Privacy policy
An affiliate network runs on measurement, so this document is mostly about measurement data — what a click record contains, who sees it, how long we keep it and how you get it deleted. It applies to www.affiliateadz.com, the publisher and advertiser dashboards, our tracking and redirect endpoints, and the APIs and postbacks that connect them.
Privacy policy sections
Who is responsible
AffiliateAdz is a brand and service operated by Catalyst Web Trendz Pvt. Ltd., a company incorporated in India with its registered office at D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048. References to “we”, “us”, “our” and “the network” are to that company. This policy is issued under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 together with the rules made under it, and addresses the GDPR and the CCPA because our traffic and partners are cross-border.
01. Scope and the two kinds of data we handle
We handle two very different categories of personal data, and almost every question about this policy is really a question about which category applies. The first is partner data: the names, contact details, business documents and payout information of publishers and advertisers who hold accounts with us. The second is measurement data: the click, impression and conversion records generated when an end user interacts with an advertisement served through a publisher and lands on an advertiser destination.
Partner data is straightforward — we decide why and how it is processed and we are accountable for it. Measurement data is more nuanced, and section 04 sets out exactly where we act on our own account and where we act on an advertiser's instructions. This policy does not cover what an advertiser does on its own landing page or inside its own product after a user arrives there; that is governed by the advertiser's own notice.
02. Tracking technologies we use
Attribution requires connecting a click to a later conversion, and there are only a few honest ways to do it. We use the following, and nothing beyond them:
- Cookies. Strictly necessary cookies keep your dashboard session alive and protect against cross-site request forgery; these are always set. Attribution cookies store a click identifier of the form aa_xxxxxxxxxxxx for the duration of the offer's click window — typically 30 days — and are only set after consent. Anonymised analytics cookies measure page performance and are also consent-gated.
- Tracking pixels and iframe tags. Small transparent requests placed on an advertiser confirmation page that tell us a conversion occurred. They carry the click identifier and the conversion parameters, and nothing about the page content.
- Server-to-server postbacks. The method we prefer and recommend. The advertiser's server calls ours directly with the click identifier and conversion details. No cookie is required, no data is read from the user's browser, and the user's device is not involved at all.
- Device and advertising identifiers. For app-install campaigns measured through a mobile measurement partner, we receive a resettable advertising identifier (GAID or IDFA) or a hashed equivalent, subject to the permissions the user has granted on their device.
- Local storage. Used inside the dashboard to remember interface preferences and your cookie-consent choice, which is stored under the key aa_consent_v1.
We do not operate cross-site tracking for advertising purposes beyond the attribution window of the specific offer clicked, we do not build interest or behavioural profiles of end users, and we do not sell measurement data to data brokers.
03. What a click and conversion record actually contains
Rather than describe this in the abstract, here is the field list. A click record contains the click identifier, the offer identifier (OFR-####), the publisher identifier (PUB-#####), up to five publisher sub-identifiers, a UTC timestamp, the truncated IP address, a coarse geographic location derived from it, the user-agent string, device type and operating system, referring domain, and the connection type reported by the network.
A conversion record adds the conversion identifier (cnv_xxxxxx), the advertiser transaction reference, the event name, the payout and currency, any order value the advertiser sends, the validation status, and — where relevant — the reversal reason code. We do not require, request or store the end user's name, email address, phone number, payment details or the contents of any form they complete on an advertiser's site. If an advertiser transmits such fields to us in error, they are dropped at ingestion and the sending party is notified.
04. Our role: data fiduciary, controller and processor
For partner data, and for the measurement data we generate to operate the network, detect fraud and calculate payouts, we act as a data fiduciary under the DPDP Act and as a controller under the GDPR. We decide the fields collected, the retention periods and the security controls, and we are accountable for them.
Where an advertiser instructs us to process personal data belonging to its own customers — for example by sending us a hashed customer reference for deduplication, or by asking us to suppress an audience — we act as a data processor on that advertiser's documented instructions. That split is recorded in the insertion order and in the data-processing addendum signed with each advertiser, and it determines who a data principal should approach first. When in doubt, write to us and we will route the request to the right party rather than sending you away.
