Skip to content

Privacy Policy

This Privacy Policy explains how OfferTrackr LLC ("OfferTrackr," "we," "us") collects, uses, shares, and protects personal information when you use the OfferTrackr service — the seller iOS app, the website at offertrackr.com, the buyer pages we serve at offertrackr.com/{seller}, and our supporting APIs. Read it alongside our Terms of Use and Cookie Policy.

For the purposes of EU/UK GDPR, OfferTrackr LLC is the data controller for the personal information described in this policy.

1. Information we collect

1.1 Information you give us

  • Account information (sellers): email address, password (stored only as a hash by Amazon Cognito), and display name. Sellers also provide a pickup address and preferred payment methods (e.g., "Cash, Venmo") so buyers know how to pay at pickup.
  • Checkout information (buyers): email address and a payment method passed directly to Stripe — we never see or store your card number or CVV.
  • Listing content: photos, titles, descriptions, asking prices, condition notes, categories, and pickup details you upload as a seller.
  • Messages and offers: bids, offers, and conversation messages between buyers and sellers (including those generated by our AI on a seller's behalf — see Section 3).
  • Acceptance records: when you click I agree, we record the version of the Terms and Privacy Policy you accepted and the server timestamp at which you accepted them. This is the only audit trail we keep of your acceptance.

1.2 Information collected automatically

  • Device and connection data: IP address, browser user agent (web), device model and OS version (mobile), and language preferences.
  • Usage data: the pages and screens you view, buttons you tap, search queries, items you reserve, and how long you spend on each screen. Captured through the cookies and tracking technologies listed in our Cookie Policy.
  • Logs: server-side request logs (URL, status code, timestamp, response time) retained for security, debugging, and abuse prevention.

1.3 Information we derive

  • AI-derived listing metadata: when sellers upload photos, our AI infers attributes (category, condition, suggested price). Sellers can override any of these before publishing.
  • Aggregate analytics: dashboards summarizing traffic, conversion, and reliability — not used to track individual users.

2. How we use information

  • To operate the marketplace — create accounts, publish listings, route bids, deliver messages, complete reservations.
  • To process the $2 platform fee through Stripe.
  • To moderate content (banned-word screening, image safety scanning, LLM policy review, CPSC recall matching). This applies to listings. We do not screen your messages automatically — a conversation is read by a person only when someone reports it, or where we are required to.
  • To run the AI features described in our Terms of Use.
  • To send transactional communications (reservation confirmations, pickup reminders, payment notices) and, with consent, marketing communications.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations, respond to lawful requests, and enforce our Terms.
  • To improve our service through aggregate analytics and product research.

3. AI processing — what goes where

We use third-party AI APIs from OpenAI and Google (Gemini). The specific data we send to each depends on the feature:

  • Listing photo analysis: photos uploaded by sellers are sent to a vision model to generate suggested attributes.
  • AI chat negotiation: the buyer's messages, the item's public listing data, and the seller's negotiation rules are sent to a chat model to generate a response.
  • Content policy review: the listing's text and (where needed) photos are sent to a model for policy classification.
  • CPSC recall matching: listing text is converted into Gemini embeddings to compare against an embedded recall corpus. No personal information is sent for recall matching.
  • Suggested email replies: the inbound email body and the relevant listing context are sent to a chat model to draft a suggested reply for the seller.

We use these AI providers under their API terms and data processing agreements, not their consumer chat products. OpenAI and Google have committed not to use API inputs or outputs to train their consumer models. We do not sell your data to anyone for AI training.

Retention of AI requests. We keep a log of each AI request and its response — including the prompt content described above — for 30 days, encrypted at rest, so we can debug incorrect AI output and investigate abuse. It is deleted automatically after that. Separately, AI negotiation transcripts and help-assistant conversations are deleted 30 days after the conversation ends. Our providers may also retain API requests for a limited period under their own abuse-monitoring terms; see the OpenAI and Google privacy policies for their retention periods.

4. Subprocessors

We use the following service providers (subprocessors) to operate the service:

  • Amazon Web Services — hosting (Lambda, DynamoDB, S3), email (SES), push notifications (SNS), authentication (Cognito). Primary region: US East (Virginia).
  • Stripe, Inc. — payment processing for the $2 platform fee. Stripe is the controller of card-network data; we do not see card numbers.
  • OpenAI, L.L.C. — AI text and vision APIs (see Section 3).
  • Google LLC — Gemini AI APIs (see Section 3).
  • PostHog Inc. — product analytics. On the web this includes session replay on signed-in pages, and no PostHog code loads until you accept the analytics category (see the Cookie Policy). In the iOS app it is limited to event analytics with a device-scoped anonymous identifier: we do not send your account identifier, and session replay is off. Acts as our processor under a data processing agreement.
  • Functional Software, Inc. (Sentry) — error and crash reporting for the website, the iOS app, and our backend. We configure Sentry not to attach user identifiers, IP addresses, or request bodies, and we strip those fields from every report before it is sent. Acts as our processor under a data processing agreement.

We update this list when we change providers. Each provider is contractually bound to use your information only to deliver the service to us.

5. Cookies and similar technologies

See our Cookie Policy for the full list of cookies and local-storage entries we set, including the PostHog analytics cookies that you can accept or reject from the consent banner.

6. How we share information

  • With other users. Your listings, display name, and pickup location are visible to buyers. Messages you send (including AI responses sent on your behalf as a seller) are visible to the other party in the conversation.
  • With our subprocessors as described in Section 4.
  • For legal compliance. We may disclose information to comply with valid legal process or to protect the rights, property, or safety of OfferTrackr, our users, or others.
  • In a business transfer. If we are acquired or merged, your information may transfer to the successor entity. We will notify you (and you may exercise your rights under Sections 9–11) if the new controller intends to use your data in a materially different way.
  • With your consent for anything else.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are used under the CCPA/CPRA.

