Skip to content
← Back to home

Privacy Policy

Last updated: 18 July 2026

Grabbit ("we", "us", "our") operates this website and the Grabbit application (collectively, the "Service"). This policy applies whenever you use the Service and explains what information we collect, how we use and share it, and your choices.

Information we collect

  • Account information. If you create an account, Microsoft Entra External ID provides Grabbit with a stable account identifier, display name, email address, and the sign-in provider you use (Google, Apple, Facebook, Microsoft, or email/password). Your password and other credentials are entered on the provider's hosted sign-in page and are not received by Grabbit.
  • Saved deals. Products you save while signed out remain in local storage in that browser or app installation. When you are signed in, saved deals are associated with your account identifier and sent to the Grabbit API so they can sync across devices.
  • Search and filtering. Search words and filters you submit are sent to the Grabbit API to return matching deals. On the website, search terms can appear in the page URL and may be processed in browser history and hosting request logs. The Grabbit API redacts raw query-string values from its Application Insights request telemetry. We do not use your searches for advertising.
  • Price alerts. For signed-in users, we store the product, target or drop price, tracking duration, source listing details, alert status, and per-alert and account-level email notification preferences. We also store your account email so we can send enabled price-alert emails and keep a limited record of each delivery attempt or skip.
  • Website analytics. If an optional privacy-friendly analytics provider is configured and you accept analytics, the website may collect pages visited, browser or device details, and approximate region to understand site usage. The native app does not include separate usage analytics.
  • App diagnostics. The app stores technical logs and a crash breadcrumb on your device, including app version, platform, operating-system version, a per-launch session identifier, and error details. When a non-blank Sentry DSN is configured for a release, the app also sends error and crash events and release-health session data to Sentry, such as stack traces, app version, environment, operating system, device context, and session status. When Sentry is not configured, no app diagnostic data is sent to Sentry.
  • Website and app storage. The website stores your consent choice in browser local storage. Optional cookieless analytics is loaded only after you accept it. The app also uses local databases and secure authentication storage for app functionality; these are not advertising cookies.

How we use your information

  • To operate your account, sync your saved deals, manage price alerts, and send enabled price-alert emails.
  • To operate, maintain, and improve the website and app.
  • To diagnose errors and crashes, including through Sentry only when remote diagnostics is configured.
  • To measure consented, aggregate site usage when optional website analytics is configured.
  • To comply with legal obligations.

We do not sell your personal information, and we do not send marketing emails.

Affiliate links

The Service participates in affiliate programs including Amazon Associates and the eBay Partner Network (EPN). eBay links contain our public EPN campaign identifier and may contain a non-personal customid or SUB-ID that identifies the Grabbit surface or source. When you open an affiliate link, the retailer may use cookies or similar identifiers and may report limited click and transaction information so commissions can be attributed. These parameters do not contain your Grabbit account identifier, email address, or search terms. This does not increase your price. See ourAffiliate Disclosure for details.

Third-party services

  • Netlify: website hosting.
  • Microsoft Azure: Grabbit API hosting, account-data storage, and Azure Communication Services delivery of enabled price-alert emails.
  • Microsoft Entra External ID: account sign-in (email/password and social sign-in via Google, Apple, Facebook, or Microsoft).
  • Sentry: remote app crash reporting and release-health diagnostics, only when a release is configured with a non-blank Sentry DSN.
  • Retailer affiliate programs: Amazon Associates and the eBay Partner Network, which provide affiliate links and commission-attribution reporting under their own privacy notices.
  • Privacy-friendly website analytics: if configured (for example, Cloudflare Web Analytics or Plausible), for consented, cookieless usage statistics.

Each third party processes data under its own privacy policy.

Cookies and consent

The website uses browser local storage to remember your consent choice. If optional Cloudflare Web Analytics or Plausible analytics is configured, its cookieless script loads only after you accept analytics; if you reject, the optional analytics script is not loaded. You can change your choice using the "Cookie settings" link in the website footer or by clearing site data in your browser. eBay and other retailers may set cookies or similar identifiers after you open their site, as described in theeBay Privacy Notice or the applicable retailer privacy policy.

Data retention

Affiliate URLs and their public campaign or reference parameters remain associated with the related source listing while it is in the Grabbit catalog. EPN may retain attribution and transaction information under its own privacy notice and configuration.

We keep app-owned account information, synced saved deals, price alerts, notification preferences, and delivery records while your account is active. You can start deletion from the app's account settings or the website's Delete accountpage. Completing the automated flow removes those app-owned server records and local favorites and permanently deletes the associated Microsoft Entra External ID sign-in profile. The Grabbit API retains a limited deletion record containing your stable account identifier, directory tenant, deletion and retry timestamps, and a short-lived random processing token so a stale sign-in token cannot recreate erased data and an interrupted directory deletion can finish; that record cannot restore your account or favorites. If required for marketplace account-deletion compliance, Grabbit also retains one-way hashes of deleted seller and listing identifiers only to prevent erased marketplace data from being reintroduced; the plaintext identifiers and seller-to-listing association are removed. If deletion of the sign-in profile cannot be confirmed immediately, the flow reports that deletion is incomplete while the API continues retrying automatically, and you can also retry. External sign-in providers may retain their own identity or authorization records under their policies. If you used Sign in with Apple, use the Apple Account settings link shown on the deletion page to revoke Grabbit's Apple authorization manually because the Entra-hosted sign-in flow does not give Grabbit the Apple token required for automatic revocation. On-device app diagnostic log files are configured for 31-day retention, and the crash breadcrumb is consumed after it is reported in the next local log. Diagnostics, email, retailer, and analytics providers may retain information under their own policies and configuration.

Your rights

Depending on your location you may have the right to access, correct, delete, or restrict processing of your personal data, and to withdraw consent. To exercise any of these rights, contact us at arpfh1979@grabbitfast.com.

Children's privacy

The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.

Contact us

Questions about this policy? Emailarpfh1979@grabbitfast.com.

Grabbit may earn a commission on qualifying purchases made through links on this site, including as an Amazon Associate. Prices and availability are pulled from retailers and can change at any time — always confirm the current price on the retailer's site before buying.