How affiliate measurement works
When Rintrade's affiliate redirect service is active, opening a /go/ link creates one redirect event before you are sent to the broker. By default, that event is recorded without a visitor or session identifier. Opening an affiliate link does not, by itself, give consent to identifier cookies.
Rintrade creates visitor and session identifiers only after you turn on identifier measurement in Cookie settings. Identifier cookies are not used for HEAD checks, suspected automation or prefetch requests, inactive-broker review fallbacks, or admin requests. Affiliate query parameters are not forwarded to the broker.
Data recorded for a redirect
The affiliate event table may contain:
- A random event ID and UTC timestamp; broker slug; affiliate link ID and revision; and the redirect reason.
- Page locale, target country, and a request country code supplied by Cloudflare when available.
- Validated source, medium, campaign, content, placement, locale, and country values.
- For a Rintrade referrer, the pathname; for an external referrer, only its hostname. Full external referrer URLs and query strings are not stored.
- Traffic classification, classifier version, and tracking mode.
- HMAC-SHA-256 visitor and session hashes, plus a hash-key version, only after identifier measurement has been enabled.
Data excluded from affiliate events
Rintrade does not persist the following in the affiliate event table:
- Raw IP addresses or raw User-Agent strings.
- Raw visitor or session cookie identifiers.
- Full external referrer URLs, referrer query strings, or affiliate destination URLs.
- Broker account, sign-up, deposit, or other conversion data in this version of the system.
Your cookie choice and privacy signals
Turning identifier measurement on stores rt_aff_consent for 365 days. An eligible redirect may then create rt_aff_vid, a rolling 90-day visitor ID, and rt_aff_sid, a session ID that lasts for 30 minutes after activity. Only keyed hashes of those IDs are written to an event record.
Turning measurement off stores rt_aff_optout for 365 days and removes the consent, visitor, and session cookies. Requests carrying Sec-GPC: 1 or DNT: 1 always override a saved opt-in and remain identifier-free.
Rintrade may still record a minimal, cookieless event to operate and count an affiliate redirect. It contains no visitor or session hash.
Retention and reporting
When D1 event storage is enabled, raw affiliate click events are scheduled for deletion after 90 days. Daily aggregate rows, which do not contain visitor or session identifiers, are retained for up to 24 months. Raw events are deleted only after their rollup has completed successfully.
Database timestamps are stored in UTC. The owner dashboard displays reporting dates and update times in Asia/Bangkok.
Cloudflare infrastructure and deployment status
The redirect source is designed to run on Cloudflare Workers and, once a production database binding is provisioned, to store measurement records in Cloudflare D1. Publishing this policy or the static website does not mean that the production Worker, D1 database, or route bindings are already active.
When the service is active, Cloudflare acts as an infrastructure provider and processor. Requests may be processed outside your country under the service configuration and applicable safeguards. The admin source is designed for owner-only access through Cloudflare Access and does not provide a public raw-event endpoint.
After the redirect, the broker handles the data your browser sends to its site under its own privacy notice. Rintrade does not give the broker access to the affiliate event table or owner dashboard.
Who is responsible and how to make a request
Rintrade is operated by Sakkarin Grinara, the controller for the affiliate measurement described here. For a privacy question or request, use the Contact page linked below. Please do not send broker account credentials or sensitive financial information.
Where applicable data protection law requires a lawful basis, Rintrade relies on its legitimate interests in operating, securing, and measuring the requested redirect for the minimal cookieless event. Consent is the basis for the optional visitor and session identifiers, and you can withdraw it at any time in Cookie settings.
Depending on the law that applies, you may also have rights to ask for access, correction or deletion, to object to or restrict processing, and to contact your local data protection supervisory authority. These rights can have legal limits and exceptions.