1. Controller and contact details
The controller of the data described in this policy is Recompensated S.R.L., a limited liability company incorporated under Romanian law, with registered office at Bd. Dinicu Golescu no. 7, ground floor, apt. SP. COM. 3, Sector 1, Bucharest, Romania, share capital RON 600, registered with the Trade Register under no. J2026046278001, sole registration code (CUI) 55294515.
For any data-protection question or to exercise a right, use the ticket system or email support@recompensated.com. A data protection officer has not been appointed because the controller has not determined that appointment is legally required; requests are handled through the stated address.
2. Scope
This policy applies to visitors and users of recompensated.com, the account, earning activities, referral programme, community, support, withdrawals, reward and skin orders, and interaction with Recompensated features.
Third-party partners may separately process data when you access their offer, website, application, survey, shop, or payout method. For that processing, the partner may be an independent controller and its own privacy policy applies directly.
3. Sources and categories of data
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email, password hash, language, avatar, Google or Facebook ID, age confirmation | Directly from you, OAuth, and account systems |
| Activity and balance | Points, offers, conversions, holds, bonuses, level, missions, codes, referrals, leaderboards | Platform use and partner reports |
| Tracking and attribution | Click ID, transaction ID, sub-ID, source, campaign, merchant, transmitted value, conversion status | Platform, cookies, and partners |
| Payouts and orders | Method, amount, delivery email, wallet address, country, Steam URL, product, payment reference and status | Directly from you and reward providers |
| Technical and fraud-prevention data | IP, user agent, device, browser, session, logins, IP reputation, account links, risk signals | Web requests, device, and fraud-prevention providers |
| Communications | Tickets, support messages, community chat, reports, and feedback | Directly from you and moderation |
| Consent and preferences | Document acceptance, marketing, cookie choices, theme, language, and interface settings | Your choices |
| KYC data | Identity documents or information requested in a justified case | Directly from you and, if applicable, a verification provider |
| Approximate country | A two letter country code used to show a flag on your member profile card | Your own choice on your profile page, or derived on our servers from an IP address already recorded on your account |
4. Purposes and legal bases
| Purpose | Main data | Legal basis |
|---|---|---|
| Create, authenticate, and administer the account | Account, identity, session, and necessary preferences | Performance of a contract, GDPR Art. 6(1)(b) |
| Attribute and validate eligible activity | Activity, tracking, and partner reports | Performance of a contract and legitimate interests in reconciliation, Art. 6(1)(b),(f) |
| Administer points, orders, and withdrawals | Balance, payouts, orders, and delivery details | Performance of a contract; accounting and tax obligations, Art. 6(1)(b),(c) |
| Security, fraud prevention, and defence of rights | IP, device, behaviour, account links, and payouts | Legitimate interests and, where applicable, legal obligation, Art. 6(1)(f),(c) |
| Support and community moderation | Tickets, chat, reports, and relevant history | Performance of a contract and legitimate interests in community safety, Art. 6(1)(b),(f) |
| Compliance with legal obligations | Financial records, payouts, investigations, and lawful requests | Legal obligation, Art. 6(1)(c) |
| Analytics, advertising, and optional technologies | Cookie identifiers and usage data | Consent, Art. 6(1)(a), together with ePrivacy rules |
| Newsletters and promotional communications | Email and choice record | Consent, Art. 6(1)(a), or another basis expressly allowed by law |
| Showing an approximate country flag on your member profile card | Country chosen by you, or a country code derived on our own servers from an IP address already held for security purposes. The lookup uses an offline database and country level only, so no city, region, or precise location is derived and your IP address is not sent to any geolocation provider | Legitimate interests, Art. 6(1)(f), in community and social features. You can select a country, clear it so no flag appears, or hide your whole stats card with the Private account switch |
When relying on legitimate interests, we pursue safe and fair platform operation, loss prevention, and defence of rights and assess necessity and impact on the individual.
5. Required data and consequences of not providing it
An email address, authentication method, and technical security data are needed to create and protect the account. Delivery information is required for the selected reward. Tracking and partner confirmation are required to attribute third-party activity.
If you do not provide necessary data or block mechanisms essential to a feature, we may be unable to create the account, validate the activity, or deliver the reward. Avatar, marketing, and optional technologies remain voluntary.
6. Offer partners and independent controllers
Advertisers, offerwalls, survey providers, merchants, cashback networks, rewarded-video providers, and reward issuers may independently decide what data they collect on their pages, what criteria they apply, and whether activity is valid. Each third party is responsible for its own notice and legal bases in those situations.
We may send the partner an internal or pseudonymous identifier, attribution information, and technical data needed for fraud prevention, and receive the status, value, and identifier of the conversion. Never send a password or 2FA code to a partner.
7. Recipients and service providers
| Category | Purpose | Current or possible examples, if enabled |
|---|---|---|
| Hosting and infrastructure | Operate the application, database, and email | Namecheap, Inc.; Namecheap Private Email |
| Authentication and security | OAuth, anti-bot protection, IP reputation, and fraud review | Google; Meta/Facebook if enabled; IPQualityScore; iphub |
| Earning partners | Offers, surveys, videos, tracking, and conversion validation | Rapido and active offerwalls; hideout.tv; integrated advertisers |
| Cashback and affiliate networks | Attribute clicks and validate purchases | Awin; CJ; Impact; Rakuten, if active |
| Reward delivery | Gift cards, PayPal, Visa, crypto, and digital products | Tremendous; NOWPayments, if the relevant automation is active |
| Skins and catalogue data | Catalogue, prices, purchase, and delivery | SkinsBack; Skinport; ByMykel/CSGO-API |
| Communications | Email, push, GIFs, and community | Active SMTP provider; browser push services; Tenor/Google; Discord |
| Optional analytics and advertising | Usage measurement and ads | Google Analytics and Google AdSense only if configured and the required consent exists |
| Professional advisers and authorities | Accounting, advice, disputes, and legal obligations | Accountants, lawyers, auditors, courts, and competent authorities |
| Country flag images | Delivers the small flag image shown on member profile cards and in the language picker. Your browser requests the image directly, so this provider sees your IP address and browser user agent as part of that request | Flagcdn (flagcdn.com) |
| Offline country database, receives no data | Licenses the country database that we install and query on our own servers to derive an approximate country. This provider receives no personal data from us, because the lookup is local and your IP address is never transmitted to it | MaxMind, Inc. (GeoLite2 Country database) |
The list reflects integrations configured in the platform. Not every service is active at all times or for every user.
