Privacy Policy
Diecast Radar is a free hobby tool. We collect as little as possible, never sell your data, and you can use almost everything without giving us an email address.
Last updated: August 2, 2026
At a glance
- No email or password needed to use the site
- Sighting photos are analysed instantly, then discarded (kept only if you contest a result, for up to 30 days)
- We never sell your data or share it for advertising profiling
- Clear your cookies any time to disassociate your data
Who we are
Diecast Radar (diecastradar.app) is a free hobby tool for diecast collectors. It tracks live retailer availability, restock and price-drop alerts, AI-assisted in-store sightings, a personal collection and wishlist, a shoppable cart optimizer, and a Hunter Score, for Hot Wheels, Mini GT, Tarmac Works, and more diecast brands across every scale.
Accounts and authentication
Diecast Radar uses Supabase anonymous sign-in by default. When you first visit the site a random device-tied UUID is created for you — no email address, no name, and no password is required. This UUID is stored in a session cookie (sb-*-auth-token) so your preferences, Hunter Score, collection, wishlist, and cart persist across visits on the same device. You can clear this data at any time by clearing your browser cookies.
You may optionally create a full account to sync across devices by signing in with a one-time email code (OTP), or with Google or Discord. We receive only the email address (and, for OAuth, the basic profile your provider returns); we do not receive your social passwords. When you create an account you also pick a username, which is shown in your account menu and on any collection or wishlist you choose to share publicly.
A separate alert email is collected only if you opt in to digest alert notifications. It is stored apart from your identity and used solely to send the restock or price-drop notifications you configure. You can remove it any time from your profile.
Account preferences and activity
Associated with your account (anonymous UUID or signed-in identity), we store:
- Username and profile preferences (default brand, light/dark theme)
- Country preference (US or CA) and, optionally, a sales-tax region for cart estimates
- Hunter Score and tier (Scout → Legend), with an immutable score-change log
- Onboarding quiz answers (brand and collecting-style preferences)
- Collection items, wishlist items (including any target prices you set), cart contents, saved searches, and your watch list of followed cars
- Alert history (pending, delivered, and interacted alerts)
- Notification preferences: which alert categories (restocks, price drops, sightings, release-calendar drops, saved-search matches, Hunter Score events) you receive by push and in-app, and (only if you type one yourself) a city name used for nearby sighting alerts. That city is stored encrypted, and we never store coordinates with these preferences.
- Collection and wishlist public share tokens — opaque random strings you can activate to share a read-only view with anyone who has the link, and revoke at any time
- Weekly collection backup (Premium, off by default): if you turn it on, we email you a zipped spreadsheet (CSV) of your own collection once a week on the day you choose, sent through our email delivery provider. It contains only your own collection data, and you can turn it off at any time from your profile.
Cookies and local storage
A few small preference cookies remember your settings outside the signed-in session:
dr_country— your selected country (US or CA). Expires after 1 year.dr_brand— your preferred brand filter. Expires after 1 year.dr_consent— remembers your cookie choice (accept or decline analytics and advertising cookies). Expires after 1 year.dr_cc_gated— records only whether your region requires a consent prompt (yes or no), so the right privacy default is applied before any analytics or advertising can load. It stores no location beyond that yes/no. Expires after 1 day.
These cookies contain no personal information and are not shared with third parties. For visitors who are not signed in, catalog saved searches are kept in your browser's local storage so they persist across reloads; signing in moves this data to your server-side account and clears the local copy.
Cookie consent
Essential cookies (sign-in, your country and consent choices) are always on, because the site can't work without them. Analytics and advertising cookies (Google Analytics and our ad network, described below) are different: in the EEA, the UK, and Switzerland a Google-certified consent management platform (CMP) asks for your consent, and through Google Consent Mode nothing is stored for analytics or advertising until you allow it.
You can change your mind at any time. Use the Your Privacy Choices link in the footer to accept or withdraw consent. It is also the California Do Not Sell or Share My Personal Information opt-out. Declining turns off analytics and advertising cookies; the rest of the site keeps working.
Sightings (user-generated content)
If you submit an in-store sighting report, we collect: the retailer, the city and state/province/territory (optional), an approximate location (latitude and longitude rounded when saved so it points to a general area rather than your exact position), the product spotted, the rarity you saw, the quantity, optional notes, and an optional photo. Photos are sent to an AI service for immediate analysis (see below) and are not stored on our servers or in our database; they are discarded as soon as analysis completes.
