TrafficBull
Home / Privacy Policy

Privacy Policy

Digital Stars Ltd · panel.trafficbull.com · Version 2.0 · Effective 6 October 2026

Version 2.0 — Effective 6 October 2026 · Replaces the version last modified February 2021.

Controller: Digital Stars Ltd, a company registered in Malta (registration no. C86214), Tagliaferro Business Centre, Level 6, Sqaq Gaiety, Sliema SLM 1551, Malta ("Digital Stars", "we", "us").

Privacy and data-protection contact: privacy@trafficbull.com

1. Who we are and what this Policy covers

Digital Stars operates the TrafficBull advertising platform at panel.trafficbull.com and related domains, including the legacy panel at up.trafficbull.com (the "Platform"). The Platform is a business-to-business service through which advertisers buy, and publishers sell, online advertising traffic.

This Privacy Policy explains how we process personal data of:

  • Account Holders — the individuals who register for, administer or use a Platform account on behalf of an advertiser or publisher, and their representatives and contacts ("you");
  • Visitors to our websites; and
  • individuals who contact our support or sales teams.

Section 4 also explains, for transparency, how personal data of End Users — the members of the websites and email lists on which Platform advertising is delivered — passes through the Platform, and who is responsible for it. End Users are not our customers; their relationship is with the publisher whose site or list they use.

The Platform is intended for businesses and for individuals aged 18 or over. We do not knowingly process data of anyone under 18.

2. Personal data we collect

2.1 Account and identity data

Name, business email address, telephone number, job title, company name and address, username and password (stored hashed), account settings, language and time-zone preferences.

2.2 Financial data

Billing address, VAT/tax identifiers, invoices, payment history, payout details (bank/IBAN or e-wallet identifiers such as Paxum). Card payments are processed by our payment processors; we store only a payment token, card type and last four digits — never full card numbers.

2.3 Compliance and verification data ("KYC")

To meet legal obligations and protect the Platform we may collect: identity documents (passport or ID card), proof of address, business registration extracts and tax numbers, beneficial-ownership information, the results of sanctions and politically-exposed-person screening, and records of onboarding decisions (including declined applications).

2.4 Usage and technical data

IP address, device and browser identifiers, log-in dates and times, pages viewed, actions taken in the Platform, campaign and zone configurations, API calls, and cookies or similar technologies as described in our Cookie Policy.

2.5 Communications

Support tickets, emails, chat and call records, and notes of meetings.

Visitors may browse our public pages without registering; in that case we collect only the technical data in 2.4 to the extent described in the Cookie Policy.

3. Why we use your data and on what legal basis

Purpose Data used Legal basis (GDPR Art. 6)
Create and manage your account; provide the Platform; deliver, measure and bill campaigns Account, financial, usage Performance of a contract (6(1)(b))
Verify identity, screen against sanctions/PEP lists, prevent fraud, money-laundering and misuse KYC, account, usage Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) in protecting the Platform and its users
Process payments and payouts; keep accounting and tax records Financial Contract (6(1)(b)); legal obligation (6(1)(c))
Service communications (security alerts, changes to the service, invoices) Account Contract (6(1)(b))
Marketing communications to business contacts about our own services Account Legitimate interests (6(1)(f)) — you may opt out at any time (Section 5)
Improve and secure the Platform; analytics; troubleshooting Usage, technical Legitimate interests (6(1)(f))
Establish, exercise or defend legal claims; respond to lawful requests Any Legitimate interests (6(1)(f)); legal obligation (6(1)(c))
Cookies and similar technologies that are not strictly necessary Technical Consent (6(1)(a)) — see Cookie Policy

Where we rely on legitimate interests we have carried out a balancing assessment; you can ask us for a summary. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, other than automated fraud and sanctions screening that is always subject to human review before an account is refused or closed.

