Privacy Policy
1. Controller
the operator of Affiliate Registry, address for service disclosed on request, the contact form — controller under the EU/UK GDPR. No data protection officer is required; privacy requests go through the request form.
2. What we process, why, and on what basis
| Data | Purpose | Legal basis (GDPR art. 6) | Retention |
|---|---|---|---|
| Account: Google subject ID, e-mail, name, avatar, country (from your IP at sign-in) | Sign-in, your account page, plan entitlement, alerts you asked for | 6(1)(b) contract | Until you delete the account, then 30 days |
| Plan and billing references (plan, dates, merchant-of-record customer/subscription IDs, portal link) | Deliver the plan you paid for; manage billing | 6(1)(b) contract; 6(1)(c) tax/accounting | Contract + statutory accounting period (up to 10 years for invoices held by the merchant of record) |
| Usage counters, saved filters, watchlist, export log (format, row count, filter, date), API key hash, acceptance records (document version, time, hashed IP) | Enforce plan limits, provide features, prove acceptance of terms, detect abuse | 6(1)(b) contract; 6(1)(f) legitimate interest (security, evidence) | Account lifetime; export log and acceptance records up to 6 years |
| Reviews, corrections, submissions, contact forms (text, optional e-mail/name), hashed IP, user agent | Publish reviews, act on requests, prevent spam | 6(1)(a) consent / 6(1)(f) legitimate interest | Published content while relevant; requests 3 years |
| Security and traffic data: IP address, headers, request path, page token (Cloudflare, Vercel, our own rate limiting) | Serve the site, block attacks and scraping, rate limits | 6(1)(f) legitimate interest | Cloudflare/Vercel logs ≤ 30 days; our counters ≤ 24 h; IPs we store are hashed |
| Product monitoring: which step of the sign-up or export flow was reached, and JavaScript errors — event name, page path, hashed IP, browser string, account ID when signed in. No page content, form values or messages. | See where the service fails and fix it | 6(1)(f) legitimate interest (a working service) | 90 days |
| Session recordings and heatmaps (Microsoft Clarity), with text and input fields masked — only after consent | Watch where people get stuck in the sign-up and export flows | 6(1)(a) consent | Per Microsoft’s retention (up to 13 months) |
| Analytics (Google Analytics, anonymised IP) — only after consent | Understand which pages are useful | 6(1)(a) consent (withdraw any time in Cookie settings) | GA default 2 months / 14 months aggregated |
| E-mail delivery (Resend) for alerts and receipts | Send what you subscribed to | 6(1)(b) contract / 6(1)(a) consent | Delivery logs 30 days |
We do not process special-category data, do not profile you for automated decisions with legal effect, and do not knowingly collect data from children under 18.
3. Personal data inside the dataset
The registry lists affiliate programmes. Some entries include business contact channels the programme itself publishes for affiliates (a manager’s name, work e-mail, Skype/Telegram, support address). We process these under legitimate interest (art. 6(1)(f)): they were published for exactly this purpose — being contacted by affiliates — are limited to professional role data, are not enriched from other sources, and are shown and exported only to Business subscribers (who receive them as independent controllers under the Data Licence and DPA, within daily quotas); every other user sees only the programme’s official mailboxes (e.g. affiliates@…), which are not personal data. Any person named may request removal or correction via the request form; requests are handled to the extent and within the time applicable law requires. Customers who receive contact data under the Data Licence become independent controllers of it and must comply with marketing and privacy law themselves.
4. Processors and recipients
| Provider | Role | Location / transfer basis |
|---|---|---|
| Vercel Inc. | Hosting and functions (region Frankfurt), privacy-friendly analytics without cookies | USA · EU-US Data Privacy Framework + SCCs |
| Cloudflare, Inc. | DNS, CDN, bot and abuse protection, Turnstile | USA / EU edge · DPF + SCCs |
| Oracle Cloud (EU Frankfurt) | Database hosting | EU |
| Microsoft Corporation (Clarity) | Session recordings and heatmaps, loaded only after analytics consent; text and inputs masked | USA · DPF + SCCs |
| Google LLC | Sign in with Google; Google Analytics (only with consent) | USA · DPF + SCCs |
| Armitage Labs OÜ (Creem) | Merchant of record for paid plans: payment, invoices, tax — independent controller for billing data | Estonia · EU/EEA |
| Resend, Inc. | Transactional e-mail | USA · SCCs |
We disclose data to authorities only when legally required, and to successors of the Service with notice. We do not sell the personal data of our users or visitors — account, billing, usage and contact-form data are never sold or shared for advertising. Business contact details contained in the registry are a separate matter: they are supplied to Business subscribers under the Data Licence and the DPA, and that supply is a “sale” as US state privacy laws define the term (see below).
5. Your rights
EU/UK GDPR: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing), withdrawal of consent, and a complaint to your supervisory authority. Requests are handled within the period the applicable law prescribes. Account holders can delete their account from Account; otherwise use the request form. We may verify identity before acting.
6. California and other US state privacy laws
If the CCPA/CPRA or a similar state law applies to you: the categories above are the personal information we collect. We do not sell or “share” the personal information of our users and visitors for cross-context behavioural advertising; analytics is opt-in. The registry is different. Business contact details that programmes publish for affiliate contact are supplied to Business subscribers for payment, which is a sale within the meaning of these laws; the categories involved are identifiers and professional or employment-related information, and the recipients are business subscribers bound by the Data Licence. We do not sell any other category, and we do not sell the personal information of anyone we know to be under 16.
You have the rights to know, delete, correct, and to opt out of sale/sharing, without discrimination. The “Do not sell or share my personal information” link in the footer switches analytics off and records that choice; we also honour the Global Privacy Control browser signal automatically. To opt out of the sale of contact details listed in the registry, or to have them removed, use the request form — that route reaches the entry itself, which the footer link does not. Authorised agents may submit requests the same way; responses follow the statutory period.
7. Cookies
Essential cookies (session, human-check, consent choice, Cloudflare security) need no consent; analytics cookies are set only after you accept them. Full list in the Cookie Policy; change your choice any time via “Cookie settings” in the footer.
8. Security and breaches
We apply technical and organisational measures appropriate to the risk, as applicable law requires. Breach notifications are made to the extent and within the time applicable law requires.
9. Changes
Changes are versioned at the top of this page and take effect when posted, subject to any notice applicable law requires.
These documents are written in good faith for a small data business and reviewed against the rules that apply in the EU/UK and the US. They are not legal advice; where mandatory law in your country grants you more rights than stated here, those rights apply.