Skip to main content
AutoFXRebate

Privacy policy

How AutoFXRebate collects, uses and protects personal data, the legal basis for each purpose, and how to exercise your rights.

Last updated: 5 September 2026

The Vietnamese version of this policy is authoritative. This translation is provided for convenience; where the two differ, the Vietnamese text governs.

1. Who is responsible for your data

AutoFXRebate ("AFR", "we") operates autofxrebate.com. We are the data controller for the personal data described in this document.

Privacy contact: [email protected]

AFR is an affiliate platform that helps traders check broker accounts and track rebates. AFR is not a broker and never holds or pays out user funds.

2. Who this policy covers

The site serves users in many countries. If you visit from the European Economic Area (EEA), the United Kingdom or Switzerland, we process your data under the GDPR and, for cookies, under the ePrivacy Directive. If you are in Vietnam, we process it under Decree 13/2023/ND-CP. In other Southeast Asian countries we apply the relevant PDPA.

Where these laws differ, we apply the higher standard to everyone rather than sorting users by where they connect from.

3. What we process

When you run a network check: the broker you select and the account identifier you enter (email, MT4/MT5 account number, or UID). We never ask for your trading password.

When you create an account: your email, your password (hashed with Argon2id, we never see the original), and your sessions. Each session stores its last-seen time and a salted hash of your browser's User-Agent string, used to detect a stolen session. That hash cannot be reversed back to the original string.

When you link a broker account: the account number and the rebate records the broker reports to us.

Technical logs: IP address, timestamp and request path, recorded by our servers and by Cloudflare for abuse prevention and debugging.

Measurement: Google Analytics runs for every visitor. Your choice decides whether there is a cookie and a durable identifier, see section 5.

We do not process special category data under GDPR Article 9, and we do not make automated decisions that produce legal effects for you.

4. Purposes and legal bases

What we doLegal basis (GDPR Article 6)
Create and maintain your account, keep you signed inContract, Art 6(1)(b)
Run the broker account checks you ask forContract, Art 6(1)(b)
Reconcile and display your rebatesContract, Art 6(1)(b)
Send operational email (verification, password reset)Contract, Art 6(1)(b)
Abuse prevention, rate limiting, platform securityLegitimate interests, Art 6(1)(f)
Administrative action logs for internal controlLegitimate interests, Art 6(1)(f)
Count page views, no cookie, no identifierLegitimate interests, Art 6(1)(f)
Cookie-based measurement via _ga (tells sessions and devices apart)Consent, Art 6(1)(a) and ePrivacy Art 5(3)

Where we rely on legitimate interests you have the right to object (see section 9). Where we rely on consent you may withdraw it at any time, and withdrawal does not affect the lawfulness of processing carried out before it.

5. Google Analytics, and why there is a banner

We use Google Analytics 4 to learn which pages get read, which devices hit display problems, and where visitors arrive from. Google Analytics stores cookies on your device and sends Google LLC your IP address (truncated by Google), the page path, browser and device information, and an approximate location derived from the IP.

Four things worth knowing:

  1. The default is decline, and declining still measures. Google's script loads for every visitor. While you have chosen nothing or pressed "Decline", we hold Consent Mode in its denied state: Google sets no _ga cookie and creates no durable identifier, so your page views cannot be joined together into one person. Google still receives a ping carrying your IP address (truncated), the page path and the device type.
  2. Accepting adds cookies. Pressing "Accept" turns on analytics_storage, Google sets the _ga cookie and can tell sessions and devices apart from then on.
  3. Declining costs you nothing. Every feature keeps working. We do not use a cookie wall.
  4. Withdrawing is as easy as agreeing. Press "Cookies" in the footer of any page. We clear the stored choice, delete the _ga cookies that were set, and send the withdrawal to Google.

We enable IP truncation and do not enable advertising features. This data is not used for ad targeting and is not joined to your AFR account.

