Legal

Privacy Policy

This policy explains what personal data Trafficore handles, why we handle it, how long we keep it, who else sees it, and what you can ask us to do about it. It also draws the line — an important one on a multi-tenant platform — between the data we decide about ourselves and the data our customers store with us.

Last updated: 31 August 2026 Effective from: 31 August 2026 Applies to: trafficore.io and the Trafficore platform

01 Introduction

Who we are

Trafficore is a software-as-a-service affiliate tracking platform published at trafficore.io, referred to in this policy as “Trafficore”, “we”, “us” or “our”.

The platform lets affiliate networks and advertisers publish offers, hand out tracking links, record clicks and conversions, route traffic by geo and device, and forward conversion data to the partner systems they choose. You can read what it does in detail at trafficore.io.

Why this policy exists

Privacy is not a footnote in a tracking product — it is the product. This policy is written to satisfy the General Data Protection Regulation (EU) 2016/679 (“GDPR”), which applies to us under Article 3(2) because we offer our services to people and organisations in the European Union and monitor behaviour that takes place there, even though we are established outside the EU. Where local law in your country gives you stronger protection than this policy describes, that local law wins.

What it covers

This policy applies whenever we decide why and how personal data is processed — when you browse our website, ask for a demo, open an account, or email us. It does not govern the data our customers load into their own workspaces; there we act on their instructions and their privacy policy applies. Section 3 explains that split, because on a multi-tenant platform it is the difference that matters most.

If you do not agree with this policy, please do not use the website or the platform.

How to reach us

Privacy enquiries
General support
Security reports

We are established outside the European Economic Area. Write to [email protected] with any question about this policy or any request under it — that address reaches the people who can act on it, and section 11 sets out how we handle such requests and how quickly.

02 Definitions

A handful of terms come up repeatedly. Anything not defined here carries the meaning given to it in our Terms of Service.

Controller
The party that decides why and how personal data is processed. For the data described in sections 4 and 5, that party is us.
Processor
A party that processes personal data on a controller's instructions rather than its own. For the data our customers store in their workspaces, that party is us.
Sub-processor
A supplier we engage to help run the platform — hosting, email delivery, payment processing, error monitoring — that may touch personal data in the course of doing so.
Customer
The organisation (or sole trader) that has an agreement with us to use Trafficore. Each Customer operates one or more Workspaces.
Workspace
A Customer's isolated instance of the platform, served on the domains the Customer provides and backed by its own separate database. Data in one Workspace is not visible from another.
Workspace Data
Everything a Customer puts into, or generates inside, its Workspace — offers, affiliate accounts, clicks, leads, conversions, payouts, integration settings. Some of it is personal data about people who are not our users at all.
Personal Data
Any information relating to an identified or identifiable natural person — directly (a name, an email address) or indirectly, by combining it with other data we hold (an IP address, a click identifier, a device fingerprint).
User / you
The natural person the personal data relates to: a visitor to our website, a person who contacts us, or a person who signs in to the platform.
Website
trafficore.io and its subdomains, excluding Customer Workspaces.

03 Our role: controller or processor

Trafficore sits in two different positions at once, and your rights depend on which one applies to you.

Where we are the controller

We decide the purpose and means of processing for the people we deal with directly: visitors to our website, prospects who request a demo, the individuals who administer a Customer account, and anyone who writes to our support or sales addresses. Sections 4 and 5 set out exactly what we hold about those people and why.

Where we are the processor

Each Customer gets its own Workspace, backed by its own database. Into it the Customer loads offers and affiliate accounts, and through it flows the traffic data the platform is built to record — clicks, and the form submissions and conversions those clicks lead to. Some of that is personal data about people who have no relationship with us at all: someone who filled in a form on a Customer's landing page, for instance.

