01 Introduction
Who we are
Trafficore is a software-as-a-service affiliate tracking platform published at trafficore.io, referred to in this policy as “Trafficore”, “we”, “us” or “our”.
The platform lets affiliate networks and advertisers publish offers, hand out tracking links, record clicks and conversions, route traffic by geo and device, and forward conversion data to the partner systems they choose. You can read what it does in detail at trafficore.io.
Why this policy exists
Privacy is not a footnote in a tracking product — it is the product. This policy is written to satisfy the General Data Protection Regulation (EU) 2016/679 (“GDPR”), which applies to us under Article 3(2) because we offer our services to people and organisations in the European Union and monitor behaviour that takes place there, even though we are established outside the EU. Where local law in your country gives you stronger protection than this policy describes, that local law wins.
What it covers
This policy applies whenever we decide why and how personal data is processed — when you browse our website, ask for a demo, open an account, or email us. It does not govern the data our customers load into their own workspaces; there we act on their instructions and their privacy policy applies. Section 3 explains that split, because on a multi-tenant platform it is the difference that matters most.
If you do not agree with this policy, please do not use the website or the platform.
How to reach us
We are established outside the European Economic Area. Write to [email protected] with any question about this policy or any request under it — that address reaches the people who can act on it, and section 11 sets out how we handle such requests and how quickly.
02 Definitions
A handful of terms come up repeatedly. Anything not defined here carries the meaning given to it in our Terms of Service.
- Controller
- The party that decides why and how personal data is processed. For the data described in sections 4 and 5, that party is us.
- Processor
- A party that processes personal data on a controller's instructions rather than its own. For the data our customers store in their workspaces, that party is us.
- Sub-processor
- A supplier we engage to help run the platform — hosting, email delivery, payment processing, error monitoring — that may touch personal data in the course of doing so.
- Customer
- The organisation (or sole trader) that has an agreement with us to use Trafficore. Each Customer operates one or more Workspaces.
- Workspace
- A Customer's isolated instance of the platform, served on the domains the Customer provides and backed by its own separate database. Data in one Workspace is not visible from another.
- Workspace Data
- Everything a Customer puts into, or generates inside, its Workspace — offers, affiliate accounts, clicks, leads, conversions, payouts, integration settings. Some of it is personal data about people who are not our users at all.
- Personal Data
- Any information relating to an identified or identifiable natural person — directly (a name, an email address) or indirectly, by combining it with other data we hold (an IP address, a click identifier, a device fingerprint).
- User / you
- The natural person the personal data relates to: a visitor to our website, a person who contacts us, or a person who signs in to the platform.
- Website
- trafficore.io and its subdomains, excluding Customer Workspaces.
03 Our role: controller or processor
Trafficore sits in two different positions at once, and your rights depend on which one applies to you.
Where we are the controller
We decide the purpose and means of processing for the people we deal with directly: visitors to our website, prospects who request a demo, the individuals who administer a Customer account, and anyone who writes to our support or sales addresses. Sections 4 and 5 set out exactly what we hold about those people and why.
Where we are the processor
Each Customer gets its own Workspace, backed by its own database. Into it the Customer loads offers and affiliate accounts, and through it flows the traffic data the platform is built to record — clicks, and the form submissions and conversions those clicks lead to. Some of that is personal data about people who have no relationship with us at all: someone who filled in a form on a Customer's landing page, for instance.
For that data we are a processor. We do not decide what is collected, from whom, for what campaign, how long it is kept, or which advertiser endpoints it is forwarded to. The Customer configures all of that — including every third-party network integration and postback the platform supports. Our handling of it is governed by the Data Processing Agreement we sign with that Customer, and by the instructions they give us under it.
If your data reached us through one of our customers — you submitted a form on their landing page, or you hold an affiliate account inside their Workspace — then that customer is the controller, not us. Please direct your access, correction or deletion request to them. If you send it to us instead, we will pass it on to the relevant Customer and support them in answering it, but we are not permitted to act on it ourselves.
