| § | Privacy Policy |
|---|---|
| 1. |
IntroductionFanzoone OÜ (registry code 16537736, Tornimäe tn 5, 10145 Tallinn, Estonia), which operates the CPA Hunter service ("CPA Hunter", the "Company", "we", "us" or "our"), respects your privacy. This Privacy Policy (the "Policy") describes how we collect, use, store and disclose data that you provide to us or that we obtain when you visit the cpahunter.io website (the "Site"), use the dashboard, the browser extension and other products and services (together with the Site, the "Service"). The Company acts as the controller of your personal data within the meaning of the EU General Data Protection Regulation 2016/679 (GDPR). We process data in accordance with the GDPR and Estonian law. For questions about the processing of personal data, write to hello@cpahunter.io. Please read this Policy carefully. By using the Service, you agree to the practices described here. If you use the Service on behalf of an organisation, you agree to this Policy on its behalf. If you do not agree with the Policy, do not use the Service. |
| 2. |
What Data We CollectData you provide. At registration, identity verification, arranging payouts and contacting support, we may collect:
This data may be personal data, that is, information that directly or indirectly identifies you. For payments and payouts, financial details are processed by third-party payment providers. We do not collect or store full bank card or account numbers; we store information about amounts, dates and statuses of transactions required for accounting. Data we collect automatically. When you use the Service, we may collect:
Data about your activity in the Service. We process information about the affiliate links you create, the clicks and sales on them, the commissions accrued and confirmed, your balance and withdrawals, and the merchants and brands you work with. If you install the browser extension, it processes data needed to create affiliate links (for example, the address of the merchant page on which you use the extension). |
| 3. |
Cookies and Similar TechnologiesCookies are small pieces of data stored by your browser. Pixel tags (web beacons) are small images or fragments of code that can recognise cookies and record page views. We use strictly necessary cookies to operate the Service, as well as analytics and marketing cookies. Non-essential cookies are set only with your consent, which you can give or withdraw via the cookie banner. You can also manage cookies in your browser settings; if you disable cookies, some features of the Service may become unavailable. |
| 4. |
Connected Accounts and Social Media VerificationThe Service lets you connect and verify ownership of your social accounts through official OAuth mechanisms. We request minimal read-only access, never receive or store your passwords, and never publish content on your behalf. Connected-account data is used solely to verify ownership and to display basic public profile information in your dashboard. We do not use this data for advertising, profiling or sale to third parties. All data transfers are protected by encryption (TLS). You can disconnect any account in your profile settings at any time – this revokes the stored tokens; to request full deletion of stored data, write to hello@cpahunter.io. YouTube (Google). We use Google OAuth 2.0 with the youtube.readonly scope (read-only). Google API data is used only to retrieve the list of your channels, verify ownership of the channel being connected, and display basic public information (channel name, subscriber count and view count). Access tokens are used only during the one-time verification and are not retained afterwards; refresh tokens are not requested. Channel metadata (ID, URL, subscriber count and view count) is stored to maintain the association with your account. You can revoke access in your Google Account security settings. The Company's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. X (Twitter). We use OAuth 1.0a and the verify_credentials endpoint (read-only); we do not post tweets or modify your profile. We store your username, follower count, profile URL and profile ID, and the tokens, for the duration of the connection. You can revoke access in your X connected-apps settings. Facebook. We request the minimal permissions email and public_profile; we do not post on your behalf, access your friends list, or manage your pages. We store your name, profile URL, email and ID, and the access token, for the duration of the connection. You can revoke access in your Facebook Business Integrations settings. Twitch. We request the user:read:email scope; we do not manage your streams or channel settings. We store your username, view count, broadcaster type and ID, and the access and refresh tokens, for the duration of the connection. You can revoke access in your Twitch Connections settings. Instagram (Meta). We request instagram_business_basic (read-only access to basic profile information); we do not publish content, read direct messages, or access your followers list. We store your username, follower count, profile URL and ID, and the access token, for the duration of the connection. You can revoke access in your Instagram apps-and-websites settings. TikTok. We use TikTok Login Kit with the user.info.basic and user.info.profile scopes; you authorise the connection on TikTok's official screen, and we never receive your password. We store your account identifiers (open ID and union ID), display name, username, avatar and profile URL, the account verification flag, and the access and refresh tokens. Disconnecting the account revokes the stored tokens. We do not post on your behalf and have no access to direct messages, followers or videos beyond the public fields listed. |
