Privacy Policy

Your data, your trust. Here's exactly how we handle it.

Last updated: 17 April 2026 (v2.0)

Information We Collect

Account Info

Name, email address, and password (hashed and salted). Basic information to identify your account.

Channel Data

Telegram channel IDs and platform tokens you provide for publishing deals to your channels.

Affiliate Data

Affiliate account credentials (encrypted at rest), commission earnings, and payout details.

Usage & Device

Click analytics, IP addresses, browser type, and device identifiers used for fraud detection.

How We Use Your Information

Operate the DealZap platform and deliver our services

Generate and track affiliate links on your behalf

Detect and prevent click fraud using IP analysis, device fingerprinting, velocity checks, and geo-anomaly detection

Calculate and process your affiliate commission earnings

Improve our AI deal scoring and recommendation algorithms

Send transactional emails such as account verification, earnings reports, and alerts

Data Protection

We implement industry-standard security measures to keep your data safe:

AES-256

Affiliate credentials encrypted at rest

TLS 1.3

All data protected in transit

Audit Log

Fraud logs maintained for full transparency

Snapshot

Immutable commission ledger entries

Data Sharing

We never sell your personal data. Sharing occurs only in these cases:

Affiliate Networks: Click and conversion data shared with Cuelinks, Amazon Associates as required for commission tracking.

Payment Processors: Payout information shared to facilitate earnings withdrawal to your bank account.

Legal Obligations: When required by law, regulation, or valid legal process under Indian jurisdiction.

Cookies

We use essential cookies for authentication and session management, and analytics cookies to understand how the platform is used. For full details on each cookie, its purpose, and expiry, see our Cookie Policy.

Your Rights (DPDPA 2023 / DPDP Rules 2025)

Under the Digital Personal Data Protection Act 2023 and DPDP Rules 2025, you have the following rights. To exercise any right, email [email protected].

Access

Obtain a summary of the personal data we process about you

Correction

Request correction of inaccurate or incomplete personal data

Erasure

Request deletion of your account and associated personal data (subject to retention obligations)

Withdraw Consent

Withdraw consent for data processing at any time without affecting prior processing

Nomination

Nominate another individual to exercise rights on your behalf in the event of death or incapacity

Grievance Redressal

Lodge a complaint with us first; if unresolved, approach the Data Protection Board of India (DPB)

DPB India contact: dpb.gov.in

Data Retention

Active

Account data

Retained while your account is active

12 months

Click & fraud logs

Retained for audit and dispute resolution

7 years

Commission records

Required by Income Tax Act, Section 149

8 years

PAN & bank details

Retention from last TDS deduction per Section 149 IT Act; required by Razorpay/Cashfree audit obligations

Upon account deletion, personal data is removed within 30 days subject to statutory retention obligations. Anonymized analytics may be retained for platform improvement.

Verification Processors

When you submit KYC information, we use the following DPDP-registered data processors:

Cashfree Payments India Pvt Ltd

PAN verification via NSDL. Your PAN number and name are transmitted to Cashfree to confirm identity against the National Securities Depository Limited database.

Razorpay Software Pvt Ltd

Bank account validation (penny-drop) and payout processing. Your bank account details are transmitted to Razorpay to confirm account ownership via NPCI.

Security Breach Notification (DPDP Rules 2025)

In the event of a personal data breach, DealZap will notify the Data Protection Board of India and affected users within 72 hours of becoming aware of the breach, with a detailed incident report. We maintain an immutable audit log and evidence hashes for all consent events to support breach investigation.

Questions about your privacy or to exercise your rights?

[email protected]

(Data Protection Officer — also reachable at [email protected])