Privacy Policy

Below you will find our Privacy Policy. If you have any questions, please contact us at support@rabatta.app

Data controller and contact information

Rabatta ApS, VAT-no.: 42232939, Kridtsløjfen 6, 2. th., 9000 Aalborg, Denmark, (in the following, Rabatta, we or us) are data controller for processing of your personal data as described in further detail below.

If you have any questions or wish to exercise your individual rights as described further below, please contact us at support@rabatta.app.

PurposeCategories of Personal DataLegal basisRetention periodRecipients and transfers to third countries
RecruitmentIdentification and contact information, general information in CV and job application, references from previous employers and personality tests.When you apply for a job with Rabatta, we obtain references from your previous employers if they are stated in the application or CV pursuant to Article 6(1)(f) GDPR but if they are not listed in the application or CVs, this is done with your prior consent under Article 6(1)(a) GDPR.

Personality tests are occasionally processed, and when they are, they are processed on the basis of our legitimate interests as they do not contain sensitive nor other special categories of personal data and because it is in our legitimate interest to obtain a personality profile of new hires to assess whether they fit the position and the team in which they are to be a part of. Thus processing is carried out on the basis of Article 6(1)(f) GDPR.

Other information in the application, CV, etc. are processed to assess your suitability for the job for which you have applied, prior to the conclusion of a possible employment contract, under Article 6(1)(b) GDPR.
Unsolicited job applications and accompanying material will be deleted after they have been read or no later than 3 months from receipt, unless consent is obtained for longer storage, e.g., in connection with future positions.

Requested applications and accompanying material will be deleted after the recruitment round is completed or no later than 3 months after, unless consent is obtained for longer storage, e.g., in connection with future positions.

If you end up being hired, the result of your personality test will be retained during your employment to ensure that we can create teams that complement each other on strengths and weaknesses. If not, the results of it will be deleted latest 3 months after the end of the recruitment round.

It may be necessary to keep job applications and accompanying material longer than 3 months if, based on the job interview, the correspondence with you or other circumstances, there is a concrete or imminent risk that we will be met with a claim as a result of the application process.
We use Gmail for communication, including in connection to recruitment.

Gmail is part of our Google Workspace suite and is provided by Google Ireland Ltd. Google Workspace is configured so that all data is hosted on Google's servers located within the European Union. However, Google's parent company, Google Inc., is located in the United States, and it is assessed that there is a risk that personal data will be transferred to the United States in connection with law enforcement requests in connection with investigations. Annual reports of requests can be found here: https://transparencyreport.google.com/user-data/overview.
However, since Google Inc. is self-certified under the Data Privacy Framework (DPF), the risk of transfers in this regard is accommodated by Google Inc. ensuring appropriate safeguards in article 45 GDPR.

We also, sometimes, recruit new employees through the LinkedIn job application tool on which case they process your personal data on our behalf. This tool is provided by LinkedIn Corp. who is located in the United States, and thus personal data will be transferred to the United States in connection with the processing of your personal data. However, since LinkedIn is self-certified under the DPF, the transfer is subject to appropriate safeguards under article 45 GDPR.

As for the DPF in general, see the recent ruling in T-553/23, Latombe, where the EU General Court upheld the DPF.
Website visitorsIdentification information, including IP address and event-based behavioural data about the use of our website.

If you interact with our live chat widget (powered by Crisp), we additionally process your email address and phone number (if you provide them), message exchanges, activity status (online/offline), IP address, device type (OS and browser), geographic location (city and country, derived from IP address), preferred language, timezone, and pages accessed.
Data about website visitors, including behavioural data, is processed according to art. 6(1)(f) GDPR because it is our legitimate interest to market our business and because the personal data collected and processed is not sufficiently intrusive that consent is required.

Consent to cookies (Including statistical cookies for PostHog, etc.) is complied with in accordance with the applicable rules in the cookie order, and the processing of personal data through cookies is carried out on the basis of Article 6(1)(a) GDPR. This includes the possible transfer of personal data to third parties specified under the cookie policy. The consent can be withdrawn by following the guide hereto in our cookie policy.

The processing of personal data through the Crisp live chat widget for customer support purposes is based on Article 6(1)(f) GDPR because it is our legitimate interest to provide customer support. Crisp IM SAS, in its capacity as an independent data controller, retains IP addresses for one year to comply with section L34-1(IIa)(3) of the French Postal and Electronic Communications Code, which requires retention of user terminal identification data to assist law enforcement authorities. After that one-year period, IP addresses are retained in aggregated form to protect against botnets and spam. This transfer is carried out on the basis of Article 6(1)(f) GDPR.
Personal data contained in cookies is deleted when the cookie expires or is deleted by you.

