Skip to content
Directly

Privacy policy / Datenschutzerklärung

This policy explains how Directly processes personal data under the EU General Data Protection Regulation (GDPR) and the German TDDDG. Short version: no account, no ads, no cross-site tracking, analytics only with your consent.

1. Controller (Art. 13(1)(a) GDPR)

Directly, , , Germany · . A data protection officer is not required (fewer than 20 people regularly process personal data, § 38 BDSG).

2. What we process, why, and on what legal basis

  • Website delivery and security — IP address, time, requested URL, browser type in server and proxy logs, kept for up to 7 days to deliver pages, prevent abuse and enforce rate limits. Art. 6(1)(f) GDPR (legitimate interest in a secure, working service).
  • Product checks — the product link or Amazon product ID you submit, and the results we compute. Art. 6(1)(b) GDPR (providing the service you request). Product data is not personal data; we do not link it to your identity.
  • Product statistics — per day we count how often each product was checked, whether a cheaper offer was found, and the country the check came from (derived by our CDN, Cloudflare, from the IP address; we never receive or store the IP for this). No device ID, browser data or time of day is stored, so these counts cannot be linked to a person and are not personal data. We use them to see which products and shops are popular.
  • Outbound clicks — when you click a result we log which result was clicked (and, only with consent, your random device ID). Needed to reconcile affiliate commissions. Art. 6(1)(f) GDPR.
  • Anonymous usage analytics (opt-in) — a random device ID stored in your browser and events such as "result viewed". Only after you click "Allow analytics". Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw consent at any time: .
  • Browser extension — runs only on Amazon product pages (and on other shops only when you press the toolbar button). It sends the product ID/link to Directly when you click "Check". Settings, a random device ID and your last 10 checks are stored locally in the extension.

3. Storage on your device (§ 25 TDDDG)

We do not use cookies. We use your browser's local storage for: your consent choice and the "swap the domain" hint (strictly necessary, § 25(2) Nr. 2 TDDDG), an offline copy of the app shell (service worker, strictly necessary), and — only with consent — a random device ID for analytics.

4. Recipients and processors (Art. 28 GDPR)

  • Cloudflare, Inc. (DNS, TLS, DDoS protection, Cloudflare Tunnel) — processes IP addresses and request metadata. Data may be processed in the USA; Cloudflare is certified under the EU-US Data Privacy Framework and we have a Data Processing Addendum with Standard Contractual Clauses.
  • Hosting — our servers are operated by us (or our hosting provider under a DPA).
  • PostHog (EU cloud, only if analytics consent is given) and Sentry (error reports, with IP addresses removed) — if enabled.
  • Product data providers (e.g. Amazon Product Advertising API, AliExpress, SerpAPI) receive the product being checked, never your identity.
  • Shops and affiliate networks — when you click a link, you leave Directly. The shop and, for affiliate links, the network (e.g. Amazon Associates, AliExpress Portals, Awin, Impact, Skimlinks) may set their own cookies under their own privacy policies.

5. Retention

  • Server/proxy logs: up to 7 days.
  • Fetched product pages: 30 days.
  • Cached results: up to 6 hours.
  • Pseudonymous analytics and click logs: 13 months; device IDs are removed from click logs after that.
  • Aggregated statistics without personal data: indefinitely.

6. Your rights (Art. 15–22 GDPR)

You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future. Send requests to ; for device-ID data, include the ID shown in your browser's local storage (key directly.deviceId).

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), e.g. the data protection supervisory authority of your federal state (e.g. BfDI / LfDI).

7. No automated decisions, no profiling

Ranking of results is automated but concerns products, not you. We do not make decisions with legal effect about you (Art. 22 GDPR) and do not build profiles. See how ranking works.

8. Obligation to provide data

You are not obliged to provide personal data. Without an IP connection the website cannot be delivered.

Last updated: 2026-09-26

Privacy policy / Datenschutzerklärung · Directly