Privacy Policy

Last updated 2026-09-14.

This policy covers themysticverdict.com. It’s written against what the site’s own code does, not from a template, so it names the actual cookie, the actual file the sales data lands in and the actual companies that see any of it. If we change the tracking, we change this page.

Who’s responsible for your data

themysticverdict.com is published by Omega Software Solutions, and that company is the data controller for everything described on this page. It decides what gets collected and why.

Questions, complaints and requests go to editorial@themysticverdict.com. There’s a postal address on the contact page.

The short version

  • We don’t ask you to create an account and we don’t run a newsletter.
  • If you arrive from a Google ad, your browser keeps a click identifier in a cookie for 30 days so we can tell which ads lead to a sale.
  • When someone buys from a seller we’ve linked to, ClickBank tells our server that a sale happened and hands back that click identifier. We never see the buyer’s name, email address or card details.
  • If you email us or use the contact form, we keep what you sent so we can answer it.
  • We don’t sell your personal information for money.

The Google Ads click identifier

Most of our traffic comes from Google Ads. Google appends a click identifier called gclid to the link you followed. A small first party script on this site, gclid-tracker.js, reads that value out of the URL and does two things with it.

  • It writes the value into a first party cookie named gclid, set for 30 days with path=/ and SameSite=Lax. Only this site can read it. It’s a plain cookie, and the script doesn’t touch localStorage or sessionStorage.
  • It appends the value to outbound affiliate links as a tid parameter, cut to 100 characters, so that if you buy something the sale can be matched back to the ad click.

The same script reads utm_campaign and utm_source from the URL when they’re there. If there’s no gclid, the first 50 characters of utm_campaign get used as the tracking value instead. These are campaign labels we set ourselves, like the name of an ad group. They don’t describe you.

The gclid value is a random string Google generates for the click. On its own it doesn’t carry your name or your email address, but Google can connect it to your Google account and to your ad profile, so we treat it as personal data and so should you. Clearing your cookies removes it.

Cookies this site sets or loads

CookieSet byWhat it holdsHow long it lasts
gclid This site, first party The Google Ads click identifier from the URL you arrived on 30 days
_gcl_* Google Ads conversion tracking Ad click information Google uses to attribute conversions Up to 90 days, set by Google
_ga, _ga_* Google Analytics, if it’s running on this site A random visitor identifier and the session state Up to 2 years, set by Google
Nelio A/B testing cookie The split testing plugin Which version of a page you were shown, so you keep seeing the same one Set by the plugin, typically the length of the test
WordPress session and comment cookies WordPress Only set if you log in or a form needs them Session or short term

Google Ads, Google Tag Manager and Google Analytics

Google Ads conversion tracking runs on this site, loaded either directly or through Google Tag Manager. Tag Manager is a container that decides which measurement tags fire. It doesn’t collect anything by itself, but the tags inside it do, and Google receives your IP address and your user agent whenever one of them loads.

What Google gets from us is the fact that a browser carrying a particular ad click identifier reached a particular page, and later that a sale was matched to that click. We use it to work out which keywords and which version of a page are worth paying for. Google’s own handling of that data sits under the Google Privacy Policy, and you can turn off personalised advertising at adssettings.google.com.

If Google Analytics is running here, it records pages viewed, how long you stayed, roughly where you are from your IP address and which site or ad sent you. We look at that in aggregate to see which reviews people read to the end.

Affiliate links and outbound redirects

Links to a seller are affiliate links. Some of them point straight at ClickBank’s hoplink domain, and some go through a cloaked redirect on our own domain that looks like /go/tina-aldea/ and forwards you to the seller. Both carry rel="sponsored nofollow noopener noreferrer", and both have the tracking value described above attached to them.

Following one of those links hands you over to ClickBank and then to the seller. From that point their cookies and their privacy policies apply, not ours. ClickBank sets its own cookie to credit the referral, typically for 60 days.

What the ClickBank sales webhook receives

When a sale, refund or chargeback happens, ClickBank’s Instant Notification Service posts an encrypted message to a script on our server. The script decrypts it with a secret key that only we and ClickBank hold, then pulls out a handful of fields.

FieldWhat it isWhere it ends up
Transaction type Sale, test sale, refund or chargeback Debug log
Receipt number ClickBank’s own order reference, like a receipt code Debug log
Tracking code The tid value we attached to the link, usually the ad click identifier Conversion file and debug log
Commission and currency What we earned on the sale Conversion file and debug log
Vendor and affiliate account Which seller sold it and which affiliate account gets credited Debug log
Transaction time When the sale went through Conversion file

The buyer’s name, email address, postal address and payment details stay with ClickBank and the seller. Our script never writes them down, because it never asks for them and wouldn’t know what to do with them. The conversion file is a spreadsheet with one row per sale, holding the click identifier, a label reading “ClickBank Soulmate Purchase”, the time, the commission and the currency. We upload it to Google Ads on a daily schedule so Google can learn which clicks turn into revenue.

Both files sit on our own server behind the web root. Nothing on the site reads them back out and they’re never shown to a visitor.

