Privacy Policy
Legal Document
How GearSteal.com collects, uses, and protects your personal information
🌿 The Short Version (Plain English)
- We collect only the data we need to run this site properly.
- We never sell your personal information to anyone, ever.
- We use cookies and analytics tools to understand how visitors use GearSteal.com.
- When you click affiliate links, the retailer may set their own cookies — we explain this below.
- You have the right to access, correct, or delete your data at any time.
- We comply with GDPR (European Union), CCPA (California), and FTC guidelines.
01 Who We Are
GearSteal.com (“we”, “us”, “our”, or “the Site”) is an independent outdoor gear deals and coupon website. We curate and publish discounts, promo codes, affiliate offers, and product recommendations for camping equipment, tents, canopies, backpacks, solar power gear, and related outdoor products.
We operate as a participant in affiliate advertising programs, meaning we earn commissions when visitors purchase products through links on our site. This does not affect the price you pay — it is how we fund the free content we provide.
Data Controller Information
For the purposes of applicable data protection law, the data controller responsible for your personal information is:
- Website: GearSteal.com
- Contact Email: privacy@gearsteal.com
- Mailing Address: [Your Business Address]
02 Information We Collect
We collect two types of information: information you provide directly to us, and information collected automatically when you browse our site.
A. Information You Provide Directly
- Contact form submissions — your name, email address, and any message you write to us.
- Newsletter / email sign-up — your email address and, optionally, your name and outdoor gear preferences.
- Comments — if you leave a comment on our site, your name, email address, website URL (optional), and comment content are collected.
- Account registration — if we offer user accounts in the future, username, email, and password (stored as a cryptographic hash, never in plain text).
- Deal submissions / user-contributed content — any deals, coupon codes, or reviews you voluntarily submit.
B. Information Collected Automatically
- Log data — IP address, browser type and version, operating system, referring URL, pages visited, time and date of visit, time spent on each page.
- Device information — device type (desktop, mobile, tablet), screen resolution, language settings.
- Click data — which links and affiliate offers you click, which deals you view, and which coupons you interact with.
- Cookie data — see Section 5 for a full breakdown of all cookies we use.
- Analytics data — aggregated behavioral data collected through Google Analytics 4 (anonymized IP addresses).
C. Information We Do NOT Collect
- Payment card numbers or banking information (we process no transactions directly).
- Social Security numbers or government-issued ID numbers.
- Precise GPS location data.
- Biometric data of any kind.
- Health or medical information.
03 How We Collect Information
We collect information through the following methods:
- Direct input — when you fill out a form, subscribe to our newsletter, or contact us.
- Cookies and similar tracking technologies — small text files stored on your device. See Section 5 for details.
- Web beacons / pixel tags — tiny invisible images embedded in emails or pages that confirm delivery and opening.
- Server logs — automatically recorded by our web server (hosted on [Hosting Provider]).
- Third-party analytics — Google Analytics 4 processes usage data on our behalf under a data processing agreement.
- Affiliate tracking — when you click an affiliate link, the destination retailer uses their own cookies and tracking systems.
04 How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Operate & improve the website | Log data, analytics, click data | Legitimate interest |
| Respond to contact form messages | Name, email, message | Contract / Legitimate interest |
| Send newsletters & deal alerts | Email address, preferences | Consent |
| Personalise content & deal recommendations | Click data, browsing history on-site | Legitimate interest / Consent |
| Track affiliate commissions | Click data, affiliate IDs | Legitimate interest |
| Prevent spam & security threats | IP address, log data | Legitimate interest |
| Comply with legal obligations | Any data required by law | Legal obligation |
| Display relevant advertising | Cookie data (with consent) | Consent |
05 Cookies & Tracking Technologies
GearSteal.com uses cookies to make the site work correctly, to understand how visitors use the site, and — with your consent — to show relevant advertising and personalised deals.
What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help us remember your preferences, keep you logged in, and understand how the site is being used. Cookies cannot run programs, carry viruses, or access other files on your device.
Categories of Cookies We Use
| Category | Cookie Name / Source | Purpose | Duration |
|---|---|---|---|
| Strictly Necessary | wordpress_*, wp-settings-*, PHPSESSID | WordPress core functionality: sessions, login, security nonce | Session / 1 year |
| Strictly Necessary | cookielawinfo-* | Remembers your cookie consent choices | 1 year |
| Analytics | _ga, _ga_*, _gid | Google Analytics 4 — tracks page views and user journeys (anonymised IP) | Up to 2 years |
| Analytics | _gat_gtag_* | Throttles request rate to Google Analytics | 1 minute |
| Affiliate Tracking | awin_*, AWC | AWIN affiliate network — attributes sales to GearSteal.com (read-only) | 30 days |
| Affiliate Tracking | Retailer-specific cookies | Set by third-party retailers when you click through from our site | Varies by retailer |
| Functional | woocommerce_*, wp_woocommerce_* | Shopping-related functionality (if applicable) | Session |
| Marketing (Consent Required) | _fbp, fr (Meta Pixel) | Facebook/Meta ad targeting (only if enabled and consent given) | 90 days |
| Marketing (Consent Required) | IDE, 1P_JAR (Google Ads) | Google display ad personalisation (only with consent) | Up to 13 months |
Managing & Disabling Cookies
You can control cookies in the following ways:
- Cookie consent banner — when you first visit the site, you can accept or decline non-essential cookies via our consent popup.
