standard Contractual Clauses contained therein (Art. 46(2)(c) GDPR). |
| Bot protection | Cloudflare — only on the forms with bot protection switched on: registration, password reset and, when enabled, the beta application. See above. |
| Shops and partner networks | When you click an offer, you open the shop's page. We transmit no data about you; what the shop collects follows its own notice. |
No data is sold, and no data is passed to third parties for advertising.
Retention
| Account | until you delete it |
|---|---|
| Sessions | 30 days, then ended automatically |
| Security log | 90 days |
| Delivered e-mail | 30 days |
| Beta applications | 6 months from receipt, then deleted. If an application turns into an account, the account keeps the period named above. |
| Price observations | permanent — product-related, no personal reference |
Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21) and complaint to a supervisory authority (Art. 77).
You can delete your account yourself at any time. Watchlist, alerts and all sessions are removed and your address is deleted from the account. What was learned about products remains — it bears no relation to you.
No tracking
This site loads no external fonts, embeds no analytics and sets no cookies. The only third-party script is the bot protection described above, on the forms it is switched on for. Transactional mail contains no tracking pixels.
We do count how often the closed-beta page /beta is opened: one number per day, per event and per campaign tag, increased by one. Individual visits are not stored – only these daily totals, and the campaign tag is one the server picked from its own list, never text taken from your address bar. There is no column for an IP address, an identifier, a timestamp or any browser characteristic. No cookie, no pixel, no outside service is involved. Your browser’s user agent is read to leave automated requests uncounted, and discarded afterwards.
What is still open
One place remains open and is marked as such rather than filled in silently: the basis for the transfer to Cloudflare. It can only be supplied by the operator, and an invented entry would be worse than a missing one. The hosting provider has been named since 29 August 2026, the data processing agreement with Resend since 20 September 2026. Everything else describes what is actually implemented. Legal review before public launch is outstanding.