We use Google Tag Manager who processed only HTTP request log information, all of which are deleted after 14 days. Other than that, the information processed does not relate to identified or identifiable natural persons. See https://support.google.com/tagmanager/answer/9323295?hl=en.

Data collected via PostHog is retained for up to 7 years for analytical purposes or until consent is withdrawn, after which it is deleted or anonymised.

Chat session cookies set by Crisp expire after 30 days. Other personal data processed through the live chat (e.g., messages, email address, phone number) is retained until deleted upon request.
We use Google Tag Manager for website traffic analysis. This is provided by Google Ireland Ltd. For transfers and risks in relation to its parent company, Google Inc., please see ‘Recruitment’ above.

PostHog Inc. (provider of PostHog, an analytics tool), which we use as a data processor, is self-certified under the DPF. Therefore, we assess that the risks involved with the transfer of personal data to said party is sufficiently accommodated by the data importers ensuring appropriate safeguards in relation to the transfer under article 45 GDPR.

We use Crisp IM SAS as both a data processor (for the live chat and customer messaging platform) and as an independent data controller for IP address retention under French law. Crisp IM SAS is located in France. All data is hosted within the EU: core infrastructure in Amsterdam (Netherlands), and plugin infrastructure in Frankfurt (Germany). No transfer of personal data to third countries takes place.
Activity on or via Rabatta social media sitesFor followers on Rabatta’s social media profiles: profile information, sometimes linking to the follower’s profiles on other social media. For interactions, followers as well as non-followers: nature of interaction and content, for instance comment or instant message.Social media follower and interaction data is processed on the basis of Article 6(1)(f) because you have chosen to follow Rabatta social media channels or interacted with us or our content yourself.Social media interaction and follower data is publicly available and accessed as such, therefore deletion and anonymisation cannot happen unless you choose to delete it.Since we obtain follower and interaction data from the relevant social media service providers, we do not transfer your data to third parties.
Existing suppliers, including external influencers; and new potential B2B customers or suppliers (B2B leads)Contact information, including address and information relating to existing or potential contractual arrangements. Specifically for influencers, photos and videos in which they figure are processed as well.Processing of personal data about suppliers, including photo and video material where external influencers figure, is carried out on the basis of Article 6(1)(f) GDPR because it is our legitimate interest to be able to contact the suppliers and exercise contractual obligations and rights; or (to the extent that they are sole proprietorships or smaller partnerships where personal data about the company is closely linked to the responsible persons) Article 6(1)(b) GDPR to the extent necessary to enter into or fulfil a contract with them.Existing suppliers: Information on suppliers, including influencers, is stored for up to 3 years after the end of the commercial relationship, unless longer storage is necessary, for example according to the rules of the Accounting Act (5 years storage of accounting material after the relevant financial year), or if the information is necessary for a claim that expires later than 3 years. Photo and video material published on social media according under contract with an influencer, however, remains available indefinitely, or until deletion is to be carried out under the contract between Rabatta and the influencer.

B2B leads: Personal data about contact persons at potential customers or suppliers is deleted or anonymised where there has been no contact over one consecutive year.
Communication with suppliers and B2B leads is done via Gmail, and contracts are stored on Google Drive. For potential transfers to Google Ireland Ltd.’s parent company, Google Ltd., please see ‘Recruitment’ above.
Rabatta browser extension and iOS app usersRabatta collects from the Rabatta browser extension a unique device ID (specific to Rabatta), behavioural data, including which websites the user visits, use and evaluation of discount codes and if a purchase has happened (but not what has been purchased), device information and information about your use of Rabatta Points offers, including communication with you in this regard.

From the Rabatta app, the same types of personal data as mentioned above in relation to the browser extension is collected, as well as web shop subscriptions and Apple Vendor or Advertiser ID, as applicable, depending on the user’s privacy settings.

Rabatta receives personal data about you from our affiliate networks, including identification data (typically a unique device ID and/or IP address) and information about your purchases at web shops that is part of that affiliate network.

If you choose to create a Rabatta account (optional, and only required in order to redeem Rabatta Points), we additionally process: your email address (used as login identifier); your marketing consent status (granted or withdrawn) and the timestamp of any consent action; your Rabatta Points balance and accrual history; and your reward redemption history. Transactional data received from affiliate networks is, post-signup, linked to your account via your unique device ID. Behavioural data about your use of the extension and app — already collected as described above — is, post-signup, linked to your account, and where you have given marketing consent, used to personalise marketing emails from selected partners. We also process email engagement data (delivery, open and click events) for emails we send you via our email provider, Resend.

