CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Privacy Policy

This policy explains what personal data CashoutGuard processes, why, and what rights people have. It covers two groups: customers (the businesses that use CashoutGuard and their staff) and end users (the visitors of our customers' websites and apps that CashoutGuard protects).

1. Who we are

CashoutGuard is operated by SSWAP MEDIA LLC, a Wyoming limited liability company, 30 N Gould St Ste N, Sheridan, WY 82801, USA ("we", "us"). Contact: support@cashoutguard.com.

For our customers' account data we are the controller. For end-user data that customers send to CashoutGuard, we act as a processor on the customer's behalf, under our Data Processing Agreement. The customer is the controller and is responsible for informing its own users.

2. Data about customers

  • Account data: name, email address, company name, website, password (stored hashed), language preference.
  • Billing data: handled by our payment provider Stripe. We receive the plan, status and the last four digits of the card, never the full card number.
  • Usage data: logins, settings changes and support messages, to run and secure the service.
  • Website visits: we count visits to our public pages without cookies. We store the page, the referring website, campaign tags, country and device type, plus a visitor code made from your IP address and browser with a key that changes every day. We never store the IP address itself, and the code can't be linked across days. Visit records are deleted after 400 days.
  • How you found us: when you first visit our website from a link with campaign tags or from another website, a first-party cookie (cg_attr, 30 days) remembers the campaign, the referring website and the page you landed on. If you sign up, we save it with your account to count signups per channel. It is not used for advertising or shared with anyone.

Legal basis: performance of the contract, and our legitimate interest in securing and improving the service.

3. Data about end users (fraud prevention)

When a customer installs CashoutGuard, our script and API process, only to detect fraud and abuse:

  • Network data: IP address and data derived from it (country, city, network provider, whether it belongs to a VPN, proxy, Tor or datacenter).
  • Device and browser characteristics: browser and operating system version, screen size, language, time zone, graphics and audio rendering characteristics, installed fonts, and signals of automation, emulation or tampering. From these we compute hashes to recognise a returning device.
  • A random identifier stored in a first-party cookie, local storage and IndexedDB on the customer's website. It contains no personal information and is used only to recognise a returning device for fraud prevention. It is not used for advertising or cross-site tracking.
  • A WebRTC connectivity check that contacts a public STUN server (stun.l.google.com) to detect IP addresses hidden behind a VPN.
  • Data the customer sends: the customer's own user ID, and optionally email address and payout address. Emails and payout addresses are stored as one-way hashes, not in clear text.
  • Events: signups, logins, offer clicks, conversions and cashout requests, with timestamps and amounts.
  • Risk signals learned across the service: fraud networks move from one website to the next, so the engine may use pseudonymous signals computed from all the traffic we protect, for example how many different time zones an IP address was seen with in the last seven days, or whether the same email address or device was blocked by another website we protect. Only the signal is used: it never reveals which websites a person visited, and no customer can see another customer's data.

We do not collect keystrokes, form contents, full page URLs with query strings, precise location, or contacts.

Legal basis: the customer's and our legitimate interest in preventing fraud, abuse and money laundering (GDPR Article 6(1)(f) and Recital 47). Storing the device identifier is strictly necessary for the security service the website provides.

4. Automated decisions

CashoutGuard gives each event a risk score and a suggested decision (allow, review or block), with the reasons behind it. The customer decides what to do with it. We recommend customers let a person review decisions that significantly affect a user, such as refusing a payout, and give users a way to contest them.

5. How long we keep data

  • End-user events: for the retention period of the customer's plan (7, 30, 90 or 365 days), then deleted automatically. Device data collected but never used is deleted after 2 days.
  • Device fingerprints, links between accounts (hashed emails and payout addresses, IP addresses) and end-user account records: kept to recognize returning fraud, and deleted automatically 12 months after the account's last activity. Accounts a customer blocked or allowlisted, and accounts with recorded cashouts, are kept while the customer's site exists.
  • Scans made with the live demo on our website: deleted after 7 days.
  • Customer account data: while the account is active and up to 90 days after it is closed, except billing records we must keep by law.

6. Sharing

We do not sell personal data. We share it only with the sub-processors that run the service:

Sub-processor Purpose Location
Hetzner Online GmbH Hosting and database Germany (EU)
Stripe, Inc. Payments (customers only) EU / USA
Email delivery provider Transactional emails (customers only) EU

We will announce changes to this list at least 30 days in advance.

7. Security

Data is encrypted in transit (TLS). Secret API keys, passwords, emails and payout addresses are stored hashed. Access is limited to the staff who need it. Each customer's data is isolated: no customer can see another customer's data (the engine may still use the pseudonymous risk signals described in section 3).

8. Your rights

People in the EU, UK and similar jurisdictions can ask for access, correction, deletion, restriction, portability, or object to processing. End users should first contact the website they used, because that website is the controller; we will help it respond. Customers can contact us at support@cashoutguard.com. You can also complain to your data protection authority.

9. Changes

We will post changes here and update the date above. Material changes will be announced to customers by email.