For that data we are a processor. We do not decide what is collected, from whom, for what campaign, how long it is kept, or which advertiser endpoints it is forwarded to. The Customer configures all of that — including every third-party network integration and postback the platform supports. Our handling of it is governed by the Data Processing Agreement we sign with that Customer, and by the instructions they give us under it.

If your data reached us through one of our customers — you submitted a form on their landing page, or you hold an affiliate account inside their Workspace — then that customer is the controller, not us. Please direct your access, correction or deletion request to them. If you send it to us instead, we will pass it on to the relevant Customer and support them in answering it, but we are not permitted to act on it ourselves.

Two further clarifications

  • We are not responsible for what our Customers collect. The lawful basis for gathering lead data, the notices shown on landing pages, and the choice of advertiser destinations are the Customer's responsibility under our Terms of Service and the DPA.
  • Company data is not personal data. If you deal with us as a legal entity rather than as an individual, the GDPR does not treat your corporate details as personal data and this policy does not apply to them. We still hold them under the confidentiality obligations in our agreement with you.

04 Data we process — website visitors

You can read almost everything on trafficore.io without telling us who you are. What we do collect when you visit, and why, is set out below.

Processing carried out when you browse trafficore.io
Purpose Legal basis Data Retention
Serving the website and remembering your choices — language, referral attribution, keeping a form submission safe from cross-site request forgery. Legitimate interestArt. 6(1)(f) Strictly necessary and preference cookies; see the cookie table in section 12. Per cookie — see section 12.
Understanding which pages are read, which features people look for, and where visitors drop off, so we can improve the product and the site. ConsentArt. 6(1)(a) Analytics cookie identifiers, pages viewed, time on page, referring site, approximate location derived from IP, device type, browser and language. Up to 14 months from your last visit.
Keeping the site up: detecting and blocking scraping, credential stuffing, denial-of-service and other abuse. Legitimate interestArt. 6(1)(f) Server logs — IP address, timestamp, requested URL, response status, user agent. 30 days, unless a log is preserved longer as evidence of a specific incident.
Answering a demo request, pricing question or other enquiry that could lead to a contract with us. Pre-contractual stepsArt. 6(1)(b) Name, work email, company, phone if you give it, and whatever you write in the message or tell us on a call. Deleted no later than 24 months after our last contact, if no contract follows.
Answering enquiries that are not about becoming a customer — press, partnerships, security reports, job applications. Legitimate interestArt. 6(1)(f) Name, email, and the content of the correspondence. 24 months from the last message in the thread.

Where we rely on legitimate interest, we have weighed our interest against your rights and concluded the processing is proportionate and within what you would reasonably expect. You can object at any time — see section 11 — and we will stop unless we can show compelling grounds that override your objection.

05 Data we process — customers and platform users

Once you open a trial or sign a contract, we process the data we need to run your account, bill you, support you, and keep the platform secure. This section covers your data as an account holder. It does not cover the traffic and lead data inside your Workspace — for that, see section 3.

