Privacy
Controller and contact
The controller for the processing of personal data on daily-cashback.info is Hasanbaba KG, Kirchenbühl 562, 6952 Hittisau, Österreich, FN 645893 v at the Landesgericht Feldkirch, UID ATU 81684358. You can reach us by email at [email protected], by phone on +43 664 1822552, or through the Contact page. We have not appointed a data protection officer, because the law does not require one for our company.
Overview
daily-cashback.info is an information portal for voucher codes, deals and shops, combined with a free cashback programme. If you only read the Website, we process very little: the technical data that every website visit produces. If you open an account and use the cashback programme, we need more, because we have to connect your purchases in the shops with your account and pay you. This policy explains which data that is, why we need it, who receives it and how long we keep it.
We do not sell personal data, we do not use it for advertising profiles and we do not load analytics or advertising scripts on this Website.
When you visit the Website
With every request, our server processes technical access data: IP address, date and time, the page requested, the referring page, browser type and operating system, and the amount of data transferred. We need this to deliver the pages, to detect and fend off attacks and to find errors. The legal basis is our legitimate interest in a secure and working website, Art. 6(1)(f) GDPR. Log data is deleted or anonymised automatically after a few weeks, unless a single record is needed to clear up a specific security incident.
Your customer account
To register, you give us your email address and a password. We store the password only as a hash, never in readable form. Your name is taken from the part of your email address before the @ until you change it. In your account settings you can add a first name, last name and phone number if you wish; these are optional. We also store your language, your country if known, the date of registration, the time of your last login and whether you have confirmed your email address.
For security and to prevent several accounts per person, we store an encrypted value of your IP address at registration and at your last login. This value is calculated with a secret key (HMAC-SHA256); we do not store the IP address itself in your account. Your browser also creates a random device ID, which is stored in the browser and sent to us as an encrypted value. Neither value is used for advertising or passed on.
The legal basis is the performance of our agreement with you, Art. 6(1)(b) GDPR, and, for the security and fraud checks, our legitimate interest in a fair programme, Art. 6(1)(f) GDPR.
Registration check with Google reCAPTCHA
On the registration form and the contact form we use Google reCAPTCHA (version 2) to stop automated sign-ups and spam. The service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The reCAPTCHA script is loaded only on these forms. It processes, among other things, your IP address, browser information and your interaction with the check, and may set or read Google cookies. When you send the form, we pass the result token to Google and receive back whether the check was passed. Data may be transferred to Google LLC in the USA, which is certified under the EU-US Data Privacy Framework. The legal basis is our legitimate interest in protecting the forms from abuse, Art. 6(1)(f) GDPR. More information: policies.google.com/privacy.
Sign-in with Google
If you choose to sign in with Google, you are sent to Google, and Google tells us your email address, your name and a Google account ID after you agree. We use this only to create or open your account. We do not receive your Google password. The legal basis is the performance of our agreement with you, Art. 6(1)(b) GDPR.
Emails about your account
We send you emails that are needed for your account: the confirmation link after registration (valid for 48 hours), password reset links (valid for 2 hours) and messages about bookings, payouts or missing cashback requests. We do not send newsletters. The legal basis is Art. 6(1)(b) GDPR.
Clicks, tracking and cashback
When you click a link to a shop, you are first sent through our own redirect at /go/. If you are logged in, we record the click with a random click ID, your account, the shop and programme, the time, the target address, the referring page, your browser identifier and an encrypted value of your IP address. We then forward you to the affiliate network and pass on the click ID as a parameter (for CJ the parameter "sid"). We do not pass your name or email address to the network or the shop.
The network and the shop set their own cookies to recognise that your order came from our link. When they report the purchase, we receive the click ID, an order number, the order value, the commission, the currency and the status. We use the click ID to find your account and book your cashback. For our cashback programme we work mainly with CJ (Commission Junction), operated by Conversant LLC, and possibly with Awin and Impact. The networks and shops process this data as independent controllers under their own privacy policies.
The legal basis is the performance of our agreement with you, Art. 6(1)(b) GDPR. For visitors without an account who click a voucher or deal link, the click is forwarded in the same way without an account reference; the legal basis is then our legitimate interest in being paid for referrals, Art. 6(1)(f) GDPR.
Payouts with PayPal
For a payout we need the email address of your PayPal account. We store it in your account as a payment method, together with your payout requests (amount, currency, date, status). To send the money, we pass your PayPal email address and the amount to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. PayPal processes the payment as an independent controller. The legal basis is Art. 6(1)(b) GDPR, and for keeping payout records our legal retention duties, Art. 6(1)(c) GDPR.
Missing cashback requests
If you report a purchase that was not tracked, we process the shop, order date, order number, order value, the click date if you give it, your message and any proof you upload (an order confirmation or invoice). We forward the information needed to the network or the shop so that they can check the order. Please black out anything on your proof that is not needed, such as your address or payment details. The legal basis is Art. 6(1)(b) GDPR.
Fraud prevention
To protect the programme from misuse, our system compares signals such as shared encrypted IP values, shared device IDs, many clicks on the same shop in a short time, a high share of cancelled orders or very early payout requests. If several signals come together, the account is marked and payouts are held for a manual check by a person. We do not make automated decisions with legal effect within the meaning of Art. 22 GDPR: a marking never leads to a penalty without human review. The legal basis is our legitimate interest in preventing fraud, Art. 6(1)(f) GDPR.
