Legal

Privacy Policy

Last updated: 31 March 2026

The short version

whataryabuyin.com does not collect your name, email address, or any account information. There is no login, no registration, and no tracking for advertising purposes. Like all websites, our hosting provider automatically records basic server logs (including IP addresses) when you visit. That is the extent of it.

1. Who we are

whataryabuyin.com ("the Site", "we", "us", "our") is an independent Australian price comparison service for video games. It is operated as a personal hobby project and is not affiliated with any retailer, publisher, or platform holder listed on the Site.

2. What information we collect

We do not collect any personally identifiable information directly. There are no user accounts, no contact forms, no email subscriptions, and no comment or review features on this Site.

However, certain information is collected automatically as a standard function of web hosting and infrastructure:

  • IP addresses — recorded automatically by our hosting provider (Vercel) in server access logs whenever a request is made to the Site.
  • HTTP request metadata — including the page or resource requested, date and time of the request, HTTP status code, bytes transferred, and referring URL (if any).
  • Browser and device information — the user-agent string sent by your browser, which may include browser type, version, and operating system. This is transmitted automatically by your browser as part of every HTTP request.

This information is collected by Vercel as part of standard server log processing and is not actively used by us to identify, profile, or track individual visitors.

The game titles, prices, and retailer data that power this Site are stored in a backend database. No personal data about Site visitors is stored in this database.

3. Cookies and local storage

The Site does not use advertising cookies, tracking cookies, or any cookies set by us for the purpose of identifying or profiling visitors.

Our hosting provider (Vercel) may set technically necessary cookies as part of its infrastructure (for example, for load balancing or bot protection). These cookies do not contain personal information and are not used for advertising.

The Site does not use browser local storage or session storage to retain information about you between visits.

4. How we use information

The server log data collected automatically by our hosting provider is used solely for the following purposes:

  • Diagnosing technical errors and maintaining the availability of the Site
  • Detecting and mitigating malicious traffic, bot activity, or abuse
  • Understanding aggregate traffic patterns (e.g. which pages are visited most)

We do not use any information collected through your use of the Site to send you marketing communications, serve you targeted advertising, or sell your information to third parties.

5. Third-party services

The Site is hosted on Vercel's platform. Vercel processes server requests on our behalf and automatically collects server logs including IP addresses and request metadata as described in Section 2. Vercel's data processing is governed by their Privacy Policy and their Data Processing Agreement.

We do not use Google Analytics, Meta Pixel, or any other advertising or behavioural analytics platform. The Site carries no advertising of any kind.

6. Links to external retailers

The Site contains links to third-party retailer websites (such as JB Hi-Fi, EB Games, Amazon AU, PlayStation Store, Xbox Store, and Nintendo eShop). When you click a "View Deal" link, you leave this Site and are subject to the privacy policy of the retailer you visit.

We have no control over, and accept no responsibility for, the privacy practices of any third-party website. We encourage you to review the privacy policy of any website you visit before providing personal information.

7. Data retention

Server log data retained by Vercel is subject to Vercel's own retention policies. Vercel's standard log retention period is 30 days for Edge Network logs.

Because we do not collect personal data directly, we have no personal data retention obligations beyond those imposed on Vercel as our infrastructure provider.

8. Australian Privacy Act

This Site is operated from Australia. To the extent the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to the operation of this Site, we are committed to complying with those obligations.

Because we do not collect personal information (as defined in the Privacy Act) directly from users, most of the APPs governing collection, use, disclosure, and storage of personal information are not directly engaged. However, to the extent any personal information is handled (for example, IP addresses retained in Vercel's server logs), we take reasonable steps to ensure it is held securely and used only for the purposes described in this policy.

If you believe we have breached the Australian Privacy Principles in relation to your personal information, you may lodge a complaint by contacting us at whataryabuyin@gmail.com. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

9. International visitors and GDPR

This Site is accessible worldwide. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation, including:

  • The right to access personal data held about you
  • The right to rectification of inaccurate personal data
  • The right to erasure ("right to be forgotten")
  • The right to restriction of processing
  • The right to data portability
  • The right to object to processing

As noted above, the only personal data that may be processed is IP address and request metadata retained in Vercel's server logs. To exercise any of the above rights in relation to data held by Vercel on our behalf, please contact us at whataryabuyin@gmail.com.

The lawful basis for any incidental processing of IP addresses and request metadata is legitimate interests (Article 6(1)(f) GDPR) — specifically, the legitimate interest of operating a secure and functional website.

10. Security

We take reasonable technical and organisational measures to protect the Site and its infrastructure from unauthorised access, alteration, or destruction. These include use of HTTPS encryption for all traffic, access controls on database credentials, and reliance on reputable infrastructure providers (Vercel, Supabase) with their own security certifications.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect the Site, we cannot guarantee absolute security.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this policy periodically. Your continued use of the Site after any changes constitutes your acceptance of the updated policy.

12. Contact

For any questions, concerns, or requests relating to this Privacy Policy or the handling of personal information, please contact us:

Email: whataryabuyin@gmail.com

Note: This privacy policy was prepared in good faith to reflect the actual data practices of this Site.