FlipFirst
Menu
← Back to FlipFirst

Privacy

What FlipFirst keeps when you use the product.

FlipFirst keeps the account, watch, listing, alert and billing records needed to run your product journey.

01

What you give us

Your account email and the watch rules you save, including the item, area, radius, included or excluded terms and optional maximum price.

02

What we use it for

To keep your watches across sessions, match source records to the correct watch, show alert delivery state and keep paid access aligned with the signed billing record. We do not publish or sell your account details.

03

What a listing record contains

A listing record keeps the named source, original URL when available, asking price, location, observation time and the watch criteria version it matched. FlipFirst does not treat an asking price as a completed sale or profit.

04

What we measure

Where the hosting edge supplies it, PostHog also receives approximate country and city, never GPS coordinates or the visitor IP address in our event payload. Location may be inaccurate. You can mark this browser as internal for one year to distinguish your testing visits; this does not identify a person or apply to other devices.

A random ID for this browser tab helps us count page visits and product actions. When browser measurement is switched on, a separate random cookie recognises return visits for up to 30 days across getflipfirst.com, app.getflipfirst.com and docs.getflipfirst.com. A visit ID groups activity until 30 minutes of inactivity, with a maximum of 24 hours. These IDs do not contain your email. Signing in links accepted product actions to your account; sharing a browser does not merge accounts.

When you open Create watch, we record an account-linked attempt ID. If you save or leave the form, we record the outcome, time taken, failed submissions and clicks on watch setup help. An attempt with no recorded end stays unresolved; it is not treated as abandonment. We do not copy your watch terms into this measurement. Do Not Track and Global Privacy Control requests skip this task record.

For homepage comparisons, a separate random browser ID keeps the same artwork for up to 30 days across our website and app. We record which version was seen and whether a watch was created. The comparison is skipped for browsers marked internal or sending a Do Not Track or Global Privacy Control signal.

Our first-party event ledger is the source of record. When PostHog is configured, the same limited fields are also sent to the selected PostHog region. We do not use PostHog autocapture.

When browser measurement is switched on, this browser sends PostHog page views, named actions, scroll milestones, page performance timings and error reports with email addresses and URL queries removed. Masked replays show page structure and interactions. All text and element attributes are masked; forms, embedded content, images and other marked sensitive elements are blocked. We do not record console logs, network headers or request bodies. Internal and automated browsers, and browsers sending Do Not Track or Global Privacy Control, are excluded. PostHog keeps replays for up to 30 days. Blocked storage or collection can leave gaps in measurement without preventing you from using the product.

05

How we limit abuse

Account, measurement and checkout rate limits use a short-lived one-way hash of your IP address. The original IP address is not stored in those rate-limit tables.

First-party event and task-attempt records older than 90 days are removed by the next applicable event or scheduled maintenance, so removal can happen later if maintenance does not run. PostHog keeps its copy under the retention settings of the configured project.

06

Your choices

Sign out when you have finished on a shared device. Account deletion and data-export controls are not available in the product yet, so do not create an account unless that limitation is acceptable.

Return to FlipFirst