You have 1 free trial analysis. · Register for free to unlock more full reports.Register
Back to home

Privacy Policy

Last revision: 14 May 2026

This Privacy Policy describes how Deal Rating (the “Site” or the “Service”) collects and processes the personal data of its users, pursuant to Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended.

1. Data Controller

The data controller is Deal Rating (titolare in fase di formalizzazione), with registered office at Lecce (LE), Italia. For any privacy request, please contact: info@dealrating.it.

2. Data Protection Officer (DPO)

Non designato (operatore di piccole dimensioni — art. 37 GDPR non applicabile)

3. Categories of data processed

The Site processes the following categories of personal data:

  • Identification and contact data: name, surname, email and profile picture provided by Google through the “Continue with Google” sign-in flow.
  • Navigation data: IP address, hashed IP for anonymous rate-limiting, user-agent, pages visited, request timestamps.
  • Service data: URLs and/or text of real-estate listings submitted by the user for analysis, AI-generated reports (score, economic analysis, risks, estimates), saved shortlists.
  • Payment data: handled entirely by Stripe Payments Europe Limited. The Site stores only the transaction ID, amount, currency, status and Stripe customer ID — never raw card data.
  • Paywall and quota telemetry: number of reports generated, remaining credits, Premium subscription expiry.
  • Technical cookies and, subject to consent, third-party analytics cookies.

4. Purposes and legal basis

We process your data for the following purposes:

  • Service provision (listing analysis, report generation, account management, shortlist): art. 6(1)(b) GDPR — performance of a contract.
  • Payment management and tax compliance: art. 6(1)(b) and (c) GDPR.
  • Security, abuse prevention, IP-hash rate-limiting: art. 6(1)(f) GDPR — legitimate interest in protecting the Service.
  • Anonymous statistics and product improvement via Google Analytics 4 and PostHog: art. 6(1)(a) GDPR — consent, granted through the cookie banner.
  • Service communications (e.g., payment confirmations, subscription expiry notices): art. 6(1)(b) GDPR.

5. Means of processing

Processing is performed with electronic tools hosted on Emergent cloud infrastructure (United States) and MongoDB. Adequate technical and organisational measures are in place (HTTPS/TLS encryption in transit, access controls, data minimisation, HttpOnly signed session cookies).

6. Recipients and processors

Your data may be shared with the following parties, designated as processors under art. 28 GDPR or acting as autonomous controllers for their respective services:

  • Google LLC / Google Ireland Limited — authentication (OAuth), Google Analytics 4.
  • Anthropic PBC — provider of the Claude language model used to generate reports (receives only the listing text, no user identifiers).
  • Stripe Payments Europe Limited — payment processing.
  • Firecrawl Inc. — automated extraction of listing content from submitted URLs.
  • Emergent Inc. — hosting and authentication infrastructure provider.
  • PostHog, Inc. — product analytics and session replay (enabled only after explicit consent).
  • Public authorities and courts, where required by law.

7. International transfers

Some processors above are based in the United States (Anthropic, Stripe US, Firecrawl, Emergent, PostHog, Google). Transfers occur under Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) and, where applicable, under the EU-US Data Privacy Framework.

8. Retention period

  • User account data: for the duration of the relationship and up to 24 months from the last login, unless deletion is requested earlier.
  • Listing analyses and shortlists: tied to the account until deletion; for guest users, max 12 months.
  • Payment and invoicing data: 10 years as required by Italian tax law (art. 2220 c.c.).
  • Scraping telemetry and IP hashes: 30 days (rolling TTL).
  • Analytics cookies: max 13 months (Italian DPA guidelines).

9. Your rights

Under articles 15-22 GDPR you have the right, at any time, to:

  • Access your personal data and obtain a copy;
  • Request rectification or update of inaccurate data;
  • Request erasure (“right to be forgotten”);
  • Request restriction of processing;
  • Object to processing based on legitimate interest;
  • Exercise the right to data portability;
  • Withdraw consent given for analytics at any time (manage from the banner or Privacy page);
  • Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

To exercise your rights, please write to info@dealrating.it. We will respond within 30 days.

10. Cookies

The Site uses the following cookie categories:

  • Technical session cookies: handle user navigation and keep the session active between pages.
  • Authentication cookies: keep the user logged-in after sign-in with Google, avoiding repeated credential entry.
  • Load-balancing cookies: distribute traffic across servers to keep the site fast and reliable.
  • Limited personalisation cookies: store the selected language (it/en) and the analytics consent state.
  • Third-party analytics cookies (Google Analytics 4 with IP anonymisation; PostHog): enabled only after explicit consent via the cookie banner.

Technical, authentication, load-balancing and limited-personalisation cookies do NOT require consent under Italian DPA decision no. 231/2021: they are strictly necessary to provide the Service requested by the user. For third-party analytics cookies you can change your choice any time from the “Manage your consent” section at the bottom of this page.

11. Profiling and automated decisions

The “Deal Score” shown in reports is generated automatically by an AI model from public listing data. It is informational only, does not constitute professional advice, and produces no legal effects on the user — so it is not profiling under art. 22 GDPR. You may request clarification on the scoring logic at any time by contacting the controller.

12. Changes to this policy

This Policy may be updated to reflect legal or operational changes. The current version is always available at this URL; users are encouraged to consult it periodically. Material changes will be prominently notified on the Site’s home page.

Manage your consent

Analytics cookies

You can grant or revoke your consent for third-party analytics cookies (Google Analytics 4 and PostHog) at any time.

Current state: Not set yet
Quick start

Paste a listing link

Copy the URL of any real-estate listing you found online and paste it here. You'll get a full report: deal score, rental yield estimate, regulatory risks.