Legal document
DealNoty Privacy Policy
This Policy describes how DealNoty processes the personal data of merchants using the Service and the data merchants record about their customers. It is written in plain language and grounded in the technical detail of the product as verified during the audit of 14 August 2026.
- Version
- 1.0.0
- Effective date
- 14 August 2026
- Last updated
- 14 August 2026
Identity of the data controller
DealNoty is a mobile application and a service operated by the entity identified in the "Contact" section. Throughout this document, "DealNoty", "we" and the "Controller" refer to that entity.
When this Policy uses the term "the merchant", it refers to the natural or legal person who registers with DealNoty to keep the records of their business. When it uses "the merchant’s customer" or "their customers", it refers to the natural persons about whom the merchant records information within DealNoty.
Scope of this Policy
This Policy describes the personal-data processing carried out by DealNoty in connection with:
- the DealNoty mobile application for iOS and Android;
- the website https://dealnoty.com (the "Site");
- the public account-deletion page available at https://dealnoty.com/delete-account and its localized variants;
- the synchronization, storage, support and customer-care services associated with the above.
DealNoty is not directed at minors. The Service is intended for adult merchants. We do not knowingly collect personal data from minors. If you believe we have received data from a minor, please write to the privacy address listed in the "Contact" section so that we may delete it.
Our role regarding the data you record
DealNoty processes two main categories of personal data and our role differs for each. This distinction determines who is responsible for responding to data-subject requests.
Merchant account data and device data. DealNoty acts as data controller. DealNoty determines the purposes and means of the processing of this data. This category includes the merchant’s email address, password, name, account identifier, device identifier, device data and the payment information derived from the app store.
Data the merchant records about customers. DealNoty acts as data processor. The merchant is the controller: the merchant decides what data is recorded, on what legal basis, and who responds to the customer when the customer requests the exercise of rights. DealNoty processes this data only on behalf of the merchant, in accordance with the purposes of the Service described in this Policy and in the Terms and Conditions.
Categories of personal data we process
DealNoty processes only the data necessary to provide the Service described in the Terms and Conditions. The categories actually processed are described below, grouped by purpose.
4.1 Merchant account data
Email address, used as a sign-in identifier, as the destination for one-time verification codes, and as the channel for operational communications (identity verification, security alerts, account recovery, deletion confirmation).
Name displayed by the merchant in their profile within the application, and the business name, description and phone number the merchant voluntarily registers.
Password, processed exclusively as an irreversible cryptographic digest (bcrypt algorithm) on our servers. The mobile application does not store the password on disk; it holds it briefly in memory only during the sign-in or password-change process.
Account identifier (an internal numeric id) and a synchronization identifier (UUID v4) used to keep the data consistent across the merchant’s devices.
Backup or recovery token, an alphanumeric code the merchant can use to link an additional device. This token is stored encrypted on our servers and, when delivered to the merchant, is sent by email. The merchant is responsible for keeping it in a safe place.
Google identifier, only when the merchant signs in with Google. The mobile application does not request or store a Google refresh token; it receives a single-use "id_token" that our servers verify against Google.
Subscription status, platform (Google Play or App Store), purchase identifier issued by the app store, start, renewal and cancellation dates, and a payment history limited to the purchase identifier.
4.2 Data the merchant records about their customers
Customer name and phone number, voluntarily registered by the merchant.
Values entered by the merchant in the custom fields they define (for example, address, email, notes). These fields are defined by the merchant and may contain any data the merchant decides to record.
Notes, sales, service orders and products the merchant records, with their amounts, dates, quantities, descriptions, statuses and other operational attributes.
Photographs, images only (no video), that the merchant associates with a product, a customer, their business profile, a note or a service order.
Files and documents, such as PDF, TXT or CSV, that the merchant voluntarily attaches to their records.
DealNoty does not use this data for advertising, does not sell it and does not share it with third parties for their own purposes.
4.3 Device data
Device model, operating system, configured language, and a device identifier (a UUID v4 generated by the application on first launch). The application-generated identifier is transmitted to our servers only at the time of first device registration; thereafter the numeric identifier DealNoty assigns to the device is used.
