Privacy Policy
This policy explains how Web3App processes personal data when you use the website, manage campaign measurement or interact with a tracking link.
1. Who is responsible
The operator is “On - Track” Krystian Tarkowski, 33-326 Koniuszowa 254, pow. nowosądecki, gm. Korzenna, woj. MAŁOPOLSKIE, Polska; NIP 7342788644; REGON 492811639. You can submit privacy requests to privacy@web3app.online or by post to this address, marked “Web3App — privacy”. Our website is web3app.online.
The operator is the controller for website administration, account security and its own campaigns. Where an account holder uses the service for its own campaigns, that holder determines the campaign purpose and lawful basis and may act as a separate controller. Any processing on behalf of another controller requires appropriate contractual arrangements before use. This policy does not replace those arrangements.
2. Information we process
Account application data includes first name, last name, phone number, email address, website URL, preferred plan, application details, privacy-notice acknowledgment, submission time and an application reference. We use this information to assess your request and contact you about access or proposed service terms. Application review at your request relies on steps taken before entering a contract, where applicable (Article 6(1)(b) GDPR). It is not used for unsolicited marketing. Application records are removed after 90 days by the scheduled cleanup job; restricted backups may retain deleted records for up to a further 7 days. If a separate service agreement is made, its account and contractual records have their own applicable retention requirements.
Account data includes your username, any email supplied by your administrator, a password hash, account creation time and sign-in information. Link data includes names, tracking identifiers, destinations, notes, status and a history of destination changes with the account that made each change.
Following an active tracking link records the timestamp, tracking identifier, destination at the time of the click, IP address according to the account’s privacy settings, User-Agent, available Referer header, derived device category, and submitted query parameters. Parameters may include keywords, creative and campaign identifiers, UTM tags, gclid, gbraid and wbraid. Country is only derived when a local GeoIP database is configured; otherwise it is recorded as unknown. We do not send click data to an external geolocation service.
Common sensitive parameter names, including passwords, tokens, email and telephone fields, are redacted. This filter cannot detect all personal information. Do not place personal details or secrets in URLs, notes or campaign parameters. Referrers and query parameters may inadvertently contain personal data.
3. IP minimization and click estimates
IP anonymization is enabled by default. Before storage, the final 8 bits of an IPv4 address or final 80 bits of an IPv6 address are removed. When an administrator disables this setting, subsequent clicks may store the complete IP address. The setting does not retroactively change older records. A keyed daily value derived from the stored IP and link is used to estimate unique daily networks. It contains no browser fingerprint and is not a cross-site identifier. Masked addresses and keyed values may still qualify as personal data; we treat them accordingly.
4. Purposes and legal bases
We process account and link information to provide the requested service and manage its operation, on the basis of contract where applicable (Article 6(1)(b) GDPR). Proportionate security, abuse prevention and first-party campaign measurement may rely on legitimate interests (Article 6(1)(f)), subject to a documented assessment and your right to object. Legal obligations may require limited processing under Article 6(1)(c). Where consent is legally required for a particular campaign or use, the campaign controller must obtain it before that processing begins. The availability of a tracker does not establish a lawful basis for every use.
We do not sell click records, build advertising audiences from them, fingerprint visitors, or change destinations based on a visitor’s identity, device, browser or advertising platform.
5. Recipients and international transfers
Authorized account users can access their own click data. Server administrators and hosting or infrastructure providers may process information as necessary to operate and secure the service. If a reverse proxy or CDN is enabled for the domain, it receives connection metadata before traffic reaches the application. The destination website receives a normal browser visit after redirection and operates under its own privacy policy. We may disclose information where legally required.
Before appointing additional providers or enabling transfers outside the European Economic Area, the operator must assess the processing arrangement and establish an applicable GDPR transfer mechanism, such as an adequacy decision or standard contractual clauses where required. Contact the operator for the current provider and transfer information relevant to your account.
6. Retention and deletion
Account administrators choose a click retention period of 30, 90, 180 or 365 days. The default is 90 days. Shortening retention deletes expired click records when the setting is saved; a daily cleanup job removes subsequently expired records. Dashboard totals and exports cover retained records, not a permanent lifetime archive. Link data and destination history remain until the link or account is deleted or an applicable legal requirement requires another period.
Restricted local database backups are retained for up to 7 days, so deleted data may remain temporarily in a backup. Backups are used for recovery rather than normal access. Following a restoration, retention cleanup must run before normal service resumes and any outstanding deletion requests must be reapplied. Application access logs are disabled in the supplied deployment; infrastructure security logs are restricted and rotated. A CDN or hosting provider may maintain separate operational logs under its agreement.
7. Cookies and security
Redirect visits do not set analytics cookies. Signed-in administration uses essential session and CSRF cookies. See the Cookie Policy. We use encrypted connections in production, password hashing, account isolation, anti-forgery protections, restricted database access and rate limits. No system can guarantee absolute security.
8. Your rights
Depending on the applicable conditions, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Send requests to the email or postal address above. Include the relevant tracking link and approximate time when possible, but do not send passwords. We may request proportionate information to verify your request; limited or masked data may make an individual record impossible to identify.
We normally respond within one month, subject to lawful extensions. You may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes UODO), or your competent supervisory authority. Information is available at uodo.gov.pl.
Email correspondence
Messages you send to our contact address are stored in our domain mailbox. Outgoing correspondence is delivered through Brevo as an email service provider. We use correspondence and contact details to respond to your request and administer the service; do not include passwords or access tokens in email.
Accepted public click-tracking events record the resolved next-hop destination. For transparent tracking requests, the validated redirect value is stored separately as technical request metadata rather than as a campaign parameter.
9. Changes and scope
We update this policy when the service or its data practices change. The date above identifies this version. Material changes affecting account users should be communicated before taking effect where required. This text describes the service and is not legal advice or a certification of GDPR compliance.