Privacy

HammerAlert privacy policy

HammerAlert is an auction-tracking service. This page describes what we collect, why, how long we keep it, and the controls you have. It is written to match what the product actually does, not as formal legal advice.

Last updated: 17 April 2026.

What we collect and why

We only collect what is needed to run the service you signed up for.

  • Account data. Your name, email address, a salted hash of your password, and your timezone. We store a password hash, not the password itself. Your timezone is used to render auction dates in your local time.
  • Preferences. The categories, regions, auction houses, and per-house exclusions you configure, along with your delivery frequency (weekly digest or dashboard-only) and the marketplace-platform toggle.
  • Saved auctions (watchlist). The event id, source, title, date, and URL of any sales you save to your watchlist.
  • Calendar subscription token. A per-account token used to build your live calendar subscription URL. You can rotate or remove this token at any time from your account.
  • Sessions and auth tokens. When you sign in, we store a hashed session token and its expiry; magic-link and password-reset emails store a short-lived hashed token with an expiry and a single-use flag.
  • Notification log. A record of which alerts we sent you so we don't send duplicates.
  • Feedback. If you submit feedback through the in-app feedback form, we store the message together with your account so we can follow up.

Email delivery

Account emails (verification, magic-link sign-in, password reset, weekly digest, and auction alerts) are sent through Postmark, a transactional email provider. Postmark processes your email address and message content strictly to deliver these messages.

Every notification email includes a one-click unsubscribe link that disables all further HammerAlert alerts for your account. You can also switch delivery to "dashboard-only" in Preferences.

Analytics and server logs

  • Plausible Analytics. Public pages load a script from plausible.io. Plausible is a privacy-oriented analytics service that does not use cookies and does not build cross-site profiles. It aggregates basic page views and referrers.
  • First-party product analytics. HammerAlert also records limited first-party page events on known HammerAlert routes so our admin dashboard can understand landing pages, exits, outbound auction-house clicks, and broad session flow. These events stay inside HammerAlert, are not used for cross-site profiling, and help us improve navigation and product design.
  • Google Analytics. If configured, public and signed-in pages may also load Google Analytics 4 for aggregate traffic and acquisition reporting. Google Analytics may set analytics cookies or similar identifiers and process page URL, browser/device, approximate location, and referrer data under Google's terms. HammerAlert uses this for site measurement, not advertising retargeting.
  • Server-side visitor analytics. Our admin dashboard also counts visits from standard access logs, filters known bot fingerprints, and caches IP-to-country lookups so we can see rough geographic distribution. We do not sell or share this information.
  • Standard access logs. Like almost any web service, our infrastructure records standard HTTP access information (IP, user agent, request path, timestamp) for reliability, debugging, and abuse prevention.

Browser storage

After you sign in, HammerAlert stores a session token in your browser's localStorage (not a cookie). It is sent back to the server on later requests to keep you signed in and is removed when you sign out or delete your account. Public pages do not require any sign-in storage.

Your controls

  • Change what you receive. Update categories, regions, houses, exclusions, and delivery frequency from Preferences at any time.
  • Unsubscribe from email. Use the one-click link at the bottom of any HammerAlert alert email, or switch delivery to dashboard-only.
  • Rotate your calendar link. Regenerate your calendar subscription token from the Calendar page; the old link immediately stops working.
  • Delete your account. The Account page has a self-service "Delete account" control. Confirming your own email address disables the account, revokes sessions, and deactivates your subscriptions. Cached operational records (e.g., notification dedupe history) may be retained briefly before routine cleanup.
  • Ask about your data. If you want to request access, correction, or deletion beyond the self-service controls above, sign in and use the in-app feedback form — it's attached to your account so we can respond without a back-and-forth about identity.

Data retention

Account data and preferences are kept while your account is active. Expired sessions and auth tokens are purged automatically. Past auction data used to render public and signed-in views (sale titles, dates, locations) is public information collected from auction-house websites; it is not personal data.

Contact

Routine controls — delete account, unsubscribe, regenerate calendar token, and change preferences — are self-service and do not require contacting us. For anything that isn't covered by those controls, sign in and use the in-app feedback form at /feedback; it attaches your message to your account so we can respond without a separate identity step. See the FAQ & support page for common questions.

Changes to this page

If this policy changes in a way that affects what we collect or how we use it, we'll update the "Last updated" date above and, where appropriate, notify active accounts by email.