Who we are
Affilitera operates an affiliate marketing platform. Advertisers use it to run affiliate programmes; publishers and creators use it to promote advertisers and earn commission. This policy explains what personal data we handle, why, and what you can ask us to do about it.
Our primary database is hosted in Ireland (EU). Our application servers run in Dublin, Ireland.
Two different roles, and why it matters
We handle personal data in two distinct capacities, and your rights differ depending on which applies:
- As a controller — for our own account holders. If you register as a publisher, creator, affiliate or advertiser user, we decide what data to collect about you and why. You can exercise your rights against us directly.
- As a processor — for shoppers who click an affiliate link or buy from an advertiser that uses us. Here we act on the instructions of the advertiser whose programme generated the click or sale. The advertiser is the controller. If you are a shopper and want your data erased, contact the advertiser whose site you visited; they can instruct us, and we will act on that instruction.
Where an advertiser and we jointly determine how attribution data is used across our network, our role may in practice be closer to joint controllership. We state our position plainly rather than claiming certainty we do not have; this classification has not yet been confirmed by a qualified lawyer.
What we collect about our account holders
- Identity and contact: name, email address, and (where you supply it) phone number and postal address. We do not store your password. Sign-in for the publisher and advertiser portals is handled by Clerk, our authentication provider. Network administrators authenticate against a password stored only as a bcrypt hash.
- Profile: website URL, promotional methods, display name, country and payout preferences.
- Financial and tax: billing address, VAT or company registration number, payout details, and tax-form data including taxpayer identification numbers. Taxpayer identification numbers, VAT numbers and payout details are encrypted with AES-256-GCM before storage, under keys separate from the database itself.
- Identity verification: where required, full name, date of birth, address and supporting documents.
- Commercial records: commissions, invoices, payouts and campaign performance.
- Acceptance records: when you accept our terms or this policy, we record the version, the timestamp and your IP address, as evidence of consent.
We do not store payment card numbers. Card payments are handled by Stripe in Stripe-hosted fields; we retain only the card brand and last four digits.
What we collect about shoppers
When you click an affiliate link that we serve, or complete a purchase on an advertiser site that uses our tracking, we record data needed to attribute that sale to the right publisher. We want to be precise about this, because it is the part people care about most.
We do not collect shopper names, email addresses, phone numbers, postal addresses or payment details. No field anywhere in our database holds a shopper name or email. What we record is:
- From a click on a tracking link: a randomly generated click identifier; the affiliate link, publisher, brand and campaign involved; a SHA-256 hash of your IP address; your browser user-agent string; the referring URL; your country, derived at our edge network from your IP; and the timestamp.
- From a purchase: the order identifier, order value, currency, any discount code used, and for single-item orders the product SKU and category, together with the click identifier that links the sale to a publisher.
- From affiliate networks: where an advertiser runs its programme through a third-party affiliate network, that network sends us its own record of the sale. Depending on the network, this can include a hashed IP address, the shopper country, the device type used, and whether the shopper was a new or returning customer. These records are stored as we receive them.
On IP addresses. IP addresses in our click records are stored as a SHA-256 hash, not in the clear. We should be honest about what that does and does not achieve: the hash uses a fixed salt, so it is pseudonymisation rather than anonymisation, and we treat it as personal data accordingly. Separately, our abuse-prevention rate limiter records raw IP addresses for a short operational window; this is a known shortcoming that we intend to bring into line with the rest of the system.
What we collect through the Shopify app
If an advertiser installs our Shopify app, we request five permissions: reading orders, reading products, creating our tracking pixel, receiving customer events, and reading themes. We do not request access to Shopify customer records — none of these is a protected customer-data permission — and we do not read customer names, email addresses or addresses from Shopify.
- Reading orders lets us receive the order webhook that tells us a tracked sale completed.
- Creating our tracking pixel and receiving customer events are both required to install the checkout pixel described below; neither can be created without the other.
- Reading themes reads exactly one file from the advertiser’s published theme — its settings file — to tell the advertiser whether our tracking snippet is switched on. It contains no customer data.
- Reading products is requested for a product feed sync we are building, which will read an advertiser’s product catalogue so their items can be listed to our affiliates. We want to state plainly that we are not using this permission yet — no part of our app reads product data from the Shopify API today. We ask for it at install because adding a permission later would require every advertiser to approve it again. The only product-related detail we hold today is the item code on an order, which arrives with the order itself. If the feed sync does not ship, we will drop this permission.
- We store the shop domain, the advertiser account it belongs to, the permissions granted, and an encrypted access token.
- For each order webhook we receive, we record only the order identifier, value, currency, any discount code, the product SKU, and our own click identifier. Orders with no affiliate click and no discount code are discarded rather than stored.
- We keep a log of which webhooks arrived and when. We deliberately do not store webhook payloads.
- Our Shopify pixel reports completed checkouts to us. It sends the order identifier, value, currency, discount code, SKU and click identifier. It does not send customer details of any kind.
Cookies and identifiers we set
The 30-day figure is a request, not a guarantee. Safari and all iOS browsers cap script-written cookies at seven days, and reduce that to about 24 hours when the visit arrives through a link-decorated redirect — which is exactly the shape of an affiliate click. On Safari and iOS the effective attribution window is therefore typically about 24 hours, with seven days as the ceiling. We would rather state this than advertise 30 days we do not always get.
Consent
We want to be straightforward here. Our click-tracking records carry a consent field, but nothing in our platform currently asks a shopper for consent at the point of a click, and that field is presently recorded as a constant. Where our tracking runs on a advertiser site, it is the advertiser who is responsible for obtaining any consent required in their jurisdiction, through their own cookie banner or consent management platform, and for configuring their site so that our tag only fires where that consent permits. For our Shopify app pixel, Shopify itself applies the advertiser consent configuration. Building a consent signal that our own tracking honours end to end is outstanding work, not a capability we currently have.
