Privacy Policy

How we collect, use, and protect your data.

Last updated: April 27, 2026

1. Information We Collect

Account Information

When you create a 2xShare account, we collect your email address, password (stored as a bcrypt hash — we never store plaintext passwords), and role (brand, affiliate, or admin).

Payment Information

Affiliates provide payment destination details (wallet addresses, bank account numbers, PayPal emails). These are encrypted with AES-256-GCM before storage. Only a masked preview is ever displayed after initial submission.

Click & Conversion Data

When a user clicks an affiliate tracking link, we collect: IP address, user agent, device type, country, city, region, ISP, UTM parameters, and referer URL. This data is used for conversion attribution, fraud detection, and analytics.

KYC Data

Affiliates who exceed payout thresholds may be required to complete KYC verification through our third-party provider (Didit). KYC data is processed and stored by the verification provider — we only store the verification status and provider reference ID.

2. How We Use Your Data

We do not sell your data to third parties. We do not use your data for advertising.

3. Data Storage & Security

Account and transaction data is stored in Neon Postgres (EU-Frankfurt region). Click analytics data is stored in ClickHouse Cloud (EU-Frankfurt region). All data is encrypted in transit (TLS 1.3) and sensitive fields are encrypted at rest (AES-256-GCM).

Admin accounts are protected by TOTP two-factor authentication. All API secrets are stored in AWS Secrets Manager — never in application code or environment variables.

4. Data Retention

Account data is retained for the lifetime of your account. Click and conversion data is retained for 24 months for analytics purposes. When you delete your account, your personal data is removed within 30 days. Anonymized analytics data may be retained longer.

5. Your Rights

You have the right to: access your data, correct inaccurate data, request deletion of your data, export your data in a machine-readable format, and withdraw consent for data processing. Contact privacy@2xshare.com to exercise these rights.

6. Cookies

See our Cookie Policy for details on how we use cookies and similar technologies.

7. Contact

For privacy-related inquiries, contact us at privacy@2xshare.com.