You can also block Google Analytics on every site using Google's official add-on: https://tools.google.com/dlpage/gaoptout

6. Cookies and on-device storage

NameKindLifetimePurposeConsent needed
afr_sessioncookie14 daysKeeps you signed inNo, strictly necessary
afr-consentcookie180 daysRemembers this very cookie choiceNo, strictly necessary
afr-langcookie1 yearRemembers the language you pickedNo, your own preference
afr-lang, afr-themelocal storageuntil you clear itLanguage and appearanceNo, your own preference
afr-guest-checklocal storageuntil you clear itMarks that you used the free guest lookupNo, needed for that feature
_ga, _ga_<id>cookieup to 2 yearsGoogle Analytics tells sessions and devices apartYes

Your browser can clear cookies and local storage at any time. Clearing afr-consent makes the banner appear again.

7. Who receives your data

We do not sell personal data. Data is processed by:

  • Cloudflare, Inc. (US): CDN and attack protection. Handles IP and request metadata.
  • Vultr Holdings (servers in Singapore): hosting and database infrastructure.
  • Google LLC (US): Google Analytics. Receives measurement data from every visitor; the cookie and durable identifier only if you consent.
  • Resend (US): operational email such as address verification and password resets.

A separate note about YouTube: the Signals page may show video thumbnails loaded straight from Google's servers (i.ytimg.com). When such an image loads, your browser discloses your IP address to Google even if you declined analytics cookies. That is how browsers fetch images from another domain, not a measurement activity of ours.

When you follow a link to a broker, that broker handles your data under its own policy and we do not control that part.

8. Transfers outside the EEA

Our servers are in Singapore and several providers above are in the United States. For users in the EEA, the UK and Switzerland these transfers rely on:

  • the European Commission's Standard Contractual Clauses, with supplementary measures; and
  • for Google LLC and Cloudflare, Inc., certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.

You can request a copy of the safeguard that applies to you at [email protected].

9. Your rights

Under the GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict processing, to object to processing based on legitimate interests, to data portability in a machine-readable format, and to withdraw consent at any time.

Decree 13/2023/ND-CP grants equivalent rights, plus the right to request provision of data and the right to complain.

Send requests to [email protected] with the identifier you used (email or account number). We answer within 30 days.

Right to complain: if you believe we handled your data wrongly, you may lodge a complaint with the data protection authority where you live. EEA users can find theirs at https://edpb.europa.eu/about-edpb/board/members_en. Users in Vietnam may write to the Department of Cybersecurity and High-Tech Crime Prevention (A05), Ministry of Public Security. We would rather you came to us first, but it is your right either way.

10. How long we keep data

DataRetention
Account and emailUntil you delete the account or ask us to
Sessions14 days from sign-in, or until you sign out
Network check requests12 months
Rebate recordsAs long as accounting and broker reconciliation require, up to 10 years
Administrative action logs24 months
Server technical logs30 days
Google Analytics data14 months, per the property's retention setting

11. Deletion requests

When you ask us to delete, we remove outright: your account and email address, every sign-in session, your sign-in history, notices we sent you, the lookups you asked for, and the link between you and any broker accounts you told us about.

Two things we keep, in a form no longer tied to you:

  1. Recorded rebate entries, which we reconcile against the broker. We drop the link to you and replace the account number in the entry with a random token, so what remains does not lead back to you.
  2. Administrative action logs, kept for internal control. We drop the link to you from those rows.

Deleted data may still exist in routine backups until those backups age out.

12. Security

Data travels over HTTPS. Passwords are hashed with Argon2id. Sensitive tokens are encrypted with AES-256-GCM. We never store your broker login credentials. Access to the admin console is per-account and every action is logged.

13. Children

The service is for people aged 18 and over. We do not knowingly collect data from children. If you believe your child has sent us data, write to [email protected] and we will delete it.

14. Changes to this policy

We may update this policy. Material changes will be announced on the site, and the update date appears at the top of this page. If the scope of processing changes enough to need fresh consent, the cookie banner will appear again.

15. Contact

Any privacy question: [email protected]