Privacy Policy
Effective Date: The 1st of March 2025
This Privacy Policy describes how CatStats.AI ("CatStats", "we", "our", or "us") collects, uses, shares, and protects your personal and business data when you use our software-as-a-service (SaaS) platform (the "Service"). CatStats.AI is owned and operated by Witanalytica S.R.L. and RocketChair S.R.L. (collectively, the "Company"). This Privacy Policy applies to users of the Service, including representatives of affiliate networks and affiliate programs.
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Data We Collect
1.1 Personal Data: When you register or interact with our Service, we collect the following types of personal data:
- Name, email address, phone number, Skype, Telegram, job title, role, timezone, currency, preferred language
- Login credentials and multi-factor authentication data
- User agent, IP address, login timestamps, and product usage statistics
1.2 Business Platform Data: We collect data via API integrations with your affiliate tracking platforms, including:
- Clicks, conversions, conversion rates, revenue, payout, gross profit, and approximate geo-location (country-level) of conversions and clicks (no granular clicks and conversions, we use data aggregated at a daily level)
- Offer, advertiser and affiliate details data (IDs, names, contacts and contact details, landing pages, descriptions, payouts, and custom payouts)
2. How We Collect Data
- Directly via signup forms, user profile setup, and in-app activity
- Via tracking tools such as Google Analytics on CatStats.ai
- Through integration with your tracking platform APIs (Everflow, Affise, Marksel, Trackdesk, etc.)
3. Why We Collect Data
- To deliver and operate the Service effectively
- To personalize the user experience and improve usability
- To support customer service and technical troubleshooting
- To develop future product features, recommendation systems, and analytics tools based on available tracking data
- To run marketing campaigns and retargeting efforts
4. Sharing and Third Parties
We do not sell your data. We only share data with:
- Google Cloud Platform (GCP), where our infrastructure is hosted and operated
- Internal employees of Witanalytica S.R.L. who are directly involved in developing, operating and supporting CatStats.AI
A Data Processing Agreement (DPA) is in place with Google Cloud to comply with GDPR and CCPA obligations.
5. Data Retention
- Data is retained for up to 6 months after account deactivation unless you explicitly delete your data..
- Expired trials or subscriptions are automatically moved to the Free Tier. We retain user data unless the account is explicitly deleted, allowing even Free Tier users to continue accessing basic actionable insights.
- To delete your data, follow these steps directly within the CatStats platform: 1) Remove your integrations (link), 2) Delete your company profile (link), and 3) Delete your users account (link). This will permanently erase all associated data.
6. Security Measures
The system has been penetration tested and certified by Zerotak Cybersecurity (https://zerotak.com/) before onboarding any customer.
We protect customer data using layered security controls aligned with ISO/IEC 27001 principles.
- Each customer is isolated using dedicated databases and Kubernetes-level segmentation.
- All data is stored within private Google Cloud networks; databases are not publicly exposed and connect via Cloud SQL Auth Proxy.
- Perimeter protection is enforced through Google Cloud Armor (WAF and DDoS mitigation).
- Access is restricted to authorized personnel only, using multi-factor authentication (MFA) and least-privilege access policies.
- No external contractors have access to infrastructure or data.
- Passwords are securely hashed; all connections use TLS encryption in transit and data is encrypted at rest.
- Centralized logging and monitoring are in place to track service health and detect anomalies.
- We conduct recurring security assessments and risk reviews to improve defenses.
- We maintain automated backups for Cloud SQL and MongoDB Atlas, with regular restore testing.
- As part of incident response, we can rapidly isolate services or disable public access if necessary.
7. Your Rights
Under the GDPR, you have the right to:
- Access, rectify, delete, or export your data
- Contact us at dpo@catstats.ai to exercise any of these rights
Under the CCPA, California residents have the right to:
- Request access to personal data we hold
- Opt-out of any data sale (note: we do not sell data)
- Contact us at dpo@catstats.ai to submit such requests
We currently do not honor browser-based "Do Not Track" signals or global privacy controls, but this may be added in future updates.
8. Children’s Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect or process any data from individuals under this age.
9. Data Location and International Transfers
All user and customer data is stored and processed on Google Cloud servers located in the United States. If you are located in the EU/EEA, this constitutes a transfer of data outside the European Union. Appropriate safeguards are in place under Google’s DPA to ensure GDPR compliance.
10. Communication and Notices
All privacy-related inquiries and official notices should be sent to dpo@catstats.ai. Email correspondence that includes delivery confirmation (e.g., read receipt or email response) will be considered valid legal communication.
11. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. Changes will be posted on our website and/or communicated via email to registered users. Continued use of the Service after changes are posted constitutes acceptance.
12. Contact Information
For any questions about this Privacy Policy or to exercise your rights, contact us at:
Data Protection Contact:
dpo@catstats.ai
Issued by:
Witanalytica S.R.L.
RocketChair S.R.L.
Thank you for trusting CatStats.AI to manage your data securely and transparently.