8. Transfers outside the European Economic Area
Some recipients may process data in the United States or other countries outside the EEA. For transfers for which Recompensated is responsible, we use a mechanism recognised by Chapter V GDPR as applicable: an adequacy decision, valid participation in the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses together with assessments and supplementary measures where required.
You may request information about the mechanism relevant to a provider category at support@recompensated.com. For data you submit directly to an independent partner, review that partner policy.
9. Cookies and similar technologies
We use cookies and local storage for session, security, language, preferences, attribution, analytics, and integrations. Technologies strictly necessary or requested for the selected feature are used for their stated purpose; analytics, advertising, and other optional technologies are controlled through the consent panel.
The Cookie Policy lists the categories, known technologies, duration, and how to change your choices.
10. Marketing and service messages
Messages necessary for the account, such as email verification, password reset, security, privacy requests, and withdrawal status, are service communications.
Newsletters and promotions are sent only on a valid legal basis. Where the basis is consent, you may withdraw it using the unsubscribe link or available setting. Withdrawal does not affect service messages or the lawfulness of earlier processing.
11. Fraud prevention, profiling, and automated decisions
To prevent multiple accounts, false conversions, payout abuse, and other fraud, we analyse technical, account, activity, referral, and payout data and may use automated scores or rules. Checks may flag an action, impose a temporary hold, or immediately block a high-risk action.
A significant measure is not based solely on an automated score where Article 22 GDPR prohibits this. You may request human intervention, present your view, and contest the result through support. We do not use fraud signals for advertising unrelated to their purpose.
12. Retention periods
| Record | Criterion and period |
|---|---|
| Active account and balance | For the life of the account; a 7-day grace period and anonymisation process apply after a closure request |
| Accounting records, withdrawals, and paid orders | Up to 10 years or the period required by applicable accounting, tax, or archiving law |
| Conversions, tracking, and partner reconciliation | As required for validation, chargebacks, disputes, and defence of rights, normally no more than 3 years unless a longer obligation applies |
| Fraud and abuse markers | Up to 3 years after the case or account is closed, limited and separated from the profile where possible |
| Tickets and correspondence | Up to 3 years after the request is closed, longer where a dispute or legal obligation exists |
| Technical and security logs | Normally up to 12 months, longer for an active incident |
| Consent and withdrawal records | As needed to demonstrate compliance, normally up to 3 years after the basis or relationship ends |
| Cookies and local storage | As described in the Cookie Policy or until removed from the browser |
13. Your rights
Subject to the GDPR, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent. You also have a right not to be subject to a solely automated decision in the circumstances covered by Article 22 GDPR.
Rights are not absolute. We may retain data or decline erasure where a legal obligation, defence of a claim, fraud prevention, or another legal exception justifies it. We will explain the applicable reason.
14. How to exercise your rights
You can request an export and account closure from the Privacy and Data area or contact support@recompensated.com. We may request proportionate information to verify identity and protect the account.
We respond without undue delay and normally within one month. The period may be extended under the GDPR for complex or numerous requests, in which case we will inform you. Requests are normally free, subject to the exceptions expressly allowed by law.
15. Account closure and anonymisation
A closure request has a 7-day grace period during which it may be cancelled. After processing, primary identifiers are removed, replaced, or anonymised, sessions and push subscriptions are revoked, and the account can no longer be used.
Records required for accounting, disputes, chargebacks, fraud prevention, partner reconciliation, security, or law remain only for as long as the purpose justifies and are separated from the public profile where possible.
16. Data security
We apply technical and organisational measures proportionate to risk, including HTTPS/TLS, password hashing, access controls, two-factor authentication for sensitive actions, logging, network protections, updates, and fraud checks.
No system is infallible. If a personal-data breach occurs, we assess the risk and notify ANSPDCP without undue delay and, where feasible, within 72 hours of becoming aware when notification is required by the GDPR. We also inform affected individuals where there is a high risk and the law requires it.
17. People under 18
The platform is not intended for people under 18 and we do not knowingly accept accounts held by minors. If we learn that a minor created an account, we may restrict it, investigate the situation, and erase or retain limited data as required by law and fraud-prevention needs.
18. Complaints to a supervisory authority
We encourage you to contact us so that we can try to resolve the issue directly. You always have the right to complain to the Romanian National Supervisory Authority for Personal Data Processing, 28-30 G-ral. Gheorghe Magheru Blvd., Sector 1, 010336 Bucharest, anspdcp@dataprotection.ro, www.dataprotection.ro, or to the competent authority in your country.
19. Changes and available languages
We may update this policy to reflect changes in the service, providers, or law. The version and date are shown at the top, and significant changes will be communicated through an appropriate method.
The policy is published only in Romanian and English. The versions are intended to have the same meaning. If there is a translation discrepancy, the Romanian version prevails to the extent permitted by law.














