Buy Traffic

How This Cheap Adult Traffic Site Handles Your Data

Last updated: 3 August 2026

This policy explains what personal data this site collects, why, on what legal basis, how long it is kept and what you can do about it. It applies to apgrimes.co.uk and to nothing else: it does not cover the ad networks named in our Buy Cheap Adult Traffic, and it does not cover what happens on those networks after you leave this site. We are a research publisher, not an advertising network and not an operator of any advertising platform, so the volume of data involved here is small and the policy says so plainly rather than reciting boilerplate written for a business with accounts and payments. Data protection questions go to [email protected].

Who operates this site

apgrimes.co.uk is an independent research site covering adult advertising networks for advertisers, operated from the United Kingdom by the editorial team described on our about page and written by the analyst named on the author page. We are the data controller for the limited personal data described below. The site is a set of static pages: there are no user accounts, no login, no newsletter, no comment system and no checkout, so the categories of data that dominate most privacy policies do not arise here.

We process personal data in accordance with the UK General Data Protection Regulation as retained in UK law and the Data Protection Act 2018. This policy takes effect on the date shown at the top of the page and replaces any earlier version.

What we collect

Data you send us deliberately. If you email one of our published addresses, we receive your email address, your name if you include it, and whatever you write. That is the only channel through which you can send us data, because the site carries no forms. We use it to answer you and for nothing else.

Data recorded automatically by the server. Serving a web page requires the server to log the request. Those logs contain your IP address, the date and time, the page requested, the HTTP status returned, your browser and operating system as reported in the user agent string, and the referring URL if your browser sends one. These logs exist for security and diagnostics: identifying abusive traffic, investigating errors, and confirming that pages are reachable.

What we do not collect. We do not collect payment details, because nothing here is for sale. We do not collect advertising account credentials, campaign data or anything about your activity on a network you reach from here. Beyond Google Analytics 4 we run no advertising tags, no remarketing pixels, no social widgets and no session recording. We do not build profiles of individual readers, we do not run remarketing against you, and we do not attempt to identify you.

Cookies. The site sets two first-party cookies, both belonging to Google Analytics 4, which measure visits at page level. Each is named, described and given a lifetime in the cookie policy, which also explains how to refuse them.

Why we process it

To answer your correspondence. Email you send us is read and replied to. Editorial mail may be quoted internally when it results in a correction, but not published without your agreement.

To keep the site available and secure. Server logs let us detect denial-of-service attempts, automated scraping that degrades performance, and errors that would otherwise go unnoticed.

To understand which research is worth repeating. Google Analytics 4 tells us which comparisons readers actually use, which ones they abandon and which sources send them. This is read at the level of pages and sessions, not people: we do not use Analytics user-ID features, we do not connect it to advertising products, and we cannot identify an individual reader from it.

To meet legal obligations. Where the law requires us to retain or disclose information, we comply, and we do not disclose beyond what is required.

Legal bases

Our processing rests on two bases. Legitimate interests under Article 6(1)(f) covers server logging for security, measuring aggregate traffic to improve what we publish, and handling correspondence you initiate; our interest is in operating a functioning, secure site that gets better at answering the questions readers arrive with, and given how little data is involved and that none of it is used to target you or sold onward, we consider that this does not override your rights. Legal obligation under Article 6(1)(c) covers any retention or disclosure required by law.

You can object to the analytics processing at any time under Article 21, and you can act on that objection yourself without contacting us: the three methods set out in the cookie policy stop the collection at your end, and nothing on this site stops working when you use them. If we ever introduce a category of processing that requires consent rather than resting on legitimate interests, consent will be requested before the relevant script loads and both this policy and the cookie policy will be updated first.

Who else sees the data

Our hosting provider. Whoever serves these pages necessarily processes the request data described above, acting on our instructions under a data processing agreement.

Our email provider. Mail you send to a published address is stored by the provider handling that mailbox.

Google. Google Analytics 4 processes the page-level data described above on our behalf, under Google's own processor terms. It receives your IP address to derive an approximate location and then discards it rather than storing it, and the property is not linked to Google Ads or any advertising product.

Nobody else. We do not sell personal data. We do not share it with advertising networks, data brokers or analytics companies. We do not pass reader data to the ad networks covered on this site. When you click one of our links you go to the destination yourself and their relationship with you begins there, governed by their own policies rather than this one.

Our outbound tracking works through parameters in the link URL rather than through anything stored about you here, which means the destination learns that a visit came from this domain and from which button, and nothing that identifies you personally. Why those links exist at all is explained in the affiliate disclosure, and the standards that keep the commercial arrangement out of the research are in the editorial policy.

Transfers outside the UK

Some service providers may process data outside the United Kingdom. Where that happens, transfers are covered either by an adequacy decision or by the International Data Transfer Agreement or standard contractual clauses with the UK addendum, together with the additional safeguards those instruments require. You can ask us for details of the mechanism applying to a specific provider by writing to [email protected].

How long we keep it

Server access logs are retained for 90 days and then deleted, which is long enough to investigate a security incident and short enough to avoid accumulating a history of readers. Analytics event data is retained by Google for 14 months, the shortest period the platform allows, after which it exists only inside aggregate reports. Email correspondence is retained for 24 months from the last message in the thread, so that a correction can be traced back to its source, then deleted. Anything we are legally required to keep is retained for the applicable statutory period and no longer. When a retention period ends, data is deleted or irreversibly anonymised.

Your rights

Access (Article 15). You can ask what personal data we hold about you and receive a copy.

Rectification (Article 16). You can ask us to correct inaccurate data or complete incomplete data.

Erasure (Article 17). You can ask us to delete your data where there is no overriding reason to keep it. In practice this usually means deleting an email thread.

Restriction (Article 18). You can ask us to stop processing while a dispute about accuracy or legitimate interests is resolved.

Portability (Article 20). Where processing rests on consent or a contract and is automated, you can receive your data in a structured, machine-readable format.

Objection (Article 21). You can object to processing based on legitimate interests, and we will stop unless we can demonstrate compelling grounds that override your rights.

Withdrawal of consent. Where processing rests on consent, you can withdraw it at any time without affecting the lawfulness of what was done before.

To exercise any of these, write to [email protected]. We acknowledge within 72 hours and respond substantively within one month, extendable by two further months for complex requests, in which case we will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive. If you are unhappy with our response you can complain to the Information Commissioner's Office, and you can do so without contacting us first.

Security

The site is served over HTTPS with TLS encryption, so traffic between your browser and the server cannot be read in transit. The site is static HTML with no database, no content management system and no user accounts, which removes the categories of vulnerability that account for most publisher breaches. Administrative access to hosting and email is restricted to the editorial team and protected by two-factor authentication. Server software is kept patched. No system is perfectly secure and we do not claim otherwise, but the small amount of data involved here limits what a breach could expose.

Age

This site is intended for advertising professionals aged 18 or over and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has sent us personal data, write to [email protected] and we will delete it.

Changes and contact

We update this policy when our processing changes or when the law does, and the date at the top always reflects the current version. Material changes will be flagged on the site rather than made quietly. For anything covered here, or to exercise a right, write to [email protected]; other routes are on the contact page.