Why we process it, and on what basis
- To run the platform and pay commission — performance of our contract with you, where you are an account holder.
- To attribute sales to publishers — our legitimate interest, and that of the advertiser, in operating affiliate marketing and paying the correct party. Where local law requires consent for the storage of or access to information on a device, that consent is the advertiser responsibility described above.
- To detect fraud and abuse — our legitimate interest in protecting the platform and advertiser budgets.
- To send transactional email — performance of our contract.
- To meet tax, accounting and anti-money-laundering obligations — compliance with a legal obligation.
How long we keep it
We would rather state our actual position than a comfortable one.
- Click and conversion records are retained indefinitely. We do not currently operate any automatic deletion or expiry of click records, conversion records, or the order records we receive from affiliate networks. These records contain hashed IP addresses, user-agent strings, referring URLs and country. There is no scheduled job that removes them, and we do not want to imply otherwise. Building time-based retention is planned work.
- Click records are deleted when the publisher who owns the underlying tracking link erases their account, because those records are removed with the link.
- Account holder data is deleted or anonymised when you erase your account, subject to the exceptions below.
- Financial, tax and commission records are retained indefinitely and are deliberately never altered by an erasure request, because they are the record of what was earned and paid. Identity-verification records and tax records are held under a retention clock of five and seven years respectively; we note honestly that the automated sweep which would delete them once that clock expires has not yet been built, so in practice they persist beyond it today.
- Landing-page diagnostic records, where enabled, are deleted after 90 days.
Your rights
If you are in the European Economic Area or the United Kingdom you have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority. Here is what we can actually do today:
- Publishers and affiliates can download a full machine-readable copy of their data, and can request account erasure, from profile settings. Erasure is scheduled after a 48-hour cancellation window and then processed automatically.
- Advertiser users can request erasure, but we do not yet offer a self-service data export. Email us and we will produce one manually.
- Shoppers should contact the advertiser whose site they visited. We hold no shopper name or email, so we cannot identify a shopper from the data we hold without information from the advertiser. If an advertiser supplies an order identifier or click identifier, we can locate and remove the corresponding records manually.
- Restriction and objection requests are handled manually by email. We do not yet have an automated suppression mechanism.
Erasure does not remove everything. Financial and commission records are retained. Account identity records are replaced with a placeholder rather than deleted outright, so that historical financial records remain internally consistent. Where a publisher operates a sub-network with active sub-publishers or unpaid balances, erasure is blocked until those are settled, and we will tell you if that applies to you.
To exercise any right, email privacy@affilitera.com. We aim to respond within one month, as required by the GDPR.
Who else receives the data (sub-processors)
We use the following providers to deliver the platform. This list is intended to be complete; if you spot an omission, tell us.
- Supabase — database and file storage. Ireland (EU).
- Vercel — application hosting. Server functions run in Dublin, Ireland; one script-serving route runs on a global edge network.
- Cloudflare — our click-tracking service on the aftrk.co domain. Runs on a global edge network and is the first system to see a visitor IP address.
- Clerk — authentication for the publisher and advertiser portals.
- Stripe — payment processing and card handling.
- Resend — transactional email delivery.
- Sentry — error monitoring and diagnostics.
- Amazon Web Services — storage of generated report exports.
- Svix — outbound webhook delivery.
- Shopify — where an advertiser uses our Shopify app.
- Anthropic — automated classification of product and advertiser category text. No customer or shopper data is sent.
- Affiliate networks — where an advertiser runs its programme through a third-party network, that network is both a source and a recipient of sale records. We send them only a publisher identifier, never a shopper identifier. Because a tracking click is a redirect through their systems, the shopper browser will disclose its own IP address and user-agent to that network directly, as it would with any link.
- Website intelligence providers — DataForSEO, Scrape.do, SimilarWeb and the YouTube Data API, used to research publisher websites and channels. These process publisher and website data, not shopper data.
We do not sell personal data. We do not inject Google, Meta, TikTok or any other third-party advertising or analytics tag into an advertiser storefront. An advertiser may choose to add such tags to their own site themselves, in which case that is their processing, not ours.
International transfers
Our database and application servers are in Ireland. Several of our providers are US-headquartered or operate global networks, so some data is processed outside the European Economic Area. Report exports are currently stored in a United States region, which we are working to relocate. Where data leaves the EEA we rely on the providers own transfer safeguards, typically Standard Contractual Clauses. We have not yet completed our own transfer impact assessment, and we would rather say so than imply a completeness we have not reached.
How we protect it
- All traffic is encrypted in transit with TLS, and the database is encrypted at rest by our hosting provider.
- Taxpayer identification numbers, payout details, VAT numbers, platform secrets and all third-party access tokens are additionally encrypted at the application level with AES-256-GCM, under separate keys.
- Row level security is enabled on every table in our production database, which blocks direct database access from public API keys.
- Access to your data by our application is scoped to your account in application code.
- Privileged administrative actions are written to an append-only audit log that cannot be modified or deleted, enforced by the database itself.
- API keys are stored only as hashes.
We hold no security certifications. We are not SOC 2 or ISO 27001 certified and have not commissioned an external penetration test. We are a small team and would rather tell you that than let a list of controls imply otherwise.
Contact
For any privacy question, or to exercise a right, contact privacy@affilitera.com. If you are unhappy with our response you may complain to your local data protection supervisory authority.