05. IP addresses, fingerprinting and fraud detection
We are explicit about this because most networks are not. On receipt of a click we process the full IP address transiently in order to score the click for fraud — checking it against datacentre, proxy and known-bot reputation lists and deriving a country and region. The full address is truncated before the record is written to durable storage; the stored record keeps the truncated form and the derived geography.
We also compute a probabilistic device signal from the user-agent, screen and language characteristics passed by the browser. This signal is used exclusively to identify duplicate and automated traffic, and it is a one-way hash: it cannot be reversed to recover the attributes it was built from, and it is never used to target advertising, to build profiles or to recognise a user across unrelated advertisers. The legitimate interest we rely on for this processing is the prevention of advertising fraud, which is also what protects honest publishers from the reversals that fraud would otherwise cause.
06. Account, KYC and financial data
Opening a publisher or advertiser account requires information we are obliged to hold. For publishers this means legal or trading name, contact details, declared traffic sources and example placements, a tax identifier such as PAN, a GSTIN where you are registered in India, and payout destination details for bank, PayPal, Payoneer or USDT-TRC20 settlement. For advertisers it means certificate of incorporation or equivalent, tax registration, an authorised signatory for the insertion order, and a named reconciliation contact.
This material is used to verify that we are paying and contracting with a real entity, to apply tax deduction at source and GST correctly, and to satisfy audit obligations. Access is restricted to finance and compliance staff on a need-to-know basis, and payout destination changes trigger a re-verification step and a seven-day hold on outgoing payments as an anti-takeover control. Please never send identity documents over WhatsApp.
07. Why we process data, and on what legal basis
- Performance of a contract. Operating your account, attributing conversions, calculating and paying commissions, invoicing advertisers and providing support.
- Consent. Setting attribution and analytics cookies, sending the weekly payout digest, and any processing you have specifically agreed to. Consent can be withdrawn at any time without affecting past lawful processing.
- Legal obligation. Tax deduction and reporting, GST records, statutory retention of financial records, and responding to lawful orders from Indian authorities.
- Legitimate interests. Fraud detection and click scoring, network and platform security, dispute resolution, and aggregate analysis of network performance. We have assessed these against the rights of the individuals concerned and use the least intrusive method that works.
08. Who we share data with
We do not sell personal data. In the ordinary course of operating the network, data moves in three directions and no others.
- To advertisers. The click identifier, sub-identifiers, offer and publisher identifiers, timestamp, coarse geography and device type of the traffic sent to them, so they can validate conversions and reconcile. Advertisers do not receive our publishers' payout rates, contact details or aggregate earnings.
- To publishers. Their own click, conversion and earnings data, including the reason code on any reversal, and the sub-identifiers they themselves passed. Publishers never receive another publisher's data, and never receive end-user personal data.
- To service providers. Cloud hosting and content delivery, payment and remittance processors, mobile measurement partners where an advertiser uses one, accounting and audit firms, and email delivery for transactional messages. Each is bound by a written agreement limiting them to our instructions.
We will also disclose data where compelled by a court, a competent authority under Indian law, or where necessary to establish or defend a legal claim. Where a business transfer or restructuring occurs, data may pass to the acquiring entity under the same terms, and you will be told before it does.
09. Cross-border transfers
Our primary infrastructure is hosted in India. Because we operate across 41 geographies, data may be processed in other jurisdictions — principally by cloud regions in Singapore and the European Union, by advertisers established outside India, and by payment providers settling to non-Indian destinations. Transfers out of India are made in accordance with section 16 of the DPDP Act and are not made to any territory restricted by the Central Government.
Where personal data of individuals in the European Economic Area or the United Kingdom is transferred, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by a transfer risk assessment and technical measures including encryption in transit and at rest. Copies of the relevant clauses are available to partners on request.
10. Consent management and opt-out mechanisms
On first visit our consent banner offers a genuine choice between accepting all cookies and accepting only those strictly necessary, with no dark patterns and no pre-ticked boxes. Declining is one click and carries no penalty; the site works either way. Your choice is stored locally under aa_consent_v1 together with a timestamp, and you can change it at any time by clearing that value or by writing to us.