If you interact with our live chat widget (powered by Crisp), we additionally process your email address and phone number (if you provide them), message exchanges, activity status (online/offline), IP address, device type (OS and browser), geographic location (city and country, derived from IP address), preferred language, timezone, and pages accessed.
The processing of personal data necessary for app/extension login, configuration of preferences, redeeming discount codes and using Rabatta Points offers happens on the basis of Article 6(1)(b) GDPR because it is necessary to deliver the services requested by you.

The processing of personal data when app users report and evaluate discount codes is carried out on the basis of our legitimate interests because it is the app users own choice to provide us the information pursuant to Article 6(1)(f) GDPR.

Processing of behavioural data for the purpose of analysing and improving our services (without cross-app tracking consent) and the processing of data from affiliates are also carried out on the basis of legitimate interests, under Article 6(1)(f) GDPR, because the information processed is pseudonymised (no direct identifiers). Rabatta acknowledges that the amount of data collected and processed is highly granular and may paint a detailed picture of you as an individual. However, since Rabatta uses the personal data collected in this connection only to gain insights into the performance of its services, including in particular the extension and app, and to exercise and fulfil its contractual rights towards Rabatta's affiliate networks, and is not otherwise transferred to third parties, Rabatta is of the opinion that your rights and freedoms are sufficiently safeguarded because the data has been pseudonymised to the extent that direct identification is very difficult and because the data is not transferred to third parties for the purpose of direct electronic marketing. The information is also not used for decisions having any kind of impact on you. Finally, Rabatta being a data-based and free platform, it is Rabatta's assessment that such processing may be reasonably expected when signing up and using the service.

Rabatta only transfers to affiliates hashed unique device IDs that are linked to customers in Rabatta's own databases to affiliates. It is neither technically nor contractually reasonably possible for the affiliates to know which customer that hash links to. Therefore, this data is only personal data to Rabatta and not the affiliates. Therefore, the transfer carries little to no risk to the rights and freedoms of the individual customer. Therefore, it is our assessment that our interests are not outweighed by yours and thus the legal basis for the transfer is Article 6(1)(f) GDPR. As for CJ Affiliates and Rakuten, who are located in the US, it is also Rabatta's assessment that the transfer can happen without a separate legal basis for transfer since the data importers are not able to identify the customer.

Provided the user consents to cross-app tracking, we process detailed, individual-level personal data about you for marketing purposes, including transferring said data to Appsflyer who then transfers on the data to third party ad platforms (including Meta, Snap, Google Ads, TikTok, Unity Ads, Apple Search Ads, Appiness, Adivinity, Mobptimal, TheColorad, AscenDad) using your personal data to tailor direct marketing to you individually based on a profile of you. This processing is based on user consent when prompted in the iOS app in accordance with Article 6(1)(a).

In some cases, we transfer identification information to Rabatta Points partners. That is because it is necessary to redeem the discount code or provide the Rabatta Points offer in question and is therefore carried out on the basis of Article 6(1)(b) GDPR.

For Rabatta account users, the processing of personal data necessary for account creation, login, authentication, and the tracking, accrual and redemption of Rabatta Points balances is carried out on the basis of Article 6(1)(b) GDPR, because it is necessary to deliver the Rabatta Points service you have signed up for. Account security notices and other purely transactional emails (e.g. notifications that your Rabatta Points are ready to redeem) are also sent on the basis of Article 6(1)(b) GDPR.

Our welcome email funnel for new account holders is sent on the basis of Article 6(1)(f) GDPR, because it is our legitimate interest to provide reasonably expected onboarding communication that helps you understand and benefit from the service you have just signed up for. The processing is limited in scope and time, and you can opt out at any time via the unsubscribe link in each email.

Marketing emails from selected partners — including emails targeted based on your browsing behaviour — are sent only if you have given your explicit consent at signup via a separate opt-in checkbox, on the basis of Article 6(1)(a) GDPR. You can withdraw your consent at any time, free of charge, via your account settings or via the unsubscribe link in each marketing email. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Note that behavioural data collected via the Rabatta browser extension on Chrome is never used for these marketing emails, in line with Chrome Web Store policies. For users on non-Chrome devices, the behavioural targeting therefore relies only on data collected outside Chrome.

The processing of personal data through the Crisp live chat widget for customer support purposes is based on Article 6(1)(f) GDPR because it is our legitimate interest to provide customer support. Crisp IM SAS, in its capacity as an independent data controller, retains IP addresses for one year to comply with section L34-1(IIa)(3) of the French Postal and Electronic Communications Code, which requires retention of user terminal identification data to assist law enforcement authorities. After that one-year period, IP addresses are retained in aggregated form to protect against botnets and spam. This transfer is carried out on the basis of Article 6(1)(f) GDPR.
User account and activity data, such as login details, discount codes, Rabatta Points offers, items purchased and contact information are kept until you delete your account.

