PokeAlerter Privacy Policy

Effective date: 8 September 2026
Last updated: 23 September 2026

This Privacy Policy explains how PokeAlerter ("PokeAlerter", "we", "us" or "our") collects, uses, stores, shares and otherwise processes personal data when you use the PokeAlerter iOS app, Android app, the website at https://pokealerter.com , the PokeAlerter backend/API, or related support services (together, the "Service").

The data controller for PokeAlerter is PokeAlerter. You can contact us about privacy at privacy@pokealerter.com .

This Policy applies only to PokeAlerter's processing. Discord, Whop, Apple, Google/Firebase, retailers and other third-party services have their own privacy practices and policies.

1. What PokeAlerter does

PokeAlerter lets an eligible user sign in using Discord, view supported restock-alert channels, choose which channels they want alerts from, select notification preferences and receive stock/restock notifications on iOS or Android.

Premium access is linked to the "Premium member" role in the relevant Discord server. Premium membership is purchased and managed through Whop. Whop is the billing and checkout provider; PokeAlerter uses the resulting Discord role/status to determine whether Premium features should be available.

2. Personal data we process

Discord account and membership data

When you sign in with Discord, PokeAlerter uses Discord OAuth and currently requests the identify and guilds.members.read scopes. We may process your Discord user ID, username/display name, avatar information, membership of the relevant Discord server and whether your account has the required Premium role. We use this information to authenticate you, link your PokeAlerter account to the correct Discord account, show your profile, and determine whether you are entitled to Premium features.

PokeAlerter does not use these OAuth scopes to read your private Discord direct messages. Separately, the PokeAlerter Discord bot processes messages and embeds in the specifically configured restock-alert channels that the bot is permitted to access, because that content is the source of the alerts delivered by the Service.

Authentication and session data

We process temporary login codes, authentication/session tokens, token expiry information and related security data so that you can remain signed in and access authenticated API functions. Authentication data may be stored securely on your device. The current Android app protects its locally stored authentication token using Android Keystore-backed encryption. We do not ask for or store your Discord password.

Device and push-notification data

To deliver notifications, we process a device push token and related status information. On iOS this is an Apple Push Notification service (APNs) device token. On Android this is a Firebase Cloud Messaging (FCM) registration token. We may also process the platform, whether a device token is active, the time it was registered or refreshed, and notification-related preferences.

A push token is an identifier used for routing notifications to an app installation. It is not your phone number and it does not give PokeAlerter access to unrelated content on your device.

Alert preferences

We store the alert channels you have enabled or disabled and the notification sound or other alert preference you select for each channel. These settings are retained so that your choices can be restored, including when Premium access is temporarily inactive and later restored.

Alert content and recent alert history

To provide alerts, the backend may process content from configured Discord restock channels, including message text, embed titles and descriptions, embed fields, product names, retailer information, product URLs, image URLs, attachment URLs, channel IDs, channel names and timestamps where those elements are present in the source Discord message.

For a logged-in user, PokeAlerter may store a recent alert history containing the alert's channel ID/name, title, body, product/deep link and timestamp. The current Service returns the most recent 30 alerts for the user in the Recent Alerts feature.

Website, API and technical data

When you access pokealerter.com or the PokeAlerter API, our web server, hosting provider and security infrastructure may process technical data such as your IP address, date and time of access, requested URL/API path, HTTP status, browser or app user-agent information, operating system/device information, referrer information, and diagnostic or security logs. We use this information to operate the Service, maintain security, investigate failures or abuse, and troubleshoot delivery problems.

Support communications

If you contact us, we process the information contained in your message and any contact details, screenshots, diagnostic information or files you choose to provide so that we can respond to and resolve your enquiry.

3. Information we do not require from the mobile apps

The current PokeAlerter iOS and Android apps do not require access to your precise location, address book/contacts, microphone, camera, photo library, health information or advertising identifier in order to provide the restock-alert service. PokeAlerter does not sell personal data and does not use the mobile apps for behavioural advertising or cross-app advertising tracking.

If the Service changes in a way that introduces new categories of personal data or new tracking technologies, this Policy and the relevant app-store disclosures will be updated before or when the change takes effect as required by law.