4. End-User data processed through the Platform

4.1 What passes through the Platform

When advertising is delivered through the Platform, technical data about the End User's request is processed: IP address, approximate location derived from it, device type and operating system, browser user-agent, language, referring page or zone, timestamp, click and conversion identifiers, cookie or advertising identifiers where set, and the sub-ID fields (sid1–sid5) that publishers attach to traffic. Publishers may use sub-ID fields to pass pseudonymous identifiers of their own End Users.

4.2 Roles

  • Publishers are controllers of their End Users' personal data. They are responsible for the privacy notice shown to End Users, for any consent required (including for marketing email and for cookies/advertising identifiers), and for the lawfulness of passing End-User data to the Platform.
  • Advertisers that receive click, conversion or sub-ID data become controllers of that data in their own right and must process it only for the purposes permitted in their agreement with us.
  • Digital Stars processes End-User data as a processor on behalf of Account Holders for the delivery, measurement and billing of advertising, under the Platform Data Processing Agreement (available from us on request and, once published, at https://panel.trafficbull.com/dpa). We also process limited End-User technical data as a controller for our own purposes of fraud prevention, security, billing reconciliation and aggregated reporting, on the basis of our legitimate interests.

4.3 Our commitments for End-User data

We process End-User data only as necessary to deliver and account for advertising; we do not build profiles of End Users for our own marketing; we do not sell End-User data; we do not use special-category data (such as data revealing sexual orientation or health) for targeting; and we retain End-User event data only for the periods in Section 8.

4.4 Rules for Account Holders

Account Holders must not pass directly identifying End-User data — such as names, email addresses or telephone numbers — in sub-ID fields or URL parameters, whether in plain text or in a reversible encoding, except through the Email Pass facility described below. Where an identifier is needed for attribution it must be a salted hash or opaque token. Account Holders must have a lawful basis, a compliant privacy notice and, where required, consent for the data they pass to or receive from the Platform, and must sign our Data Processing Agreement or data-sharing terms before receiving any End-User data.

4.5 Email Pass

Some publishers operate services whose members have consented to receive offers from third-party advertisers. Where such a publisher, as controller, instructs us in writing to do so, we transmit the member's email address — in encoded form and over encrypted connections — to advertisers that buy through specific Email Pass-enabled buying models (currently oRTB and CPC campaigns targeting the Email ad type) and that have signed an Insertion Order incorporating our Terms & Conditions. Advertisers on any other buying model or ad type do not receive email addresses. In doing this we act as the publisher's processor. Advertisers that receive an address become independent controllers and are contractually bound to use it only within the scope of the member's consent, to honour unsubscribes and suppression lists within 48 hours, not to enrich, share or resell it, and to delete it on request or when consent is withdrawn (Terms & Conditions §16.11). Encoding is not anonymisation; we treat these addresses as personal data throughout.

4.6 End Users' rights

If you are an End User and wish to exercise your rights over data processed through the Platform, please contact the website or email list you used, as that publisher is the controller. You may also contact us at privacy@trafficbull.com; we will forward your request to the relevant publisher and assist as required by law.

5. Marketing communications

We may send Account Holders information about Platform features, rates and services relevant to their business. You can opt out at any time using the unsubscribe link in each message, through your account settings, or by emailing privacy@trafficbull.com. We will continue to send service communications necessary to operate your account. We do not share your contact details with third parties for their own marketing.

6. Who we share your data with

We share personal data only as described here. We do not sell personal data.

  • Service providers acting as our processors: hosting and infrastructure (data centre located in the United States — see Section 7), email delivery, customer-support and CRM tools, analytics, security and fraud-detection services, identity-verification and sanctions-screening providers, and accounting software. Each is bound by a written data processing agreement.
  • Payment processors and financial institutions, which act as independent controllers for payment processing and may send us updates about your payment method.
  • Group companies, including TM International Limited (Guernsey), where necessary to provide the Platform, for internal administration, and under an intra-group data agreement.
  • Professional advisers (lawyers, auditors, insurers) under duties of confidentiality.
  • Public authorities, regulators, courts and law-enforcement bodies where we are legally required to do so or to protect our rights, the Platform or its users. We disclose only what is legally required and, unless prohibited, will notify you of a compelled disclosure.
  • A buyer or successor in the event of a merger, acquisition or sale of assets, subject to this Policy.