Two further clarifications
- We are not responsible for what our Customers collect. The lawful basis for gathering lead data, the notices shown on landing pages, and the choice of advertiser destinations are the Customer's responsibility under our Terms of Service and the DPA.
- Company data is not personal data. If you deal with us as a legal entity rather than as an individual, the GDPR does not treat your corporate details as personal data and this policy does not apply to them. We still hold them under the confidentiality obligations in our agreement with you.
04 Data we process — website visitors
You can read almost everything on trafficore.io without telling us who you are. What we do collect when you visit, and why, is set out below.
| Purpose | Legal basis | Data | Retention |
|---|---|---|---|
| Serving the website and remembering your choices — language, referral attribution, keeping a form submission safe from cross-site request forgery. | Legitimate interestArt. 6(1)(f) | Strictly necessary and preference cookies; see the cookie table in section 12. | Per cookie — see section 12. |
| Understanding which pages are read, which features people look for, and where visitors drop off, so we can improve the product and the site. | Art. 6(1)(a) | Analytics cookie identifiers, pages viewed, time on page, referring site, approximate location derived from IP, device type, browser and language. | Up to 14 months from your last visit. |
| Keeping the site up: detecting and blocking scraping, credential stuffing, denial-of-service and other abuse. | Legitimate interestArt. 6(1)(f) | Server logs — IP address, timestamp, requested URL, response status, user agent. | 30 days, unless a log is preserved longer as evidence of a specific incident. |
| Answering a demo request, pricing question or other enquiry that could lead to a contract with us. | Pre-contractual stepsArt. 6(1)(b) | Name, work email, company, phone if you give it, and whatever you write in the message or tell us on a call. | Deleted no later than 24 months after our last contact, if no contract follows. |
| Answering enquiries that are not about becoming a customer — press, partnerships, security reports, job applications. | Legitimate interestArt. 6(1)(f) | Name, email, and the content of the correspondence. | 24 months from the last message in the thread. |
Where we rely on legitimate interest, we have weighed our interest against your rights and concluded the processing is proportionate and within what you would reasonably expect. You can object at any time — see section 11 — and we will stop unless we can show compelling grounds that override your objection.
05 Data we process — customers and platform users
Once you open a trial or sign a contract, we process the data we need to run your account, bill you, support you, and keep the platform secure. This section covers your data as an account holder. It does not cover the traffic and lead data inside your Workspace — for that, see section 3.
| Purpose | Legal basis | Data | Retention |
|---|---|---|---|
| Setting up and running a free trial or demo workspace so you can evaluate the platform. | Pre-contractual stepsArt. 6(1)(b) | Name, email, company, chosen workspace name, sign-up time, and the actions you take in the trial. | For the trial plus 90 days. If you convert to a paid plan, the row below applies instead. |
| Creating and maintaining your account and Workspace: authentication, roles and permissions, team members, the domains you point at us, notification settings. | Performance of contractArt. 6(1)(b) | Name, email, phone, password (stored only as a salted hash), two-factor secrets, role assignments, profile and locale settings, sign-in history, API tokens you issue. | For the term of the agreement, plus 90 days afterwards so you can export your data. Then deleted or irreversibly anonymised. |
| Taking payment, managing your subscription, issuing invoices and handling dunning. | Performance of contractArt. 6(1)(b) | Billing entity name and address, tax identifiers, plan and invoice history, and a payment-method token held by our payment provider. We never store full card numbers. | For the term of the agreement, then as long as tax law requires (see below). |
| Providing support: answering tickets, investigating reported issues, and — only when you ask us to look into something — inspecting the relevant records in your Workspace. | Performance of contractArt. 6(1)(b) | Correspondence, ticket metadata, and access logs recording which of our staff opened what, and when. | 24 months after the ticket is closed. |
| Keeping the platform available and secure: rate limiting, abuse detection, error diagnosis, capacity planning and performance work. | Legitimate interestArt. 6(1)(f) | API and panel request logs, error traces and stack context, IP addresses used to sign in, feature usage counters. | 12 months. |