Processing carried out when you hold or administer a Trafficore account
Purpose Legal basis Data Retention
Setting up and running a free trial or demo workspace so you can evaluate the platform. Pre-contractual stepsArt. 6(1)(b) Name, email, company, chosen workspace name, sign-up time, and the actions you take in the trial. For the trial plus 90 days. If you convert to a paid plan, the row below applies instead.
Creating and maintaining your account and Workspace: authentication, roles and permissions, team members, the domains you point at us, notification settings. Performance of contractArt. 6(1)(b) Name, email, phone, password (stored only as a salted hash), two-factor secrets, role assignments, profile and locale settings, sign-in history, API tokens you issue. For the term of the agreement, plus 90 days afterwards so you can export your data. Then deleted or irreversibly anonymised.
Taking payment, managing your subscription, issuing invoices and handling dunning. Performance of contractArt. 6(1)(b) Billing entity name and address, tax identifiers, plan and invoice history, and a payment-method token held by our payment provider. We never store full card numbers. For the term of the agreement, then as long as tax law requires (see below).
Providing support: answering tickets, investigating reported issues, and — only when you ask us to look into something — inspecting the relevant records in your Workspace. Performance of contractArt. 6(1)(b) Correspondence, ticket metadata, and access logs recording which of our staff opened what, and when. 24 months after the ticket is closed.
Keeping the platform available and secure: rate limiting, abuse detection, error diagnosis, capacity planning and performance work. Legitimate interestArt. 6(1)(f) API and panel request logs, error traces and stack context, IP addresses used to sign in, feature usage counters. 12 months.
Sending service messages you cannot opt out of — security alerts, billing notices, breaking changes, scheduled maintenance. Performance of contractArt. 6(1)(b) Name, email, and delivery metadata. For the term of the agreement.
Sending product news and occasional marketing about features we think you will use. ConsentArt. 6(1)(a) Name, email, and whether you opened or clicked. Until you unsubscribe — every message carries a one-click link.
Meeting accounting, tax and other statutory obligations. Legal obligationArt. 6(1)(c) Invoicing and payment records. The period the applicable law prescribes — typically 7 to 10 years from the end of the financial year in which the transaction fell.
Establishing, exercising or defending legal claims, and responding to audits and regulators. Legitimate interestArt. 6(1)(f) Contract records, billing history and the correspondence relevant to the matter. Until the applicable limitation period expires, plus one year to allow for a late claim.

Data we do not want

We do not process special categories of personal data about you — health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — and we do not ask for them anywhere in the product. Our Terms of Service prohibit Customers from loading special-category data into a Workspace. If you believe such data has ended up in the platform, tell us at [email protected] and we will work with the responsible Customer to remove it.

06 Who we share data with

We do not sell personal data, and we do not share it with third parties for their own advertising. The disclosures we do make fall into five buckets.

Sub-processors

Running a platform of this kind means relying on specialist suppliers: cloud hosting and managed databases, transactional email delivery, payment processing, error and uptime monitoring, and the tooling our support team uses. Each is engaged under a written contract that binds them to confidentiality, to process only on our instructions, to apply security measures at least equivalent to ours, and to accept audit. A current list of our sub-processors is available on request from [email protected], and Customers are notified before we add a new one.

Our people

Employees and contractors see personal data only where their role requires it, under least-privilege access that is logged, and under confidentiality obligations that survive the end of their engagement.

Destinations you configure

This one is specific to what Trafficore does, and Customers should read it carefully. When you connect an integration, add a webhook, or set a postback URL, the platform sends the fields you have mapped to the endpoint you have specified — an advertiser, a CPA network, a CRM, your own server. Those transfers happen on your instruction. Choosing the destination, mapping the fields, and having a lawful basis for sending personal data there are your responsibility as controller. We do not add recipients of our own.

Legal obligations

We may disclose personal data where we are legally required to: a binding order from a court or a competent authority, a statutory reporting duty, or the defence of a legal claim. We assess every request for validity and scope, disclose no more than is necessary, and — unless the law forbids it — tell the affected Customer or individual before we comply.

Corporate transactions

If we are involved in a merger, acquisition, financing or sale of assets, personal data may be disclosed to the counterparty and its advisers under confidentiality, and may transfer as part of the transaction. Any acquirer remains bound by this policy until you are notified of a replacement.

07 International transfers

We are established outside the European Economic Area, and our infrastructure and sub-processors sit in more than one country. So personal data covered by the GDPR will, in the ordinary course of using the platform, leave the EEA.

Where the destination country has an adequacy decision from the European Commission, that decision is the basis for the transfer. Where it does not, we rely on the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), concluded with each recipient, together with the supplementary measures our transfer impact assessments identify as necessary — in practice, encryption in transit and at rest, strict access control, data minimisation before transfer, and a commitment to challenge disproportionate government access requests.

For UK personal data we use the UK International Data Transfer Addendum to those clauses; for Swiss data, the Swiss annex. You can request a copy of the safeguards that apply to a specific transfer by writing to [email protected].

