Privacy Policy
Last updated: 23 August 2026
The controller for personal data processed by Albion Profit Forge (albionprofitforge.com) is Ahmed Ghanafer, a private individual in Sweden, Gränsvägen 18 13741, [email protected]. This policy says what we collect, why, how long we keep it, who sees it and what you can do about it. The short version: no advertising, no third-party analytics, no selling of data.
1. Cookies
We set at most four first-party cookies. Two of them (pf_anon and pf_ref) are set only after you click Accept in the cookie banner; the other two are necessary:
- pf_consent (12 months): your Accept or Decline choice. Strictly necessary, so it needs no consent itself.
- pf_anon (12 months, with consent): a random visitor id used to count visits and to see which pages lead to sign-ups. If you register, it is attached to your account so we can see the pages you read before signing up.
- pf_ref (90 days, with consent): the source tag you arrived with, such as reddit or discord, so we know which posts bring people.
- pf_refcode (90 days, no identifier): set only when you open a partner's referral link. It remembers that link so the partner is credited if you later subscribe. It is needed to deliver the referral you followed, and it holds nothing about you.
Decline and nothing but pf_consent is stored; the site works the same. You can change your choice at any time: reset the cookie choice (also linked in every footer). Separately from cookies, the app keeps in your browser what it needs to work: your sign-in token and settings in localStorage, a cache of the last results so the page opens instantly, and a one-time key during the Discord or Google sign-in. These are necessary for the service you asked for and are never sent anywhere except to our own server. Remembering your last tab is a convenience and happens only with consent or when you are signed in.
2. What we collect and why
- Page views (path and time) on every page, counted with no identifier. Basis: our legitimate interest in knowing which pages work. With your consent the view also carries the visitor id and the source tag, so we can see the path a visitor took before signing up. Basis: consent.
- Usage events in the app (which tab or detail was opened, a paywall or sign-in prompt shown, a checkout started), tied to your account. Basis: legitimate interest in improving the product. You can switch this off in Menu, Account (Usage analytics), or object by email, and we stop recording them for your account.
- Account data: an account id, a label, the hash of your access token (and the key of your private data feed if you use one), your Discord or Google id and display name when you link one, and creation and last-use times. Basis: performing the contract with you. The source tag you signed up with, if you consented to cookies. Basis: consent. Partners see the accounts they referred as a masked label and a sign-up date only.
- Your content: private prices, carts, records and filter settings. Basis: the contract.
- Subscription data: your Paddle customer id, the premium end date, whether a trial was used, and for each payment the amounts Paddle reports (price, tax, fee, net). Paddle holds your card and invoice details; we never see card numbers. Basis: the contract and our bookkeeping duty.
- Partner data, only if you ask to be paid referral commission: legal name, whether you are a private individual or a business, country and address, tax or VAT id, F-skatt number if Swedish, country of tax residence, PayPal email and its verification, the terms version you accepted, commission and payout records, and the self-billing statements we issue in your name. Above a yearly payout threshold we ask for a copy of an identity document by email, which we keep only as long as needed to confirm the details and then delete; that check is our own fraud policy, not a legal requirement. For partners resident in Sweden we also store the personnummer, because payments to them are reported to Skatteverket. Basis: the contract, our legal duties (bookkeeping, VAT and tax reporting) and our legitimate interest in preventing fraud.
- Server logs (IP address, path, status, user agent) for security and debugging. Basis: legitimate interest.
3. Who processes data for us
We use these providers, each bound by its own data processing terms:
- Paddle.com Market Ltd (UK) and its group: checkout, payment, tax and invoices. Paddle is the seller of record and a controller for the purchase itself.
- PayPal (Europe) S.à r.l. et Cie, S.C.A.: partner payouts (name and PayPal email).
- Resend, Inc. (US): transactional email (verification codes, payout notices).
- Cloudflare, Inc. (US): DNS, TLS and proxying of all traffic, and routing of our support mailbox to a Google mailbox.
- Discord Inc. (US) and Google LLC (US): sign-in, and for Discord the Premium role on our server.
- Google Fonts, the Tailwind, cdnjs and jsDelivr content delivery networks, and Paddle's checkout script: your browser fetches these directly under its own connection, which reveals your IP address to them. We have no agreement with the public delivery networks; they process that request under their own terms.
- Item icons are loaded by your browser from render.albiononline.com (Sandbox Interactive GmbH), which sees your IP address.
- The Albion Online Data Project: we fetch market data from it on our server; it receives nothing about you.
Some of these providers process data in the United States. Transfers rely on the EU-US Data Privacy Framework where the provider is certified and on the European Commission's standard contractual clauses otherwise.
4. How long we keep data
- Account data and your content: until you delete the account.
- Page views and usage events: deleted after 13 months.
- Server logs: 30 days on our server. Cloudflare keeps its own edge logs under its policy. Encrypted database backups are kept 14 days, so deleted data can persist in a backup for that long.
- Payment records, partner statements and the partner details shown on them: 7 years after the end of the year they were issued, as Swedish bookkeeping law requires, even after account deletion.
- The Discord or Google id used for a free trial: kept after deletion so a trial cannot be claimed twice.
- Identity documents: deleted once the check is done.
5. Your rights
You can export the data held against your account and delete the account yourself from Menu, Account in the app (deleting forfeits any referral commission not yet paid out; request a payout first). You also have the right to access, correct, restrict or object to processing, to data portability, and to withdraw consent (for cookies, through the reset link above). Email [email protected] from the address linked to your account, or include your account label, so we can confirm it is you; we answer within one month. You can complain to the Swedish Authority for Privacy Protection, IMY (imy.se), or to the supervisory authority where you live.
6. Email
We send email about your account, payments and payouts when needed, and notices of changes to these policies. Emails about new features and offers go only to people who ticked the box in Menu, Account (a few times a year at most). Basis: consent. Every such email carries a one-click unsubscribe link, and the box can be unticked at any time.
7. Children
The Service is not directed at children under 13 and we do not knowingly collect their data. Paid features and the referral program require you to be 18; the age is self-declared when you start a trial or accept the partner terms.
8. Changes
Changes to this policy are announced on this page and in the app. The date at the top is the current version.