← Legal · All programs

Privacy Policy

Summary. We keep as little personal data as the Service needs: your Google sign-in identity if you create an account, what you export and save, contact forms you send, and short-lived security logs. Analytics cookies are off unless you accept them. We do not sell personal data — not our users’, not our visitors’, and not the contact details of people named in the registry. The registry supplies only the official channels a programme publishes for affiliates (role mailboxes such as affiliates@…); details of named individuals are withheld from every account on every plan, and anyone named can have them removed with one message.

1. Controller

the operator of Affiliate Registry, address for service disclosed on request, the contact form — controller under the EU/UK GDPR. No data protection officer is required; privacy requests go through the request form.

2. What we process, why, and on what basis

DataPurposeLegal basis (GDPR art. 6)Retention
Account: Google subject ID, e-mail, name, avatar, country (from your IP at sign-in)Sign-in, your account page, plan entitlement, alerts you asked for6(1)(b) contractUntil you delete the account, then 30 days
Plan and billing references (plan, dates, merchant-of-record customer/subscription IDs, portal link)Deliver the plan you paid for; manage billing6(1)(b) contract; 6(1)(c) tax/accountingContract + statutory accounting period (up to 10 years for invoices held by the merchant of record)
Usage counters, saved filters, watchlist, export log (format, row count, filter, date), API key hash, acceptance records (document version, time, hashed IP)Enforce plan limits, provide features, prove acceptance of terms, detect abuse6(1)(b) contract; 6(1)(f) legitimate interest (security, evidence)Account lifetime; export log and acceptance records up to 6 years
Reviews, corrections, submissions, contact forms (text, optional e-mail/name), hashed IP, user agentPublish reviews, act on requests, prevent spam6(1)(a) consent / 6(1)(f) legitimate interestPublished content while relevant; requests 3 years
Security and traffic data: IP address, headers, request path, page token (Cloudflare, Vercel, our own rate limiting)Serve the site, block attacks and scraping, rate limits6(1)(f) legitimate interestCloudflare/Vercel logs ≤ 30 days; our counters ≤ 24 h; IPs we store are hashed
Product monitoring: which step of the sign-up or export flow was reached, and JavaScript errors — event name, page path, hashed IP, browser string, account ID when signed in. No page content, form values or messages.See where the service fails and fix it6(1)(f) legitimate interest (a working service)90 days
Session recordings and heatmaps (Microsoft Clarity), with text and input fields masked — only after consentWatch where people get stuck in the sign-up and export flows6(1)(a) consentPer Microsoft’s retention (up to 13 months)
Interaction replay and heatmaps on a sample of visits (self-hosted, first-party), with all text and form fields masked in your browser before transmissionSee where a page is confusing or a control is missed6(1)(f) legitimate interest — no cookie, no device storage, no identifier, and the content of the page is never captured; object at any time using the contact route below30 days
Analytics (Google Analytics, anonymised IP) — only after consentUnderstand which pages are useful6(1)(a) consent (withdraw any time in Cookie settings)GA default 2 months / 14 months aggregated
E-mail delivery (Resend) for alerts and receiptsSend what you subscribed to6(1)(b) contract / 6(1)(a) consentDelivery logs 30 days

We do not process special-category data, do not profile you for automated decisions with legal effect, and do not knowingly collect data from children under 18.

3. Personal data inside the dataset

The registry lists affiliate programmes. What an account can see and export is the programme’s official contact channels — role mailboxes such as affiliates@…, partners@… or support@…, sign-up and tracking links — which identify a function, not a person, and are not personal data.

Where a source page also published the details of a named individual (a manager’s name, a personal work mailbox, a Skype or Telegram handle, a direct phone number), those are not shown, not exported and not supplied to any customer, on any plan, at any price. Anything of that kind still held from earlier collection is withheld from every account and is reachable only by the operator, for the sole purpose of identifying and actioning correction and removal requests; it is processed on the legitimate interest of answering those requests (art. 6(1)(f)) and is not enriched from other sources. Any person named may request removal or correction via the request form; requests are handled to the extent and within the time applicable law requires.

4. Processors and recipients

ProviderRoleLocation / transfer basis
Vercel Inc.Hosting and functions (region Frankfurt), privacy-friendly analytics without cookiesUSA · EU-US Data Privacy Framework + SCCs
Cloudflare, Inc.DNS, CDN, bot and abuse protection, TurnstileUSA / EU edge · DPF + SCCs
Oracle Cloud (EU Frankfurt)Database hostingEU
Microsoft Corporation (Clarity)Session recordings and heatmaps, loaded only after analytics consent; text and inputs maskedUSA · DPF + SCCs
Google LLCSign in with Google; Google Analytics (only with consent)USA · DPF + SCCs
Merchant of record for paid plansPayment, invoices and tax for paid plans — independent controller for billing data. Identified at checkout and on the invoice.Named at checkout
Resend, Inc.Transactional e-mailUSA · SCCs

We disclose data to authorities only when legally required, and to successors of the Service with notice. We do not sell personal data. Account, billing, usage and contact-form data are never sold or shared for advertising, and the personal contact details of individuals named in the registry are not supplied to customers under any plan — what a subscription buys is programme terms and official channels, licensed under the Data Licence.

5. Your rights

EU/UK GDPR: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing), withdrawal of consent, and a complaint to your supervisory authority. Requests are handled within the period the applicable law prescribes. Account holders can delete their account from Account; otherwise use the request form. We may verify identity before acting.

6. California and other US state privacy laws

If the CCPA/CPRA or a similar state law applies to you: the categories above are the personal information we collect. We do not sell or “share” personal information within the meaning of these laws — not the information of our users and visitors for cross-context behavioural advertising (analytics is opt-in), and not the contact details of people named in the registry, which are supplied to no customer for payment or for anything else. We do not sell the personal information of anyone we know to be under 16.

You have the rights to know, delete, correct, and to opt out of sale/sharing, without discrimination. The “Do not sell or share my personal information” link in the footer switches analytics off and records that choice; we also honour the Global Privacy Control browser signal automatically. To have contact details listed in the registry corrected or removed, use the request form — that route reaches the entry itself, which the footer link does not. Authorised agents may submit requests the same way; responses follow the statutory period.

7. Cookies

Essential cookies (session, human-check, consent choice, Cloudflare security) need no consent; analytics cookies are set only after you accept them. Full list in the Cookie Policy; change your choice any time via “Cookie settings” in the footer.

8. Security and breaches

We apply technical and organisational measures appropriate to the risk, as applicable law requires. Breach notifications are made to the extent and within the time applicable law requires.

9. Changes

Changes are versioned at the top of this page and take effect when posted, subject to any notice applicable law requires.

These documents are written in good faith for a small data business and reviewed against the rules that apply in the EU/UK and the US. They are not legal advice; where mandatory law in your country grants you more rights than stated here, those rights apply.