Privacy Policy
Effective Date: The 18th of May 2026
This Privacy Policy describes how CatStats.AI ("CatStats", "we", "our", or "us") collects, uses, shares, and protects your personal and business data when you use our software-as-a-service (SaaS) platform (the "Service"). CatStats.AI is owned and operated by Witanalytica S.R.L. and RocketChair S.R.L. (collectively, the "Company"). This Privacy Policy applies to users of the Service, including representatives of affiliate networks and affiliate programs.
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Data We Collect
1.1 Personal Data: When you register or interact with our Service, we collect the following types of personal data:
- Name, email address, phone number, Skype, Telegram, job title, role, timezone, currency, preferred language
- Login credentials and multi-factor authentication data
- User agent, IP address, login timestamps, and product usage statistics
1.2 Business Platform Data: We collect data via API integrations with your affiliate tracking platforms, including:
- Clicks, conversions, conversion rates, revenue, payout, gross profit, and approximate geo-location (country-level) of conversions and clicks (no granular clicks and conversions, we use data aggregated at a daily level)
- Offer, advertiser and affiliate details data (IDs, names, contacts and contact details, landing pages, descriptions, payouts, and custom payouts)
1.3 AI-Generated Data
When you use the AI Affiliate Assistant feature, your messages and relevant business data from your integration are processed by Google's Gemini AI models via Google Cloud's Vertex AI service. This processing occurs within Google Cloud Platform infrastructure. AI-generated responses, conversation history, and any facts you ask the assistant to remember are stored in our databases for the duration of your account.
2. How We Collect Data
- Directly via signup forms, user profile setup, and in-app activity
- Via tracking tools such as Google Analytics on CatStats.ai
- Through integration with your tracking platform APIs (Everflow, Affise, Marksel, Trackdesk, etc.)
- Through AI-powered features that process your business data using large language models hosted on Google Cloud Platform (Vertex AI)
3. Why We Collect Data
- To deliver and operate the Service effectively
- To personalize the user experience and improve usability
- To support customer service and technical troubleshooting
- To develop future product features, recommendation systems, and analytics tools based on available tracking data
- To run marketing campaigns and retargeting efforts
- To provide AI-powered conversational analytics and personalized insights through the AI Affiliate Assistant
4. Sharing and Third Parties
We do not sell your data. We only share data with:
- Google Cloud Platform (GCP), where our infrastructure is hosted and operated. This includes Google Cloud's Vertex AI service (Gemini models), which processes your business data when you use the AI Affiliate Assistant. Data sent to Vertex AI is used solely to generate responses to your queries and is not used by Google to train or improve their AI models.
- Postmark (by ActiveCampaign), which we use to deliver transactional and recommendation emails on your behalf. Postmark processes only the email addresses and message content necessary for delivery.
- Stripe, which processes subscription payments and credit pack purchases. Stripe receives only the billing and payment information necessary to complete transactions.
- Internal employees of Witanalytica S.R.L. who are directly involved in developing, operating and supporting CatStats.AI
Data Processing Agreements (DPAs) are in place with Google Cloud, Postmark, and Stripe to comply with GDPR and CCPA obligations.
5. Data Retention
- Data is retained for up to 6 months after account deactivation unless you explicitly delete your data..
- Expired trials or subscriptions are automatically moved to the Free Tier. We retain user data unless the account is explicitly deleted, allowing even Free Tier users to continue accessing basic actionable insights.
- To delete your data, follow these steps directly within the CatStats platform: 1) Remove your integrations (link), 2) Delete your company profile (link), and 3) Delete your users account (link). This will permanently erase all associated data.
- AI conversation history is retained for as long as your account is active. You may delete individual conversations at any time through the AI Assistant interface.
6. Security Measures
The system has been penetration tested and certified by Zerotak Cybersecurity (https://zerotak.com/) before onboarding any customer.
We protect customer data using layered security controls aligned with ISO/IEC 27001 principles.
- Each customer is isolated using dedicated databases and Kubernetes-level segmentation.
- All data is stored within private Google Cloud networks; databases are not publicly exposed and connect via Cloud SQL Auth Proxy.
- Perimeter protection is enforced through Google Cloud Armor (WAF and DDoS mitigation).
- Access is restricted to authorized personnel only, using multi-factor authentication (MFA) and least-privilege access policies.
- No external contractors have access to infrastructure or data.
- Passwords are securely hashed; all connections use TLS encryption in transit and data is encrypted at rest.
- Centralized logging and monitoring are in place to track service health and detect anomalies.
- We conduct recurring security assessments and risk reviews to improve defenses.
- We maintain automated backups for Cloud SQL and MongoDB Atlas, with regular restore testing.
- As part of incident response, we can rapidly isolate services or disable public access if necessary.
7. Your Rights
Under the GDPR, you have the right to:
- Access, rectify, delete, or export your data
- Contact us at dpo@catstats.ai to exercise any of these rights
Under the CCPA, California residents have the right to:
- Request access to personal data we hold
- Opt-out of any data sale (note: we do not sell data)
- Contact us at dpo@catstats.ai to submit such requests
We currently do not honor browser-based "Do Not Track" signals or global privacy controls, but this may be added in future updates.
8. Children’s Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect or process any data from individuals under this age.
9. Data Location and International Transfers
All user and customer data is stored and processed on Google Cloud servers located in the United States. If you are located in the EU/EEA, this constitutes a transfer of data outside the European Union. Appropriate safeguards are in place under Google’s DPA to ensure GDPR compliance.
10. Communication and Notices
All privacy-related inquiries and official notices should be sent to dpo@catstats.ai. Email correspondence that includes delivery confirmation (e.g., read receipt or email response) will be considered valid legal communication.
11. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. Changes will be posted on our website and/or communicated via email to registered users. Continued use of the Service after changes are posted constitutes acceptance.
12. Contact Information
For any questions about this Privacy Policy or to exercise your rights, contact us at:
Data Protection Contact:
dpo@catstats.ai
Issued by:
Witanalytica S.R.L.
RocketChair S.R.L.
Thank you for trusting CatStats.AI to manage your data securely and transparently.
Change Log
Version 2.0 - Added provisions for: AI Affiliate Assistant data processing (Privacy Policy §1.3, §2, §3, §4, §5); disclosed Postmark and Stripe as third-party data processors (§4).
Previous version effective March 1, 2025 — May 17, 2026.