Privacy Policy

Last updated 27 August 2026 · Applies to organictraffic.io

The short version. To sell you a file we need your email address and your country. That is essentially it. Your card never touches our servers, and we do not sell or share customer data with anyone. The only tracking we run is Google Ads conversion measurement — and if you are in the EEA, the UK or Switzerland, that is switched off too.

1. Who is responsible

TikFuel B.V., trading as OrganicTraffic, of Hoograamstraat 129, 6211BJ Maastricht, the Netherlands, is the controller of personal data described in this policy. Contact: support@organictraffic.io.

This policy covers data about you, our customer. It does not cover the business contact data contained in the files we sell — that is addressed on our compliance page.

2. What we collect

DataWhyLawful basis
Email addressTo deliver your file and send your receiptPerformance of a contract
Billing countryTo apply the correct tax treatmentLegal obligation
Order contents and any notes you addTo build the right filePerformance of a contract
Payment confirmation (last 4 digits, brand, status)Reconciliation and refundsLegal obligation
Name and message, if you use the contact formTo answer youLegitimate interest
Aggregate, non-identifying request logsSecurity, abuse prevention and uptimeLegitimate interest

We do not collect or store your card number, CVC or expiry date. Those are submitted directly to Stripe on Stripe's own infrastructure.

3. Cookies and tracking

Your cart is kept in your browser's own local storage. It never reaches us until you press pay, and clearing your browser data deletes it. Nothing about it is shared with anyone.

We run Google Ads conversion tracking so that we can tell which of our adverts actually lead to an order. Google's tag loads on every page and, where permitted, sets Google advertising cookies so that a click on one of our adverts can be matched to a later purchase or discount-code signup. What it reports is the value of the order and our own order reference. It is not sent your name or your email address.

If you are in the EEA, the UK or Switzerland, those cookies are not set. The tag runs with Google Consent Mode defaults of denied for advertising and analytics storage in those regions, so no such cookie is written and no advertising identifier is sent. That is why there is no consent banner to click through: we do not ask, because in those regions we do not use it. Elsewhere the cookies are set, subject to local law, purely to measure our own advertising.

4. Who we share it with

Only the processors required to run the service:

  • Stripe — payment processing. Receives your email and billing details.
  • Cloudflare — hosting and content delivery. Processes request metadata.
  • Resend — sends your order confirmation and discount-code emails. Receives your email address.
  • Google Ireland Ltd — advertising conversion measurement. Receives that an order happened, its value and our order reference. Not used for visitors in the EEA, the UK or Switzerland.

We do not sell, rent or trade customer data. We do not share it for anyone else's marketing.

5. How long we keep it

  • Order and invoice records: 7 years, as required by tax law.
  • Delivered files: 90 days, so we can re-issue a lost download link, then deleted.
  • Contact form messages: 24 months.
  • Server logs: 30 days.

6. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or port your personal data, to object to processing based on legitimate interest, and to withdraw consent at any time. Under GDPR you also have the right to complain to your supervisory authority.

To exercise any of these, email support@organictraffic.io. We respond within 30 days and there is no charge. Note that we may need to keep invoice records even after a deletion request, because tax law requires it.

7. International transfers

Our processors may handle data outside your country, including in the United States. Where that happens, transfers are covered by Standard Contractual Clauses or an equivalent approved mechanism.

8. Security

The site is served over TLS. Payment data is handled entirely by a PCI-DSS Level 1 processor. Access to order records is restricted to people who need it to fulfil or support orders. If a breach affecting your data occurs, we will notify you and the relevant authority within the legally required timeframe.

9. Children

This is a business-to-business service and is not directed at anyone under 18. We do not knowingly collect data from children.

10. Changes

Material changes will be reflected in the “last updated” date above and, where the change affects you meaningfully, notified by email.