| Sending service messages you cannot opt out of — security alerts, billing notices, breaking changes, scheduled maintenance. | Performance of contractArt. 6(1)(b) | Name, email, and delivery metadata. | For the term of the agreement. |
| Sending product news and occasional marketing about features we think you will use. | Art. 6(1)(a) | Name, email, and whether you opened or clicked. | Until you unsubscribe — every message carries a one-click link. |
| Meeting accounting, tax and other statutory obligations. | Legal obligationArt. 6(1)(c) | Invoicing and payment records. | The period the applicable law prescribes — typically 7 to 10 years from the end of the financial year in which the transaction fell. |
| Establishing, exercising or defending legal claims, and responding to audits and regulators. | Legitimate interestArt. 6(1)(f) | Contract records, billing history and the correspondence relevant to the matter. | Until the applicable limitation period expires, plus one year to allow for a late claim. |
Data we do not want
We do not process special categories of personal data about you — health, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — and we do not ask for them anywhere in the product. Our Terms of Service prohibit Customers from loading special-category data into a Workspace. If you believe such data has ended up in the platform, tell us at [email protected] and we will work with the responsible Customer to remove it.
07 International transfers
We are established outside the European Economic Area, and our infrastructure and sub-processors sit in more than one country. So personal data covered by the GDPR will, in the ordinary course of using the platform, leave the EEA.
Where the destination country has an adequacy decision from the European Commission, that decision is the basis for the transfer. Where it does not, we rely on the Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), concluded with each recipient, together with the supplementary measures our transfer impact assessments identify as necessary — in practice, encryption in transit and at rest, strict access control, data minimisation before transfer, and a commitment to challenge disproportionate government access requests.
For UK personal data we use the UK International Data Transfer Addendum to those clauses; for Swiss data, the Swiss annex. You can request a copy of the safeguards that apply to a specific transfer by writing to [email protected].
Customers who need data residency in a particular region should raise it with us before signing, so we can tell them what is possible.
08 Minors
Trafficore is a business tool. It is offered only to people aged 18 or over, and we do not knowingly process the personal data of children. If we learn that we hold data about someone under 18 without a valid basis, we will delete it promptly. If you are a parent or guardian and believe that has happened, write to [email protected] and we will act on it.
09 Do we really need it?
We try to hold the least data that will do the job. Sign-up asks for a name, an email address and a workspace name; billing details are collected only when you start paying; nothing in the product asks for personal information it does not use. Analytics data is aggregated wherever aggregation answers the question.
Some data is genuinely unavoidable — we cannot authenticate you without an identifier, or invoice you without billing details. If you would rather not provide it, the consequence is simply that you cannot use the corresponding part of the service. Optional fields are marked as optional, and leaving them blank costs you nothing.
10 Security
We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. What that means in practice:
Technical measures
- Encryption in transit. Every connection to the website, the platform and our APIs runs over HTTPS with modern TLS. Plain HTTP is redirected, never served.
- Encryption at rest. Databases, file storage and backups are encrypted on disk.
- Tenant isolation. Each Customer's Workspace has its own database rather than a shared table filtered by a tenant column. Cross-tenant leakage is prevented by the storage architecture, not only by application logic.
- Credential handling. Passwords are stored only as salted hashes and are never recoverable in plaintext, by us or by anyone else. API access uses bearer tokens you can revoke at any time.
- Access control inside the product. Optional two-factor authentication, and granular role-based permissions so that owners, admins, managers, media buyers, accountants and advertisers each see only what their role needs.
- Backups. Automated daily backups, held encrypted, with restores exercised periodically rather than assumed to work.
