Provestats
    Back to Provestats
    Back to Provestats

    Privacy Policy

    Effective date: 10 July 2026

    Provestats lets affiliates connect their affiliate-platform accounts through read-only APIs and share verifiable, view-only statistics with operators. This policy explains what personal data we collect when you use provestats.com, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR). We have tried to keep it as plain as the product itself.

    1. Data controller

    The controller responsible for your personal data is:

    Techedz
    Amaliegade 6, 2nd tv
    1256 Copenhagen, Denmark
    E-mail: info@techedz.com
    Company number/VAT: DK-40764615

    2. Data we collect

    a) Account data. When you sign up we ask for your e-mail address, your Telegram handle and a password. The password is stored as a salted hash — we cannot read it. We deliberately do not ask for your name, company details or identity documents.

    b) Platform connection data. When you connect an affiliate platform (for example CellXpert, Affilka, RefferOn, Income Access, MyAffiliates or NetRefer), we store the read-only API credentials you provide — such as platform URL, affiliate ID and API key — in encrypted form. Through that connection we retrieve the statistics the platform API returns: reconciliation figures and pseudonymized player-level metrics (geo, deposit counts and amounts, turnover, NGR, bonus figures and activity dates). We never pull your platform password, system player IDs, tracking links or your commission data — the connection is limited to read-only reporting functions by design.

    c) Share-link data. When you create a share link we store its settings (selected fields, date range, expiry, one-time view) and log accesses by viewers: timestamp, IP address and browser type. These logs exist so you can see that your report was opened and so we can enforce expiry and one-time-view rules.

    d) Partner program data. If you join the partner program, we record clicks on your personal referral link (provestats.com/r/<id>) — timestamp, IP address and browser type — and the registrations that result from them, so we can attribute verified sign-ups to you and detect fraudulent traffic.

    e) Payment data. Paid plans are billed through Stripe (card and Apple Pay) and BitPay (cryptocurrency). Your card number and full payment details go directly to those providers; we never store card numbers. We keep only what we need for billing records, such as the plan, amount, date and a payment reference.

    f) Support communications. If you contact us by e-mail or Telegram, we process the messages you send us and the contact details you use, in order to help you.

    3. Purposes and legal bases

    We process personal data only where the GDPR gives us a legal basis to do so:

    • Performance of a contract (Art. 6(1)(b)): creating and running your account, connecting platforms, generating and serving share links, operating the partner program, and billing paid plans.
    • Legitimate interests (Art. 6(1)(f)): preventing fraud and abuse — including enforcing the rule that one platform account can only ever be linked to one Provestats account — securing the service, keeping viewer access logs, and improving the product.
    • Legal obligations (Art. 6(1)(c)): keeping accounting and billing records as required by Danish bookkeeping law.
    • Consent (Art. 6(1)(a)): where a specific feature requires it. You can withdraw consent at any time without affecting processing that happened before withdrawal.

    4. What we never do

    • We never sell personal data — yours or anyone else's.
    • We never show your commissions, system player IDs or tracking links to the people who view your share links. These fields are not retrieved in the first place.
    • We never write to your platform accounts. Connections are read-only, and we cannot modify anything at the source.

    5. Recipients and processors

    We share personal data only with service providers who help us run Provestats, under data processing agreements where required:

    • Our hosting provider, which stores the service's data on our behalf.
    • Email delivery — Resend (transactional email: account and security messages; EU data-residency region; processed under a Data Processing Agreement).
    • Stripe, for card and Apple Pay payments.
    • BitPay, for cryptocurrency payments.
    • Telegram, when we communicate with you for support or send you notifications on the handle you provided.
    • The affiliate platforms you connect (for example CellXpert, Affilka, RefferOn, Income Access, MyAffiliates or NetRefer), to the extent needed to execute the API connection you set up.

    6. International transfers

    Our service is hosted in the EU/EEA. Where a provider processes data outside the EEA — for example a payment provider or Telegram — we rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs) to protect the transfer. Our email delivery processor, Resend, is configured for the EU data-residency region and is bound by the same Standard Contractual Clauses (SCCs) safeguard for any residual cross-border processing.

    7. Retention

    • Account data is kept while your account is active, and afterwards only as long as statutory periods require.
    • API credentials are deleted when you disconnect a platform or delete your account.
    • Viewer access logs and expired-link data are kept for a maximum of 12 months.
    • Partner referral click logs keep the visitor's IP address and browser type for a maximum of 12 months; after that we remove both and keep only the anonymous click count.
    • Billing records are kept for 5 years under the Danish Bookkeeping Act.

    When you delete your account, we immediately and irreversibly anonymize the account record: your e-mail address is replaced with an anonymized identifier, your password and stored platform credentials are destroyed, and your Telegram link is removed. Your notification history, security tokens and data exports are deleted at the same time. What remains afterwards is kept in a form that no longer directly identifies you — billing records (5 years, under the Danish Bookkeeping Act), the record that a platform account has been claimed by a Provestats account (kept for fraud prevention — see the one-account rule in section 3), aggregate partner-program statistics, and internal security-audit entries.

    8. Security

    All traffic to and from Provestats is encrypted in transit using TLS. Platform API credentials are encrypted at rest. Access to production data is restricted to personnel who need it, and platform connections are read-only by design — even in the worst case, a Provestats connection cannot be used to change anything in your platform account.

    9. Your rights

    Under the GDPR you have the right to:

    • access the personal data we hold about you;
    • have inaccurate data rectified;
    • have your data erased ("right to be forgotten");
    • restrict processing in certain circumstances;
    • receive your data in a portable format;
    • object to processing based on legitimate interests;
    • withdraw consent at any time, where processing is based on consent.

    To exercise any of these rights, e-mail info@techedz.com. We respond within one month. You also have the right to lodge a complaint with Datatilsynet, the Danish Data Protection Agency (www.datatilsynet.dk), or with the supervisory authority in your own EU country.

    10. Cookies

    Provestats uses only strictly necessary cookies and local storage — the minimum needed to keep you logged in and keep the service secure. We do not use advertising cookies, analytics cookies or any third-party trackers, so there is no cookie consent banner to click through.

    Fonts are self-hosted; no font requests leave our servers.

    11. Player data in reports

    Reports on Provestats contain pseudonymized player-level metrics (geo, deposit counts and amounts, turnover, NGR, bonus figures and activity dates) as returned by the affiliate platform. Provestats displays this data without alteration and does not attempt to re-identify anyone. Affiliates control who sees their reports through share-link settings (field selection, expiry, one-time view) and remain responsible for their own sharing choices — if you share a report with an operator, that is your decision about your data.

    12. Age limit

    Provestats is a business tool for the iGaming affiliate industry and is intended for adults only. You must be at least 18 years old to create an account. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.

    13. Changes to this policy

    We may update this policy when the service or the law changes. The effective date at the top always shows the current version. For material changes, we will notify you by e-mail or Telegram before they take effect. Continued use of Provestats after that date means the updated policy applies.

    14. Contact

    Questions about this policy or about how we handle your data? Write to info@techedz.com and we will get back to you.

    © 2026 Provestats · Terms of Service · Back to Provestats