Privacy notice
What we collect, why we have it, and how long we keep it — covering both the businesses we work with and the end users who complete offers on a publisher's property.
Drafted 20 September 2026.
Template text — not yet reviewed by a lawyer
1. Who is responsible for what
For business contacts — the people who apply, sign in and run campaigns or placements — OpusWall decides why and how the data is processed.
For a publisher's end users, the publisher holds the account and the identity. We receive an opaque identifier and technical details about the request, and we use them only to attribute and pay for conversions. We never receive a user's name, e-mail address or payment details from a publisher, and publishers are contractually required not to send them.
2. Data about business contacts
We use it to assess applications, to operate accounts, to answer questions and to keep the platform from being abused. The lawful basis is the performance of a contract, or our legitimate interest in running the service and defending it against fraud.
- Application details: company, contact name, e-mail address, country, website, and the answers about traffic or product given on the form.
- Account details: name, e-mail address, role, organization and the timestamp of the last session.
- Correspondence: messages sent through the contact form or by e-mail, and our replies.
- Technical details of a submission: the browser user agent, a one-way digest of the IP address, and any campaign parameters in the link that brought you here.
3. Data about a publisher's end users
This exists to attribute a completed goal to the right publisher and to pay for it, and to detect automated or duplicated completions. Raw IP addresses are not stored: they are reduced to an irreversible digest used for rate limiting and fraud checks.
We do not build advertising profiles, we do not sell data, and we do not use this information to target anyone with advertising elsewhere.
- The opaque user identifier the publisher sends us, and any pass-through values it attaches to it.
- Which offers were opened, when, and which placement they were opened from.
- Technical details of the request: user agent, approximate country, device type and a one-way digest of the IP address.
- Conversions attributed to those clicks, with their amounts in cents.
5. How long we keep it
How long something is kept follows from why we hold it, so there is no single expiry date across the platform. In outline:
- Applications and the decisions on them: kept while the relationship lasts, and afterwards for as long as we may need to explain a decision.
- Accounts: for the life of the organization.
- Clicks and conversions: kept as financial records for as long as the money they represent may be questioned.
- Contact messages: kept while the question is open and for a reasonable period afterwards.
- Rate-limiting digests: pruned automatically after a short window.
- Postback logs: an advertiser's postbacks for 90 days; test notices to a publisher for 30 days; real notices to a publisher for as long as the conversion they belong to.
6. Your rights
Depending on where you live, you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive a copy.
An end user should start with the publisher whose site or app they used, because the publisher holds the account that connects an identifier to a person. If something still needs resolving on our side, write to us with the site and the approximate date and we will find it.
7. Where the data lives
The platform database is hosted in the European Union. Where a supplier processes data outside it, that transfer is covered by the safeguards the law requires.
8. Contacting us
Privacy questions and requests go to our legal address, listed on the contact page. The identity of the operating company and its data protection representative are to be completed before launch.
Questions about this document: legal@opuswall.net