- Maintenance. Infrastructure and dependencies are patched on a regular cycle; changes to production code pass review and an automated test suite before release.
- Monitoring. Rate limiting, anomaly detection and alerting on the paths that matter — authentication, billing and data export.
Organisational measures
- Confidentiality. Every employee and contractor is bound by confidentiality obligations that outlast their engagement.
- Least privilege. Production access is granted by role, reviewed periodically, revoked on departure, and logged when used.
- Logging. Access to personal data, and changes and deletions, are recorded and retained so that an incident can be reconstructed after the fact.
- Training. Staff receive regular data protection and security training, including phishing and social-engineering awareness.
- Incident response. We maintain a documented procedure. Where we act as processor, we notify affected Customers without undue delay so they can meet their own deadlines. Where we act as controller, we notify the competent supervisory authority within 72 hours of becoming aware of a notifiable breach, and notify affected individuals where the risk to them is high.
- Supplier review. Sub-processors are assessed before engagement and re-reviewed periodically.
No method of transmission or storage is completely secure, and we will not pretend otherwise. Please use a strong, unique password, turn on two-factor authentication, keep your API tokens out of shared documents and client-side code, and revoke access for team members who leave. If you find a vulnerability, report it to [email protected] — we will not pursue researchers who act in good faith.
11 Your rights
Where we act as controller, you have the following rights over your personal data. They are not conditional on being a paying customer.
- Access. Ask whether we process data about you and, if so, get a copy of it along with the details in this policy applied to your specific case.
- Rectification. Have inaccurate data corrected and incomplete data completed. Most account fields you can edit yourself in the panel at any time.
- Erasure. Ask us to delete your data where it is no longer needed, where you withdraw the consent it rested on, or where you successfully object — subject to records we are legally required to keep, such as invoices.
- Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, or have us transmit it to another controller where technically feasible.
- Objection. Object to processing based on our legitimate interests, including profiling based on them. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Objection to direct marketing is absolute — we stop, no balancing test.
- Withdrawal of consent. Where processing rests on consent — analytics cookies, marketing email — you may withdraw it at any time. Withdrawal does not affect the lawfulness of what we did before.
- Complaint. Lodge a complaint with a supervisory authority. As we are established outside the EEA, the competent authority is the one in your country of residence, your place of work, or the place where the alleged infringement occurred. UK residents may complain to the Information Commissioner's Office at ico.org.uk.
No automated decision-making
We do not make decisions about you solely by automated means that produce legal effects concerning you or similarly significantly affect you. The platform's traffic-quality and fraud signals operate on campaign and traffic-source metrics and are reviewed by people before any account action is taken.
How to exercise a right
Email [email protected] with your full name, the contact details we hold for you, and what you want us to do. If we cannot identify you from that, we will ask for the minimum extra information needed to verify it — we would rather ask than hand your data to someone else. If you are submitting a request on someone else's behalf, please include proof of your authority.
We respond to valid requests within one month. If a request is complex, or you send several at once, we may extend that by up to two further months; we will tell you within the first month, and explain why. Requests are free. If one is manifestly unfounded, excessive or repetitive, we may charge a reasonable administrative fee or decline it — and if we decline, we will say so, give our reasons, and tell you how to challenge the decision.
If your data lives inside a Customer's Workspace, see the note in section 3: the Customer, not us, is the one who can act on your request.
13 Changes to this policy
We amend this policy only in writing, and the version published here is always the one in force. The “last updated” date at the top tells you when it last changed.
For minor edits — clarified wording, a new sub-processor category, a corrected address — publication here is the notice. For changes that materially affect how we handle your data or narrow your rights, we will tell account holders by email at least 30 days before the change takes effect, so you have time to object, export your data, or end the agreement. Where a change requires your consent, we will ask for it rather than assume it.
Continuing to use the website or the platform after a change takes effect means you accept the updated policy. It is worth re-reading this page occasionally; we keep previous versions and will send you one on request.