Contesting a verification. The one exception is if you contestan "couldn't verify" result on a photo sighting. Only then, and only with your explicit action, is that photo stored (in a private bucket) so a moderator can review it. It is deleted as soon as the contest is resolved, and in any case within 30 days (an unreviewed contest is automatically resolved in your favor and the photo deleted). We tell you this before you contest.
Sightings appear publicly on the Sightings map and feed, including the product, store, and approximate location. They never show who reported them.
You choose a visibility each time you report:
- Public(default): you earn Hunter Score points and the report appears in your “My History”. For a trailing 30 dayswe keep a recoverable, encrypted link between you and the report (so a confirmed false report can be penalized, and so your history can show it). After 30 days that link is automatically severed and the sighting can no longer be traced back to you. During that window, “My History” shows you the product you reported and, for public sightings, the store and approximate location.
- Anonymous: no points, and no link between you and the report is ever stored, so it never appears in your history and cannot be traced back to you.
If your profile is private, new sightings default to Anonymous so your identity is never attached to a report unless you choose Public yourself.
Flagging. Any signed-in user can flag a sighting they believe is inaccurate. We record which sightings you have flagged using a blinded (hashed) identifier rather than your raw account id. This lets us count one flag per person, stop you flagging your own sighting, show you what you have already flagged, and let you revoke a flag. When enough members flag a sighting it is hidden pending review.
Reporting a note. If a sighting includes a written note that is spam, abusive, or otherwise breaks our community rules, any signed-in user can report it (the same way comments can be reported). We store the report with your account so moderators can review it; a moderator may remove the note while leaving the sighting itself.
“Near Me” searches. If you use the Near Me feature on the Sightings map, your device asks for your location and your browser asks for your permission first. Your position is used once, inside that single request, to find sightings around you, and is then discarded. We never store, log, or associate your precise location with your account — not in our database, analytics, or error reports. The optional city search works the same way: the city you type is geocoded for that one search and not retained. If you decline location access, the feature simply falls back to the city search.
Store restocks.You can also report a general “fresh restock” at a store, without naming a product. A restock report stores the store name, the approximate location you provide, your account (so we can award points if it is confirmed and enforce daily limits), and a coarse device signal used only to stop someone confirming their own restock from a second account. You only earn points once a different hunter confirms the restock; an unconfirmed restock expires after two weeks. To keep this fair we limit how many restocks you can report per day, allow only one report per store per day, and limit how often the same two members can earn points by confirming each other.
Community content (comments, ratings, suggestions)
If you post a comment, leave a star rating or review, submit a product suggestion, or vote on one, we store that content along with your account so it can be displayed, attributed, and counted toward your contribution totals. When your profile is public, this content is shown next to your username and links to your profile; when your profile is private, it appears as “Anonymous User” with no link. You can edit or delete your own comments and ratings at any time.
Community content is subject to moderation. To keep the community healthy we may hide, remove, or limit the reach of content that breaks our Terms of Service, and we keep a record of moderation actions and any reports you file.
Founding Collectors: if you are a Founder, you can opt in to be listed by your username and Founder number on our public Founding Collectors page. This is off by default, you choose it at checkout or in your profile, and you can turn it off at any time. You are only ever shown there while your profile is public.
Friends and blocking
You can search for other collectors by username and send them a friend request, with an optional short note. A friendship only takes effect when both people accept. Once you are friends, each of you can privately view the other’s full collection details (owned items, quantities, verification status, and series completeness). This friends-only view is not visible to non-friends or the public, and being friends never makes your collection public. We store the friend request, its optional note, and its status (pending, accepted, declined, or ignored) so both people can see where a request stands. When someone sends or accepts a request, we notify the other person; the requester’s username is shown to the person who receives the request.
You can remove a friendat any time, which revokes both people’s access to each other’s collection. You can also block another collector: blocking removes any existing friendship, prevents them from sending you requests, and hides your collection from them. Blocking is fully reversible from your Blocked liston the Friends page. Your Friends page also shows a recent-activity feed of your friends’ awards and Hunter Score tier-ups, drawn from information those friends already earned on the site.