Device session state (active or revoked), date and time of the last access, and a cryptographic digest (SHA-256) of the device session token.
A simultaneous cap of up to ten (10) devices linked per account.
4.4 Technical and diagnostic data
Crash and error logs from the application, sent to an error-monitoring service operated by an external provider (Sentry, operated by Functional Software, Inc., based in the United States). These logs contain the error message, the stack trace and the context of the operation in progress. They do not contain the content of your notes, sales, products, customers, passwords, tokens or email addresses.
IP address of the device, recorded in the verification-codes table during the verification process (for example, when signing in, changing the password or requesting account deletion). This IP address is retained for thirty (30) days and deleted automatically.
IP address of the device, included in the security emails DealNoty sends the merchant when signing in from a new device or when changing the password. These emails are part of the account’s security log and, once delivered to the mail provider, cannot be recalled.
4.5 Payment and billing data
4.6 Data DealNoty does NOT process
DealNoty does not process the following categories of data:
- Precise location data (GPS, coordinates, altitude).
- Geolocation data derived from the IP address.
- The device’s contact list.
- SMS or MMS messages, call logs, contents of the merchant’s email.
- Voice recordings, music files or other audio files.
- Health, fitness or biometric data.
- Device calendar events.
- Other applications installed on the device.
- Web browsing history (when using the mobile application).
- Device advertising identifiers (IDFA, AAID).
- Payment data or financial information beyond the purchase identifier issued by the app store.
DealNoty does not sell personal data, does not engage in targeted advertising, does not use cross-app tracking, does not build profiles for marketing purposes and does not make automated decisions with legal effects on the merchant or their customers.
Purposes of the processing
DealNoty processes the personal data described in section 4 for the following purposes:
- Provision of the Service. Creating and maintaining the merchant account, authenticating the user, synchronizing data across linked devices, storing the merchant’s notes, sales, products, customers and other records, enabling data export and responding to support requests.
- Security and fraud prevention. Verifying the merchant’s identity on sensitive operations (password change, account recovery, account deletion, sign-in from a new device), detecting unauthorized access, notifying the merchant of sensitive activity in their account, and protecting the infrastructure.
- User care and support. Responding to the merchant’s queries and requests, diagnosing and resolving technical issues, and managing post-deletion feedback when the merchant voluntarily provides it.
- Compliance with legal obligations. Retaining data that applicable laws require us to retain, and responding to lawful requests from competent authorities.
- Improvement of the Service. Analysing errors and operational metrics from the crash reports sent to Sentry, in order to detect and fix application defects.
DealNoty does not use personal data for marketing, advertising, profiling, data sale or any other commercial purpose beyond those listed above.
Legal bases
DealNoty processes personal data on the following legal bases, as applicable:
- Performance of the contract for the provision of the Service entered into with the merchant upon acceptance of the Terms and Conditions. This basis covers the processing of account data, synchronization across devices, subscription billing through the app store, and user support.
- Legitimate interest of DealNoty in maintaining the security of the platform, preventing fraud, detecting and correcting errors, and protecting the integrity of the Service. This legitimate interest is balanced on a case-by-case basis and, where appropriate, measures are applied to minimise the impact on the privacy of the merchant and their customers.
- Consent where required, particularly for processing that is not necessary for the performance of the contract. When consent is required, DealNoty will request it in advance, in a specific and informed manner, and the merchant may revoke it at any time without affecting the lawfulness of the prior processing.
- Compliance with legal obligations when an applicable law requires DealNoty to retain or disclose certain data, or to respond to requests from competent authorities.
For the specific case of data the merchant records about customers, the legal basis for the processing must be determined by the merchant themselves, in their capacity as controller. DealNoty, as data processor, processes this data only on behalf of the merchant and in accordance with the instructions the Service enables the merchant to give.
Account deletion
A detailed description of what data is destroyed, what is retained, what is delayed and how to request deletion is set out in section 12. The operational summary is:
- The merchant may request deletion at any time from within the mobile application or by visiting https://dealnoty.com/delete-account (or its localized variants).
