/ Privacy
Try free Back home
Legal

Privacy Policy

Effective January 1, 2026 · TDS GLOBAL, Georgia

1. Overview

TDS GLOBAL ("Service", "we") respects your privacy. This policy describes what data we collect when you use tds.so and the dashboard at app.tds.so, how we use it, and what rights you have.

By using the service, you agree to this policy. If you don't agree — please don't use the service.

2. What data we collect

2.1 Account

  • Email — for sign-in, notifications, password recovery.
  • Name or handle (optional) — for display in the UI.
  • Telegram ID (if connected) — for ban alerts.
  • Payment data — payment method, amount and status are stored; transactions are processed by our payment providers. We never see or store card or wallet credentials.

2.2 Usage data

  • IP address and User-Agent of dashboard visits — for security and audit.
  • Action logs — link creation, template edits, domain activation.
  • Product metrics — clicks, conversions, AI-generator usage.

2.3 Click data from your traffic

When a visitor follows a link created through the service, we process technical data about that click to provide click analytics and fraud / bot protection to the link owner:

  • IP address, approximate geolocation (country / region / city) and ISP.
  • User-Agent, browser, operating system, device type and language.
  • Bot, proxy / VPN and Tor signals used to assess traffic quality.
  • Referrer and tracking parameters (sub-IDs) passed in the link.

This data is kept separately per account and is not combined into a cross-customer visitor profile.

2.4 What we do NOT collect

  • Content of your landings or creatives outside our infrastructure.
  • Content of third-party sites you link to.
  • Card or wallet credentials — these stay with the payment provider.

3. Cookies and tracking

We use cookies and similar technologies for:

  • Sessions — to keep you signed in.
  • UI preferences — theme, language, stats period (stored in your browser).
  • Analytics — Google Analytics / Google Tag Manager, loaded only after you consent, to see which pages perform best.
  • Security & functionality — Google reCAPTCHA (anti-spam), Google Fonts, and our Chatwoot live chat.

You can disable cookies in your browser at any time. The cookie banner on the landing page lets you choose between "Accept all" and "Essential only"; analytics and advertising storage stay denied until you accept, and you can withdraw consent later by choosing "Essential only" or clearing the choice in your browser.

4. How we use data

  • Service delivery (TDS, antibot, analytics).
  • Billing and tax compliance.
  • Security: fraud detection, abuse protection.
  • Support: contact via email or Telegram if you reach out.
  • Product improvement: aggregated usage analytics (which features are used).
  • Marketing: email updates only (you can unsubscribe).

4.1 Applicable data protection law

We are established in Georgia, so our processing is governed in the first instance by the Georgian Law on Personal Data Protection (in force 1 March 2024), which applies to all of our processing wherever the data subject is located. Where we process personal data of people in the European Economic Area or the United Kingdom in connection with offering the Service to them or monitoring their behaviour, the GDPR and UK GDPR apply in addition, and we honour the rights described in Section 6 for those people regardless of where they live.

4.2 Legal bases (GDPR Art. 6)

Where the GDPR applies, we rely on the following legal bases: performance of a contract (Art. 6(1)(b)) — providing the Service, billing, support; legal obligation (Art. 6(1)(c)) — tax and accounting retention; legitimate interests (Art. 6(1)(f)) — security, fraud and abuse prevention, product analytics, defending legal claims; consent (Art. 6(1)(a)) — analytics cookies and marketing emails, withdrawable at any time.

5. Who we share data with

We don't sell your data. We share it only with the service providers (sub-processors) needed to run the Service, and only as far as necessary:

  • Hosting, CDN & security: Cloudflare (DDoS protection, WAF, CDN) and our server and object-storage providers.
  • Payments: our third-party payment processor (billing data only). We never see or store card or wallet credentials. The current processor is named in our Data Processing Agreement.
  • Analytics: Google Analytics / Google Tag Manager — loaded only after you accept analytics cookies.
  • Anti-spam & fonts: Google reCAPTCHA and Google Fonts.
  • Support: Chatwoot live chat and ticketing.
  • Email delivery: our transactional email / SMTP provider.
  • AI content generation: AI providers for text and image generation, when you use the AI features.
  • Safety & anti-abuse: domain-safety, bot-protection and IP-intelligence / geolocation providers.
  • Legal requirements: lawful court orders or government requests under applicable Georgian law (and, for users in the EU, EU law).
  • Merger / acquisition: with at least 30 days' notice.

5.1 International transfers

Some of the providers above (for example Google and Cloudflare) are located outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses (SCCs), supplemented by technical and organisational safeguards. An up-to-date list of sub-processors can be requested at privacy@tds.so, and we give advance notice of new sub-processors on request.

6. Your rights

Regardless of your country, you have the right to:

  • Access — request a copy of your data.
  • Correction — update or correct profile data.
  • Deletion — have your account and related data erased, except what we must legally retain (billing records — 7 years). Request this at privacy@tds.so and we action it within 30 days.
  • Export / portability — receive a copy of your data in a structured, machine-readable format (JSON or CSV). Request this at privacy@tds.so and we provide it within 30 days.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
  • Withdraw consent — at any time, without affecting processing before withdrawal.
  • Unsubscribe — opt out of marketing emails.

Requests — to privacy@tds.so. We respond within 30 days.

If you are in the EEA or the UK, you may lodge a complaint with the data protection authority of your country of habitual residence, place of work, or the place of the alleged infringement. That authority is the right first point of contact for you.

Our own supervisory authority, as a controller established in Georgia, is the Personal Data Protection Service of Georgia (personaldata.ge), which you may also contact.

7. Data security

  • All connections — HTTPS with TLS 1.3.
  • Passwords stored as a bcrypt hash; API and unsubscribe tokens stored hashed (SHA-256).
  • Two-factor authentication (TOTP) — recommended for all users.
  • Backups — daily, encrypted at rest.
  • Access to production data is limited to authorized personnel on a need-to-know basis, with audit logging.

8. Retention

  • Active account: as long as it exists.
  • Click-level traffic data (see 2.3): retained for the life of the account so you can run analytics, and deleted when the account is deleted.
  • After deletion: 30-day soft-delete (recoverable), then full deletion.
  • Billing records: 7 years (tax law requirement).
  • Security logs: 90 days.

9. Policy changes

For material changes, we'll notify you 14 days in advance via email and dashboard banner. The last-updated date is at the top of this page.

10. Contact

We are the controller for your account, billing, support and security data. For the click-level data we process about visitors to your links, you are the controller and we act as your processor — those terms are set out in our Data Processing Agreement.

The controller's details are:

TDS GLOBAL
Individual entrepreneur
Georgia, Batumi, Airport Highway Street, N 186, Apartment N33
Reg. No.: 345849610
Email: privacy@tds.so