Separately, you can choose to make your collection public from the Collection Visibility setting in your profile (off by default). When it is on, anyone who visits your profile page can browse the cars you own — including quantities, verification status, and any items you mark as favorites — and a preview of your favorite and newest cars appears on your profile page. This is a separate choice from your profile visibility, we record when you opt in, and you can turn it off again at any time, which immediately restores the friends-only view. Blocking someone hides your collection from them even while it is public.
Discord linking
Linking your Discord account is optional. If you choose to link it, we store your Discord user ID and share it with Discord so we can add you to our community server and grant the roles your membership includes. We never receive your Discord password. You can unlink at any time from your account settings, which removes the granted roles.
Feedback, bug reports, and fraud signals
If you submit a bug report or product-inaccuracy report, we store the category, description, the page URL where the issue occurred, and your browser user-agent string, used only to investigate and resolve the report.
During onboarding we silently collect a small set of risk signals — such as timing between quiz questions, pointer-interaction patterns, and browser characteristics — to detect automated bots and scalper tools. These signals are visible only to site administrators, are never exposed through any client or public endpoint, and are never used for advertising or sold to third parties. Your IP address is used server-side as part of this check and is not stored beyond the request.
AI processing (xAI Grok)
Diecast Radar uses the xAI Grok API for these purposes:
- Sighting photo analysis.A photo you attach is sent to Grok's vision API to identify the product on the shelf and verify your sighting. The image is processed ephemerally — xAI does not train on API inputs, and we discard the image immediately after analysis. It is stored only if you choose to contest a verification result (see Sightings above), and then only until the contest is resolved or 30 days pass.
- Collection photo identification.When you add cars to your Collection from a photo, the image is sent to Grok's vision API to identify the cars and is then discarded immediately — it is never stored. To improve this experimental feature we keep a text-only record of what was identified and which car you confirmed or corrected (the photo itself is never kept). If you have Premium and add from a live camera photo, that same photo may also be used to verify the cars you add, which keeps a cryptographic fingerprint of it as described in Collection verification below (the photo itself is still never kept).
- Collection verification (Premium).A live camera photo you take to verify items you own is sent to Grok's vision API and discarded immediately — the photo is never stored. We keep a text-only audit record of each attempt (which item, the outcome, a confidence value) plus a cryptographic fingerprint (SHA-256 hash) of the photo, used solely to detect the same image being re-submitted. The fingerprint cannot be turned back into the photo.
- Product research.Automated background jobs use Grok's web search to discover upcoming releases and restock news. No personally identifiable information is included in these queries.
xAI's data practices are governed by their Privacy Policy.
Analytics: Google Analytics 4
We use Google Analytics 4 to understand how visitors use the site (page views, session duration, navigation paths). It sets cookies (including _ga and _gid) to distinguish users. IP addresses are truncated by Google before storage; we do not receive full IP addresses. In the EEA, the UK, and Switzerland this runs only after you consent (see “Cookie consent” above), and anyone can turn it off any time via the footer Your Privacy Choices link.
You can also opt out across all sites using the Google Analytics Opt-out Browser Add-on.
Advertising
Diecast Radar may display advertisements served by Google AdSense, Mediavine, or a comparable ad network. These networks may use cookies and similar technologies to show ads based on your prior visits to this and other sites. In the EEA, the UK, and Switzerland we gather consent through a Google-certified CMP and, via Google Consent Mode, set no advertising cookies until you allow it; everyone can opt out using the Your Privacy Choices link in the footer.
You can also opt out of personalised advertising via Google Ad Settings or the NAI opt-out tool. This policy will be updated if we change ad networks.
Push notifications
If you grant browser notification permission, the push subscription endpoint your browser issues (a URL from your browser vendor) is stored so we can deliver the notifications you have enabled. Push is per device: we keep one subscription per browser you turn it on in, together with that device's browser and operating system (read from your browser's user-agent) so we can label it for you. Your profile lists every device you have notifications on and lets you remove any of them; you can also revoke notification permission in your browser settings at any time. Expired or revoked endpoints are removed automatically.
Every notification category (restocks, price drops, sightings, release-calendar drops, saved-search matches, Hunter Score events) can be toggled on or off individually — for push and for in-app notifications separately — from your profile's Notifications section.
