MagicRoute PPC
Affiliate Platform
How we handle personal data in the MagicRoute PPC platform: both the data we hold about our own customers, and the click and conversion data our customers process through the service.
Last updated: 1 August 2026
MagicRoute PPC (“MagicRoute PPC”, “we”, “us”) provides a software-as-a-service affiliate traffic management platform. The platform lets organisations create tracking links, route clicks by geography and device, record click and conversion events, and manage connected advertising accounts.
MagicRoute PPC is the data controller for the account data described in section 3. For any privacy question, or to exercise the rights described in section 9, contact us at [email protected].
MagicRoute PPC is a multi-tenant platform, and the distinction below determines who is responsible for which data.
If you are an end visitor who clicked a tracked link and you want your data removed, your request should go to the organisation that ran that campaign, not to us. We will assist that organisation in responding, but we cannot act on their data without instruction.
When an organisation is provisioned on the platform, and when users are added to it, we collect and store:
This is the core of what the platform does. When a visitor follows a tracked link belonging to one of our customers, we record, on that customer's behalf:
An IP address is personal data in most jurisdictions. It is collected here because geographic routing and fraud detection cannot function without it, and it is retained only for as long as described in section 7. Organisations using the platform are responsible for having a lawful basis for this processing, and for disclosing it in their own privacy notice to their own visitors.
Organisations may connect third-party advertising and infrastructure accounts to the platform. Where they do, we store the credentials required to operate those connections:
These are among the most sensitive values we hold, because they grant access to systems that can spend money. They are encrypted at rest using AES-256-GCM, are excluded from ordinary database reads, and are redacted from all audit logs. We use them only to perform the actions the organisation has configured, and never for our own purposes.
If you need the retention period that applies to your own organisation confirmed in writing, contact [email protected].
We do not sell personal data, and we do not share it for advertising purposes. We disclose data to service providers only to the extent needed to run the platform:
Each is bound by contract to process data only on our instructions. A current list of our sub-processors is available on request from [email protected]. We may also disclose data where legally compelled, or to establish or defend legal claims.
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, or withdraw consent where consent is the basis we rely on. You may also lodge a complaint with your local data protection authority.
To exercise any of these, contact [email protected]. We will respond within the period required by applicable law. If your request concerns click data collected by one of our customers, see section 2. We will route your request to that customer.
Measures currently in place include: passwords stored as bcrypt hashes; credentials for connected services encrypted at rest with AES-256-GCM; session tokens issued as signed JWTs held in HTTP-only cookies, marked Secure in production; transport encryption in transit; rate limiting on authentication endpoints; role-based access control; and query-level tenant isolation designed so one organisation cannot read another's records.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.
The application sets only what it needs to keep you signed in: a session cookie and a refresh cookie, both HTTP-only and inaccessible to JavaScript. They are strictly necessary and cannot be disabled while using the platform. We set no advertising or analytics cookies in the application itself.
Tracked redirect links are a separate matter. Any cookie or identifier set during a redirect is configured by the organisation running the campaign, and falls under that organisation's own cookie disclosure.
Our infrastructure and sub-processors may be located outside your country. Where personal data leaves a jurisdiction that restricts transfers, we rely on an appropriate safeguard, such as the European Commission's Standard Contractual Clauses or an adequacy decision. Details are available on request.
The platform is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. If you believe a child's data has reached us, contact us and we will delete it.
We may update this policy as the platform changes. The “last updated” date at the top always reflects the current version. Where a change materially affects your rights, we will notify account administrators before it takes effect.
For any question about this policy, about how your data is handled, or to exercise any of the rights in section 9, contact us at [email protected].
© 2026 MagicRoute PPC. All rights reserved.