A current list of the categories of our sub-processors is available on request from privacy@trafficbull.com.

7. International transfers

Digital Stars is established in Malta (EU). Our Platform databases are hosted in Miami, Florida, United States, and some service providers and Account Holders are located outside the European Economic Area (EEA) and the United Kingdom. Where personal data is transferred to a country not recognised by the European Commission (or the UK Government) as providing adequate protection, we rely on:

  • the EU-U.S. Data Privacy Framework (and UK Extension) where the recipient is certified; or
  • the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), with the UK International Data Transfer Addendum for UK data, together with a transfer impact assessment and supplementary measures where needed.

You may request a copy of the relevant safeguards at privacy@trafficbull.com.

8. How long we keep your data

Data Retention Reason
Account and profile data Life of the account + 24 months Contract; disputes
Invoices, payments, payout records 10 years from end of the fiscal year Maltese tax and accounting law
KYC documents and screening results 5 years after the relationship ends (or after a declined application) AML/sanctions record-keeping; legal claims
Platform usage and security logs 12 months Security, fraud investigation
End-User event data (clicks, impressions, sub-IDs) Raw: 90 days; aggregated statistics: indefinitely (no personal data) Billing reconciliation, fraud, reporting
Support communications 3 years after closure Service quality; disputes
Marketing opt-out records Indefinitely To honour your choice

When a retention period ends we delete or irreversibly anonymise the data. Where a claim, investigation or legal hold is pending we keep the relevant data until it is resolved.

9. How we protect your data

We apply technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and of credentials and payment tokens at rest; role-based access control and multi-factor authentication for administrative access; logging and monitoring of administrative operations and access patterns; regular vulnerability management; segregated environments; backups; and confidentiality obligations for all staff and contractors. We review these measures regularly. No system is completely secure; please keep your credentials confidential and tell us immediately if you suspect unauthorised access.

10. Personal data breaches

If a personal data breach is likely to result in a risk to individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will inform affected individuals without undue delay where the risk is high. Where we act as a processor, we will notify the relevant controller without undue delay so that it can meet its own obligations.

11. Your rights

Subject to the conditions in data-protection law, you have the right to:

  • access your personal data and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • data portability — receive data you provided to us in a structured, machine-readable format;
  • withdraw consent where processing is based on consent, without affecting prior processing;
  • not be subject to solely automated decisions with legal or similarly significant effects.

To exercise any right, email privacy@trafficbull.com. We may ask you to verify your identity. We respond within one month, extendable by two further months for complex requests, and free of charge unless requests are manifestly unfounded or excessive.

You may lodge a complaint with the Information and Data Protection Commissioner (IDPC), Malta — idpc.org.mt — or with the supervisory authority in the EU country where you live or work. UK residents may complain to the Information Commissioner's Office (ico.org.uk).

12. Cookies

We use cookies and similar technologies on our websites and in the delivery of advertising. Details, including how to manage your preferences, are in our Cookie Policy at https://panel.trafficbull.com/cookie-policy.

13. Third-party websites

Our websites and the Platform may link to third-party sites, including advertiser landing pages and publisher websites. Those sites have their own privacy policies and we are not responsible for their content or practices.

14. Changes to this Policy

We may update this Policy from time to time. We will post the new version here with a new effective date and, for material changes, notify Account Holders by email or through the Platform before they take effect.

15. Contact

Digital Stars Ltd · Tagliaferro Business Centre, Level 6, Sqaq Gaiety, Sliema SLM 1551, Malta · privacy@trafficbull.com · data-protection contact: privacy@trafficbull.com

Related documents: Terms & Conditions https://panel.trafficbull.com/terms · Cookie Policy https://panel.trafficbull.com/cookie-policy · Platform Data Processing Agreement (on request; https://panel.trafficbull.com/dpa once published)