Who we are and who controls your data
Recompensated operates the website at recompensated.com and its reward systems. The operator acts as the "controller" of the personal data described in this policy, meaning it decides why and how that data is processed.
The operator and data controller is Recompensated S.R.L., a limited liability company incorporated under Romanian law, with its registered office at Bd. Dinicu Golescu no. 7, ground floor, ap. SP. COM. 3, Sector 1, Bucharest, Romania, and a share capital of 600 RON. The application for registration was filed with the Trade Register Office attached to the Bucharest Tribunal on 9 July 2026; the Trade Register number and the sole registration code (CUI) will be published here as soon as they are issued. The company is not currently registered for VAT.
For privacy questions or to exercise your rights, contact support@recompensated.com. A Data Protection Officer has not been appointed; the same address handles all data protection matters. General support is available through the support ticket system in your account.
This identity block will be updated with the Trade Register number and the CUI as soon as the Trade Register issues them.
Scope and applicable law
This policy is intended to reflect the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"); Romanian Law no. 190/2018 implementing the GDPR at national level; the ePrivacy rules as implemented in Romania by Law no. 506/2004 (covering cookies, similar technologies, and electronic marketing); and, where relevant, EU and Romanian consumer-protection, e-commerce, and digital-services rules.
Processing of personal data is supervised in Romania by the Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).
What data we process, why, and on what legal basis
Depending on how you use the platform, we process the categories below. "Legal basis" refers to GDPR Article 6.
| Data category |
Purpose |
Legal basis |
| Account identifiers (name, email, password hash, social-login ID, avatar, language) |
Create and secure your account; authenticate you |
Contract (Art. 6(1)(b)) |
| Points balance, earning logs, holds, withdrawals, reward and skin orders |
Operate the rewards service and process payouts; keep financial records |
Contract; Legal obligation for accounting/tax (Art. 6(1)(b),(c)) |
| Offer, survey, cashback, PTC, and shortlink tracking identifiers and conversion data |
Credit valid activity and reconcile it with providers |
Contract; Legitimate interests in fraud prevention and reconciliation (Art. 6(1)(b),(f)) |
| Referral relationships and commissions |
Operate the referral programme |
Contract (Art. 6(1)(b)) |
| Device and browser signals, fingerprint, IP address, login and activity history |
Security, fraud and abuse prevention, provider compliance |
Legitimate interests; Legal obligation where applicable (Art. 6(1)(f),(c)) |
| Support tickets and community chat content |
Provide support and moderate the community |
Contract; Legitimate interests (Art. 6(1)(b),(f)) |
| Payout details (wallet address, payout email, Steam trade URL, country/address) |
Fulfil withdrawals and skin orders |
Contract (Art. 6(1)(b)) |
| Cookie / local-storage identifiers for analytics, marketing, affiliate tracking, and embeds |
Measure usage and run optional marketing/affiliate tools |
Consent (Art. 6(1)(a)) + ePrivacy |
| Your email address for newsletters or promotional updates |
Send marketing communications you opted in to |
Consent (Art. 6(1)(a)) |
| Identity/KYC data, only if specifically requested |
Verify identity for a payout or a fraud/legal review |
Legal obligation; Legitimate interests (Art. 6(1)(c),(f)) |
Required and optional data
Some data is required to provide the service: an email and password (or a social login), and, when you request a payout, the payout destination for the method you choose. Without these we cannot create your account or complete the relevant action.
Other data is optional and under your control, such as an avatar, marketing-email consent, and optional analytics, functional, marketing, and affiliate cookies. Declining optional items does not stop you using the core service.
Cookies, local storage, and tracking technologies
Strictly necessary cookies and similar storage are used for sign-in, secure sessions, CSRF protection, fraud controls, and other essential functions. Optional analytics, functional preferences, advertising, affiliate tracking, and third-party embeds stay disabled until you give the relevant consent, and non-essential technologies are not loaded before consent.
You can accept, reject, or customise optional categories, and withdraw consent at any time, from the Cookie settings link in the footer. Full details are in the Cookie Policy.
Marketing communications
Service and transactional messages (for example email verification, security alerts, withdrawal updates, and other messages needed to run your account) are sent on the basis of our contract with you and are not marketing.
Newsletters and promotional messages are sent only where you have opted in, and you can withdraw that consent at any time using the unsubscribe link in each message or your account settings. Withdrawing marketing consent does not affect service messages.
Fraud prevention, security, and automated decisions
To protect the platform, users, advertisers, and payout systems, we process anti-fraud data such as IP reputation and history, login activity, device and browser signals, referral relationships, payout-destination overlap, suspicious earning patterns, and provider feedback. This is based mainly on legitimate interests and, where relevant, legal obligations.
Some checks are automated and can hold or block a registration, an earning, or a withdrawal, or flag an account for review. Where an automated decision would produce a legal or similarly significant effect on you, you can ask for human review, express your point of view, and contest the outcome by contacting support. We do not use this data for unrelated advertising profiling.