- The process requires the account password and a one-time eight (8) digit code sent to the associated email, with a five (5) minute lifetime.
- If the account was created only with Google and no password was ever set, DealNoty will ask the merchant to set a password from within the mobile application before continuing.
- After confirmation, DealNoty performs the destruction of the data in a single transactional operation, retains the amounts, dates, quantities and statuses of the sales notes in anonymised form, and retains the records of linked devices marked as revoked until the other devices receive the deletion notification.
International transfers
Some of the service providers listed in the "Third-party service providers" section may process personal data in countries other than the merchant’s country of residence. In particular, diagnostic reports from the mobile application are sent to Sentry, transactional emails are sent through Resend, the perimeter network infrastructure relies on Cloudflare, and when the merchant uses Google Sign-In, validation of the "id_token" takes place against Google services — all of which may process data in the United States of America or other regions.
These transfers are carried out under the safeguards required by applicable law. Where the law so requires, DealNoty will enter into the agreements and, where applicable, the standard contractual clauses necessary to guarantee a level of protection equivalent to that required by the law of the merchant’s country of residence.
Third-party service providers
DealNoty shares personal data with the following service providers, to the extent necessary for the provision of the Service:
- Sentry (Functional Software, Inc., United States of America). Error monitoring service. DealNoty configures Sentry not to include personally identifiable data in the reports.
- Resend (Resend, Inc., United States of America). Transactional email service (verification codes, security alerts, deletion confirmation).
- Cloudflare (Cloudflare, Inc., United States of America). Content delivery network and perimeter protection service.
- Google (Google LLC, United States of America). Authentication service, used only when the merchant chooses to sign in with Google. DealNoty receives from Google a single-use "id_token" and a public account identifier.
- Apple and Google, regarding subscription billing through the App Store and Google Play, respectively.
DealNoty does not sell personal data, does not disclose it to third parties for their own purposes, does not use it for targeted advertising, and does not build profiles for commercial purposes.
Rights of the merchant
The merchant may exercise, in the terms provided by applicable law, the rights described below. To do so, write to the privacy address listed in the "Contact" section. DealNoty will respond within the time limits set by applicable law and, where appropriate, will request additional information needed to confirm the requester’s identity.
- Access. Obtain confirmation of whether DealNoty processes the merchant’s personal data and, if so, access that data.
- Rectification. Request the correction of inaccurate or incomplete personal data.
- Cancellation or erasure. Request the erasure of personal data, on the terms described in section 12.
- Objection to processing. Object to processing based on legitimate interest, on grounds relating to the merchant’s particular situation.
- Restriction of processing. Request the restriction of processing in the cases provided by law.
- Portability. Receive the personal data the merchant has provided to DealNoty, in a structured, commonly used and machine-readable format, and transmit it to another controller where technically possible.
- Withdrawal of consent. Withdraw any consent given, where the processing is based on consent, without affecting the lawfulness of the prior processing.
- Complaint to the supervisory authority. File a complaint with the data-protection authority competent in the merchant’s jurisdiction.
For merchants resident in Mexico, these rights correspond to the ARCO rights (Access, Rectification, Cancellation and Opposition) provided by the Federal Law on Protection of Personal Data Held by Private Parties and its Regulations. The data controller is the entity identified in the "Contact" section, and the department in charge of responding to requests is reachable through the privacy address listed in that same section.
Encryption and security measures
11.1 Encryption in transit
Communications between the mobile application, the Site and DealNoty servers take place over HTTPS. DealNoty does not use certificate pinning in the current version of the mobile application.
11.2 Encryption at rest on DealNoty servers
DealNoty encrypts at rest, on its servers, the following categories of data: the merchant’s backup token and the Google refresh token, using AES-256-CBC; one-time verification codes and the email digest for deleted accounts, using HMAC-SHA-256 with an independent secret; per-device session tokens, using SHA-256; and passwords, using bcrypt. The main encryption key is unique per environment and managed as an operational secret.
