Privacy Policy
MonacoWebPix (C/o CATS, Le Forum, 28 Boulevard Princesse Charlotte, 98000 Monaco) is the controller of the personal data described here. Questions and data requests: [email protected]. Representative in the Union under Article 27 GDPR: designated where the conditions of Article 27 GDPR are met; until then all data-protection matters go directly to the Monaco operator, who is the controller.
Two companion pages carry the detail that would bury this one: Cookie Policy names every cookie and storage key, and Subprocessors names every company that can touch your data on our behalf.
What we store, and why
| Data | Why | Kept for |
|---|---|---|
| Email, username, password hash (bcrypt) | Your account and sign-in | Until you delete the account |
| Profile name, bio, avatar, interests | Your public profile and feed personalisation | Until you delete the account |
| Posts, boards, comments, likes, follows | The service itself | Until you delete them or the account |
| Outbound clicks: destination, device type, coarse country, referrer, hashed IP | Click stats for the creator whose link was clicked | 90 days, then deleted |
| Click notice: product, page the click came from, device type, city and country, IP address | Letting the team see real store visits as they happen and spot fraudulent click traffic (legitimate interest) | In a private Telegram group until a team member deletes it |
| Reports you file or receive | Moderation and abuse handling | 2 years after the case is closed |
Your IP address
Click records in our database hold a one-way HMAC-SHA256 hash of the IP, not the address itself. It lets us count one click per person per day without being able to recover who that person was. This is pseudonymisation, not full anonymisation — so we treat it as personal data and delete it on the schedule above.
One exception: when you follow a product link to a store, a notice with your IP address, approximate location and device goes to a private Telegram group used by the Avahit team, so we can tell real shoppers from bot traffic that affiliate networks penalise. Telegram is listed in Subprocessors.
Cookies
Avahit itself sets four cookies, all strictly necessary for signing in. We run no analytics of our own: no page-view tracker, no advertising cookie, no profile of what you browse.
Creator storefronts are the exception, and the reason you see a consent banner. A creator can connect their own Meta Pixel or Google Analytics 4 property to their profile and product pages, the same way LTK or ShopMy storefronts work. Those scripts belong to the creator, not to us, and they set third-party cookies under Meta’s and Google’s own policies. They load only after you press Accept. Press Decline, or ignore the banner, and no pixel runs anywhere on the site. Your choice is kept in your browser’s local storage, not in a cookie, and you can change it by clearing site data.
authjs.session-token— keeps you signed in.authjs.csrf-token— blocks cross-site request forgery on sign-in forms.authjs.callback-url— returns you to the page you came from after signing in.__Secure-variants of the above on HTTPS.
Fonts are served from our own server, so no request goes to Google Fonts. If you sign in with Google, Google sets its own cookies on its own domain under its own policy.
Who else sees your data
We do not sell personal data. It is processed on our own servers. Two things leave our infrastructure:
- When you tap a product link, the destination store sees a normal web visit from you, including your IP and any affiliate tracking that store uses. That store’s privacy policy applies from that point.
- When someone posts a product URL, our server fetches that page once to read its title, price and image.
Your rights
Under the GDPR you may access, correct, export, restrict or delete your data, and object to processing. Two of these are self-service and immediate:
- Export — Settings → Download my data returns a JSON file with your profile, posts, boards, comments and likes.
- Delete — Settings → Delete account erases your account and content. It cannot be undone.
For anything else write to [email protected]; we answer within 30 days. You also have the right to complain to Commission de Contrôle des Informations Nominatives (CCIN), 12 avenue de Fontvieille, 98000 Monaco, or to the data protection authority where you live. We do not charge for any of this and we do not require you to justify a request.
If you are in the United States
California, Virginia, Colorado, Connecticut, Texas and a growing list of other states give you rights that overlap with the ones above: to know what is collected, to get a copy, to correct it, to delete it, and to opt out of sale, sharing and targeted advertising. Use the same address, [email protected], or the self-service export and delete buttons in Settings.
We do not sell or share personal information as those terms are defined in the CCPA, and we do not use it for cross-context behavioural advertising. There is nothing to opt out of, which is why you will not find a “Do Not Sell or Share My Personal Information” toggle: adding one would imply a practice we do not have.
The one nuance worth stating plainly: a creator may connect their own Meta or Google pixel to their own storefront pages. Those scripts load only if you press Accept on the cookie banner, and what they do afterwards is governed by Meta’s and Google’s policies, not ours. Declining the banner, or sending a Global Privacy Control signal, keeps them off entirely.
Categories collected in the last 12 months, in CCPA terms: identifiers (email, username, hashed IP, and the IP address in click notices), internet activity (posts, clicks you make on our own links), and commercial information (products you saved). Sources: you, and your browser. Purposes: running the account, showing your posts, counting clicks for the creator, safety. Disclosures for a business purpose: only to the processors listed in Subprocessors. We do not knowingly collect data from anyone under 16.
If you post here
Creators hand over a little more than visitors, and it is worth naming: the posts themselves, the click statistics for their own links, and — if they connect one — the identifier of their own Meta or Google pixel. We do not process payment or tax details, because we do not pay creators: commission comes to them from their affiliate networks directly, under those networks’ own privacy terms.
Those networks are the creator’s partners, not ours. When someone taps a product link, the destination store and its network set their own cookies on their own domains and attribute the sale. We send them nothing about you; the obligations of Amazon Associates, Awin, CJ, Impact, ShareASale, Rakuten and the rest sit with the creator who joined them. The deal for creators is written out in Creator Terms.
Affiliate tracking, in detail
Tapping a product sends you through /go/ on our domain, which counts the click for the creator and forwards you to the store. At the store, an affiliate network sets its own cookie on its own domain so that a purchase can be credited. For that cookie the network is the controller, not us: it decides what to collect and for how long, and its policy governs.
Networks whose cookies you may encounter after leaving Avahit: Awin, CJ Affiliate, Impact, ShareASale, Rakuten Advertising, Amazon, Meta, Google, Pinterest.
Two things we do not do, which are worth stating because they are common elsewhere: we do not send the networks anything about you from our side, and we do not receive their reports about individual visitors. What comes back to a creator is their own commission statement, from their own account.
Where your data lives
On our own server in the EU. Backups stay on the same machine and in the same country. Data reaches the United States in exactly three narrow ways: the proxy in front of the site (Cloudflare), the push service your browser chose for notifications, and — only if you accepted the banner on a creator’s storefront — that creator’s pixel. Those transfers rest on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as applicable to each company.
Automated decisions
None that affect you legally or significantly. Feed ranking is automated, but it decides the order of products, not anything about you. Moderation uses automated signals to flag and to hide a post temporarily; the decision that sticks is made by a person, and you can appeal it — see content moderation & appeals.
Security and breaches
Passwords are hashed with bcrypt, sessions are httpOnly cookies over HTTPS only, and a password change invalidates every other session. Backups run daily and the restore is tested weekly rather than merely scheduled. If a breach affects your data, we notify the supervisory authority within 72 hours of becoming aware of it, and we tell you directly when the risk to you is high. How to report a hole you have found: /security.
Changes to this policy
The date at the bottom of the page is the date of the current text. When a change affects what we collect or why, we tell account holders by email before it takes effect rather than relying on you to re-read the page.
Legal basis
Running your account and showing your posts is performance of a contract. Click statistics, moderation and abuse prevention rest on our legitimate interest in making the service work and keeping it safe; you may object to these at [email protected].
Children
Avahit is not for people under 16. If you believe a child has an account, write to [email protected] and we will remove it.