Settings

Privacy Policy

Last updated: 2026-08-24

Who We Are

Raddel is a deal-discovery service that lets you swipe through product deals sourced from third-party marketplaces, available as a web application and as a Telegram Mini App (together, the Service). The data controller is Giovanni Mantovani, operating Raddel as a private individual, reachable at support@raddel.com. This policy is written to satisfy the EU/UK General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDP Act), and comprehensive US state privacy laws such as the California CCPA/CPRA.

Information We Collect

An account can exist in three forms. When you first open Raddel — even if the first page you visit is this policy — we create an anonymous account and session for you, identified by a random ID, together with a country (inferred from the page language until you confirm one) and a display language; this is what lets you swipe without registering, and anonymous use is limited to a lifetime number of swipes (currently five) before you are asked to register. If you register, we also collect your email address and password (or, if you sign up with Google, the email address Google shares with us), your country and your language, together with a record of your acceptance of the Terms and of your confirmation that you meet the minimum registration age; passwords are stored only as salted hashes. If you use Raddel inside Telegram, your anonymous session is converted in place after we validate Telegram's signed launch data, and we store only your numeric Telegram user and chat IDs under a synthetic, non-deliverable internal address; your Telegram name, username and photo are discarded and never stored; your language code is used only to choose the app and reply language and is not stored itself. As you use the Service we record your swipe actions (buy, pass, save — an undone swipe or unsaved deal is marked inactive but the record is kept), the deals shown to you each day, the content sources you enable or disable, and the affiliate links you open (an internal log readable only by our administrators). If you enable push notifications we store the delivery endpoint and encryption keys issued by your browser (at most 20 active devices per account) and a log of sends — event type, channel, delivery status and retry attempts. If you join the waiting list for a country we have not opened yet, we store the email address you provided and the time of your request. If you confirm access to age-restricted content, we record that answer (see “Age and Restricted Content” below). If your first visit reaches us through an advertising link (for example a Google Ads or Meta ad), we also store on your account which advertising network, campaign and landing page brought you here, so we can measure which of our advertising works; arriving any other way stores nothing, and your account simply counts as organic.

What We Do Not Collect

We use no third-party analytics or tracking SDKs of any kind — no session replay, no advertising pixels, no data shared with advertising networks; the only acquisition measurement is the first-party ad-attribution record described above. The application itself does not log IP addresses or browser user-agent strings; our authentication service does record the IP address and browser signature of each sign-in session, kept for the life of that session for security purposes and deleted with it. Our hosting providers additionally keep standard, short-lived infrastructure logs under their own policies, and our own application logs may briefly capture limited technical identifiers for debugging; neither is used as a system of record. We never store your Telegram name, username or photo, we hold no payment data, we do not read your device's location (your country is self-declared), and we collect no special categories of data such as health, biometric or political information.

How We Use Your Information

We use this information to run the Service: to build your deal feed, remember your preferences and saved deals, open the correct marketplace links for your country, and keep your session working — processing that rests on the performance of our contract with you. Two uses rest on your consent instead, and you can withdraw either at any time: the one-time waiting-list email telling you Raddel has opened in your country, and the optional deal-reminder notifications, which stay off unless you turn them on in Settings. Reminders involve a limited form of profiling — we identify accounts with no activity for roughly three to four days — with no legal or similarly significant effect and no automated decision about your access. Aggregate statistics visible only to administrators help us improve the Service (legitimate interest), and records of your Terms acceptance and of your age and restricted-content declarations are kept to meet our legal obligations. We do not sell your personal information and we do not use it for third-party advertising.

Cookies and Local Storage

We use cookies and similar storage: mostly our own, set and read only by us, plus marketing cookies from Google and Meta that are used only with your consent (described at the end of this section). Ours are: the session cookies that keep you signed in (set with SameSite=None, Secure and Partitioned so the Service can work inside Telegram's cross-site frame), the NEXT_LOCALE cookie remembering your language, a raddel-theme entry in local storage remembering light or dark mode, a short-lived session-storage entry carrying Telegram launch data (cleared when the tab closes), and local-storage entries remembering whether you installed the app (raddel:installed-here), the deals you saved while trying the demo (raddel:demo-saved:v1) and your answer to the advertising-cookie question below (raddel:attr-consent:v1, raddel:cookie-consent:v1). In addition — only when your first visit reaches us through an advertising link, and only if you agree when we ask — we set a raddel_attr cookie recording which advertising network, campaign and landing page brought you here, kept for at most 90 days and removed once that information has been stored on your registered account. If you decline, no such cookie is set and only your refusal is remembered on this device; we keep a record of the time and content of your agreement, as the law requires. If you allow marketing cookies, Google and Meta each set their own cookies on this device to measure how well our advertising works; only those two companies can read those particular cookies. If you decline, Meta's pixel is not loaded at all and Google's tag runs in a cookieless mode that stores nothing on your device and carries no identifier. Beyond this, no third party can read our cookies, and nothing they contain is shared with anyone. We also keep an entry on this device (raddel:ads-conv:v1) noting that your registration has already been reported once, so it is not counted twice.

Third-Party Links

Our Service contains affiliate links to third-party marketplaces such as Amazon and AliExpress. When you open a deal, your browser navigates directly to the marketplace (for deals in the Indian market, via our affiliate partner Cuelinks) in a new tab with the noopener and noreferrer protections, and we transmit none of your personal data with that click — the site you land on sees only what your browser normally sends to any website, and applies its own privacy policy. We separately keep an internal, administrator-only record that a click occurred; this log is not visible to you in the app. We earn a commission on qualifying purchases at no additional cost to you.

