Privacy policy
Last updated: 22 September 2026
This page describes what the DealJE app actually does with your data: what it collects, why, who else handles it, how long it is kept, and how you can see or erase it. The French version is the reference text; this translation says the same thing.
- DealJE is run by an individual, not a company.
- No analytics, no advertising, no trackers.
- Your data is never sold, rented or handed to anyone.
- Other users see your public name, not your real name or your number.
- You can delete your account from the app, immediately.
1. Who is responsible
The data controller is Daniel Laera, Geneva, Switzerland — a private individual, not a company. For any question or request about your data: contact@dealje.cloud.
2. The data we process, and why
Your account
- Phone number. This is your login identifier: you sign in with a code sent by SMS. It is kept for as long as your account exists.
- First name, last name and email address. Asked for at signup, for account integrity (reviews, disputes, support). They are never shown as such to other users.
- Public name. By default "first name + last initial" (for example "Daniel L."), editable in your profile. It is the only name other people see on your profile, your listings and your reviews.
- The date you accepted this policy and the terms of use.
Your listings
- Title, description, price, category, condition, accepted payment method, and whether you are willing to travel.
- The meeting point. Its coordinates are rounded to 3 decimal places (about 110 m) before they are stored: the precise position is never saved. The rounded coordinates, along with the neighbourhood and locality name, are publicly visible on the listing.
- Photos. They are kept in public-read storage: anyone who has a photo's address can open it, with no account and no login. So don't photograph anything you wouldn't want public (number plates, mail, faces…).
- Photo metadata (EXIF). In its current version, the app re-compresses every photo on your phone before uploading it, which strips EXIF metadata, including the GPS position where the picture was taken. This is the app's behaviour, not a server guarantee: the server does not check or clean metadata itself.
Your location
- If you allow it, the app reads your phone's position to show you listings around you and display distances. It is sent to the server with each search to compute those distances, but it is not stored in the database.
- To show your locality's name (for example "Listings near Thônex"), the app asks your operating system's geocoding service — Apple on iPhone, Google on Android — to turn your position into a place name. The same service names the meeting point when you create a listing.
- You can refuse location access: the app still works, with a feed that isn't limited to your area.
Messages and offers
The content of your conversations and the price offers exchanged are stored on our server so both participants keep their history. They are not analysed automatically, and not read, unless that is necessary to handle a report or a legal request.
Your phone number is never displayed to the person you are talking to, nor sent to their app.
Reviews, reports and blocks
- Reviews: the rating and any comment are public, with the author's public name.
- Reports: the reason, the optional detail and the listing concerned are kept for manual review. Nothing is decided automatically.
- Blocks: the list of people you have blocked, used to hide their listings and stop their messages.
Alerts and favourites
Your favourites and your saved searches (keyword, category, area and radius). The centre of an alert's area is also rounded to about 110 m before it is stored. Only you can see this data.
Notifications
If you accept notifications, your phone sends us a device identifier (notification token) and the system type (iOS or Android), used only to tell you about a new message or a listing matching one of your alerts.
3. What is public
Visible to anyone using the app, even without an account: your listings (text, photos, rounded meeting point, locality), your public name, your average rating and number of reviews received, and the reviews themselves.
Never visible to others: your real first and last name, your email, your phone number, your location, your favourites, your alerts, your reports and your blocks.
4. Who else handles your data
We only use the providers the app needs to work. Each one receives only what is described here.
- Hostinger — hosting. The server (database, photos, application) is a virtual private server located in Germany.
- ASPSMS (Switzerland) — sending login SMS. Receives your phone number and the SMS text, which contains your one-time code.
- Firebase Cloud Messaging (Google) — delivering notifications. Receives your device token and, for a message notification, the sender's public name and up to 120 characters of the message. For an alert, the listing's title. On iPhone, the notification is then delivered by Apple's push notification service.