Retailer data and affiliate links
We automatically poll roughly 25 major and specialty diecast retailers — including Mattel Creations, Walmart, Target, Amazon, Dollar General, Kroger, Canadian Tire, and independent diecast shops — to fetch product availability, prices, and stock status. This uses publicly accessible product APIs and web pages; no personal data about you is sent to retailers.
Links to retailers may include affiliate parameters. If you make a purchase after clicking one, we may receive a small commission at no extra cost to you. Retailer sites have their own privacy policies; we are not responsible for their data practices.
Third-party service providers
To operate the site we also rely on:
- Supabase — database and authentication hosting (US-based servers)
- Vercel — hosting, CDN, and serverless compute. We also use Vercel BotID (invisible bot detection) on a few sensitive actions (reporting or flagging a sighting, and signing in) to block automated abuse. It analyzes request and device signals to tell humans from bots; it is not used to track you or for advertising.
- Inngest — background job orchestration (no personal data in payloads)
- Upstash Redis — rate limiting (request counts keyed by anonymous UUID or IP; not retained long-term)
- Resend — transactional email for alert digests (only if you opt in to email alerts)
These providers process data only as necessary to deliver the service and are contractually prohibited from using it for other purposes.
Data retention and deletion
Your account record (UUID or identity, Hunter Score, preferences, collection, wishlist, and cart) is retained as long as you continue using the site. Delivered alerts are retained for 30 days, then pruned. Background-job event logs are pruned after 14 days. Sighting data is removed from the public map after 48 hours; the underlying record may be kept for analytics in anonymised form.
Delete your account yourself. Signed-in members can permanently delete their account and personal data at any time from profile settings(“Delete Account”). This erases your email and profile details and removes your collection, wishlist, cart, saved searches, alerts, and notifications; cancels any Premium subscription; and severs the link between you and your sightings. Your public comments and ratings remain but are shown as “Anonymous User”. For anonymous (not signed-in) use, clearing your browser cookies disassociates your UUID. You can also contact us and we will action your request.
You can download a copy of the personal data we hold for your account at any time from your profile settings(“Your Data → Download my data”).
Legal bases for processing
If you are in the EEA, the UK, or Switzerland, we rely on these legal bases:
- Contract — to run your account and provide the features you use (collection, wishlist, cart, alerts, sightings, Hunter Score).
- Consent — for analytics and advertising cookies, and for optional email digest alerts. You can withdraw consent at any time.
- Legitimate interests — to keep the service secure and abuse-free (rate limiting, bot and scalper detection, moderation), balanced against your rights.
- Legal obligation — where we must keep certain records to comply with the law.
Your privacy rights
Depending on where you live (for example the EEA, the UK, Switzerland, or US states such as California), you have some or all of these rights over your personal data:
- Access and portability— see and download your data (“Your Data → Download my data” in your profile).
- Rectification — correct your details from your profile settings.
- Erasure— delete your account and personal data (“Delete Account” in your profile).
- Withdraw consent — turn off analytics and advertising cookies, or remove your alert email, at any time.
- Object or request restriction of certain processing, and the right not to be discriminated against for exercising any of these rights.
Use the in-app controls above, or email privacy@diecastradar.app and we will respond within the time the law allows (within one month for EEA/UK requests). You may also lodge a complaint with your local data protection authority.
International data transfers
Diecast Radar is operated from, and uses service providers based in, the United States (see “Third-party service providers” above). If you access the site from outside the US, your data is transferred to and processed in the US. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our providers.
California privacy rights
We do not sell your personal information for money. Like most ad-supported sites, our use of advertising cookies may be considered “sharing” for cross-context behavioural advertising under California law. You can opt out using the Your Privacy Choices link in the footer (the Do Not Sell or Share My Personal Informationopt-out), which turns off advertising cookies on this browser. California residents also have the rights to know, access, delete, and correct their information, described in “Your privacy rights” above, and we will not discriminate against you for exercising them.
Children
Diecast Radar is not directed at children under 13, and we do not knowingly collect data from them. Creating an account requires confirming you are at least 13 years old. If you believe a child under 13 has given us personal data, email privacy@diecastradar.app and we will delete it.
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the site after changes constitutes acceptance of the revised policy.
Contact
Questions about your data? Email privacy@diecastradar.app.