Getting in touch
If you write to us by email or through the contact form, we process your details to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns your account, otherwise Art. 6(1)(f) GDPR. Our mailbox [email protected] runs on Google Workspace, provided by Google Ireland Limited, which processes the messages on our behalf under Art. 28 GDPR. Processing in the USA cannot be ruled out; it is based on standard contractual clauses and the EU-US Data Privacy Framework.
Cookies and browser storage
In the EU, the EEA, Switzerland and the United Kingdom, a notice asks for your choice on cookies. At present we do not load any analytics or advertising scripts, whatever you choose. We do not set our own tracking cookies. The networks and shops set their cookies only after you have clicked through to them. Cloudflare may set a technically necessary security cookie.
We store the following entries in your browser's local storage or session storage. They stay on your device and are used only for the functions named:
- sb_kunde_dailycashback: your login key. Normally it is kept only in session storage and disappears when you close the browser. If you tick "Remember me", it is kept in local storage until you log out; on our side it expires after 30 days.
- sb_geraet: a random device ID used for security and fraud checks, see above.
- sb_ref: a referral code, only if you arrived through a link containing one.
- dc_cookie_wahl: your choice in the cookie notice, the time and the version of the notice.
- sb_app_weg_dailycashback: the time you closed the note about adding the Website to your home screen, so that it does not appear again for seven days.
- kb_profil and kb_flash (session storage): your name and email address for the account header and short status messages, deleted when you close the browser or log out.
The legal basis for these entries is that they are strictly necessary for the service you request, § 165(3) of the Austrian Telecommunications Act (TKG) and Art. 6(1)(b) and (f) GDPR. You can delete them at any time in your browser settings; you will then be logged out.
Cloudflare
Our pages run behind Cloudflare, a network service that forwards requests to our server, speeds up delivery and protects against attacks. Cloudflare processes technical connection data on our behalf as a processor under Art. 28 GDPR. Because Cloudflare operates worldwide, data may be processed outside the EU, for example in the USA; this is based on standard contractual clauses and Cloudflare's certification under the EU-US Data Privacy Framework. The legal basis is our legitimate interest in a secure and fast website, Art. 6(1)(f) GDPR.
Hosting
daily-cashback.info runs on a server that we operate with Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Deutschland. The server is located in Germany. Hetzner provides the infrastructure and processes data only on our behalf, under a data processing agreement pursuant to Art. 28 GDPR.
Who receives your data
In summary, personal data goes only to: the affiliate networks (CJ and, where used, other networks) and the shops, as far as needed for tracking and missing cashback requests; PayPal for payouts; Google for reCAPTCHA, for our mailbox and, once offered, for sign-in with Google; Cloudflare and Hetzner as technical service providers; and authorities or courts where we are required by law. We do not sell or rent data to anyone.
How long we keep data
- Account data: as long as your account exists. When you delete your account, we remove your name, email address, phone number, payment methods, login keys and linked Google sign-in at once; the account remains only as an anonymous record.
- Clicks, bookings and payouts: these are part of our accounting with the networks and are kept for the statutory retention period of seven years under Austrian law (§ 132 BAO), even after your account is deleted, but without your name and email address.
- Missing cashback requests and uploaded proof: until the request is finished and any follow-up questions are settled.
- Server log data: a few weeks.
- Emails: until your enquiry is dealt with, unless retention duties apply.
- Confirmation and password links expire after 48 or 2 hours; login keys after 30 days.
Transfers outside the EU
We are based in Austria and our server is in Germany. Data goes to countries outside the EU where Cloudflare, Google, CJ or PayPal process it, in particular the USA. These transfers are based on the EU-US Data Privacy Framework where the recipient is certified, or on the standard contractual clauses of the European Commission, Art. 46(2)(c) GDPR. If you live outside the EU, for example in the USA, Canada or Australia, please note that your data is processed in the EU and protected under EU law.
Your rights
You have the right to access your data (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on our legitimate interest (Art. 21). You can withdraw any consent at any time with effect for the future. Many details you can change or delete yourself in your account settings, including deleting your account. For everything else, a short message to [email protected] is enough. We may ask you to confirm your identity from the email address of your account.
You can complain to a data protection authority. The authority responsible for us is the Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, Österreich. You can also contact the authority in the country where you live.
Notice for visitors in the United States
We do not sell personal information and we do not share it for cross-context behavioural advertising, as these terms are understood under the California Consumer Privacy Act (CCPA) and similar US state laws. We have not done so in the past twelve months. The categories of personal information we collect are those described above: identifiers (email address, account ID, encrypted IP value, device ID), commercial information (clicks, purchases reported by networks, cashback, payouts), internet activity on our Website, and the content of messages you send us. We use them only for the purposes described in this policy.
You can ask us to tell you what personal information we hold about you, to correct it or to delete it. We will not treat you differently for using these rights. You can make a request by email to [email protected]; an authorised agent can also make a request for you if you confirm this to us. We do not knowingly collect information from people under 18.
Children
The cashback programme is open only to people aged 18 or over. We do not knowingly collect data from children. If you notice that a child has opened an account, please tell us and we will delete it.
Changes to this policy
We update this policy when our service or the law changes. Members are informed by email about important changes. The version published on this page applies.
Last updated: 8 October 2026.