Privacy Policy
Last updated: 8 September 2026
1. Scope
This explains what DealsFixers collects when you use dealsfixers.com, why we collect it, and what you can do about it. It covers the website, the mobile app and the escrow service behind them.
2. What we collect
You give us:
- Account details — email address, name, username, mobile number, and your initials for your avatar. The number is stored as you gave it plus the country it belongs to; we do not send a verification code to it, so treat it as a contact number on file rather than a proven one.
- Profile details — country, and (only if you request a business statement) a mailing address.
- Deal content — gig listings, order details, direct messages, and everything written or attached inside a deal room.
- Payment details — the USDT transaction hash of a deposit, and the destination wallet address for a withdrawal. We never ask for, and cannot accept, card or bank details.
- Identity documents — only if we ask you to verify your identity. They are stored privately and are covered in full by the AML & KYC Policy.
We record automatically:
- A last-seen timestamp so other users can see whether you are online.
- Standard server and security logs kept by our hosting provider, which include IP addresses.
- A theme preference in your browser’s local storage, and a language preference in a cookie.
We do not use advertising cookies and we do not run third-party analytics or tracking pixels on the site. The Cookie Policy lists every single thing we store in your browser — there are three.
Since 8 September 2026 a deal room needs a registered account on both sides, which is why we hold a real email address and mobile number for everyone in one. Before that date a room could be opened on a lightweight guest account that collected nothing at all — a placeholder name, an internal address at a domain that receives no mail, and no password. Those accounts still exist where they are attached to an old room, so its history stays readable, but no new one can be created.
Who at DealsFixers can see your details. A moderator running your room sees the room and the people in it by their display names — not your email address or your mobile number. An administrator can open the full details of the two parties to a room when they need to deal with fraud or a dispute, and every one of those views is written to an internal log recording who looked, at whom, and when.
3. Why we use it
- To run your account and let you log in — including two-factor authentication if you enable it.
- To operate escrow: to hold, release, refund and account for money on a deal.
- To let a moderator watch a deal room and resolve a dispute fairly, which requires reading the room’s messages.
- To send you service email — deal notifications, withdrawal updates, and password resets. We do not send marketing email.
- To reach you about a deal you are party to, including on the mobile number on your account if a room needs an answer and email is not getting one.
- To detect fraud and abuse, and to keep records of transactions we have processed.
4. Who else processes it
We keep this list short on purpose — the platform runs on one provider rather than a chain of them. Your data is handled by:
- Cloudflare — effectively all of it. Cloudflare Workers hosts and runs the site, Cloudflare D1 is the database, Cloudflare R2 stores uploaded files (gig images, deal-room attachments and, separately and privately, identity documents), Cloudflare Email Sending delivers our transactional email, and Cloudflare provides the DNS, CDN and routing for mail sent to our address.
- Expo — only if you use the mobile app and turn on push notifications. The push token issued by your phone is passed to Expo's push service so the alert can reach your device.
There is no analytics provider, no advertising network, no third-party email marketing tool and no external fraud-scoring service in the loop. The fonts the site uses are served from our own domain, so loading a page does not call anyone else.
We do not sell your personal data, and we do not share it with advertisers. We will disclose data if we are legally required to, or where it is necessary to investigate fraud or abuse of the service — see the AML & KYC Policy.
5. What other users can see
- Your name, username, initials, country and online status are visible to people you deal with.
- Your email address is not shown to other users.
- Inside a deal room the moderator’s real identity is deliberately hidden from both parties — you see the role, not a personal account.
- Anything you write in a deal room or a direct message is visible to the other party, and to a moderator or administrator watching it or reviewing a dispute.
- Identity documents are never shown to another user and never appear on your profile.
6. How long we keep it
- Account and profile data — until you delete your account. Deleting it removes your profile, credentials, wallet record, gigs, orders, deal-room participation, messages, saved gigs and notifications.
- Deal rooms, orders and messages — retained after a deal closes, because they are the evidence behind an escrow decision and may be needed if a dispute is reopened.
- Transaction records — retained for accounting purposes, and where the law requires us to keep them for a minimum period, for that period.
- Identity documents — retained with their review decision for as long as we may need to evidence the check.
- A business statement you generate stays verifiable through its link until you ask us to revoke it.
7. Your rights
You can view and edit most of your data directly in your profile. You can delete your account from the profile page — this is blocked only while you have an order in progress, a balance in your wallet, or a deposit awaiting review. See Delete your account.
Depending on where you live you may also have the right to request a copy of your data, to have it corrected or erased, or to object to how we use it. Write to support@dealsfixers.com and we will respond.
8. Security
Every request is checked against your session on the server before any record is returned, so one user cannot read another user's wallet, orders or messages. Sessions are opaque random tokens held in a cookie your browser's JavaScript cannot read, and logging out destroys the session on our side rather than merely forgetting it. Passwords are stored only as bcrypt hashes. Login, two-factor and password-reset attempts are rate-limited. Identity documents live in a private storage bucket with no public URL, reachable only through routes that check the caller is one of our reviewers first.
Two-factor authentication is available on every account and we recommend turning it on. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
9. Children
The service is not for anyone under 18 and we do not knowingly collect their data.
10. Changes and contact
If this policy changes, the “last updated” date above will change with it.
Privacy questions or requests: support@dealsfixers.com