11.3 Encryption at rest on the device
Data retention
DealNoty retains personal data for as long as necessary to fulfil the purposes described in this Policy and, thereafter, for as long as required by applicable law. The specific periods, verified against the current implementation of the Service, are:
| Category | Retention period | Justification |
|---|---|---|
| Merchant account data | Until the account is deleted | Necessary to provide the Service while the account is active |
| Data of the merchant’s customers | Until the account is deleted | The merchant may edit or delete it at any time from the application |
| One-time verification codes and associated IP address | 30 days | Privacy-critical table with daily cleanup |
| Outgoing sync queue (pending changes) | Until sent and acknowledged by the server, with an operational cap of 30 days | Required for retries on disconnections |
| Synchronised change feed | 90 days, with monthly cleanup; data of deleted accounts is removed regardless of age | Required so a device that was offline can reproduce the state |
| Sync operations log | 180 days, with monthly cleanup | Technical diagnostics; no content of notes, sales, products or customers |
| Orphan file folders in storage | 15 days, with weekly cleanup | Operational margin for newly uploaded files with no associated row |
| Anonymous or guest accounts never associated with an email | 90 days from last activity | Accounts never claimed by a merchant |
| Cancelled subscriptions | Until the account is deleted | Required to reflect the payment history to the merchant |
| Application logs | 14 days on disk, rotated | Operational diagnostics |
| Database backups | The Service does not run automated backups; responsibility lies with the infrastructure provider | Continuity of the Service |
| IP addresses included in already-delivered security emails | Until the merchant deletes them from the inbox or until the account is deleted, whichever occurs first | Once delivered, the email cannot be recalled |
Data of the merchant’s customers
DealNoty processes the personal data the merchant records about their customers in the capacity of data processor. The merchant is responsible for:
- Obtaining, where applicable, the consent or relying on the appropriate legal basis for processing their customers’ data.
- Informing their customers about the processing of their personal data in the terms required by applicable law.
- Responding to their customers’ requests regarding the exercise of rights over their personal data.
- Not using the Service to process special categories of data (for example, health data, data on religious or philosophical beliefs, data on sexual orientation, biometric data, data of minors) for which the Service is not designed.
DealNoty provides the merchant, from within the application, with the tools necessary to access, correct, export and delete the data of each of their customers, so that the merchant can respond to their customers’ requests without needing to contact DealNoty.
Minors
DealNoty is not directed at minors and is not designed to process the personal data of minors. DealNoty does not knowingly collect personal data from minors. If the operator of the Service identifies that data of a minor has been registered, it will be deleted. If you believe we have received personal data of a minor, please write to the privacy address listed in the "Contact" section.
Cookies and tracking technologies on the Site
The Site https://dealnoty.com does not use tracking cookies, does not use tracking pixels, does not integrate web analytics services and does not include third-party content that can track the visitor. The Site only uses the browser’s local storage to remember the visitor’s language preference and theme preference (light or dark). This local storage is not transmitted to DealNoty or to third parties.
To the extent that the Site incorporates cookies or tracking technologies in the future, DealNoty will update this section and, where required by applicable law, will request the visitor’s prior consent.
Changes to this Privacy Policy
DealNoty may modify this Privacy Policy to reflect, among other things, changes in the Service, in applicable law or in industry practices. Where the changes are material, DealNoty will notify the merchant through the available contact channels, with reasonable advance notice before the changes take effect. The updated version will indicate the date of its last update at the top of this document.
The merchant is deemed to accept the modified Privacy Policy if they continue to use the Service after the effective date of the updated version. If the merchant does not agree with the changes, they may request the deletion of their account on the terms described in this Policy.
Contact
For any matter relating to this Privacy Policy, the processing of your personal data or the exercise of your rights, you can contact DealNoty at:
- Privacy and support email: support@dealnoty.com
- Business inquiries email: hello@dealnoty.com
- Data controller: Edain Jesús Cortez Cerón
- Country of operation: México
For security matters, please use the support channel and include the word "Security" in the subject line.
This Privacy Policy is published free of charge and is available on the Site, in the merchant support section, and in the mobile application menu. It is valid in its version in force from the date indicated at the top of this document.