AhaFind
Privacy
This page describes personal information the current AhaFind application handles. Later features may change this. It will be reviewed again before a commercial launch.
Draft for review before a commercial launch. This page describes the current product. It is not legal advice and it is not a claim that AhaFind meets any particular law.
Last updated: October 5, 2026
Account and sign-in
Creating an account uses an email address and a password. Sign-in is handled by Supabase Auth. The password is used to authenticate you. It is not written into outbound click events, and pages do not display it.
A signed-in session is kept in a cookie on this site only. That cookie holds the access token and the refresh token for the session. It is not an advertising cookie.
Staff access
A role can be stored for an account so editors and administrators can open staff pages. Ordinary public pages do not publish that role.
Saved opportunities
Saving an opportunity stores your account id, that opportunity's id, and the time you saved it. The list appears on your dashboard. You can remove a saved opportunity. The list is not demo data.
Market preference
If you choose a market, the browser stores a cookie named selected-market. The value is only a market code: GLOBAL, PL, GB, or US. It can remain for up to one year. It does not contain your name, email, or location.
Outbound clicks
When a public offer has a trusted destination, opening it goes through an AhaFind /go page. That visit can store one click event before the browser continues to the partner.
A click can include a click identifier, the opportunity or earn offer, an optional partner, campaign, or source identifier, the active market, the kind of destination, and the time it was created. If you are signed in, the event can include your account id. If you are not, that field is empty. Sign-in is not required.
What a click does not store
The current click event does not store your IP address, precise location, device fingerprint, email address, user agent, access token, refresh token, password, or the destination URL.
This description is about the current click event. It is not a promise about every future feature.
Application logs
When sign-in or role lookup fails, the application can write a log with the site host, an account id, and an error code or message. Those logs are not written to include the access token, refresh token, or password.
The application database does not store your IP address for clicks. The companies that host the site and the database operate their own systems. This page does not describe their logs.
Services that run AhaFind
Supabase provides authentication and the database. When the site is deployed, Vercel hosts it. The application does not load an analytics script or an advertising script.
How long information is kept
A published retention schedule is not set. Click events remain until an administrator deletes them. A sign-in session lasts for the life of that authentication session. The market cookie can last up to one year.
Asking about your account
You can ask what this application holds for your account, or ask to close the account, once a contact address is configured. The contact page says whether that address is available. This draft does not state that a particular legal right has already been assessed.