Customers who need data residency in a particular region should raise it with us before signing, so we can tell them what is possible.

08 Minors

Trafficore is a business tool. It is offered only to people aged 18 or over, and we do not knowingly process the personal data of children. If we learn that we hold data about someone under 18 without a valid basis, we will delete it promptly. If you are a parent or guardian and believe that has happened, write to [email protected] and we will act on it.

09 Do we really need it?

We try to hold the least data that will do the job. Sign-up asks for a name, an email address and a workspace name; billing details are collected only when you start paying; nothing in the product asks for personal information it does not use. Analytics data is aggregated wherever aggregation answers the question.

Some data is genuinely unavoidable — we cannot authenticate you without an identifier, or invoice you without billing details. If you would rather not provide it, the consequence is simply that you cannot use the corresponding part of the service. Optional fields are marked as optional, and leaving them blank costs you nothing.

10 Security

We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. What that means in practice:

Technical measures

  • Encryption in transit. Every connection to the website, the platform and our APIs runs over HTTPS with modern TLS. Plain HTTP is redirected, never served.
  • Encryption at rest. Databases, file storage and backups are encrypted on disk.
  • Tenant isolation. Each Customer's Workspace has its own database rather than a shared table filtered by a tenant column. Cross-tenant leakage is prevented by the storage architecture, not only by application logic.
  • Credential handling. Passwords are stored only as salted hashes and are never recoverable in plaintext, by us or by anyone else. API access uses bearer tokens you can revoke at any time.
  • Access control inside the product. Optional two-factor authentication, and granular role-based permissions so that owners, admins, managers, media buyers, accountants and advertisers each see only what their role needs.
  • Backups. Automated daily backups, held encrypted, with restores exercised periodically rather than assumed to work.
  • Maintenance. Infrastructure and dependencies are patched on a regular cycle; changes to production code pass review and an automated test suite before release.
  • Monitoring. Rate limiting, anomaly detection and alerting on the paths that matter — authentication, billing and data export.

Organisational measures

  • Confidentiality. Every employee and contractor is bound by confidentiality obligations that outlast their engagement.
  • Least privilege. Production access is granted by role, reviewed periodically, revoked on departure, and logged when used.
  • Logging. Access to personal data, and changes and deletions, are recorded and retained so that an incident can be reconstructed after the fact.
  • Training. Staff receive regular data protection and security training, including phishing and social-engineering awareness.
  • Incident response. We maintain a documented procedure. Where we act as processor, we notify affected Customers without undue delay so they can meet their own deadlines. Where we act as controller, we notify the competent supervisory authority within 72 hours of becoming aware of a notifiable breach, and notify affected individuals where the risk to them is high.
  • Supplier review. Sub-processors are assessed before engagement and re-reviewed periodically.

No method of transmission or storage is completely secure, and we will not pretend otherwise. Please use a strong, unique password, turn on two-factor authentication, keep your API tokens out of shared documents and client-side code, and revoke access for team members who leave. If you find a vulnerability, report it to [email protected] — we will not pursue researchers who act in good faith.

11 Your rights

Where we act as controller, you have the following rights over your personal data. They are not conditional on being a paying customer.

  • Access. Ask whether we process data about you and, if so, get a copy of it along with the details in this policy applied to your specific case.
  • Rectification. Have inaccurate data corrected and incomplete data completed. Most account fields you can edit yourself in the panel at any time.
  • Erasure. Ask us to delete your data where it is no longer needed, where you withdraw the consent it rested on, or where you successfully object — subject to records we are legally required to keep, such as invoices.
  • Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, or have us transmit it to another controller where technically feasible.
  • Objection. Object to processing based on our legitimate interests, including profiling based on them. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Objection to direct marketing is absolute — we stop, no balancing test.
  • Withdrawal of consent. Where processing rests on consent — analytics cookies, marketing email — you may withdraw it at any time. Withdrawal does not affect the lawfulness of what we did before.
  • Complaint. Lodge a complaint with a supervisory authority. As we are established outside the EEA, the competent authority is the one in your country of residence, your place of work, or the place where the alleged infringement occurred. UK residents may complain to the Information Commissioner's Office at ico.org.uk.

