LEGAL
Privacy Policy
Version 2026-08-21 · Effective August 21, 2026
This policy explains how TrafficWar handles information when you use the service.
Who we are and our roles
TrafficWar is an online service operated by Mohammed Albadri, an individual based in New Cairo, Cairo, Egypt; it is not operated by an incorporated company. For account, website, support, security, and billing-administration data, the operator determines why and how the data is used. For event data a customer submits about its users, the customer ordinarily acts as controller and TrafficWar acts as processor under the Data Processing Addendum. Customers remain responsible for their notices, lawful bases, instructions, and responses to their end users.
Account and authentication data
We process email address, password hash, role, plan and entitlements, email-verification and password-reset records, accepted terms version, session records, MFA status and authentication or recovery records, services, API-key metadata, configured browser origins, alert destinations, and support communications. Secret payment-card details are handled by Polar rather than stored by TrafficWar.
Customer event data
Customers choose what they send. Event data may include event and service identifiers, received and client timestamps, latency, labels, source, user-agent, route or path, trace and distinct identifiers, status and error fields, derived geography and client fingerprint, and arbitrary properties JSON. Customers should avoid sending unnecessary personal or sensitive data in properties.
Network, device, and location data
We and Cloudflare process request metadata such as IP address, user-agent, request time, route, and security signals to deliver and protect the service. TrafficWar may transiently process a direct or customer-supplied IP address to derive country and city and a salted client fingerprint. Raw IP addresses are not stored in event rows. Local in-memory lookup caches may temporarily retain lookup results; Cloudflare may add country or city headers at the edge.
Usage and billing data
We process plan selection, subscription status, Polar customer or product references, period and grace dates, event and alert usage, storage and request attribution, and quota outcomes to provide entitlements, operate billing, prevent abuse, and estimate service costs. Polar separately processes checkout identity, payment, tax, invoice, and transaction data as Merchant of Record under Polar’s own notices.
Purposes and legal grounds
We use information to create and secure accounts; verify email; provide MFA and recovery; ingest, store, aggregate, display, export, and delete events; operate alerts and optional destinations; enforce limits; administer subscriptions; answer support requests; diagnose failures; prevent abuse; and comply with law. Depending on the context, this is necessary to perform our agreement, follow a customer’s processing instructions, meet legal obligations, or pursue legitimate interests in operating and securing TrafficWar. We do not sell personal data or use customer event data for advertising.
Providers and disclosures
We disclose data only to providers needed to operate TrafficWar, when a customer enables an integration, when a person asks us to, in connection with a lawful business or service transfer, or when law requires it. Current providers and purposes are listed on the Subprocessors page. Optional Telegram delivery occurs only when configured by a customer.
Locations and international processing
Primary TrafficWar compute and object storage are hosted with OVHcloud in Frankfurt, Germany. Optional secondary archive storage or delivery uses HostBrr infrastructure in Germany. Cloudflare operates a global edge network, and Polar, mail providers, or Telegram may process data in other countries. Where required, we rely on the provider’s contractual transfer safeguards or another lawful transfer mechanism.
Retention and deletion
Event access and physical archive retention depend on the applicable plan and global retention settings. Recent rows are held in a short-lived hot buffer before verified archive export. Service archive deletion suppresses eligible archived data from queries promptly and removes eligible files asynchronously; boundary or shared data can remain stored until its normal retention or rewrite. Account, security, billing, audit, and support records are retained while needed to provide the service, resolve disputes, prevent abuse, meet legal obligations, and maintain necessary records.
Security
Safeguards include TLS in transit, Secure and HttpOnly session cookies, email verification, optional or required MFA, scoped API keys, origin controls for browser ingest, rate and quota enforcement, access controls, service-level query scoping, operational monitoring, and controlled retention and deletion. TrafficWar uses self-hosted ClickHouse and Redis services on controlled infrastructure and a local MaxMind database for geo lookup. No internet service can guarantee absolute security.
Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, and to withdraw consent where processing relies on consent. Contact [email protected]; we may verify your identity. Requests about event data collected by a TrafficWar customer should normally go first to that customer, which can send us an authenticated instruction.
Children and required data
TrafficWar is intended for people acting in a business or technical capacity and is not directed to children. Some account and security information is required to provide an account; without it, we may be unable to provide the service.
Changes and contact
We may update this policy as the service, providers, or law changes. The version and effective date above identify the current notice. Privacy requests may be sent to [email protected]; general questions may be sent to [email protected]. The operator is Mohammed Albadri, New Cairo, Cairo, Egypt.