Legal

Privacy Policy

Last updated: August 1, 2026

This Privacy Policy explains what information BetweenAffiliates ("we", "us") collects when you use our site, register an account, or embed our ad-serving code on your site, and what we do with it. It applies to registered users (affiliates and advertisers) and to visitors of pages that embed our ads.

1. Data controller and applicable law

BetweenAffiliates is based in Norway, and this policy is written to comply with the Norwegian Personal Data Act and the EU General Data Protection Regulation (GDPR), which applies in Norway as part of the EEA agreement. For the purposes of the GDPR, BetweenAffiliates is the "data controller" for the personal data described below.

2. Information we collect from registered users

When you create an account, we collect:

  • Your name and email address.
  • The domain(s) and site(s) you register to embed ads on.
  • Billing information processed by Stripe, our payment processor for your BetweenAffiliates subscription (see §5). We do not store your card details ourselves.
  • Any information you send us directly, such as through the contact form.

3. Information we collect from visitors of embedded ads

When someone views a page that embeds our ad code, our server records data about that request in order to select and serve a relevant ad, prevent abuse, and provide you with accurate statistics:

  • IP address, and the country derived from it.
  • User agent string, and the browser/operating system/device type derived from it.
  • The referring page, requested language, and which ad was shown or clicked.
  • Basic bot/crawler detection signals.

This data is used in aggregate for ad targeting and for the statistics shown on your dashboard. We do not sell this data, and we do not use it to build advertising profiles outside of this service.

4. Our legal basis for processing

Under the GDPR, we rely on the following legal bases:

  • Performance of a contract — for your account details and billing information (§2), because we need them to provide the service you signed up for.
  • Legitimate interest — for visitor request data (§3), because it's necessary to select and serve ads, produce your statistics, and detect abuse, and doesn't outweigh visitors' privacy interests given the data isn't used to identify or profile individuals across other services.
  • Legitimate interest — for the AI-assisted content matching in §6, because it's limited to your own publicly published page content, not personal data.
  • Consent — where we ask for it explicitly, such as optional marketing emails.

5. Third parties we share data with

  • Stripe — payment processing for your BetweenAffiliates subscription. Stripe's own privacy policy governs how they handle your billing data.
  • OpenAI — page-content summarization and semantic embeddings (§6).
  • Pinecone — storage of the vector embeddings used for ad matching (§6).

We do not sell personal data to third parties for their own marketing purposes. Stripe, OpenAI, and Pinecone are based outside the EEA; where personal data is transferred to them, we rely on the safeguards each provider offers for international transfers (such as Standard Contractual Clauses), as required under the GDPR.

6. AI-assisted content matching

To match ads to the content of your pages, we may fetch a page's public content and send it to OpenAI to generate a written summary and a vector embedding, which is stored with a third-party vector database provider (Pinecone) for semantic matching. Only publicly accessible page content is processed this way — not visitor personal data.

7. Cookies

We use a session cookie to keep you signed in and to protect the site against cross-site request forgery. We do not use third-party advertising or tracking cookies on betweenaffiliates.com itself.

8. Data retention and your rights

You can ask us to close your account and remove your account data, your ads, and your pages at any time — contact us (§10) to request this. Aggregate, anonymized statistics that can no longer be tied to your account may be retained.

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request erasure of your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, where processing is based on consent.

Contact us (§10) to exercise any of these rights. If you believe we haven't handled your data properly, you also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), datatilsynet.no.

9. Security

We take reasonable technical and organizational measures to protect the data we hold, including encrypting connections to the site and never storing raw payment card details. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Changes and contact

We may update this policy from time to time; material changes will be communicated by email to registered users. If you have questions about this policy or your data, contact us.