What we collect

We keep the list short on purpose.

Where your data lives

Your account details, verification records, saved offers, redemption records, and any proof image still waiting in storage live on Cloudflare's infrastructure. We don't run separate application servers or hand this data to another hosting provider.

The apps keep your signed-in session token on your own device using iOS Keychain or Android encrypted storage.

Cloudflare and, when configured as our email fallback, Amazon Web Services process data on our behalf to host the service and deliver transactional email. An email provider receives the destination address and message content needed for delivery.

How you sign in

The Uni Deals doesn't use passwords. When you sign in, we email you a one-time code that expires quickly. Only you can act on it from your inbox, so keeping your email account secure keeps your account with The Uni Deals secure too.

Deleting your account and your data

You're free to leave at any time.

Deleting your account removes your account record, saved offers, verification history, visible redemption history, and any student ID or proof image we still have on file. A pooled discount code that was already assigned may remain marked as used without an active account record so it cannot be issued again. This is permanent, and we can't undo it once it's done.

How long we keep your data

We keep your account, verification, saved-offer, and redemption information while your account is active. An approved proof image is deleted from object storage after the decision. A rejected proof image stays with its verification record until account deletion. If you delete your account, we remove the data described above promptly, except where we must keep limited records by law or keep a used pooled code from being issued again.

Who this is for

The Uni Deals is built for university students in Pakistan aged 16 and over. We don't knowingly collect data from anyone younger, and if we learn that we have, we'll delete it.

If you are a brand using our integrations

The Shopify app, the WooCommerce plugin, and the checkout widget each send us less than a partner portal login does, and none of them sends us anything about your customers as people.

None of these integrations ever sends us a customer's name, email address, or postal address. We don't ask for them, and there is nowhere in any of these integrations to put them.

We prune minted-code records after 90 days. Order records, the small set of fields listed above, are kept for invoicing.

Changes to this policy

If we change how we handle your data, we'll update this page and move the effective date above. We won't make a material change without making it easy to notice.

Contact us

Questions, concerns, or a deletion request that isn't covered above? Email hello@theunideals.com and a person will get back to you.

This policy is governed by the laws of Pakistan.