Xoxo, everyone — it’s Reznik again, and today we’re plugging a hole I personally taught you to exploit.
I’ve already shown you how to find the contact of almost any direct advertiser in the crypto vertical. The trick is that advertisers sign their users in through an autologin link. Handle that link the right way, and anyone can squeeze a surprising amount of interesting information out of it.
That post is four years old now, and the life hack in it still hasn’t gone stale: brokers hand out the autologin link exactly like they used to, which means you can still pull a contact out of it exactly like you used to.
Affiliate networks try to protect their advertisers’ contacts. Otherwise some affiliates stop running traffic through the network, and the network loses its slice of the profit. On top of that, once competitors get hold of an advertiser’s contacts, they can hook that advertiser up to their own network — every bit as unpleasant.
So can information this sensitive be protected at all?
And How Do You Do That?
Sadly, there’s no perfect method that’s universal and reliable at the same time. You have to get creative. The ugly kind of creative. There are three main ways to do it, and each has its downsides. Which one to use for a specific advertiser’s contacts — that you decide case by case.
Method 1. Turn Off the Autologin Link
Yes, you can just switch it off, and any attempt to hunt down the direct advertiser’s contacts is dead on arrival.
The mechanics of how the advertiser talks to the user will change. On every call, the call center staff will have to email the user a fresh link. Conversion will drop, but not by much.
Another downside: plenty of advertisers insist, hard, that the autologin link stay on. With some of them you’ll manage to negotiate. With others you won’t.
For the ones you can’t, there’s a workaround: the autologiner hack. The broker demands that the link gets clicked? It’ll get its click — just not from the user, from the system. The system slips the lead’s real IP and user agent into the request headers and follows the autologin link on its own. Will any broker ever check whether that visit came from a live human? Never, thanks to their legendary laziness. I took this trick apart in detail in the “save or cheat” post. What matters here is something else entirely: the link never reaches a living person, and the advertiser’s contacts can be protected from competitors without a second thought.
Inside AlterCPA Pro and AlterCPA Cloud, turning off the autologin link looks like this:

Open the integration settings of the company you need, scroll down toward the bottom, and in the “Synchronous sending of leads for registration” block set the mode to “Disabled”.
The block hasn’t even been renamed since. The help page still spells it out to this day: “Required to implement the automatic login mechanism.” No synchronous sending, no autologin. No autologin, nothing to gut.
Method 2. White Label
This one you have to negotiate with the advertiser. On their side, they move the entire technical part of the funnel over to a domain that belongs to the affiliate network.
Then the only contact anyone can dig up is yours — the one the network set and listed in your domain’s WHOIS. You could even use that to pose as the direct advertiser. But the more honest move is simply to list no contacts at all.

The downside: not every advertiser will agree to burn their staff’s time over an affiliate network’s whim. And there can be other reasons to refuse, technical ones above all: white label usually needs setup on the payment gateway side, which makes the whole thing a lot harder to pull off.
Method 3. DIY Grabbing
This is the previous method, except you do all the work of moving the technical structure onto your own domain yourself.
I’ve already told you about one such option: parking a domain on a smartlink. You can use AlterCPA White in its classic setup. You can do it all directly with a properly configured nginx.
Or you can grab PrivateFlare. Back in 2022, when I was writing this post, access was strictly who-you-know: it was our in-house toy, for our own people. The who-you-know part is cancelled. Now it’s a standalone service that lets everyone in, even people who’ve never met me: two weeks free, no card required, then from $15 a month for a hundred domains.
Under the hood it’s simple: a reverse proxy plus a WAF. You point your domain at a PrivateFlare node, and the node is what talks to the real backend and shuttles traffic back and forth. The headline feature, built for exactly our problem, is masking. The node swaps the domain on the fly, so the affiliate with devtools open from that very contact-hunting article sees only the domain you chose to show them. The real domain and the backend IP never stick out, and spy services come away empty-handed too. It works with the whole AlterCPA line (Pro, Cloud, Lite, One, Red) out of the box: if you’re already with us, hooking it up won’t turn into a separate project. And if a domain gets burned, a new one goes up in half a minute, with nothing touched on the backend.
How to implement any of these options technically — from AlterCPA White to nginx and PrivateFlare — I chewed through in detail in a separate article on how to mask a site’s domain.
The downside: if the advertiser’s payments aren’t integrated and the user gets redirected to a third-party checkout, the link won’t work. This method is ideal for advertisers with an integrated payment method.
Conclusion
The vast majority of affiliate networks don’t protect their direct advertisers’ contacts, and affiliates and rival networks take full advantage. For those who’d rather keep private information private, there are no fewer than three ways to do it. In the vast majority of cases, one of them will work with any advertiser.
