f.fazadeals
UAENRU
Back to offers

Privacy

Version: 2026-09-20-draft-3

Draft document: sales have not started yet. Service provider details and final terms must be filled in before payments are enabled.

This draft describes current technical processing and planned payments. The data controller, request contact and final retention periods are still to be specified. Payments are disabled.

1. Who is responsible

Data controller: [full legal business name or sole trader’s name]. Address: [to be supplied]. Data-protection contact: [to be supplied]. The Faza Deals brand name alone does not replace these details.

2. Browser and cart data

The service uses a random browser-session identifier, your selected language and cart contents. The cart is stored on the server and linked to the session.

We do not ask you to create an account or enter an email address or phone number to browse the catalogue. If you later choose to send information to support, it will be processed to respond and resolve your request.

Recovery stores the secret code’s hash, version, order and granted browser sessions. The plain code is not stored in the database or sent in a URL. An order number alone does not grant access.

3. Order and payment data

When payments are enabled, the service will store the order number, selected offers, amount, currency, time, payment identifier and status, and a snapshot of the source information at the time of the order.

Card details are entered on monobank’s page. Faza Deals does not receive or store the full card number, CVV or banking password. The payment provider processes data under its own terms.

4. Why data is used

Data is needed to operate the cart, remember your chosen language, verify payment, provide purchased access, and handle support and refunds.

Hosting logs may contain an IP address, request time, browser information and errors. They support site operation and security. Advertising tracking and analytics trackers are not currently installed.

Faza has separate 1–5 scores for offer usefulness and communication with the seller. Only buyers of information access can rate; this does not verify a hardware purchase. Seller raters additionally self-confirm contact. We store the score, subject, qualifying order and timestamps. Each buyer has one score per subject, which can be edited or deleted. Public summaries show averages and counts without buyer names. Scores are excluded after a refund is recorded; payment-status checks are not instantaneous.

5. Grounds and recipients

Processing is limited to data needed for your request or contract, the provider’s legal duties, and protection of the service where permitted by law. Marketing consent is not a condition of use.

Hosting and server-database suppliers are involved in processing; the payment provider will also be involved once payments open. Before launch, the provider must identify their legal entities, processing locations and the applicable safeguards for any international transfers.

6. Retention

The session cookie and cookie-choice record have a browser lifetime of up to 365 days. The language cookie has the same lifetime and is set only after you enable the optional remember-language setting. You may delete cookies earlier. Their lifetime does not determine server-record retention.

A cart that has not yet become an order expires after 30 days of inactivity. Its previous contents are no longer used after expiry. This rule does not apply to locked-in orders or paid accesses.

Snapshots of purchased offers are preserved with the order to support purchased access. The provider must still approve final retention periods for orders, payment confirmations, support requests, logs and backups, taking account of legal duties. This draft does not promise automatic deletion of these records on an unspecified schedule.

7. Your requests

You may ask what data about you is processed, request access, seek correction of inaccurate data or deletion where legal grounds exist, and object to unlawful processing. Where processing relies on consent, you may withdraw it.

Request contact: [to be supplied before launch]. Finding an order may require its number and evidence that it belongs to you. Do not send a CVV, banking password or full card details. You may also contact the Ukrainian Parliament Commissioner for Human Rights or a court.

8. Protection and updates

The session cookie uses HttpOnly and SameSite=Lax. A recovery code is a secret granting access to one order only. Do not publish it or send it to a seller. Replacing it in the original browser revokes access restored with the previous code.

Before adding accounts, mailing lists, analytics or new suppliers, this notice must be updated and separate consent obtained where required. The final version will state its effective date.