4. How we use personal data

We use personal data to provide and secure the Service. This includes authenticating you through Discord; checking your server membership and Premium role; maintaining your app session; registering your iOS or Android device for push delivery; showing supported Discord alert channels; saving your channel and sound preferences; processing monitored Discord restock messages; generating and delivering notifications; maintaining recent alert history; restoring access when Premium status returns; preventing unauthorised use; diagnosing delivery and service failures; responding to support enquiries; enforcing our terms; and complying with legal obligations.

We do not use your Discord identity, push token, alert preferences or alert history to sell your personal data to third parties.

5. Legal bases for processing

Where UK GDPR or equivalent law applies, we rely primarily on performance of a contract where processing is necessary to provide the PokeAlerter service you request, including authentication, Premium access checking, preferences and push-alert delivery. We rely on legitimate interests where necessary to operate, secure, monitor and improve the Service, prevent fraud or abuse, maintain technical logs and provide support, provided those interests are not overridden by your rights and interests. We rely on legal obligation where processing is necessary to comply with applicable law.

Where consent is legally required, we rely on consent. This includes non-essential cookies or similar device-storage technologies where applicable. Mobile operating systems also ask you whether you want to allow notifications; you can change that permission at any time in iOS or Android settings.

6. Push notifications, Apple and Firebase

PokeAlerter uses third-party push infrastructure to deliver alerts. iOS notifications are delivered using Apple Push Notification service (APNs). Android notifications are delivered using Google Firebase Cloud Messaging (FCM). To provide this functionality, the relevant provider receives the device push token and the notification information required to route and deliver the message.

A notification payload may include information such as the alert title, body, source channel, product URL and, where used, an image URL. On iOS, PokeAlerter's Notification Service Extension may automatically retrieve a product image from a retailer, image host or content-delivery network so it can be attached to the notification. When that happens, the third-party image host receives a normal network request from the device and may therefore receive technical information such as the device's public IP address and request headers under that third party's own privacy practices.

On Android, FCM is used to deliver the push message to the PokeAlerter app, which then creates the local notification on the device.

You can disable PokeAlerter notifications using the operating-system notification settings. Disabling notifications stops visible push alerts on that device but does not by itself delete your PokeAlerter account or saved channel preferences.

7. Whop and Premium membership

Premium membership is purchased, billed and managed through Whop. Whop is a separate service with its own terms and privacy practices. To create/use a Whop account and complete the Whop process required to become a PokeAlerter Premium member, you must agree to or otherwise accept/acknowledge the applicable Whop Terms of Service and Whop Privacy Policy as presented by Whop. Whop's privacy terms apply in addition to this PokeAlerter Privacy Policy; this Policy does not replace or modify Whop's policy.

Whop may independently collect and process information such as account/contact information, transaction and purchase information, payment-related information, device/browsing information, cookies and other information described in Whop's Privacy Policy. PokeAlerter does not require your Whop password and does not need to receive or store your full payment-card details to operate the Premium access check. PokeAlerter ordinarily determines Premium entitlement from the Discord "Premium member" role/status provisioned as part of the Whop membership flow.

Whop's current privacy policy is available at https://whop.com/privacy and its terms are available at https://whop.com/tos (or the applicable regional terms shown by Whop).

8. Discord

Discord authentication and Discord server functionality are provided by Discord. When you choose to sign in with Discord, you are redirected to or interact with Discord's OAuth authorisation process. Discord processes your information according to its own Privacy Policy and terms. PokeAlerter receives only the information made available under the permissions/scopes you authorise and the server/bot information required to operate the Service.

You may be able to review or revoke authorised applications through your Discord account settings. Revoking access may prevent PokeAlerter from authenticating or verifying your account until you authorise it again.

Discord's privacy policy is available at https://discord.com/privacy .

9. Cookies and similar technologies on pokealerter.com

PokeAlerter may use cookies and similar technologies, including browser storage such as local storage, to operate pokealerter.com. These technologies fall into the following categories depending on the site's deployed configuration:

Strictly necessary technologies. These may be used where essential to provide a service you request, for example security, authentication/session handling, fraud or abuse prevention, load balancing, remembering a privacy/cookie choice, or other essential site functionality. Where an applicable e-privacy law provides an exemption for strictly necessary storage/access, these technologies may be used without opt-in consent, but we still provide information about their purpose.

Preference technologies. These can remember choices such as interface or site preferences. If a preference technology is not strictly necessary, we will seek consent where applicable before using it.

