Legal
Privacy Policy
Last updated: July 17, 2026
This policy explains what information dipd collects when you use our service, how we use it, and the choices you have. We've tried to keep it short and plain. If anything is unclear, email contact@dipd.ai.
Who we are
dipd is a price-tracking service that watches product pages on your behalf and emails you when prices drop. “dipd”, “we”, “us”, and “our” refer to the team operating dipd.ai. You can reach us at contact@dipd.ai.
Information we collect
Account information
When you sign up with email we collect your email address and a password. The password is hashed before storage; we never see or store the plaintext.
If you sign in with Google or Sign in with Apple instead, we receive your name, your email address, and an account identifier from the provider, and we store those. No password exists for such accounts unless you later set one. If you use Apple's Hide My Email, the relay address Apple creates is treated like any other email address.
Product tracking data
When you ask us to track a product, we store the URL you submit and the data we extract from that page on each check: title, price, image, and a snapshot or screenshot of the page used by our AI to read the price.
Approximate location
When you sign in, we derive a two-letter country code from your IP address, either from a network-level country header where available or by looking the IP up with the ipinfo.io service. We store only the resulting country code (plus a country-center map point used for regional defaults, such as which store region to check). We never derive or store your precise location. This data is erased if you delete your account.
Usage data
We log basic activity needed to operate the service: when scrapes run, when alerts go out, when you sign in, your tier, and your notification preferences. We do not run advertising or cross-site tracking.
How we use information
- To check prices on the products you ask us to track.
- To email you when a price drops below the threshold you set.
- To manage your account, subscription, and preferences.
- To secure the service, including bot protection on sign-up and sign-in forms, and to detect and prevent abuse (e.g. excessive tracking that would hurt the source sites we scrape).
- To improve dipd over time.
We do not sell your personal data and we do not share it with advertisers.
Legal bases for processing
For users in the EU/EEA and UK, we rely on the following bases under the GDPR:
- Performance of a contract: running the tracking, sending alerts, and managing your account.
- Legitimate interests: preventing abuse, keeping the service secure and reliable, measuring aggregate usage, and improving dipd. We balance these against your privacy and only use what we need.
- Consent: where we ask for it explicitly (for example, optional marketing email). You can withdraw consent at any time.
Third-party services we use
dipd runs on a small set of services that necessarily process data on our behalf:
- Railway: hosting for our application, database, and background-job queue, with our primary region in the EU.
- Resend: sends the transactional emails (price alerts, account verification) from alerts@dipd.ai.
- Google Gemini: reads the snapshots/screenshots of product pages to extract prices. We send only the page content; we do not send your account information. Google does not use paid Gemini API content to train its models.
- Google and Apple: if you choose to sign in with them, they act as your identity provider under their own privacy policies.
- Cloudflare Turnstile: bot protection on our sign-up, sign-in, password-reset, and newsletter forms. It processes your IP address and browser signals to tell humans and bots apart.
- PostHog: product analytics across our marketing site, interactive demo, and the web app, configured cookieless (it stores nothing on your device); hosted in the European Union. While you are signed in, usage events are linked to your account ID so we can see which features get used; we do not send your email address or name to PostHog, and we do not record your screen.
- Sentry: error monitoring for our servers; error reports can include request metadata such as IP addresses for a short period.
- ipinfo.io: the IP-to-country lookup described under “Approximate location”.
- Page-fetching providers: infrastructure partners that retrieve some product pages on our behalf. They receive the product URLs being checked, never your account information.
Each provider processes data under its standard data-processing terms.
Screenshots, captures, and thumbnails
The screenshots we take are of public product pages (visited by an automated browser with no logged-in session). They are not recordings of you; they are bot captures of the same page anyone would see. We retain them as evidence for the price we showed you and to retry extraction if it failed the first time.
We may also keep a reduced-size copy (thumbnail) of a product's public image so we can display it reliably, since some stores block direct image embedding. Thumbnails are stored and served from our own infrastructure and contain no personal data.
Browser extension
The dipd Chrome extension is optional. When you click Trackon a product page, the extension sends only that page's URL to dipd; our servers then fetch the product's title, price, and image. It does not send the page's contents, does not read pages you haven't asked it to track, and does not collect your browsing history. It authenticates with the same dipd-token cookie used by the web app, and never injects UI into the pages you visit.
Mobile app
The dipd mobile app talks to the same API as the web app and uses the same account. It lets you view your tracked products and add new ones with a single tap via your device's share sheet; the URL you share is the only thing the app sends to dipd. Signing in with Google or Apple uses the provider's on-device SDK; the resulting sign-in token is all that reaches our servers. We do not read your clipboard, contacts, device location, or other apps (your approximate country is derived server-side from your IP, as described above).
Security
All traffic to and from dipd is encrypted in transit (HTTPS). Account passwords are stored as one-way hashes. Our database and backups are encrypted at rest by our hosting provider. Access to production data is limited to the people who need it to operate the service.
Data retention and deletion
We keep your account data while your account is active. You can delete your account at any time from your dashboard. When you do:
- Your email, password hash, and social sign-in identifiers are removed.
- Your tracked-product list, notifications, and preferences are removed, along with our record of the alert emails we sent you and your stored country/location data.
- Anonymized product, price, and run history may be retained to power the service (e.g. so price history on a popular product stays useful for everyone); these no longer reference you.
We may retain specific data for longer where the law requires it, or where it is reasonably needed to resolve disputes or enforce our terms.
Your rights
If you are in the EU/EEA, the UK, or another jurisdiction with equivalent rights, you can ask us to:
- Show you what data we hold about you.
- Correct anything that's wrong.
- Delete your account and the data associated with it.
- Export your data in a portable format.
- Stop using your data for a particular purpose.
- Lodge a complaint with your local data-protection authority (in the UK, the ICO; in the EU/EEA, your national supervisory authority).
Email contact@dipd.ai from the address on your account (so we can verify the request is really yours) and we'll respond within 30 days.
Children
dipd is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has signed up, email us and we'll delete the account.
International data transfers
Our providers operate in both the EU and the United States. For example, hosting runs in the EU; analytics, AI processing, and IP lookups run in the US. Your data may be processed in either region. Where personal data leaves the EU/EEA, we rely on safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where a provider is certified, the EU–US Data Privacy Framework.
Changes to this policy
If we change this policy we'll update the date above. For changes that materially affect you, we'll give notice by email or in the product before they take effect. Continuing to use dipd after a change takes effect means you accept the updated policy.
Contact
Questions, complaints, or data requests: contact@dipd.ai.