Independently of our banner you may block or delete cookies in your browser settings, reset or limit your device advertising identifier in your operating system's privacy settings, and enable Global Privacy Control — which we honour as a valid opt-out signal for California residents. Marketing email carries a working unsubscribe link in every message and we action it within 72 hours. Opting out of marketing does not stop transactional messages such as payout notifications, which are part of operating your account.
11. How long we keep things
| Category | Retention | Reason |
|---|---|---|
| Raw click and impression logs | 24 months | Longest attribution window plus dispute and audit period |
| Conversion and payout records | 8 years | Income-tax and Companies Act record-keeping |
| KYC and tax documents | 8 years | Statutory financial obligations |
| Support and dispute correspondence | 36 months | Evidence for contractual claims |
| Marketing contact data | Until opt-out | Consent-based, deleted within 30 days of withdrawal |
| Consent records | 36 months | Demonstrating lawful basis |
At the end of a retention period records are deleted or irreversibly aggregated into non-identifying statistics. Backups roll off on a 35-day cycle, so a deletion request is fully effected across all copies within that window.
12. Your rights
Under the DPDP Act 2023 you may request access to a summary of the personal data we hold about you and the processing we carry out, correction or completion of inaccurate data, erasure where the purpose is served and no legal obligation requires retention, and nomination of another person to exercise your rights in the event of death or incapacity. You may also withdraw consent and use the grievance route in section 13 before approaching the Data Protection Board of India.
Where the GDPR applies you additionally have rights of portability, restriction, objection to processing based on legitimate interests, and complaint to your supervisory authority. Where the CCPA and CPRA apply you have rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share personal information as those terms are defined, and we honour Global Privacy Control regardless. We do not discriminate against anyone who exercises a right. Requests are verified against your registered account details, acknowledged within 24 hours and answered within 30 days, free of charge unless a request is manifestly repetitive.
13. Grievance Officer
Grievance Officer — appointed under the DPDP Act, 2023 and the IT Act, 2000
The Grievance Officer, AffiliateAdzCatalyst Web Trendz Pvt. Ltd.
D 29, 2nd Floor, Greater Kailash Enclave 2,
Greater Kailash, New Delhi – 110048 info@catalystwebtrendz.com +91-9953590779 Monday–Friday, 10:00 AM – 7:00 PM IST
Mark the subject line “DPDP GRIEVANCE” and include your registered email address and, if you hold an account, your publisher or advertiser identifier. Grievances are acknowledged within 24 hours and resolved within 30 days. If you remain dissatisfied you may approach the Data Protection Board of India.
14. Security, children and changes to this policy
We protect data with encryption in transit and at rest, role-based access control with mandatory multi-factor authentication for staff, network segregation between the tracking collector and the payout systems, immutable audit logging of administrative actions, and periodic penetration testing. No system is perfect; where a personal data breach is likely to cause harm we will notify the Data Protection Board of India, affected data principals and affected partners without undue delay and with a factual account of what happened.
Our services are directed at businesses. We do not knowingly collect personal data from anyone under 18, and no offer on the network may be targeted at children. If you believe a child's data has reached us, write to the Grievance Officer and we will delete it.
We update this policy when the law, our systems or our partners change. The “last updated” date at the top of the page always reflects the current version, and material changes are notified to account holders by email at least 14 days before they take effect. Continued use of the network after that date constitutes acceptance of the revised policy. This policy is governed by the laws of India, and the courts at New Delhi have exclusive jurisdiction over any dispute arising from it.
Questions about this policy?
Data questions do not go to a ticket queue. Write to the desk and the compliance team answers directly — and if your question is really a data principal request, say so and we will treat it as one from the moment it arrives.
Terms of service
Account terms, prohibited traffic, clawbacks, payout terms, liability and arbitration in New Delhi.
Disclaimer
Why earnings figures are illustrative, how tracking discrepancies are reconciled, and what third-party pages are not our responsibility.