PRIVACY POLICY




1. Introduction
This Privacy Policy explains how ROIHEADS ("we", "us", "our") collects, uses, and protects personal data when you use our website and services related to media buying and traffic acquisition in the iGaming industry.
We process personal data in accordance with the General Data Protection Regulation (GDPR).
2. Data Controller
3. Data We Collect
Website Visitors
- IP address
- Device and browser data
- Pages visited, interactions
- Session recordings (Hotjar)
- Cookies and tracking identifiers
Business Contacts & Leads
- Name / nickname
- Contact data (Telegram, email, etc.)
- Company or affiliation (if provided)
4. Tracking Technologies
We use:
- Meta (Facebook) Pixel
- Google Analytics 4 (GA4)
- Hotjar (behavior analytics & session recordings)
These tools collect:
- Behavior data
- Traffic sources
- Interaction patterns
Used for analytics, optimization, and retargeting.
5. Purpose of Processing
We process data to:
- Analyze website performance
- Optimize marketing campaigns
- Run retargeting ads
- Communicate with partners and clients
- Prevent fraud and abuse
6. Legal Basis
We rely on:
- Consent — for cookies, tracking, retargeting
- Legitimate interest — for B2B communication
Tracking tools are only activated after user consent via cookie banner.
7. Retargeting
We use retargeting tools (e.g., Meta Pixel) to display ads to users who have previously visited our website.
This may involve tracking user behavior across platforms.
8. Data Sharing
We may share data with:
- Meta Platforms, Inc.
- Google LLC
- Hotjar Ltd.
- Hosting providers (Webflow)
We do not sell personal data.
9. International Transfers
Data may be transferred outside the EEA.
We rely on:
- Standard Contractual Clauses (SCCs)
- GDPR-compliant providers
10. Data Retention
- Analytics data: up to 14–26 months
- Leads: up to 24 months
11. User Rights
Users have the right to:
- Access their data
- Request correction or deletion
- Withdraw consent
- Object to processing
Requests:
[contact@roiheads.com]
12. Security
We implement:
- HTTPS encryption
- Access restrictions
- Internal data protection practices