Privacy Policy

Last updated: May 18, 2026

The AffPixel service ("Service") is operated by Cao Cu Quoc Cuong ("we"), which is the data controller for the personal data described in this policy.

1. Data we collect

  • Account information: email, encrypted password, display name.
  • Postback data received from affiliate networks: order ID, conversion value, sub_id, click ID (fbclid, gclid, ttclid).
  • Payment information processed by a third-party partner (Paddle). We do not store card numbers.
  • Technical logs: IP address, user-agent, access time for security and anti-abuse purposes.

2. Purposes & legal basis

  • Provide and operate the Service, forward conversions according to your configuration — basis: contract performance.
  • Send transactional emails (invoices, technical alerts, plan changes) — basis: contract performance.
  • Security, fraud detection, technical logging — basis: legitimate interests.
  • Compliance with legal obligations (accounting, tax, requests from authorities) — basis: legal obligation.
  • Email marketing (if any) — basis: consent, you can withdraw at any time.

3. Data sharing

We do not sell personal data. Data is only shared with:

  • Infrastructure providers (hosting, database) under data processing and security agreements.
  • Paddle.com Market Limited — our Merchant of Record, processing payments, managing subscriptions, invoices, and tax compliance.
  • Advertising platforms (Google, Meta, TikTok) according to your set configuration.
  • Professional advisors (legal, accounting) when necessary.
  • Law enforcement agencies when legally required.

4. Data retention

  • Account data: stored for the duration of the account's activity and 30 days after account closure, then deleted or anonymized.
  • Postback / conversion data: stored for a maximum of 13 months for reporting and reconciliation.
  • Technical and security logs: stored for a maximum of 90 days
  • Invoices and payment documents: stored according to legal accounting requirements (minimum 10 years).

5. Cookies

We use technical cookies (session, login) and localStorage to store settings (language, timezone). We do not use third-party advertising cookies.

6. Your rights

Depending on the applicable law, you have the right to: access, correct, delete, restrict processing, data portability, object to processing, withdraw consent, and lodge a complaint with a competent data supervisory authority. To exercise these rights, please contact us through the Contact page. We respond within 30 days.

7. Security

Data is transmitted over HTTPS, passwords are hashed, and tokens are stored encrypted. Database access is restricted by Row-Level Security and role-based access control.

8. Policy changes

Any changes will be posted on this page. Continued use of the Service after the policy changes signifies your acceptance of the new policy.

9. Advertising & Google Ads data

When you use AffPixel to measure Google Ads campaigns, we process advertising data under the following principles:

  • We only process click identifiers (gclid, wbraid, gbraid, fbclid, ttclid), sub_id, conversion value and type — we do not collect end users' names, emails, phone numbers or addresses unless you deliberately send hashed data for Enhanced Conversions.
  • Enhanced Conversions data (if you enable it) is SHA-256 hashed on your side or ours before being sent to Google; we do not retain the un-hashed original.
  • We do not use advertising data to build cross-site user profiles, do not sell data, do not use fingerprinting, and do not build audience segments for resale.
  • We do not process sensitive categories restricted by Google Ads policies (health, religion, sexual orientation, financial hardship, children's data).
  • You — as the advertiser — are responsible for complying with Google's EU User Consent Policy and obtaining valid consent on your landing pages before sending measurement data to us.
  • Conversion forwarding to Google is performed under the Google Ads Data Processing Terms and only according to the configuration you set.

10. Click tracking links

When someone opens one of your /r/... short links, we record the minimum data needed for fraud prevention and reconciliation:

  • Click timestamp, click identifiers from the URL, referrer, user-agent, country inferred from IP, and a one-way hashed IP address.
  • A tracking link performs a single 302 redirect straight to the registered destination; no interstitial page, no injected ads, no third-party code, and no tracking cookies set in the user's browser.
  • Raw click logs are retained for a maximum of 90 days, after which only anonymized aggregate metrics are kept.

11. International data transfers

Our infrastructure and processors (hosting, payments, ad platforms) may be located in the EU, the United States, or elsewhere. For EEA/UK data, transfers rely on the EU Standard Contractual Clauses (SCCs) or an equivalent lawful mechanism.

12. Children

The Service is intended for businesses and adults. We do not knowingly collect data from children under 16 and do not permit the Service to be used for measuring ads directed at children. If we discover such data, we delete it.

13. Contact & data deletion requests

Data controller: Cao Cu Quoc Cuong, AffPixel (affpixel.com), Vietnam. Any request to access, correct, or delete data — yours or an end user's — can be submitted through the Contact page. We process it within 30 days and confirm by email.