Service Providers

A small number of providers process data on our behalf and under our instructions: Supabase (database, authentication and storage), Vercel (application hosting), and Resend (sending the emails described in this policy). If you enable push notifications, delivery goes through your browser vendor's push service (for example Google, Mozilla or Apple), which receives an encrypted payload. Telegram processes your use of the Mini App and our bot messages under its own policy, and the marketplaces you open — and, for Indian-market deals, Cuelinks — are independent services with their own privacy policies. The providers we use to ingest deals (for example RapidAPI for Amazon data, the AliExpress open platform and Bright Data for Flipkart) only fetch public product listings and never receive any of your personal data. Product images are re-hosted on our own storage (or come from Unsplash), so displaying deals does not make your browser contact a marketplace.

International Data Transfers

Our providers may process and store data outside your home country, including in the European Union and the United States. Where personal data leaves the EEA, the UK or another region with transfer restrictions, we rely on recognised mechanisms such as adequacy decisions and Standard Contractual Clauses through our processors' compliance programmes. You can ask us for details about the safeguards that apply to your data using the contact below.

Data Retention

We retain your account data, preferences and interaction history for as long as your account exists, and we run no automatic deletion: undone swipes and unsaved deals are marked inactive but kept, and the only recurring cleanup is the removal or replacement of dead push subscriptions. Deleting your account removes your data immediately (see “Account Deletion” below). One narrow record survives deletion, because the law permits keeping what is necessary for the defence of legal claims: a minimal proof that you accepted the Terms — the time, the version accepted and the place of acceptance — kept under a pseudonymous identifier with no email address or other contact data attached.

Age and Restricted Content

Raddel is for adults: creating an account requires confirming by self-declaration that you are at least 18, on every registration path. Some content sources belong to regulated categories (currently gambling-related and trading-related offers). In countries where such content is age-restricted, we show it only after you confirm by self-declaration that you may view it; in countries where it is not permitted, we do not show it at all. Your answer is recorded with your user identifier, the content category, the decision you took, the country selected at the time, and a timestamp. We do not record IP addresses or device information with these declarations.

Retention of These Declarations

Your age confirmation and your restricted-content answers are kept for as long as your account exists, so you are not asked again, and they are deleted together with your account when you delete it in Settings. A year of birth declared on an account created before we introduced the age confirmation is kept and deleted on the same terms.

Where This Applies

Whether a regulated category is age-restricted or not permitted in your country is determined by a per-country catalogue we maintain for each category, based on the rules of the countries where the Service is offered. Today this applies to gambling-related and trading-related sources; the catalogue is updated as sources and countries are added.

Your Rights in the EU and UK

If you are in the EU or the UK, you have the right to access, rectify, erase and receive a portable copy of your personal data, to restrict or object to certain processing, to withdraw consent at any time without affecting what was lawfully done before (for the waiting-list email and deal reminders, directly in Settings or through the unsubscribe link in the email itself), and to lodge a complaint with your supervisory authority. We do not yet offer a self-service data export; if you request a copy, we will provide it manually within a reasonable time after verifying your identity.

Your Rights in India

If you are in India, the DPDP Act gives you the right to obtain a summary of the personal data we process about you, to correct, complete, update or erase it, to nominate another person to exercise your rights in the event of death or incapacity, and to withdraw consent at any time. Our Grievance Officer is Giovanni Mantovani, reachable at support@raddel.com; if your grievance is not resolved, you may escalate it to the Data Protection Board of India.

Your Rights in the United States

If you live in a US state with a comprehensive privacy law (such as California, Colorado, Connecticut or Virginia), you have the right to know and access the personal information we hold about you, to correct or delete it, to opt out of its sale or sharing, and not to be discriminated against for exercising these rights, with an appeal where your state provides one. We do not sell personal information for money and we do not share it for cross-context behavioural advertising — we run no ad-tech integrations at all — and we honour Global Privacy Control signals as a valid opt-out where the law requires it, even though there is currently nothing to opt out of.

Children

Raddel is not directed at children: creating an account requires confirming by self-declaration that you are at least 18. We do not knowingly collect personal data from anyone under that age. If you believe a person under 18 has created an account, contact us using the details below and we will address it, including deletion where the law requires.

Security and Data Breaches

We rely on our infrastructure providers' security controls — encryption in transit and at rest, access controls, and passwords stored only as salted hashes — to protect your data. No system is completely secure and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will assess it and, where the law requires, notify the competent authority (within 72 hours under the GDPR) and affected users without undue delay.

Account Deletion

You can permanently delete a registered account from the Settings page by typing the confirmation word. Deletion is immediate and synchronous, with no grace period and no undo: your swipe history (including undone swipes) is removed, and your user record is deleted, which cascades to your profile, Telegram identifiers, click log, feed state, push subscriptions, notification history, channel preferences and sessions. Anonymous sessions have no self-service delete — contact us to have anonymous data removed. Two limits apply: our providers' routine backups may retain deleted data until they age out, and data already passed to third parties — a click already forwarded to a marketplace, a Telegram message already delivered — cannot be recalled. The one record we keep after deletion is described under “Data Retention”.

Changes to This Policy

We may update this policy from time to time. If we make material changes, we will update the date at the top and, where the law requires, give you additional notice in the app or by email.

Contact Us

For any question about this policy or to exercise any of the rights above, contact Giovanni Mantovani at support@raddel.com. A postal address is not yet published; please contact us by email in the meantime. Depending on where you live, you can also contact your data-protection supervisory authority (EU/UK), the Data Protection Board of India, or your state Attorney General (US).