No automated decision-making

We do not make decisions about you solely by automated means that produce legal effects concerning you or similarly significantly affect you. The platform's traffic-quality and fraud signals operate on campaign and traffic-source metrics and are reviewed by people before any account action is taken.

How to exercise a right

Email [email protected] with your full name, the contact details we hold for you, and what you want us to do. If we cannot identify you from that, we will ask for the minimum extra information needed to verify it — we would rather ask than hand your data to someone else. If you are submitting a request on someone else's behalf, please include proof of your authority.

We respond to valid requests within one month. If a request is complex, or you send several at once, we may extend that by up to two further months; we will tell you within the first month, and explain why. Requests are free. If one is manifestly unfounded, excessive or repetitive, we may charge a reasonable administrative fee or decline it — and if we decline, we will say so, give our reasons, and tell you how to challenge the decision.

If your data lives inside a Customer's Workspace, see the note in section 3: the Customer, not us, is the one who can act on your request.

12 Cookies

A cookie is a small file the site stores on your device and reads back on your next request. We use them sparingly, in three categories. Strictly necessary cookies make sign-in and form security work and are set without consent because the service cannot function without them. Preference cookies remember choices you made. Analytics cookies are set only if you agree. We do not set advertising or cross-site tracking cookies on our own website.

Cookies set on trafficore.io and the platform
Name Category Purpose Expires
trafficore_session Strictly necessary Ties your requests to a server-side session so you stay signed in as you move between pages. The exact name follows the deployment's application name. 2 hours of inactivity
XSRF-TOKEN Strictly necessary Carries the cross-site request forgery token that proves a form submission came from our own pages. 2 hours of inactivity
remember_web_* Strictly necessary Set only if you tick “remember me” at sign-in, so you are not asked for credentials on every visit. 5 years, or until you sign out
locale Preference Remembers the interface language you picked, so a visitor who switched language still gets it on the next visit. 5 years
referral Preference Records which partner referred you, so a referral is credited to the right account if you later sign up. Contains a partner key, not information about you. 5 years
_ga, _ga_<id> Analytics Google Analytics. Distinguishes one visitor from another and measures how the site is used. Set only with your consent. 2 years

Third-party content

Our pages load web fonts from Google Fonts. Doing so discloses your IP address to Google as the request is made, under Google's own privacy terms. Where we embed anything else — a scheduling widget, a video, a status page — we say so at the point of embedding.

Your choices

You can change or withdraw your cookie consent at any time using the cookie settings control on our site, and you can block or delete cookies in your browser. Blocking strictly necessary cookies will prevent you from signing in; blocking analytics cookies costs you nothing.

Note for the site owner: the statements above — that analytics cookies are set only after consent, and that a cookie settings control exists — describe the compliant target state. The landing page currently loads Google Analytics unconditionally and has no consent banner. Ship a consent banner that gates the gtag.js tag, or remove Analytics, before publishing this policy. Delete this note once that is done.

13 Changes to this policy

We amend this policy only in writing, and the version published here is always the one in force. The “last updated” date at the top tells you when it last changed.

For minor edits — clarified wording, a new sub-processor category, a corrected address — publication here is the notice. For changes that materially affect how we handle your data or narrow your rights, we will tell account holders by email at least 30 days before the change takes effect, so you have time to object, export your data, or end the agreement. Where a change requires your consent, we will ask for it rather than assume it.

Continuing to use the website or the platform after a change takes effect means you accept the updated policy. It is worth re-reading this page occasionally; we keep previous versions and will send you one on request.

Questions about this policy
This version
Effective 31 August 2026