Who receives your data (recipients, processors, and subprocessors)
We share personal data only as needed to run the service, and with providers acting as our processors under contract, or with independent third parties (such as offer, survey, and payout providers) that operate under their own privacy policies. The categories and current providers are listed below.
| Recipient category |
Role / purpose |
Current providers |
| Hosting and infrastructure |
Runs the website, database, and storage |
Namecheap, Inc. (VPS hosting) |
| Email delivery |
Sends transactional and (opt-in) marketing email |
Namecheap Private Email (SMTP) |
| Authentication and bot protection |
Social login and spam/bot mitigation |
Google (OAuth, reCAPTCHA); Meta/Facebook (OAuth, currently disabled) |
| Fraud and IP intelligence |
Scores IP/device risk |
IPQualityScore; iphub |
| Offer, survey, ad, and reward-video networks |
Provide earning inventory and report completions |
Offerwall and survey partners (for example Rapido); hideout.tv |
| Cashback networks |
Track qualifying purchases |
Awin; CJ (Commission Junction); Impact; Rakuten |
| Payout and fulfilment |
Deliver gift cards, PayPal, Visa, and skins |
Tremendous; SkinsBack; skin price and catalog sources (Skinport, ByMykel) |
| Communications and media |
Push notifications, GIF search, community announcements |
Browser push services; Tenor (Google); Discord |
| Analytics and advertising (consent only) |
Usage measurement and optional ads |
Google Analytics; Google AdSense (if ads are enabled) |
| Professional and legal |
Accounting, legal, and authorities where required |
External accounting and legal advisers; competent authorities on lawful request |
We keep the list of processors and subprocessors under review and update this table whenever a provider is added, replaced, or removed.
International data transfers
Some providers listed above may process data outside Romania or the European Economic Area (EEA), for example in the United States. Where personal data is transferred internationally, it is protected by an appropriate GDPR transfer mechanism, such as an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, or Standard Contractual Clauses with supplementary measures.
We review the transfer mechanism relied on for each provider whenever our providers change, and document it as part of our GDPR records.
How long we keep data
We keep personal data only for as long as necessary for the purpose it was collected for, then delete or anonymise it. Different records are kept for different periods; the criteria are below. Where a specific law requires a longer period, the legal period applies.
| Record |
Retention criterion |
Indicative period |
| Active account data |
Kept while the account is open |
Until closure, then a 7-day grace period and anonymisation |
| Financial, withdrawal, and reward records |
Accounting and tax obligations under Romanian law |
Up to 10 years, as required by Romanian accounting and tax law |
| Anti-fraud / abuse markers (post-deletion) |
Preventing repeat abuse, duplicate rewards, and code reuse |
Up to 3 years, detached from the profile where possible |
| Support tickets and correspondence |
Handling and evidencing your requests |
Up to 3 years after the ticket is closed |
| Security and server logs |
Security monitoring and incident response |
Up to 12 months |
| Consent and consent-withdrawal records |
Demonstrating a valid legal basis (accountability) |
Up to 3 years after consent is withdrawn |
Your rights
Subject to the GDPR and Romanian law, you may have the rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where consent is the legal basis. Withdrawing consent does not affect processing carried out before withdrawal.
You can exercise the most common rights directly from the Privacy & Data section of your account: download a copy of your personal data as a structured JSON export (available for a limited time via a private link tied to your account) and request account closure.
If you cannot reach that section (for example because your account is locked) or you prefer to contact us, open a support ticket or write to support@recompensated.com. We aim to respond within one month, in line with GDPR Article 12, and will tell you if an extension lawfully applies.
Account closure and what is retained
When you request account closure it enters a grace period during which you can cancel it from the same Privacy & Data section. After the grace period the account is anonymised: identifiers (name, email, avatar, address, social-login IDs, trade URLs) are scrambled or removed, sessions and push subscriptions are revoked, and the account can no longer log in, earn, withdraw, or appear in public listings such as the leaderboard, chat, or referral pages.
Some records are kept after anonymisation where required for legitimate purposes such as fraud and abuse prevention, prevention of duplicate rewards and code reuse, accounting and tax obligations, chargeback and dispute handling, partner reconciliation, security investigations, and legal compliance. Wherever possible, retained records are detached from your visible profile.
Complaints and the supervisory authority
If you believe your personal data has been processed unlawfully, please contact us first through the support route or at support@recompensated.com so we can try to resolve it.
You also have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336, Bucharest, Romania; email anspdcp@dataprotection.ro; website www.dataprotection.ro. If you are in another EEA country, you may also contact your local data-protection authority.
Children and minimum age
The service is not intended for anyone under 18. In Romania the minimum age for a child to consent to information-society services on their own is 16 under Law no. 190/2018; because the platform involves real payouts and skin trading, the operator sets the minimum age to use the service at 18.
If you believe a child has provided personal data to the platform, contact us so we can review and handle the case appropriately.
Security of your data
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include encrypted connections (TLS/HTTPS) for data in transit, hashed and salted password storage, role-based access controls, server-level firewalls, regular software and dependency updates, and automated fraud detection.
Processors we engage are required to maintain comparable security standards. No system can guarantee absolute security, but we review and improve our safeguards in line with GDPR Article 32. If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours where feasible and, where required, inform affected users without undue delay.
Changes to this policy
We may update this policy as the platform, our providers, or the law change. The current version and its last-updated date are shown at the top of this page. Material changes will be communicated by a suitable means, such as an on-site notice or, where appropriate, an email. Continuing to use the platform after an update means the updated policy applies to your ongoing use.