- OpenStreetMap — map tiles. When you view a map, your phone downloads tiles from OpenStreetMap's servers, which therefore see your IP address and the map area you are looking at.
- Apple or Google (geocoding) — as described above, your system's service receives the position to turn into a place name.
Some of these providers may process data outside Switzerland and the European Union, notably in the United States (Google, Apple) and the United Kingdom (OpenStreetMap). These transfers rely on the safeguards provided for by the nFADP and the GDPR, such as standard contractual clauses and the Swiss/EU–US Data Privacy Framework these companies participate in.
5. How we protect your data
- All traffic between the app and the server is encrypted (HTTPS).
- SMS codes: valid for 5 minutes, deleted as soon as they are used, and erased no later than about ten minutes after sending if they are not.
- Sessions: the token that keeps you signed in is stored on the server only as a SHA-256 hash, so a copy of the database would not let anyone sign in as you. On your phone, tokens are kept in the system's secure keychain.
- Server logs: phone numbers are masked (only the last 3 digits remain readable).
6. How long we keep your data
- Account data: for as long as the account exists.
- Listings: an active listing automatically becomes "expired" after 60 days, and stays linked to your account.
- Deleted listing: it disappears from the app and its photos are deleted from storage. Its text stays stored, linked to the conversations about it, until you delete your account.
- SMS codes: a few minutes (see above).
- Session tokens: up to 60 days unused, 1 year at most, then deleted. Signing out revokes them.
- Notification tokens: until the account is deleted, or as soon as Firebase reports them as invalid.
- Database backups are made during maintenance operations and kept on the same server. They may contain data erased since, until they are themselves deleted.
7. Deleting your account
From your profile in the app. Deletion is immediate and irreversible: there is no grace period, and the account cannot be restored.
What is erased
- Your phone number, first name, last name, email and public name.
- The photos of all your listings, deleted from storage. Your listings are removed from the app and no longer visible to anyone.
- The reviews you received.
- Your favourites, alerts, blocks (in both directions) and the reports you filed.
- Your notification tokens, your sessions and any pending SMS code.
What is kept, anonymised
- Your messages: a conversation also belongs to the other person, who keeps their history. Your messages remain in it, signed "Utilisateur" (User).
- The reviews you wrote: they are part of another seller's reputation. They stay visible, signed "Utilisateur".
- Reports filed against you: they are kept (reason, detail, date), attached to the anonymised account, so that deleting and signing up again does not wipe a record of conduct.
- The text of your former listings stays in the database, invisible, attached to the anonymised account, because the conversations that grew out of them depend on it.
- The date on which you had accepted this policy.
Once this data is detached from your name, number and email, nothing in DealJE links it back to you. Your number becomes free for a new signup.
8. Legal basis
DealJE is subject to the Swiss Federal Act on Data Protection (nFADP / nLPD). Because the app can also be used from the European Union (the border region, for instance), we also apply the General Data Protection Regulation (GDPR) where it applies.
- Performance of a contract (Art. 6(1)(b) GDPR): account, login, listings, messages, notifications — what the app cannot work without.
- Consent (Art. 6(1)(a) GDPR): your location and notifications, which you allow in your phone's settings and can withdraw at any time.
- Legitimate interest (Art. 6(1)(f) GDPR): security, abuse prevention, keeping reports and technical logs.
9. Your rights
Under both the nFADP and the GDPR, you can:
- access your data and learn how it is processed;
- correct it — name, email and public name directly in your profile;
- erase it — by deleting your account (section 7) or by writing to us;
- receive it in a common, machine-readable format (portability);
- object to processing based on legitimate interest, or ask for it to be restricted;
- withdraw your consent at any time, without affecting what was done before.
For anything the app doesn't let you do directly, write to contact@dealje.cloud from your account's email address; we will reply within 30 days.
You can also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch, or, if you live in the European Union, with your country's data protection authority (in France, the CNIL).
10. Changes
If the app changes the way it handles your data, this page will be updated and its date changed.