- Browser settings — all major browsers let you block or delete cookies. Note: blocking strictly necessary cookies will break core site functionality.
- Google Analytics opt-out — install the Google Analytics opt-out browser add-on.
- Interest-based advertising — opt out via AboutAds.info or NAI opt-out tool.
06 Affiliate Links & Third-Party Retailers
GearSteal.com participates in affiliate advertising programmes. This means that many links on our site are affiliate links — when you click them and make a purchase, we may receive a commission from the retailer at no extra cost to you.
What Happens When You Click an Affiliate Link
- You are redirected to the retailer’s website (e.g. REI, Backcountry, Amazon, Cabela’s).
- The retailer’s website may set its own cookies on your device to track that the referral came from GearSteal.com.
- If you make a purchase, the retailer pays us a commission based on their affiliate programme terms.
- The retailer’s own privacy policy governs any data they collect from you after you arrive on their site.
- We do not receive any personal payment information from you or the retailer.
Affiliate Networks We Work With
- AWIN — privacy policy at awin.com/privacy-policy
- Amazon Associates — privacy policy at amazon.com/privacy
- ShareASale — privacy policy at shareasale.com/privacy
- CJ Affiliate (Commission Junction) — privacy policy at cj.com/legal/privacy
- Other individual retailer programmes as applicable.
07 Third-Party Services & Data Processors
We use carefully selected third-party services to operate GearSteal.com. Each of these processes your data on our behalf under a data processing agreement or as an independent controller:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Google Analytics 4 | Website analytics | Anonymised usage data | policies.google.com |
| WordPress.org | CMS platform | None directly | automattic.com/privacy |
| Akismet | Spam protection for comments | Comment content, IP, email | akismet.com/privacy |
| Mailchimp / [Email Provider] | Newsletter delivery | Email address, name | mailchimp.com/privacy |
| Cloudflare | CDN, DDoS protection, speed | IP address, log data | cloudflare.com/privacy |
| Google reCAPTCHA | Spam & bot prevention on forms | IP address, browser data | policies.google.com |
| Hosting Provider ([Name]) | Server & infrastructure | All site data (server level) | Hosting provider’s policy |
08 How We Share Information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- Service providers — trusted third parties listed in Section 7 who process data on our behalf under confidentiality agreements.
- Affiliate networks — click data shared with AWIN and other networks purely to track commissions. No personal information is included beyond what is technically necessary.
- Legal requirements — if required by a court order, subpoena, or applicable law, we may disclose information to government or law enforcement authorities.
- Protection of rights — if we believe disclosure is necessary to protect the rights, property, or safety of GearSteal.com, our users, or the public.
- Business transfer — if GearSteal.com is acquired, merged, or undergoes a change of ownership, your information may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
09 Data Retention
We retain your personal information only as long as necessary for the purposes described in this policy or as required by law:
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form messages | 3 years | Support history & legal disputes |
| Email newsletter subscribers | Until you unsubscribe | Ongoing consent-based service |
| Comment data | Indefinite (moderated) | Published content |
| Server log files | 90 days | Security & debugging |
| Google Analytics data | 14 months | GA4 default (configurable) |
| Cookie consent records | 1 year | Legal compliance |
| Affiliate click logs | 13 months | Commission reconciliation |
After the retention period, data is securely deleted or anonymised so it can no longer be attributed to any individual.
10 Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, accidental loss, destruction, or disclosure:
- HTTPS / SSL encryption — all data transmitted between your browser and GearSteal.com is encrypted via TLS.
- Secure hosting — our servers are hosted in a data centre with physical security controls and regular security patching.
- Password hashing — any user passwords are stored using strong cryptographic hashing (bcrypt). We never store passwords in plain text.
- Access controls — site admin access is restricted to authorised personnel with two-factor authentication enabled.
- Plugin & software updates — WordPress core, themes, and plugins are kept updated to minimise vulnerabilities.
- Regular backups — automated daily backups are retained offsite for 30 days.
- Spam & bot protection — Google reCAPTCHA and Akismet are used to prevent automated abuse of forms and comments.
