Last updated:
GDPR Privacy Notice
This notice explains the processing of personal data in connection with TrafficSaviour where the General Data Protection Regulation (GDPR) applies. It supplements our general Privacy Policy and explains how to contact us about your data.
TrafficSaviour is operated by Zypnotics LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA. We provide cloaking services and related campaign tools. For privacy matters, contact [email protected].
1. Our role and customer campaign data
Zypnotics LLC is the controller for the administration of its own TrafficSaviour website, customer relationships, and support communications. For visitor data handled on a customer's instructions through campaign tools, the customer may be the controller and TrafficSaviour may act as a processor. The applicable service agreement and the actual processing determine these roles.
If your request relates to a website or campaign operated by a customer, contact that operator first where possible. You can also contact [email protected] with the website address and approximate visit date so the appropriate party can be identified.
2. Personal data and sources
At signup we collect your name and email address. Our traffic logs store IP addresses; they do not store device details. We also process campaign settings you provide and information you send in support messages. Subscription-related information may be involved when you purchase a service. IP addresses can be personal data even when a person's name is not recorded.
Website analytics are separate from these traffic logs. We use Google Analytics to understand website activity. It can involve online identifiers and website usage information. The website also includes Google Tag Manager.
Information comes from you, campaign traffic, and website interactions. Providing information necessary to administer an account or fulfil a service request enables those functions. Avoid supplying sensitive personal information that is not needed for the service.
3. Purposes and legal grounds
The legal ground depends on the particular processing activity:
- Contract: processing necessary to provide a service you have requested, such as administering your account or subscription.
- Legitimate interests: proportionate activities such as securing the service, detecting abuse, and resolving support issues, subject to balancing those interests against your rights.
- Legal obligation: processing required by applicable law, such as certain accounting records or valid legal demands.
- Consent: processing that requires your consent, including non-essential tracking where required. Consent can be withdrawn without affecting the lawfulness of earlier processing.
A legal ground must relate to the actual purpose; these grounds are not interchangeable permissions for any use of data.
4. Website analytics and cookies
We do not use Meta Pixel. We use Google Analytics to understand website activity, and the website includes Google Tag Manager. These can process online identifiers and usage information. The website does not currently provide an Accept/Reject cookie consent banner. Read our Cookie Policy for the described cookie uses and browser controls. Contact [email protected] about tracking choices or to withdraw consent for processing based on consent. Deleting a cookie alone does not necessarily stop future collection or remove records already held.
5. Recipients and international processing
We use Hostinger for hosting and PayPal and Dodo Payments for payment processing. These providers receive information relevant to the services they perform. Payment providers may also process information under their own privacy notices and legal obligations.
We do not sell personal information.
Our general Privacy Policy describes providers supporting hosting, billing, communications, and analytics, as well as disclosures for legal or security reasons. Customer account permissions can also determine who can view campaign data.
Processing outside the European Economic Area must meet the applicable GDPR transfer requirements. Depending on the transfer, an adequacy decision or appropriate safeguards, such as applicable contractual clauses, may be relevant. To ask where data associated with your service is processed, which recipients are involved, or what transfer safeguards apply, contact [email protected].
6. How retention is determined
We retain each IP traffic log for 30 calendar days from the date it is recorded, then delete it. Account information needed to provide the service is retained while the account is active. We delete that account information within 30 calendar days after account closure or receipt of a verified account-deletion request, whichever occurs first. A deletion request can also cover specified personal information without closing the account. These periods do not extend any shorter deadline required by applicable law. You can request deletion of your account and associated personal information at [email protected], subject to applicable legal exceptions. Payment providers may retain their own transaction records under their privacy notices and legal obligations. Contact us about other records, customer-controlled processing, or the handling of a specific deletion request.
7. Your rights
Subject to the GDPR's conditions and exceptions, you may request access, correction, erasure, restriction of processing, and a portable copy of eligible data. You may object to processing based on legitimate interests and to processing for direct marketing. Where processing relies on consent, you may withdraw it.
You also have protections relating to decisions based solely on automated processing that produce legal or similarly significant effects. TrafficSaviour's campaign tools apply configured rules and traffic signals to classify or route visits. For concerns about a specific campaign decision, identify the campaign or website so the customer responsible for its rules can be involved.
8. Requests, timing, and complaints
Send your request to [email protected] and explain which information or processing it concerns. Include the account email or other information that helps identify the relevant records, but do not send a password. Where there are reasonable doubts about identity, additional information may be needed.
Under the GDPR, requests must generally receive a response within one month. An extension of up to two further months can apply to complex or numerous requests, with notice and reasons provided within the first month. If a request is refused, the response should explain why and identify available complaint and judicial remedies.
You may complain to a supervisory authority, in particular in the country of your habitual residence, workplace, or alleged infringement. The European Data Protection Board's directory helps you find the relevant authority.
9. Related information and changes
Read this notice with our Privacy Policy and any applicable agreement for customer-controlled processing. The revision date identifies the latest version. Privacy questions can be sent to [email protected].
Questions about your privacy?
Zypnotics LLC
30 N Gould St, STE R
Sheridan, WY 82801, USA
All privacy and account or data deletion requests are handled at [email protected].