Data safety
This notice reflects the tracking, notification, security, and retention controls implemented by Vouchercode.
When you search or open an offer, we may record the search text, offer and merchant identifiers, timestamps, referral and campaign fields, browser user-agent, a visitor or session identifier, and a salted hash of the network address. Affiliate providers may send order and commission references required to confirm attribution. We do not store affiliate webhook secrets or raw signing credentials in event logs.
We use this data to deliver redirects, prevent replay and abuse, measure offer performance, reconcile affiliate commissions, honor communication preferences, diagnose failures, and maintain security audit records. We do not sell raw tracking or authentication data.
Expired sessions are removed after 30 days and webhook replay guards after 7 days. Search queries are removed after 90 days. PostgreSQL click records and analytics are anonymized after 90 days; anonymized analytics are removed after 400 days. Notification payload details are redacted after 90 days and terminal notification records after 400 days. Secure email preference links expire after 30 days; old expired or revoked token hashes are removed under the 365-day preference-token retention policy. Audit network addresses are removed after 90 days while security audit records may be retained for up to seven years. Raw ClickHouse click logs expire automatically after two years.
You can use the communication-preference link in a message to opt out. You may also request access, correction, or deletion where applicable. Financial, fraud-prevention, and security records may be retained when legally or operationally required. Contact the site operator through the published support channel for a privacy request.
Effective date: July 26, 2026.