Analytics/performance technologies. If PokeAlerter deploys analytics or performance cookies or similar non-essential technologies, they will be used to understand how the website is used and improve reliability or performance. Where consent is required, these technologies will not be activated until you consent.

Advertising/marketing technologies. PokeAlerter does not use the mobile apps for behavioural advertising. If the website ever introduces advertising, remarketing, pixels or other non-essential marketing technologies, we will update our disclosures and obtain consent where required before placing or accessing them.

Under UK cookie rules, non-essential cookies and similar technologies should not be placed or accessed before valid consent is obtained. Where PokeAlerter uses a cookie-consent interface, rejecting non-essential technologies should be as straightforward as accepting them, and you should be able to revisit your choice. You can also control cookies through your browser, although blocking strictly necessary technologies may cause parts of the site to stop functioning correctly.

Links from pokealerter.com to Discord, Whop, retailers or other external services may take you to third-party websites. Once you visit those sites, their cookies and tracking practices are governed by their own policies. If a third-party service is embedded directly within pokealerter.com, any cookies or similar technologies set through that embed must also be disclosed and handled through the site's consent controls where required.

Cookie register: The exact cookie/storage names, providers, purposes and lifetimes must match the technologies actually deployed on pokealerter.com. PokeAlerter should maintain an up-to-date cookie register or consent interface showing those details. This Policy must be updated if the deployed cookie technologies change materially.

10. Local storage in the mobile apps

The iOS and Android apps may store information locally on the device where necessary to keep you signed in, remember settings, manage notification state and provide normal app functionality. This local app storage is not a browser advertising cookie. Where local device storage is strictly necessary to provide the app functionality requested by you, it is used for that purpose. PokeAlerter does not use the current mobile apps to store advertising identifiers for behavioural advertising.

11. When we share personal data

We disclose personal data only where reasonably necessary to operate the Service, where you direct us to do so, or where required by law. Recipients may include:

  • Discord, for OAuth authentication, server membership and Premium-role verification, and operation of the monitored Discord alert channels;
  • Whop, as the independent platform/payment provider through which Premium membership is purchased and managed;
  • Apple, for APNs delivery to iOS devices;
  • Google/Firebase, for FCM delivery to Android devices;
  • hosting, infrastructure, network, security and technical service providers that process data on our behalf to host, protect and operate pokealerter.com and the PokeAlerter API;
  • retailers, image hosts and content-delivery networks when you open a product link or, on iOS, where the notification extension retrieves a product image; and
  • courts, regulators, law-enforcement agencies, professional advisers or other parties where disclosure is necessary to comply with law, establish or defend legal rights, investigate fraud/security incidents, or protect users and the Service.

We do not sell your personal information.

12. International transfers

Some providers used by PokeAlerter, including Discord, Whop, Apple and Google/Firebase, operate internationally. As a result, personal data may be processed in countries outside the United States or your country of residence. Where PokeAlerter is responsible for an international transfer and applicable law requires safeguards, we use an appropriate lawful transfer mechanism, such as an adequacy regulation/decision, approved contractual clauses, the UK International Data Transfer Agreement/Addendum, or another legally recognised safeguard as appropriate to the circumstances.

Third-party providers may make their own international transfers as independent controllers under their own privacy policies.

13. Data retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, maintaining security, resolving disputes and meeting legal obligations.

PokeAlerter currently exposes the most recent 30 alert-history records for each user. Account/profile information, saved channel preferences and active push tokens may be retained while your PokeAlerter account remains active or while they are needed to provide the Service. Invalid, obsolete or inactive push tokens may be disabled and subsequently deleted. Temporary authentication credentials and login codes are time-limited; operational records relating to them may remain for a limited period where necessary for security or troubleshooting. Server/security logs are retained for a proportionate period based on operational, security and legal needs.

When you request deletion of your PokeAlerter account/data, we will delete or anonymise the personal data associated with the PokeAlerter account unless we need to retain specific information for a legal obligation, fraud/security prevention, dispute resolution or the establishment, exercise or defence of legal claims. Any retained data will be limited to what is necessary and kept only for the applicable retention period.

Deleting PokeAlerter data does not automatically delete your Discord, Whop, Apple or Google accounts or data held independently by those providers. Requests concerning those accounts must be made to the relevant provider.

14. Security

We use reasonable technical and organisational measures designed to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include HTTPS for production API communications, access controls, separation of server-side credentials from the mobile apps, and secure handling of authentication and push credentials. The current Android app encrypts its locally stored PokeAlerter authentication token using Android Keystore-backed cryptography.