| 5. |
Purposes and Legal Bases for ProcessingWe process personal data only where there is a legal basis under the GDPR:
|
| 6. |
To Whom We Disclose DataWe may disclose data to the following categories of recipients:
We may disclose de-identified and aggregated data that does not identify specific users. |
| 7. |
Transfers of Data Outside the EEAThe Company is located in Estonia (EU); however, some of our processors and partners are located outside the European Economic Area, including in the United States. When transferring data outside the EEA, we apply appropriate safeguards provided for by the GDPR – the Standard Contractual Clauses approved by the European Commission (SCC) and, where applicable, European Commission adequacy decisions. |
| 8. |
Retention PeriodsWe retain personal data only for as long as necessary for the purposes of processing and within the limits required by law:
After closure of the account, we may retain some data to prevent fraud, protect our rights, resolve disputes and comply with the law. |
| 9. |
Your RightsIn relation to your personal data, you have the right to:
To exercise your rights, write to hello@cpahunter.io or change your data in the dashboard settings. We will respond within the periods set by the GDPR, generally within one month. If we refuse your request, you may ask for an internal review. The review is carried out by a member of staff who was not involved in the original decision, and we will inform you of the outcome. This does not limit your right to lodge a complaint with the supervisory authority. |
| 10. |
Right to Lodge a Complaint with the Supervisory AuthorityIf you believe we are breaching data-protection requirements, you have the right to lodge a complaint with the supervisory authority. In Estonia, this is the Data Protection Inspectorate: Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia · info@aki.ee · +372 6274135 · www.aki.ee You also have the right to contact the supervisory authority of your country of residence or work. |
| 11. |
Artificial Intelligence and Automated DecisionsWe use artificial intelligence and machine learning ("AI") technologies to: analyse the performance of content and links; personalise your experience and match relevant merchants and products; detect fraud, invalid traffic and inflation; generate recommendations; and improve and develop the Service. We do not make decisions producing legal or similarly significant effects for you solely by automated means without appropriate safeguards. Your loyalty-tier status is determined on the basis of factual data – confirmed commission. For training and improving models, we use only de-identified and aggregated data that does not identify you. We do not allow third-party AI providers to use your personal data to train their own models and algorithms. |
| 12. |
Marketing MessagesIf you do not wish to receive marketing messages from us, you can opt out via the "unsubscribe" link in any email, in your settings, or by writing to hello@cpahunter.io. Even if you opt out of marketing, we may send you service messages related to your account and the Service. |
| 13. |
Social MediaThe Service may allow you to post data to third-party services and platforms, including social media. If you use this feature, your activity may be visible to other users of the relevant platforms. If you connect social media, we may receive data you have made available to those services. Use of such data is governed by the policies of the relevant platforms, which we do not control. |
| 14. |
Links to Third-Party SitesThe Service contains links to third-party sites, including to merchants and brands via the cpa.cx domain. These sites are operated by third parties and are not controlled by us. This Policy does not apply to them. We recommend reviewing the privacy policies of such sites. |
| 15. |
SecurityWe take reasonable technical and organisational measures to protect personal data from loss, misuse and unauthorised access. Nevertheless, no transmission of data over the internet or by email is entirely secure, so please be careful when sending us information. In the event of a personal-data breach, we will notify the supervisory authority within 72 hours where required, and data subjects if the breach poses a high risk to their rights. |
| 16. |
ChildrenThe Service is intended for persons aged 18 or over. We do not knowingly collect personal data of minors. If we become aware that we have received a minor's data, we will delete it. If you believe we may hold such data, write to hello@cpahunter.io. |
| 17. |
Changes to the PolicyWe may amend this Policy from time to time. When we make changes, we will publish the new version on this page and update the date at the top, and will notify you of material changes by reasonable means. Changes take effect upon publication; your continued use of the Service constitutes acceptance of the revised version. |
| 18. |
ContactFor questions about the processing of personal data, the exercise of your rights, and for general questions and support: hello@cpahunter.io. Data controller: Fanzoone OÜ · registry code 16537736 · Tornimäe tn 5, 10145 Tallinn, Estonia · cpahunter.io |