Privacy Policy

Privacy Policy

Last updated: 26 August 2026

This policy describes, in accordance with the General Data Protection Regulation (GDPR), how your personal data is processed when you use the Service.

1. Data controller

The publisher of the Echange de Liens website, reachable via the contact page or the site’s e-mail address, is the data controller for your personal data.

2. Data we collect

  • Account data: username, e-mail address, password (stored only in hashed form), referral link.
  • Content data: submitted URLs, banners, assigned points, points and order history.
  • Technical and anti-fraud data: IP address, visit timestamps and duration, browser, in order to apply anti-fraud limits (unique visits per IP and per period, bot detection).
  • Payment data: no banking data is processed by the Service. PayPal payments are processed by PayPal; cryptocurrency payments are verified publicly on the blockchain (destination address, transaction identifier).

3. Purposes and legal bases

  • Performance of the contract: management of the account, points, links and orders.
  • Legitimate interest: security of the Service, prevention of fraud and abuse, audience measurement.
  • Consent: placement of non-essential cookies, where applicable.
  • Legal obligation: retention of certain billing data where the law requires it.

4. Cookies and trackers

The Service only uses strictly necessary technical cookies (login session, language and theme preferences) and, where applicable, anonymised audience measurement. No third-party advertising cookies are placed by the Service. Visited member websites may, however, use their own cookies, under their sole responsibility.

5. Retention periods

  • Account: for the duration of use, until deletion or erasure request.
  • Anti-fraud logs (IP, visits): strictly as long as needed for the limits (from a few minutes to 24 hours depending on the mechanism), then deletion or aggregation.
  • Points and order history: lifetime of the account.
  • Passwords: hashed, never stored in plain text.

6. Recipients of the data

  • The Service’s hosting provider, for secure storage.
  • Payment providers (PayPal) for VIP purchases, each acting as a separate data controller.
  • Blockchain networks for cryptocurrency payments (pseudonymous data, public by nature).
  • No sale, rental or exchange of your data to third parties for advertising purposes.

7. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection. You may exercise them via the contact page or the site’s e-mail address. You may also lodge a complaint with the CNIL (cnil.fr) or your local supervisory authority.

8. Security

Measures implemented: HTTPS encryption of traffic, hashed passwords, CSRF protection on forms, rate limiting and IP-based anti-fraud, regular backups.

9. Automated decisions and anti-fraud

Visit and point validation relies on automated processing (minimum visit duration, uniqueness per IP address). These processes do not produce significant legal effects; if you disagree (points not credited, suspended account), you may request human review via the contact page.

10. Minors

The Service is intended for persons aged 16 or over. If you are under 16, do not use the Service without the authorisation of a legal guardian.

11. Transfers outside the European Union

Your data is hosted within the European Union. Should providers located outside the EU be used, appropriate safeguards (standard contractual clauses or adequacy decisions) are put in place.

12. Changes to this policy

If this policy evolves, the new version will be published on this page with its update date; for material changes, a notice will be displayed on the site.