No internet service, storage method or transmission method can be guaranteed to be completely secure. You are responsible for protecting access to your Discord, Whop and device accounts and for keeping your devices appropriately secured.

15. Your choices and data-protection rights

You can change which alert channels are enabled, change notification sounds/settings, disable PokeAlerter notifications at operating-system level, revoke PokeAlerter's Discord authorisation through Discord, and manage website cookie choices where applicable.

Depending on where you live, you may have rights over your personal data. Under UK GDPR these can include the right to request access, correction, erasure, restriction of processing, data portability, and to object to certain processing. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. These rights are subject to legal conditions and exemptions.

If you have concerns about how PokeAlerter uses your personal data, please contact us first so that we have an opportunity to address your concerns. If you remain dissatisfied, or if you believe your data-protection rights have been infringed, you have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's independent data-protection regulator.

You can contact the ICO at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF , by telephone on 0303 123 1113, or through https://ico.org.uk/make-a-complaint/ . You may also have the right to complain to another competent data-protection authority if you are located outside the United Kingdom.

You can request deletion of your PokeAlerter account and associated PokeAlerter data using our dedicated online account deletion form:

https://pokealerter.com/delete-account

The deletion form asks for information needed to identify the relevant PokeAlerter account and verify the request. You may also contact privacy@pokealerter.com for other privacy or data-protection enquiries.

16. Account deletion

PokeAlerter provides a dedicated account-deletion request form at:

https://pokealerter.com/delete-account

The account-deletion form can be accessed through a normal web browser and does not require you to reinstall or open the PokeAlerter mobile app.

To help us identify the correct PokeAlerter account, the deletion form may request your contact email address, Discord username and, optionally, your Discord User ID and additional information relevant to identifying your account.

The deletion form also uses an anti-spam verification check to help prevent automated or abusive submissions. We will never ask you to provide your Discord password as part of an account-deletion request.

Once a deletion request has been received and verified, we will delete or anonymise PokeAlerter account data that is no longer required. This may include associated Discord account identifiers held by PokeAlerter, registered APNs or FCM device push tokens, saved alert-channel preferences, notification sound/preferences and PokeAlerter alert-history records.

Some information may be retained where necessary to comply with a legal obligation, prevent fraud or abuse, resolve disputes, maintain security, or establish, exercise or defend legal claims. Any retained information will be limited to what is necessary and retained only for the applicable period.

Submitting a PokeAlerter deletion request does not delete your Discord account, Whop account, Apple account or Google account. Those services are operated independently and requests relating to data held by those providers must be made directly to the relevant provider.

Account deletion is also separate from cancelling Premium membership. Premium billing and cancellation are handled through Whop. Requesting deletion of your PokeAlerter account/data does not automatically cancel a Whop subscription, and cancelling a Whop subscription does not by itself constitute a request to delete your PokeAlerter account data.

17. Third-party product links

PokeAlerter alerts may contain links to retailers or other third-party websites. If you follow a product link, the destination site receives the normal information associated with a web request and may use its own cookies, analytics or other technologies. PokeAlerter does not control the content, availability, privacy practices or purchasing processes of those third-party sites. You should review the destination site's privacy and cookie information before providing personal data or making a purchase.

18. Children

PokeAlerter is not intended for children under 13. Users must also satisfy the age and account requirements imposed by Discord, Whop and the relevant app store in their jurisdiction. If you are not legally able to enter into the applicable agreement on your own, you should use the Service only with the involvement and permission of a parent or legal guardian where permitted by the relevant services and law.

If we learn that we have collected personal data from a child in circumstances where we were not legally permitted to do so, we will take appropriate steps to delete it.

19. Changes to this Policy

We may update this Privacy Policy when the Service, technology, legal requirements or our data-processing practices change. We will update the "Last updated" date at the top of this Policy and, where required, provide additional notice or seek renewed consent.

Material changes that affect app data collection, sharing or tracking will also be reflected in the relevant Apple App Store privacy information and Google Play Data Safety disclosures where applicable.

20. Contact us

For privacy questions or data-protection rights requests, contact:

privacy@pokealerter.com

To request deletion of your PokeAlerter account and associated PokeAlerter data, use:

https://pokealerter.com/delete-account


Search