Privacy Policy
Last updated: August 21, 2026
This Privacy Policy explains what data Affset, operated by Elusione OÜ, a company registered in Estonia ("Affset," "we," "us"), collects through affset.com, the Affset dashboard, and the ad-serving infrastructure we operate for our customers, how we use it, and who we share it with.
Affset is a white-label ad-serving platform: our customers ("tenants") use it to run their own CPA networks, with their own publishers and advertisers. For account, billing, and dashboard data, Affset is the data controller. For click, impression, and conversion data generated by a tenant's ad-serving traffic, Affset acts as a data processor on that tenant's behalf — the tenant decides what targeting, tracking, and postbacks to configure, and is the right party to contact about how that data is used in their campaigns.
1. Information We Collect
Information you give us directly: name and email when you submit the contact form or request access to the Service; company name, timezone, branding, and similar settings once you have an Account.
Information collected through ad serving: when a link served through a tenant's Affset zone is clicked, we process the destination zone and campaign, a country derived from the request (via Cloudflare's edge network, which also processes the underlying IP address to route and secure the request), device type, operating system, and browser (parsed from the user-agent string), and any click-identifier parameters the tenant's tracking link carries — such as a source click ID or sub-tracking labels passed in the URL by the traffic source. This tracking is cookieless: we do not set browser cookies to attribute clicks or conversions.
Information collected automatically in the dashboard: standard operational data such as API request metadata, used for security, rate limiting, and diagnosing issues.
3. How We Use Information
- To operate ad serving, targeting, tracking, and postback delivery for our tenants;
- To provide the dashboard, reporting, and account management;
- To process billing and send account, security, and service notices;
- To respond to support and contact requests;
- To detect and prevent fraud, abuse, and security incidents;
- To measure and improve affset.com (only with analytics consent, see Section 2);
- To comply with legal obligations.
5. Data Retention
Account and billing data is retained for as long as the Account is active, and for a limited period after closure as needed for legal, tax, and dispute-resolution purposes. Ad-serving event data (clicks, impressions, conversions) is retained according to the tenant's plan — retention windows are published on our pricing page and vary by plan tier.
6. Your Rights
If you are an Affset account holder, you can access, update, export, or request deletion of your account data by signing in to the dashboard or contacting support@affset.com.
If you are an end user who clicked a tracking link served through a tenant's Affset zone, Affset processes limited, cookieless click/conversion data on that tenant's behalf. The tenant who owns the campaign is best placed to handle requests about that data; you can also contact us and we will route your request to the relevant tenant where we are able to identify them.
Depending on where you're located, you may have additional rights under laws such as the GDPR or CCPA/CPRA, including the right to object to or restrict certain processing. We will honor valid requests under applicable law.
7. Children's Privacy
The Service is not directed at children, and we do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will delete it.
8. International Data Transfers
Affset runs on Cloudflare's global network, which means data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
9. Security
We use reasonable technical and organizational measures to protect data — including namespace-level tenant isolation and API-key-based authentication — but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice (such as an email to your Account's contact address or a notice in the dashboard) before the change takes effect.
11. Contact
Questions about this Privacy Policy can be sent to support@affset.com or via our contact page. See also our Terms of Service.