PandaCPS (operated by FULLHOUSE ASSET Management LLC, Los Angeles, CA; collectively "we") takes your privacy seriously. This policy explains what we collect, why, and your rights.
1. What We Collect
1.1 Account Information (Brands & Publishers)
- Legal entity / business name, primary contact email, contact name
- WeChat ID, Slack/Telegram handles (optional, support-only)
- Tax form data (W-9 / W-8 BEN) — encrypted at rest, accessible only via authenticated RPCs
- Payout method & bank/Wise/PayPal credentials — encrypted at rest in a separate secrets table, never returned via standard PostgREST queries
1.2 Tracking Data
- Click events: timestamp, IP address (hashed), user agent, referrer, country code, UTM parameters
- Conversion events: order amount, currency, brand-supplied order reference, attribution click ID
- First-party cookie on Brand domains (optional, 30-day default window)
1.3 Usage Logs
- Dashboard sessions, API key usage, postback request logs (for debugging + fraud detection)
2. How We Use Your Data
- Operate the affiliate network: track clicks, attribute conversions, calculate commissions, issue payouts & invoices
- Detect fraud (cookie stuffing, impossible geographies, $0 orders)
- Comply with tax reporting (1099-NEC for U.S. publishers earning $600+ annually)
- Respond to support requests via the provided contact channel
- Send transactional emails: signup confirmation, payout notifications, terms updates
We do not use your data for marketing emails, sell it to third parties, or use it to train AI models.
3. Third-Party Services
- Supabase (database + auth) — hosted in U.S. East
- Cloudflare (CDN, DDoS protection, edge worker) — global network
- Stripe Connect (payouts, when enabled) — PCI-DSS compliant
- Wise (international payouts, when enabled)
- Resend / SendGrid (transactional email, planned)
- Google Analytics (pandacps.com landing page only, IP-anonymized)
4. Data Retention
- Click events: 90 days raw, then aggregated
- Conversion events: 7 years (tax retention requirement)
- Payout records: 7 years
- Account data: while account active + 2 years after termination, then anonymized
5. Your Rights
5.1 California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know — what personal information we collect
- Access — get a copy of the data we hold about you
- Delete — request deletion (subject to legal retention requirements)
- Correct — fix inaccurate data
- Opt-out of sale/sharing — we do not sell or share personal information
- Non-discrimination — exercising rights does not affect service
Email privacy@pandacps.com to exercise rights. We respond within 45 days.
5.2 EEA / UK (GDPR / UK GDPR)
If you are in the EEA or UK, you additionally have the right to data portability, restriction of processing, objection, and to lodge a complaint with your supervisory authority. Lawful basis for processing is contract performance (running the network) or legitimate interest (fraud detection).
6. Security
- HTTPS everywhere, HSTS enabled
- Database row-level security (RLS): brands see only their data, publishers see only their offers/earnings
- Bank/payout secrets stored in a separate table, accessible only via authenticated RPC calls (never directly readable via API)
- API keys hashed and rotatable; old keys can be revoked instantly
- Audit log on sensitive admin actions (settlements, mark-paid, account termination)
7. Children
The Service is not directed at children under 13. We do not knowingly collect data from minors. If you believe we have, contact privacy@pandacps.com and we will delete it.
8. International Transfers
Data is processed primarily in the United States. EEA/UK users: by using the Service, you consent to transfer to the U.S. We rely on Standard Contractual Clauses where applicable.
9. Changes
Material changes will be notified via email + platform banner with 30 days' notice. Continued use after the effective date constitutes acceptance.
10. Contact
Privacy: privacy@pandacps.com
DPO (acting): privacy@pandacps.com
Operating entity: FULLHOUSE ASSET Management LLC, Los Angeles, California, USA