Privacy Policy — DealFinder by Cottontail MCP Server
Last updated: 2026-10-09. Replace "DealFinder by Cottontail" and the contact line with your legal entity before publishing.
What this service does
DealFinder by Cottontail is a tool that an AI assistant (such as Claude) can call to look up current prices for a product the user named, and to return purchase links. Some links carry an affiliate code that may earn DealFinder by Cottontail a commission from the merchant. The price the user pays is not affected, and results are ranked by price only.
What we receive
When the assistant calls this service, we receive only the arguments of the tool call:
findbestprice: the product name the user asked about, and how many results to return.resolve_link: the product URL the user pasted.watch_price(optional): the product name, the target price, and the mobile number the user chose to give for a one-time alert.
We do not receive, request, or store the rest of the conversation, the user's identity, email, account, or any Claude memory or history. The only personal data we ever hold is a mobile number a user explicitly provides for a price alert (see below). The assistant decides when to call us; we cannot pull data from it.
What we store
- Operational logs: timestamp, tool name, response time, number of results, which affiliate network (if any) tagged each link, and error messages. These contain no product names and no URLs.
- Optionally (off by default), a truncated one-way hash of the product query, used only to count repeat lookups. The hash cannot be reversed to the query.
- Link records: for links routed through our click redirect, the merchant page URL and the affiliate link it forwards to, keyed by a random token, so the link keeps working. These are product pages, not personal data.
- Click records: when a redirect link is clicked, the time, the merchant, a salted one-way hash of the IP address (not the IP), and whether the browser looked like a phone, a desktop, or a bot. Used to count traffic per partner and detect fraud.
- Merchant demand counts: which merchants were requested and how often. No user identity.
- Price alerts (optional, opt-in): if you ask the assistant to text you when a product's price drops, we store the mobile number you give, the product, your target price, and an expiry (90 days). We use the number for exactly one text message, sent only if the price reaches your target, and then delete it. The number is also deleted if you open the cancel link in the alert or reply STOP, or when the alert expires. Alerts are sent through Twilio, which processes the number under its own privacy policy. We never use the number for anything else.
- Partner (publisher) accounts: for developers who integrate our API — business name, contact email, payout email, and commission records. Not shoppers.
- Logs are retained for 30 days, then deleted. Click and commission records are retained for as long as needed to reconcile and pay commissions (typically 13 months) and for tax records as required by law.
Third parties
To answer a price query we send the product name only to our price-data provider (SerpAPI, which queries Google Shopping). Affiliate links route the user's click through the affiliate network (Skimlinks, Sovrn Commerce, or Amazon Associates when enabled) before reaching the merchant; those networks and merchants have their own privacy policies and may set cookies on the user's browser when the link is clicked. We receive aggregate commission reports from the networks, not per-user purchase data.
What we never do
- Never read or store the user's conversation.
- Never replace or remove an affiliate code that was already on a link the user pasted.
- Never alter the ranking of results based on commission.
- Never execute a purchase, hold payment details, or touch a cart.
- Never sell or share the data described above.
Your rights
California, EU/UK, and other residents may request access to or deletion of any data we hold. Apart from active price-alert numbers (deleted on request, on STOP, on the cancel link, when the alert fires, or at expiry), we store no per-user data, so such requests will normally be answered with confirmation that nothing identifiable is held.
Contact
hello@gocottontail.com