Privacy Policy
Effective 25 September 2026. Applies to theunideals.com, The Uni Deals apps on iOS and Android, and the Shopify app and WooCommerce plugin we publish for merchants. The Uni Deals is operated by Avenith, a company registered in Pakistan.
The Uni Deals exists to get real discounts to real students, and that only works if you trust us with a little of your information. This page explains, in plain language, what we collect, why we collect it, and how you stay in control of it.
What we collect
We keep the list short on purpose.
- Your email address and a random account identifier, so we can sign you in, send one-time login codes, and keep your account separate from other accounts.
- Your university email, claimed university, degree, graduation date, and verification status when you provide them for student verification. Your name is optional.
- A photo of your student ID or other proof of enrollment, but only if you choose photo verification. A member of our team reviews it manually. We delete an approved image from object storage after the decision. If a submission is not approved, the image remains linked to its verification record until you delete your account.
- When you arrive through one of our campaign links, the site counts the visit for that link without storing any personal data, and if you sign up, the campaign tag you arrived with is saved with your account.
- The offers you save, the discount codes you choose to reveal, and the date, offer, brand, store branch, and redemption path recorded when you redeem online or in store. We use these records to show your history, prevent code reuse, and operate the service.
What we don't do
- We don't sell your personal data to anyone.
- We don't run ad trackers on the site or in the apps.
- We don't currently use any third-party analytics tools.
- We don't read your contacts or collect your device's precise or approximate location.
- We don't show third-party ads or use advertising identifiers.
If any of that changes, we'll update this policy first.
Where your data lives
Your account details, verification records, saved offers, redemption records, and any proof image still waiting in storage live on Cloudflare's infrastructure. We don't run separate application servers or hand this data to another hosting provider.
The apps keep your signed-in session token on your own device using iOS Keychain or Android encrypted storage.
Cloudflare and, when configured as our email fallback, Amazon Web Services process data on our behalf to host the service and deliver transactional email. An email provider receives the destination address and message content needed for delivery.
How you sign in
The Uni Deals doesn't use passwords. When you sign in, we email you a one-time code that expires quickly. Only you can act on it from your inbox, so keeping your email account secure keeps your account with The Uni Deals secure too.
Deleting your account and your data
You're free to leave at any time.
- In the app, go to Profile and tap Delete account.
- Or email hello@theunideals.com and we'll do it for you.
Deleting your account removes your account record, saved offers, verification history, visible redemption history, and any student ID or proof image we still have on file. A pooled discount code that was already assigned may remain marked as used without an active account record so it cannot be issued again. This is permanent, and we can't undo it once it's done.
How long we keep your data
We keep your account, verification, saved-offer, and redemption information while your account is active. An approved proof image is deleted from object storage after the decision. A rejected proof image stays with its verification record until account deletion. If you delete your account, we remove the data described above promptly, except where we must keep limited records by law or keep a used pooled code from being issued again.
Who this is for
The Uni Deals is built for university students in Pakistan aged 16 and over. We don't knowingly collect data from anyone younger, and if we learn that we have, we'll delete it.
If you are a brand using our integrations
The Shopify app, the WooCommerce plugin, and the checkout widget each send us less than a partner portal login does, and none of them sends us anything about your customers as people.
- The Shopify app stores your shop domain, an encrypted access token, and a table of the discount codes it has minted, each recorded against the shop and offer it belongs to. Uninstalling the app deletes all of this on our side.
- The WooCommerce plugin sends your partner key and a discount code to confirm that the code is real and read the discount it carries. If you leave order reporting on, it also sends the order id, the code, the subtotal, and the currency for an order that used a student code.
- The checkout widget sends the same handful of fields when a store calls its order-reporting function directly on its own thank-you page: an order id, a discount code, a subtotal, and a currency.
None of these integrations ever sends us a customer's name, email address, or postal address. We don't ask for them, and there is nowhere in any of these integrations to put them.
We prune minted-code records after 90 days. Order records, the small set of fields listed above, are kept for invoicing.
Changes to this policy
If we change how we handle your data, we'll update this page and move the effective date above. We won't make a material change without making it easy to notice.
Contact us
Questions, concerns, or a deletion request that isn't covered above? Email hello@theunideals.com and a person will get back to you.
This policy is governed by the laws of Pakistan.