We’re setting a fixed retention window for both files. Until it’s published here, treat them as kept for as long as the campaign runs.

The contact form and email

The contact form asks for your name, your email address and your message. Submissions are stored in this site’s WordPress database and emailed to editorial@themysticverdict.com. Most form plugins also record the time and the IP address the message came from, as a spam check.

We keep what you send us so we can answer it and so we have a record of a correction request. Ask us to delete it and we will, unless we need it for a legal reason such as an unresolved complaint.

Server logs

Our web host records the usual access log for every request, meaning your IP address, the page requested, the time, the referring page and your browser’s user agent. That’s how the server gets run and how we spot an attack.

Who else sees any of this

  • Google. Ad clicks, page views and the conversion rows we upload, through Google Ads, Google Tag Manager and Google Analytics.
  • ClickBank. The payment platform for the offers we review. It sees your click when you follow an affiliate link and it handles your purchase and any refund.
  • The seller. Tina Aldea, or whoever else we’ve linked to. Anything you type into their order form goes to them under their own privacy policy, and we never see it.
  • Our hosting provider and the plugins on this site. They process data on our instructions so the site runs.

We don’t sell personal information for money and we don’t hand your details to data brokers. Sharing ad identifiers with Google for advertising can count as “sharing” for cross context behavioural advertising under California law, which is covered below.

Why we’re allowed to do this under GDPR

  • Consent for advertising and analytics cookies, where you’re in a region that requires it. The consent banner is where you give or refuse it, and you can change your mind at any time.
  • Legitimate interests for measuring our own advertising, matching a sale to the ad that produced it, keeping the site up and defending it from abuse. We’ve weighed that against your privacy and limited what we hold to a click identifier and a commission figure.
  • Legitimate interests, or steps taken at your request, for answering an email you sent us.
  • Legal obligation where tax or accounting rules require us to keep a record of commission earned.

Your rights in the EU and the UK

You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing based on legitimate interests, and ask for your data in a portable format. Where we rely on consent, withdrawing it is as easy as giving it, and withdrawing it doesn’t undo what was lawful beforehand.

Email editorial@themysticverdict.com with “privacy request” in the subject. We answer within one month. We may ask you for enough detail to find your data, which in practice means the click identifier or the email address you wrote from, because we have no other way to identify you. If you’re unhappy with how we handle it, you can complain to your national data protection authority, or to the Information Commissioner’s Office if you’re in the UK.

Your rights in California

Under the CCPA as amended by the CPRA you can ask what categories of personal information we’ve collected about you, ask for a copy, ask us to delete it, ask us to correct it, and tell us not to share it for cross context behavioural advertising. We won’t treat you differently for asking.

We don’t sell personal information for money. We do let Google receive online identifiers and browsing activity for advertising, which the CPRA calls sharing. To opt out, email editorial@themysticverdict.com with “Do Not Sell or Share My Personal Information” in the subject, or refuse advertising cookies in the consent banner, or send a Global Privacy Control signal from your browser, which we honour. An authorised agent can make the request for you with written proof.

The categories we handle are identifiers such as an IP address and an ad click identifier, internet activity such as the pages you viewed, and the contents of any message you send us. Nothing else. We collect no financial account details, no precise location and no biometric data.

How to get your data deleted

Email editorial@themysticverdict.com and say what you want removed. Tell us the email address you wrote from if it’s a message you want deleted. If it’s ad data, the click identifier from the URL you arrived on is what lets us find the row. We’ll delete the contact form entry from the WordPress database and the matching row from the conversion file, and confirm when it’s done.

Two things we can’t delete for you. Google holds its own copy of the ad click data under its own terms, so that request goes to Google. ClickBank and the seller hold your purchase record, which they keep for accounting and refund purposes, so a purchase deletion request goes to ClickBank at clkbank.com.

Clearing cookies in your browser removes the gclid cookie and the Google cookies straight away, without needing to ask us.

Children

This site is for adults. The services we review are sold to buyers aged 18 and over, and our content is written for that audience. We don’t knowingly collect personal information from anyone under 13, which is the line COPPA draws in the United States, and we don’t knowingly process the data of anyone under 16 without parental consent in countries where GDPR sets that age. If you believe a child has sent us something, email editorial@themysticverdict.com and we’ll delete it.

Where your data goes

Our service providers are mostly in the United States, so data about your visit is processed there. Transfers out of the EU and the UK rely on the European Commission’s standard contractual clauses and the equivalent UK addendum, or on a provider’s certification under the EU US Data Privacy Framework where they hold one.

Security

The site runs over HTTPS. The webhook message from ClickBank is encrypted in transit and decrypted with a secret key held in the server environment rather than in the code. The conversion and debug files sit outside the public web root. No system is proof against everything, and we can’t promise otherwise.

Changes to this policy

When the tracking changes, this page changes with it and the date at the top moves. If a change means we’re doing something materially different with your data, we’ll say so at the top of the page rather than hiding it in a paragraph.

This policy explains what we do. It isn’t legal advice and it hasn’t been through a law firm.