MagicRoute PPC

Affiliate Platform

Privacy Policy

How we handle personal data in the MagicRoute PPC platform: both the data we hold about our own customers, and the click and conversion data our customers process through the service.

Last updated: 1 August 2026

1. Who we are

MagicRoute PPC (“MagicRoute PPC”, “we”, “us”) provides a software-as-a-service affiliate traffic management platform. The platform lets organisations create tracking links, route clicks by geography and device, record click and conversion events, and manage connected advertising accounts.

MagicRoute PPC is the data controller for the account data described in section 3. For any privacy question, or to exercise the rights described in section 9, contact us at [email protected].

2. Our two roles: controller and processor

MagicRoute PPC is a multi-tenant platform, and the distinction below determines who is responsible for which data.

  • We are the controller for account and administrative data: the organisations we provision, the users within them, login credentials, contact details, billing records, and our own security and audit logs. We decide how this data is used to operate and secure the service.
  • We are a processor for the traffic data an organisation pushes through the platform, meaning click events, visitor IP addresses, conversion records, and campaign configuration. The organisation using the platform is the controller of that data. They decide what to collect and why; we process it on their instructions in order to provide the service.

If you are an end visitor who clicked a tracked link and you want your data removed, your request should go to the organisation that ran that campaign, not to us. We will assist that organisation in responding, but we cannot act on their data without instruction.

3. Account data we collect

When an organisation is provisioned on the platform, and when users are added to it, we collect and store:

  • Organisation name, contact email address, telephone number, and postal address.
  • Each user's email address, which serves as their login identifier.
  • A password, stored only as a salted bcrypt hash. We never store or have access to plaintext passwords.
  • The role assigned to each user and the permissions that role grants.
  • An optional WhatsApp number, used solely to deliver the operational alerts described in section 6.
  • Account status, and a flag recording whether the user must set a new password at next sign-in.

4. Click and conversion data

This is the core of what the platform does. When a visitor follows a tracked link belonging to one of our customers, we record, on that customer's behalf:

  • The visitor's IP address, and the approximate country derived from it. This is what drives geographic routing.
  • Browser user-agent, and the device and operating system inferred from it.
  • The referring URL and any query parameters attached to the tracked link.
  • The campaign, link, and tracking identifiers involved, and the routing decision taken.
  • A timestamp, and the outcome of the redirect, including any failure.
  • Conversion events subsequently reported back by the affiliate network, and their associated values.

An IP address is personal data in most jurisdictions. It is collected here because geographic routing and fraud detection cannot function without it, and it is retained only for as long as described in section 7. Organisations using the platform are responsible for having a lawful basis for this processing, and for disclosing it in their own privacy notice to their own visitors.

5. Credentials for connected services

Organisations may connect third-party advertising and infrastructure accounts to the platform. Where they do, we store the credentials required to operate those connections:

  • Google Ads OAuth access and refresh tokens, together with the client and developer identifiers needed to call the Google Ads API on the organisation's behalf.
  • Proxy endpoint hostnames, ports, usernames and passwords, where an organisation configures its own proxies for routing.
  • Affiliate network API keys and client identifiers used to receive conversion postbacks.

These are among the most sensitive values we hold, because they grant access to systems that can spend money. They are encrypted at rest using AES-256-GCM, are excluded from ordinary database reads, and are redacted from all audit logs. We use them only to perform the actions the organisation has configured, and never for our own purposes.

6. How we use data, and our lawful bases

  • To provide the service: routing clicks, recording events, running campaigns, and rendering reports. Basis: performance of our contract with the organisation.
  • To authenticate and authorise: verifying sign-in, resolving permissions, and confining each session to its own organisation's data. Basis: performance of contract.
  • To send operational alerts: advertising API quota warnings and campaign failure-rate notifications, delivered by WhatsApp to users who have supplied a number and hold the relevant permission. Basis: legitimate interest in keeping customers' campaigns running. These are service alerts, not marketing; we do not send marketing messages through this channel.
  • To maintain an audit trail: recording which user changed what, and when, within each organisation. Basis: legitimate interest in security and accountability.
  • To secure the platform: rate limiting, abuse and fraud detection, and incident investigation. Basis: legitimate interest in the security of the service.
  • To comply with law: retaining records where we are legally required to. Basis: legal obligation.

7. Retention

  • Account and organisation records are kept while the account is active, and after closure for as long as needed to settle billing and meet our legal and accounting obligations.
  • Click and conversion logs are kept for as long as the organisation needs them for reporting and reconciliation, and are then deleted or irreversibly aggregated. An organisation may ask us to delete its own logs sooner.
  • Password reset tokens expire one hour after they are issued, and are destroyed as soon as they are used.
  • Audit logs are kept for as long as needed for security and accountability purposes.
  • Credentials for connected services are destroyed when the connection is removed or the account is closed.

If you need the retention period that applies to your own organisation confirmed in writing, contact [email protected].

8. Sub-processors and disclosure

We do not sell personal data, and we do not share it for advertising purposes. We disclose data to service providers only to the extent needed to run the platform:

  • Cloud hosting and managed database providers, which store the platform's data.
  • Google, through the Google Ads API, when an organisation has connected an advertising account.
  • Our transactional email provider, for password reset and account notification messages.
  • Our messaging provider, for WhatsApp operational alerts where enabled.
  • Proxy providers configured by the organisation itself, which necessarily see the traffic routed through them.

Each is bound by contract to process data only on our instructions. A current list of our sub-processors is available on request from [email protected]. We may also disclose data where legally compelled, or to establish or defend legal claims.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, or withdraw consent where consent is the basis we rely on. You may also lodge a complaint with your local data protection authority.

To exercise any of these, contact [email protected]. We will respond within the period required by applicable law. If your request concerns click data collected by one of our customers, see section 2. We will route your request to that customer.

10. Security

Measures currently in place include: passwords stored as bcrypt hashes; credentials for connected services encrypted at rest with AES-256-GCM; session tokens issued as signed JWTs held in HTTP-only cookies, marked Secure in production; transport encryption in transit; rate limiting on authentication endpoints; role-based access control; and query-level tenant isolation designed so one organisation cannot read another's records.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.

11. Cookies

The application sets only what it needs to keep you signed in: a session cookie and a refresh cookie, both HTTP-only and inaccessible to JavaScript. They are strictly necessary and cannot be disabled while using the platform. We set no advertising or analytics cookies in the application itself.

Tracked redirect links are a separate matter. Any cookie or identifier set during a redirect is configured by the organisation running the campaign, and falls under that organisation's own cookie disclosure.

12. International transfers

Our infrastructure and sub-processors may be located outside your country. Where personal data leaves a jurisdiction that restricts transfers, we rely on an appropriate safeguard, such as the European Commission's Standard Contractual Clauses or an adequacy decision. Details are available on request.

13. Children

The platform is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the platform changes. The “last updated” date at the top always reflects the current version. Where a change materially affects your rights, we will notify account administrators before it takes effect.

15. Contact

For any question about this policy, about how your data is handled, or to exercise any of the rights in section 9, contact us at [email protected].


© 2026 MagicRoute PPC. All rights reserved.