11 Your Privacy Rights
Regardless of where you are located, you have the following rights in relation to your personal data:
Right of Access
Request a copy of all personal data we hold about you.
Right to Rectification
Ask us to correct inaccurate or incomplete information.
Right to Erasure
Request deletion of your personal data (“right to be forgotten”).
Right to Object
Object to processing based on legitimate interests or for direct marketing.
Right to Restriction
Ask us to restrict processing while a dispute is resolved.
Right to Portability
Receive your data in a portable, machine-readable format.
Right to Withdraw Consent
Withdraw consent at any time (e.g. unsubscribe from emails).
Right to Complain
Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at privacy@gearsteal.com. We will respond within 30 days (or 45 days where legally permitted for complex requests).
12 GDPR – Rights of EU/EEA Residents
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) grants you additional rights and places additional obligations on us.
Legal Bases for Processing
We rely on one or more of the following legal bases when processing your personal data:
- Consent (Art. 6(1)(a)) — for newsletters, marketing cookies, and optional features.
- Contract (Art. 6(1)(b)) — to fulfil any service we agreed to provide you.
- Legitimate Interest (Art. 6(1)(f)) — for analytics, site security, and affiliate tracking, where this does not override your rights.
- Legal Obligation (Art. 6(1)(c)) — where processing is required by law.
International Data Transfers
Some of our service providers (e.g. Google, Mailchimp) are based in the United States. Where we transfer data outside the EEA, we ensure adequate safeguards are in place, such as:
- EU Standard Contractual Clauses (SCCs) with service providers.
- Adequacy decisions by the European Commission.
- Data processing agreements that include appropriate technical and organisational measures.
Supervisory Authority
EU residents have the right to lodge a complaint with their national data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.
13 CCPA – Rights of California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you specific rights regarding your personal information.
Your CCPA Rights
- Right to Know — you may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete — you may request deletion of personal information we collected from you, subject to certain exceptions.
- Right to Opt-Out of Sale — we do not sell personal information. However, if this changes, we will provide a “Do Not Sell or Share My Personal Information” link.
- Right to Non-Discrimination — we will not discriminate against you for exercising your CCPA rights.
- Right to Correct — you may request correction of inaccurate personal information we hold.
- Right to Limit Use of Sensitive Personal Information — we do not collect sensitive personal information as defined under CCPA.
Categories of Personal Information Collected (CCPA)
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Name, email, IP address | ✅ Yes |
| Internet activity | Pages visited, links clicked | ✅ Yes |
| Geolocation data | Precise GPS location | ❌ No |
| Financial information | Payment card details | ❌ No |
| Sensitive personal information | SSN, biometrics, health data | ❌ No |
| Inferences / profiles | Deal preferences, gear interests | ✅ Limited |
To submit a CCPA request, email us at privacy@gearsteal.com with the subject line “CCPA Rights Request”. We will verify your identity before processing the request.
14 Children’s Privacy (COPPA)
GearSteal.com is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@gearsteal.com and we will delete such information promptly.
We comply with the Children’s Online Privacy Protection Act (COPPA). If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will take immediate steps to delete that information.
15 Links to External Websites
GearSteal.com contains links to third-party websites, including retailer sites, affiliate partners, and information resources. When you click on these links, you leave our website and any personal information you provide to those websites is subject to their own privacy policies.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites. We strongly encourage you to review the privacy policy of every site you visit.
The presence of a link on GearSteal.com does not constitute our endorsement of the linked site or its privacy practices.
16 Email Communications
Newsletters & Deal Alerts
If you subscribe to our newsletter, we will send you periodic emails containing outdoor gear deals, coupon codes, and product recommendations. By subscribing, you consent to receive these communications.
- Unsubscribe: Every email contains an unsubscribe link. You can opt out at any time.
- Data used: Your email address and, optionally, your name and gear preferences.
- Frequency: We aim to send no more than [X] emails per week.
- Email open tracking: Our email service provider uses pixel tracking to measure open rates. This data is anonymised and used only to improve our communications.
Transactional Emails
We may send you transactional emails (e.g. confirmation of contact form submission, password reset if accounts are offered). These are not marketing emails and cannot be opted out of while you use relevant features.
17 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last Updated” date at the top of this page.
- Post a notice on the homepage or in a prominent location on the site.
- Where required by law or where changes are significant, notify you by email (if you are subscribed) at least 30 days before the changes take effect.
Your continued use of GearSteal.com after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. We encourage you to review this page periodically.
Previous versions of this Privacy Policy are available upon request by emailing privacy@gearsteal.com.
Questions or Privacy Requests?
We’re committed to transparency. If you have questions about this policy, want to exercise your rights, or need to report a concern, reach out to our privacy team directly.
Formal rights requests (access, erasure, portability) are handled within 30 days.
