Brickheist

Privacy policy

Last updated: August 24, 2026

What data we collect

Brickheist collects only what's needed to run the site and provide you with a usable account.

  • Account — email address, hashed password (if you set one), verification status, optional marketing consent, and an optional display name used in mail salutations.
  • Social-login identities — if you sign in via Google or Facebook, we store the provider's user ID and the email + name they return. We never receive or store your social password. You can unlink any provider under Account → Connected accounts.
  • Sessions — IP address and user-agent at login, session token cookie.
  • Affiliate clicks — server-side log entry per click (timestamp + product, IP stored only as a salted hash), no personal data, no third-party cookies.
  • Analytics — anonymised, aggregated page views via Google Analytics 4 (Consent Mode v2, IP anonymisation). Only sent after you give consent in the consent message.

Where your data lives

  • Postgres database — Hetzner Cloud, Falkenstein, Germany (EU).
  • Email delivery — Brevo (sendinblue.com), France (EU). Used to send verification mails, password resets, and (if you opt in) deal alerts. Brevo signs an EU-standard DPA and processes only what's needed to deliver the email.
  • Analytics — Google Analytics 4. Aggregated data only; no personal identifiers.

How long we keep it

  • Account — until you delete it.
  • Active sessions — until you sign out, or 30 days of inactivity.
  • Server logs — 90 days, then auto-rotated.
  • Affiliate clicks — 24 months for commission reconciliation.

Your rights

Under GDPR you can exercise the following rights from your account page (or by emailing us):

  • Access — download a JSON export of everything we hold about you under Account → Download your data.
  • Rectification — change name, email, password, or marketing consent under Account.
  • Deletion — wipe your account and all associated data under Account → Delete account. Confirmation email sent.
  • Objection / Withdrawal — turn off marketing emails any time under Account → Email preferences.
  • Portability — the data export is in machine-readable JSON.
  • Complaint — you can lodge a complaint with the Danish Data Protection Authority (Datatilsynet).

Cookies

Brickheist collects your consent for analytics and advertising via Google's certified consent platform (IAB TCF v2.2), shown on your first visit. Your choice is stored in a cookie (FCCDCF) on brickheist.com.

  • Necessary — session, CSRF, the consent choice itself. Affiliate-click logging is server-side and anonymous (hashed IP, no personal data, no client cookie).
  • Search history — first-party heist_recent_searches cookie (1 year) remembers your recent searches so they can be shown in the search field. Only set if you turn on "Save search history" in the search field yourself; contains only your search terms and can be cleared via "Clear history" or turned off again in the same place. Stored on your account instead when signed in.
  • Analytics — Google Analytics 4 with Consent Mode v2 and anonymised IP. Sends no data until you give consent in the consent message. Opt-in.
  • Advertising — Google AdSense. Without consent, non-personalised ads are shown without cookies; with your consent in the consent message, Google and partners may set cookies for personalisation.

You can change or withdraw your consent anytime via the in the footer — it opens Google's consent message again.

Affiliate links

Brickheist earns a commission when you click through to a retailer and complete a purchase. This does not affect the price you pay. Click logging happens server-side and is anonymous (hashed IP, no personal data).

Contact

Questions about your data? Email hello@brickheist.com — we reply within 5 working days.