Privacy Policy
This Privacy Policy explains how HotEUDeals ("we", "our", "us") collects, uses, and protects information when you use our website at hoteudeals.com, our Android application, and any related services (together, the "Service"). HotEUDeals is operated by HERDO, MB, V. Nageviciaus g. 3, 08237 Vilnius, Lithuania. We act as the data controller for the personal data described below and process it in accordance with the EU General Data Protection Regulation (GDPR).
1. Information We Collect
We are a price-comparison service for Amazon marketplaces and we intentionally collect as little personal data as possible. You do not need to create an account to browse deals.
Information collected automatically when you visit the website or use the Android app:
- IP address (used for rate-limiting, fraud prevention, and approximate country detection)
- Browser type, operating system, device type, and screen size
- Pages or screens viewed, deals clicked, search terms entered, and referring URL
- Date, time, and duration of your visit
- For the Android app: app version and anonymous device identifier used by Firebase App Check to verify the app is authentic
Information you provide directly:
- Email address and message content when you contact us via the contact form or by email
- Preferred market/language selection (stored locally in your browser)
2. How We Use Information
We process your personal data for the following purposes and legal bases:
- To operate the Service — display deals, remember your market preference, serve affiliate links (legal basis: legitimate interest, Art. 6(1)(f) GDPR)
- To secure the Service — prevent abuse, bots, and fraud; validate Android app authenticity via Firebase App Check (legal basis: legitimate interest)
- To analyse usage — understand which deals and categories are popular, in aggregate (legal basis: legitimate interest, or consent where required)
- To respond to enquiries — reply to messages you send us (legal basis: legitimate interest)
- To comply with the law — meet our legal, tax, and regulatory obligations (legal basis: legal obligation, Art. 6(1)(c) GDPR)
We do not sell your personal information. We do not use your data for automated decision-making or profiling that produces legal effects.
3. Cookies and Similar Technologies
We use cookies and similar technologies (local storage, session storage) to make the Service work and to understand how it is used. For detailed information, including a per-cookie list, please see our Cookie Policy.
In short, we use:
- Essential cookies — a session cookie (lifetime: up to 120 minutes) and your stored market/language preference. These cannot be disabled because the Service cannot work without them.
- Analytics cookies — used only if you accept them, to measure traffic in aggregate.
You can refuse non-essential cookies in your browser settings, and you can clear all cookies and local storage at any time.
4. Third Parties We Share Data With
We do not sell or rent your personal data. We do share limited data with the following categories of recipients:
- Amazon EU S.à r.l. — when you click an affiliate link, Amazon receives your IP address, referrer, and our affiliate tag. Your interactions with Amazon are governed by Amazon's own privacy notice.
- Google LLC (Firebase) — the Android app uses Firebase App Check to verify that requests come from a genuine, unmodified app. Firebase receives a device-bound attestation token (not your name, email, or precise location).
- Google Play — distributes the Android app and processes installation and crash data under its own privacy policy.
- Hosting, CDN, and email providers — process data strictly to deliver the Service on our behalf under data-processing agreements.
- Authorities — if required by EU or national law, a valid court order, or to protect our rights.
Some of these providers are based outside the EEA (notably the USA). Where this is the case, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
5. Amazon Affiliate Programme
HotEUDeals participates in the Amazon Associates Programme. When you click an affiliate link and complete a qualifying purchase, we may earn a commission from Amazon at no additional cost to you. Commissions are based on anonymous, aggregated reports from Amazon — we do not see what you buy, when, or for how much.
6. Data Retention
- Server access logs and security logs: up to 90 days
- Aggregated analytics data: up to 26 months
- Contact-form messages and email correspondence: up to 24 months after the matter is closed
- Records we must keep by law (e.g. tax): for the period required by applicable law
After these periods, data is deleted or irreversibly anonymised.
7. Your Rights Under the GDPR
If your data is processed in the EEA, you have the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — have inaccurate data corrected
- Erasure — ask us to delete your data ("right to be forgotten")
- Restriction — ask us to limit processing
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — at any time, where processing is based on consent
- Complain — to your local data protection authority
To exercise any of these rights, email contact@hoteudeals.com. We will respond within one month.
8. Android Application
Our Android app is distributed via Google Play and does not require you to create an account. In addition to the information described above, the app:
- Uses Firebase App Check to prove it is a genuine, unmodified build before it can call our API. The attestation token identifies the app install, not you.
- Does not access your contacts, photos, SMS, microphone, or precise location.
- Stores your market/language preference and cached deal images locally on the device.
- Communicates with our API over HTTPS only.
You can uninstall the app at any time to stop all processing by the app itself.
9. Security
We use HTTPS everywhere, encrypt sensitive data at rest, restrict access to production systems on a need-to-know basis, and keep our software patched. No system is perfectly secure, so we cannot guarantee absolute security — but we will notify users and the competent supervisory authority in the event of a data breach that is likely to result in a risk to your rights.
10. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version is always available on this page, with the "Last updated" date below. Material changes will be announced on the website.
12. Contact
For any question about this Privacy Policy or your personal data, please contact us at contact@hoteudeals.com.
Last updated: April 18, 2026