Privacy Policy
Effective Date: September 2026 • Your privacy and data security are our top priorities.
Passwords are cryptographically salted and hashed. We never store plain passwords.
We never sell, rent, or trade your personal or campaign information to third parties.
Security telemetry protects account integrity and filters malicious automated traffic.
1. Introduction
At Rumble Traffic ("we", "our", "platform"), we are committed to respecting your privacy and protecting the personal and operational data you share with us. This Privacy Policy details the types of information we collect, how it is stored and processed, and your rights regarding your data.
2. Information We Collect
We collect only the minimum necessary information required to provide reliable services:
Your display name, email address, and a securely hashed password. If you authenticate with Google, we store your Google ID, verified email, and profile avatar.
UPI transaction IDs (UTR), deposit timestamps, bonus amounts, and optional payment receipt screenshots uploaded for manual verification by administrators.
Destination URLs submitted for traffic campaigns, target quantities, selected duration tiers, and real-time delivery status logs.
IP addresses, browser User-Agent headers, session tokens, and security logs collected for rate limiting, DDoS mitigation, and anti-fraud enforcement.
3. How We Use Your Information
- To provision your user wallet, process UPI top-ups, and dispatch automated traffic campaigns.
- To monitor campaign delivery and automatically credit pro-rata refunds for any undelivered hits.
- To send critical service notices, password reset OTPs, support ticket replies, and account updates.
- To detect and prevent fraudulent payments, credential abuse, or bot attacks against our infrastructure.
- To comply with applicable legal obligations and resolve customer inquiries.
4. Cookies & Local Tracking
We utilize essential HTTP-only cookies to keep you logged in safely and protect platform integrity:
- auth_token: Cryptographically signed JWT cookie verifying your active session.
- blog_view_[id]: 24-hour expiration cookie used to deduplicate real blog article views and prevent refresh spam.
- Anti-bot tokens: Ephemeral tokens used to authenticate genuine browser requests against automated scrapers.
We do not use invasive third-party cross-site advertising trackers or sell your browsing history.
5. Data Storage & Infrastructure Security
Your data is stored in enterprise-grade cloud databases (Supabase PostgreSQL) hosted in secure data center environments. All communications are strictly encrypted in transit using modern TLS/SSL (HTTPS). Access to administrative tools is gated behind role-based authentication, multi-factor guards, and Discord approval integrations.
6. Third-Party Service Providers
We partner only with trusted infrastructure providers necessary to operate the application:
- Cloud Database: Supabase (PostgreSQL engine with continuous automated backups).
- Email Delivery: Transactional SMTP servers (for password resets and OTP verification).
- Traffic Dispatch Engine: High-speed automated residential nodes for executing campaign hits.
These providers process data strictly on our instructions and are prohibited from using your data for any other purpose.
7. Your Rights & Account Deletion
You have the right to access, rectify, or request the deletion of your account and personal information at any time. You can delete your account instantly from your in-app Settings or submit a web deletion request via our public Account & Data Deletion Portal without needing to install the application. Upon verification, all associated personal records will be securely purged from active databases.
8. Contact Our Privacy Team
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact our support team via Contact Support or by submitting an inquiry from your user panel.