Refer & Earn — Privacy Notice
Last updated: · v1
Effective date: 22 October 2026
This notice explains how we process your personal data in connection with the Refer & Earn programme and the premium friend gift. It supplements the Fanchaty Privacy Policy, which applies to anything not covered here. It is prepared under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
- FANCHATY AI LTD, a company registered in England and Wales, company number 16983888, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, is the controller of your personal data.
- Contact: [email protected]
2. Who this notice covers
- Affiliates: people who join the programme.
- Gift senders and recipients.
- Referrals: people who come to Fanchaty through an invite link, code or gift link.
3. What data we process
3.1 Programme account
- Your account ID and the email address on your account (taken from your account).
- Programme status, join date, account currency, your invite codes and links.
- The documents you accepted: version, language, a content fingerprint (SHA-256), acceptance date and your IP address at acceptance (encrypted).
3.2 Statistics
- Clicks on invite links are kept as daily totals per code. Unique visitors are estimated with a probabilistic counter that does not identify anyone; no personal data is stored in these statistics.
- Which site a click came from — the site name only, e.g. "instagram.com" — is kept as a daily total per code. The path and query string of the address are not read or stored, and nothing is recorded about individual people. We use this to check that the Promotion Rules are being followed, and it is not shown in the Affiliate's dashboard.
- Sign-up and premium counts.
3.3 Link and earnings records
- Which Referral is linked to which Affiliate, link dates, transaction numbers and amounts of the related payments, earnings calculations, refund and chargeback records.
- Referrals are shown to an Affiliate only under a pseudonym that is different for each Affiliate and with day-level dates. Affiliates never see a Referral's name or email address.
3.4 Fraud prevention signals
- Hashed with a secret key so they cannot be reversed (HMAC): device identifier, IP address (the /64 block for IPv6), normalised email address, payer email received from the payment provider, card fingerprint if provided by the payment provider, wallet address and a fingerprint of identity details.
- Rejected code and gift redemption attempts.
3.5 Payout data
- Your USDT (TRC20) wallet address (encrypted).
- Identity details requested at your first withdrawal: full name, country of residence, date of birth, tax declaration (encrypted; only ever shown masked in the Dashboard).
- Security events: changes to your wallet, identity details and automatic withdrawal setting.
- Payout records: amount, exchange rate, USDT amount, blockchain transaction ID, date.
3.6 Gift data
- Gift code, sender, whether the sender chose to show their name, and their short note.
- The account that redeemed the gift, the time of redemption, and their choice about showing their username to the sender.
3.7 Leaderboard
- Your name is shown on the leaderboard in shortened form (first two characters and "***"); your earnings for the month are used for ranking.
3.8 Communications
- Programme notifications we send you and emails you send us.
4. Purposes and lawful bases
- Running the programme (membership, links and codes, attribution, calculating earnings, payouts, the Dashboard): performance of a contract (Article 6(1)(b)).
- Preventing fraud and abuse, security (signals, reviews, the device cookie, checking whether a wallet is blocked): legitimate interests — protecting the programme and the integrity of payments (Article 6(1)(f)).
- Identity details at first withdrawal, age checks, sanctions screening, accounting and tax records: legal obligation and legitimate interests (Article 6(1)(c) and (f)).
- Showing the recipient's username to the gift sender: legitimate interests — letting the sender see that the gift reached the right person. This setting is on by default; you can turn it off when redeeming, or object later by writing to us. The gift works either way.
- Showing the sender's name and note on the gift page: at the sender's own choice and request (performance of a contract).
- Leaderboard (shortened names): legitimate interests — running the programme transparently and motivating participation.
- Programme notifications (earnings, payout and security emails): performance of a contract.
- Programme announcements and marketing emails: only with your consent (Article 6(1)(a)). You can withdraw consent at any time.
- Recording document acceptance and defending legal claims: legitimate interests.
5. Cookies
- __Host-fc_ref — remembers for 30 days that an invite link was clicked, so the link can be credited to the right Affiliate. It is set only on page navigation and cannot be set from inside other sites.
- __Host-fc_did — a random device identifier kept for 400 days, used to prevent fraud.
- When a gift link is opened, a 10-minute cookie is used to keep the code out of the address bar. Google Analytics and Meta measurement tools are not loaded on the gift page.
- These cookies are classified as necessary for security and for the service to work.
6. Who we share data with
- Infrastructure providers: hosting (AlexHost, Moldova), Cloudflare (network and security), Brevo (email).
- Our payment provider Centrobill: we use its transaction records to match earnings to real transactions. Your identity details are not sent to it.
- TronGrid (TRON network service): your wallet address is sent to this service to check that it is valid and not blocked, and to verify payout transactions.
- The wallet or exchange service we send USDT from (Binance): your wallet address is saved there to make the transfer.
- Binance: we only fetch public exchange rates; we do not send any personal data.
- Our legal, accounting and tax advisers.
- Public authorities: where the law requires (tax, sanctions, law enforcement).
- Business transfer: a buyer, if the company or business is transferred.
- Other programme participants: only the limited information described in this notice (gift sender–recipient names and note, shortened names on the leaderboard).
We do not sell your personal data.
7. The public blockchain
USDT payouts are recorded permanently on the public TRON blockchain. The wallet address, amount and time are visible to anyone, and nobody, including us, can delete that record. Anyone who knows your address can see the payment. We do not publish your name with the transaction.
8. International transfers
- We are based in the United Kingdom. Our service providers may process data in the UK, the European Economic Area, the United States and other countries.
- For transfers outside the UK we rely on adequacy regulations or safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
- Records written to the public blockchain are global; no transfer safeguard can apply to them.
9. How long we keep data
- Fraud prevention signals: 180 days.
- Rejected code and gift attempts: 90 days.
- Wallet and identity details: while your programme account is open and, after it closes, for the period required by tax and accounting law: six years.
- Earnings and payout records: as financial records, for the statutory retention periods and the limitation period for legal claims: six years.
- Document acceptance records: for the duration of the agreement and the limitation period after it ends: six years.
- Gift records (who sent a gift and who redeemed it): three years.
- Aggregated click statistics: indefinitely, as they contain no personal data.
10. Automated decisions
We use automated checks to stop obvious abuse: for example, an attempt to redeem your own gift from the same device is rejected automatically, and some payout lines are automatically flagged for review. No payout is permanently cancelled without a person reviewing it. You can write to us to challenge the result of an automated check and ask for a human review.
11. Security
Wallet and identity details are encrypted with a separate key (AES-GCM). Fraud signals are hashed with a secret key. Access is restricted and logged. Money operations require a second verification step.
12. Children
The programme is for people over 18 only. We do not knowingly process data of anyone under 18; date of birth is checked at the first withdrawal.
13. Your rights
- To access your data and to ask for it to be corrected, erased, restricted or ported.
- To object to processing based on legitimate interests (including gift name display and the leaderboard).
- To withdraw consent where processing is based on consent.
- To challenge decisions based solely on automated processing and ask for a human review.
- To complain to the UK Information Commissioner's Office (ICO): ico.org.uk.
Data we must keep for tax, accounting or fraud-prevention reasons may be kept for those periods even if you ask us to erase it. To exercise your rights, write to [email protected]. We reply within one month.
14. Changes
We may update this notice. We will tell you about material changes by email and in the Dashboard.
15. Contact
[email protected] · FANCHATY AI LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