7. Data retention

  • Account data: retained while your account is active.
  • Listings, bids, and reservations: retained while needed to operate the marketplace and for a reasonable period thereafter for dispute resolution, accounting, and legal compliance.
  • Acceptance records: retained for as long as we may need to demonstrate the version of the Terms you accepted.
  • Messages between buyers and sellers: retained while the conversation exists. They are deleted when the conversation is deleted, or when either participant deletes their account — there is no automatic expiry, because a conversation is the record of how a sale was agreed.
  • AI negotiation transcripts and help-assistant conversations: 30 days, then deleted automatically by DynamoDB TTL.
  • AI request logs: 30 days, encrypted at rest — see Section 3.
  • Notification history: a 30-day rolling window, after which entries are deleted automatically by DynamoDB TTL.
  • Server logs: 30 days in production, then deleted automatically.
  • Deleted accounts: when you delete your account we hold it for a 14-day grace period — during which you can restore it by signing in — and then erase it. Erasure completes well inside the 30 days we promise below. Some records (financial records for tax purposes, abuse-prevention signals, or material required by legal hold) may be retained longer, and records with two parties are anonymized rather than deleted so the other person keeps their own copy of the transaction.

8. Your choices and controls

  • Profile: update your account information from the in-app account settings.
  • Marketing email: use the unsubscribe link in any marketing message, or update your preferences in the app.
  • Push notifications: control through your device's settings.
  • Cookies: use the consent banner or the Cookie Preferences link in the page footer.
  • Account deletion: from the in-app account settings, which triggers our deletion flow.

9. GDPR — EEA, UK, and Swiss users

If you are in the European Economic Area, the United Kingdom, or Switzerland, the following rights and information apply to you. OfferTrackr LLC is the data controller. Contact us at privacy@offertrackr.com with any GDPR question.

9.1 Lawful bases

We rely on different lawful bases depending on the processing:

  • Performance of a contract (Art. 6(1)(b)) — to create your account, publish your listings, process reservations, charge the $2 fee, and deliver service-related communications.
  • Consent (Art. 6(1)(a)) — for non-essential cookies, marketing email, and any optional feature the app asks you to enable.
  • Legitimate interests (Art. 6(1)(f)) — for fraud prevention, security, abuse detection, content moderation, internal analytics on aggregate usage, and limited product improvement. We balance these interests against your rights and you can object as described in Section 9.3.
  • Legal obligation (Art. 6(1)(c)) — to comply with applicable law and respond to lawful requests.

9.2 International transfers

Our infrastructure is hosted in the United States (primary region: AWS US East). When we transfer your personal information out of the EEA, UK, or Switzerland to the United States or to a subprocessor listed in Section 4, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures such as encryption in transit and at rest. You can request a copy of our SCCs by emailing privacy@offertrackr.com.

9.3 Your rights

Subject to applicable conditions, you have the right to:

  • request access to the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request erasure of your data ("right to be forgotten");
  • request restriction of processing;
  • object to processing based on our legitimate interests, including direct marketing;
  • request portability of data you provided to us, in a structured, machine-readable format;
  • withdraw consent at any time where we rely on consent (without affecting prior processing);
  • not be subject to a solely automated decision that produces legal or similarly significant effects without human review. Our content-moderation pipeline includes both automated decisions and a human-review queue; you can request human review of a moderation outcome by emailing support@offertrackr.com. Decisions about messages and accounts are made by a person, not automatically.

To exercise any right, email privacy@offertrackr.com or use the account-deletion flow in the app. We may need to verify your identity. We will respond within 30 days; if we need more time, we will tell you.

9.4 Supervisory authority

You have the right to complain to your local data-protection authority. We have not yet appointed an EU/UK Article 27 representative; if you need one, contact us at privacy@offertrackr.com and we will support your request.

10. California, Colorado, and other US state rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another US state with a comprehensive privacy statute, you have the right to:

  • know what personal information we collect, the categories of sources, the purposes of processing, and the categories of recipients;
  • request access to and a copy of the personal information we hold about you;
  • request correction of inaccurate personal information;
  • request deletion of your personal information;
  • opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising);
  • limit the use of sensitive personal information (we do not use sensitive personal information to infer characteristics about you);
  • not be discriminated against for exercising any of these rights.

To exercise these rights, email privacy@offertrackr.com. You may use an authorized agent. We may need to verify your identity. We do not charge a fee for the first request in a 12-month period.

11. Children

OfferTrackr is for users 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, email privacy@offertrackr.com and we will delete it.

12. Security

We protect your information with TLS 1.2 or better in transit and encryption at rest under a customer-managed key that we control, covering our databases, file storage, queues, and secrets. Access is limited by scoped IAM permissions, administrative interfaces require multi-factor authentication, and changes to our infrastructure are recorded in an access log with alerting on sensitive events. Passwords are hashed by Amazon Cognito and never visible to us. We support multi-factor authentication for sellers. No system is 100% secure, and we cannot guarantee absolute security.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change we will update the "Last updated" date and, where required, give notice and obtain consent. Your continued use of the service after the effective date constitutes acceptance of the updated policy.

14. Contact

  • Privacy questions and data-subject requests: privacy@offertrackr.com
  • General support: support@offertrackr.com
  • Postal: OfferTrackr LLC, 18970 Bryant Rd, Lake Oswego, OR 97034, USA