Behavioural data, that is not necessary for the performance of the services requested by the user, are collected on event level and only stored in identifiable form for 6 months until it is aggregated and thus anonymised. Some transaction data need, however, to be validated by the affiliate networks before being usable and thus, those transactions are aggregated (anonymised) 6 months after they have been validated.

Behavioural data, that is necessary for the performance of the services requested by the user, are collected on event level and stored in identifiable form for 7 years until it is aggregated and thus anonymised.

For Rabatta account users, account data (email address, authentication credentials, Rabatta Points balance and accrual/redemption history, and marketing consent status) is retained until you delete your account. We are establishing a procedure for handling inactive accounts, under which accounts inactive for a defined period will be flagged for deletion after a notice has been sent and the user has not reacted or become active again.

Marketing consent and the email address associated with it are kept until the consent is withdrawn. We keep documentation that you have withdrawn your consent for up to 2 years after the consent has been withdrawn, in order to be able to protect ourselves against any claims made for violation of the Danish Marketing Act pursuant to its section 37(3) and section 93(1)(1) of the Danish Penal Code, however only if there is an actual risk that such a claim will be made from the data subject.

Email engagement logs (delivery, open and click events) are retained by Resend for 30 days, after which they are deleted.

Chat session cookies set by Crisp expire after 30 days. Other personal data processed through the live chat (e.g., messages, email address, phone number) is retained until deleted upon request.
Neon, LLC (provider of the database used for extension and app data), is a fully owned subsidiary of Databricks, Inc. Neon is listed as an “Other Covered Entity” under Databricks’ self-certification to the EU-U.S. Data Privacy Framework (DPF). As such, Neon is covered by Databricks’ participation in the DPF.

Cloudflare Inc. (provider of Cloudflare, a web server traffic administration tool), PostHog Inc. (provider of PostHog, an analytics tool) and Functional Software Inc. (provider of Sentry.io, an error reporting tool), are self-certified under the DPF. Therefore, we assess that the risks involved with the transfer of personal data to said parties is sufficiently accommodated by the data importers ensuring appropriate safeguards in relation to the transfer under article 45 GDPR.

Appsflyer Ltd., provider of the Appsflyer software, is located in Israel that, according to an adequacy decision by the EU Commission, ensures adequate safeguards for data protection comparable to the data protection level of the EU.

Resend, Inc. (provider of Resend, the email-sending platform we use for account-related, transactional and marketing emails to logged-in account users), is self-certified under the DPF. Therefore, we assess that the risks involved with the transfer of personal data to said party is sufficiently accommodated by the data importer ensuring appropriate safeguards in relation to the transfer under article 45 GDPR. Resend acts as a sending relay and does not store recipient email addresses beyond what is necessary to deliver the email and report delivery and engagement events.

The data transferred from Rabatta to the affiliate networks in order for us to exercise our rights in the contracts with them is in a form that is non-identifiable to the affiliate networks, thus the transfer carries little to no risk to the rights and freedoms of you.

We use Crisp IM SAS as both a data processor (for the live chat and customer messaging platform) and as an independent data controller for IP address retention under French law. Crisp IM SAS is located in France. All data is hosted within the EU: core infrastructure in Amsterdam (Netherlands), and plugin infrastructure in Frankfurt (Germany). No transfer of personal data to third countries takes place.

Your rights

You have the rights outlined below which you can exercise by contacting us using the details provided above. Your request will be processed free of charge and as quickly as possible, and no later than one month after we receive it, except if the request is complex or you lodge numerous requests, then it may take up to two months.

Rabatta logo footer
Mentions légalesConditions d'utilisationPolitique de confidentialitéImpressumUtilisateurInstaller RabattaNous contacterProfessionnelRabatta pour les entreprisesSuivez-nousTikTokInstagramFacebookLinkedIn
Télécharger Rabatta sur l'App StoreTélécharger Rabatta sur le Chrome Web Store

Copyright © 2026 - All rights reserved. All content of this website is protected under copyright law. Rabatta ApS reserves all rights to the content, including the right to exploit the content for the purposes of text and data mining, in accordance with Section 11b of the Danish Copyright Act and Article 4 of the DSM Directive. This also applies to any API endpoints on this domain. All data accessible via such endpoints is likewise protected, and Rabatta ApS reserves all rights, including the right to prevent data mining.