Skip to content
Rental Deal Analyzer

Privacy policy

Effective 2026-09-24. This policy covers Rental Deal Analyzer, the hosted service, run by Roger Booto Tokime (sole proprietor), referred to here as "we." If a local version is still distributed, that version sends nothing to us; this policy is about the hosted service.

Version
1.0.0
Last updated
2026-09-24

The short version

  • The free analysis runs on our servers. What you type is sent there, worked out, and sent back. We don't save it.
  • If you buy a report, The PDF is stored privately for 24 hours, counted from when your purchase completes. When that window ends, access ends immediately; an automated cleanup deletes the file soon after, though not always at the exact second.
  • Card details go to Stripe, our payment processor. They never reach our servers.
  • A one-off purchase needs no account and no sign-in. The checkout form asks for an email address, because Stripe needs one to confirm a payment; depending on your payment method, it may also ask for a billing name, country or postal code. All of it goes to Stripe, not to us.
  • We don't sell personal information, and we don't sell or share the listing content you upload.

Who is responsible

Roger Booto Tokime (sole proprietor), New Brunswick, Canada. This is a home-based, one-person business with no public mailing address; email is the fastest and most reliable way to reach us. Roger Booto Tokime is responsible for privacy here. Write to support@proofthedeal.com.

What we collect, and why

When you run an analysis (free)

The figures and listing details you enter go to our servers so the analysis can run. The result comes back to your browser. We don't store your inputs, and we don't write them to our logs.

In your browser

The form keeps what you type in it, so a reload doesn't lose it. It also keeps any deal you choose to save, and your light or dark setting. These stay in your browser until you delete them; we can't see them.

When you buy a report

  • Session cookie. Before you pay, we set one cookie that links this browser to your purchase. It contains nothing about you. It lasts 24 hours.
  • Payment. A one-off purchase needs no account and no sign-in. The checkout form asks for an email address, because Stripe needs one to confirm a payment; depending on your payment method, it may also ask for a billing name, country or postal code. All of it goes to Stripe, not to us. Stripe gives us whether the payment went through, the amount and currency, and its reference numbers. We never see or store your full card number.
  • Purchase record. With the payment, we ask Stripe to store a scrambled fingerprint of the report's inputs, the version of our software that made it, and the random session code. The fingerprint can't be turned back into your address or figures.
  • The PDF. The report includes what you entered, such as the property address and your figures. The PDF is stored privately for 24 hours, counted from when your purchase completes. When that window ends, access ends immediately; an automated cleanup deletes the file soon after, though not always at the exact second.
  • Download record. When a paid report is downloaded, we record which purchase it was for, when, and whether the whole file went out, along with what the request looked like: the IP address, the country, the browser's own description of itself, and Cloudflare's id for the request. It doesn't carry your name, your email address or the property address. It is how we can show a report was delivered if a payment is disputed later, and it is what a refund request is checked against. We keep it for 120 days, the usual window for a card dispute.

Operational logs

Our hosting providers record standard request data: IP address, time, the page or service requested, and the result. We use it to keep the service running and to stop abuse, for example rate limits. These logs are kept for 30 days.

What we don't do

We don't use analytics or advertising trackers. We don't sell personal information. We don't sell, license or share the listing content you upload, and we don't use it to train AI models. We don't build a profile of you.

Cookies

  • Session cookie — set by us, only when you start a purchase. Links this browser to what you bought. Lasts 24 hours.
  • Payment cookies — set by Stripe inside its own payment form, for payment security and fraud checks.

All are needed for the service to work. There are no advertising or tracking cookies.

Who processes data for us

  • Vercel — serves the website. Handles your requests, including what you type, in transit, and request logs.
  • Railway — runs the analysis and makes the PDF. Handles your inputs while the analysis runs, and request logs.
  • Cloudflare — private file storage (R2), and handing the paid PDF to your browser when you download it. Holds the stored file for 24 hours and records that the download happened.
  • Stripe — payments. Handles card and billing details and payment records. A one-off purchase needs no account and no sign-in. The checkout form asks for an email address, because Stripe needs one to confirm a payment; depending on your payment method, it may also ask for a billing name, country or postal code. All of it goes to Stripe, not to us.

Stripe also uses payment data for its own fraud prevention, under Stripe's own privacy policy. Vercel serves the website from Montreal, Canada. Railway, which runs the analysis and makes the PDF, runs in the United States. We haven't been able to confirm which region Cloudflare's R2 storage (where a paid PDF is held, and from which it is handed to your browser) runs in; until we can, treat that storage as potentially outside Canada too. Data processed outside Canada is subject to that country's laws.

How long we keep things

  • Your inputs, on our servers — not kept after the response.
  • Generated PDF — The PDF is stored privately for 24 hours, counted from when your purchase completes. When that window ends, access ends immediately; an automated cleanup deletes the file soon after, though not always at the exact second.
  • Download link — 60 seconds after it is made.
  • Session cookie — 24 hours.
  • Download record — 120 days, the usual window for a card dispute.
  • Payment records, in Stripe — kept by Stripe under its own financial record-keeping rules, not ours to set.
  • Hosting logs — 30 days.
  • Data in your browser — until you delete it.

Your choices and requests

You can see, correct or delete personal information we hold about you. Email support@proofthedeal.com. We answer within 30 days.

A one-off purchase has no account, so we may ask for something that ties you to the payment, such as the Stripe receipt number, or the date, amount and last four digits of the card.

Some records we must keep. Deleting a PDF doesn't delete the payment record Stripe keeps for tax and fraud rules. We can delete a PDF before its deadline if you ask.

You can clear what's kept in your browser yourself, on the Saved deals page or in your browser settings.

If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or the privacy regulator for your province.

Security

The PDF storage is private; no file is public. A download link is made only after we check your purchase. Each download link works for 60 seconds after it is made. A new link can be requested until the 24-hour window closes. Card details never touch our servers. No system is perfectly secure. If a breach puts you at real risk of significant harm, we'll tell you and the Privacy Commissioner, as the law requires.

Who this is for

The service is meant for people 18 or older. We don't knowingly collect personal information from anyone younger.

Changes

If this policy changes, we'll update the date at the top. If the change is significant, we'll say so on the site before it takes effect.