Privacy Policy
1. Controller
the operator of Affiliate Registry, address for service disclosed on request, the contact form — controller under the EU/UK GDPR. No data protection officer is required; privacy requests go through the request form.
2. What we process, why, and on what basis
| Data | Purpose | Legal basis (GDPR art. 6) | Retention |
|---|---|---|---|
| Account: Google subject ID, e-mail, name, avatar, country (from your IP at sign-in) | Sign-in, your account page, plan entitlement, alerts you asked for | 6(1)(b) contract | Until you delete the account, then 30 days |
| Plan and billing references (plan, dates, merchant-of-record customer/subscription IDs, portal link) | Deliver the plan you paid for; manage billing | 6(1)(b) contract; 6(1)(c) tax/accounting | Contract + statutory accounting period (up to 10 years for invoices held by the merchant of record) |
| Usage counters, saved filters, watchlist, export log (format, row count, filter, date), API key hash, acceptance records (document version, time, hashed IP) | Enforce plan limits, provide features, prove acceptance of terms, detect abuse | 6(1)(b) contract; 6(1)(f) legitimate interest (security, evidence) | Account lifetime; export log and acceptance records up to 6 years |
| Reviews, corrections, submissions, contact forms (text, optional e-mail/name), hashed IP, user agent | Publish reviews, act on requests, prevent spam | 6(1)(a) consent / 6(1)(f) legitimate interest | Published content while relevant; requests 3 years |
| Security and traffic data: IP address, headers, request path, page token (Cloudflare, Vercel, our own rate limiting) | Serve the site, block attacks and scraping, rate limits | 6(1)(f) legitimate interest | Cloudflare/Vercel logs ≤ 30 days; our counters ≤ 24 h; IPs we store are hashed |
| Product monitoring: which step of the sign-up or export flow was reached, and JavaScript errors — event name, page path, hashed IP, browser string, account ID when signed in. No page content, form values or messages. | See where the service fails and fix it | 6(1)(f) legitimate interest (a working service) | 90 days |
| Session recordings and heatmaps (Microsoft Clarity), with text and input fields masked — only after consent | Watch where people get stuck in the sign-up and export flows | 6(1)(a) consent | Per Microsoft’s retention (up to 13 months) |
| Interaction replay and heatmaps on a sample of visits (self-hosted, first-party), with all text and form fields masked in your browser before transmission | See where a page is confusing or a control is missed | 6(1)(f) legitimate interest — no cookie, no device storage, no identifier, and the content of the page is never captured; object at any time using the contact route below | 30 days |
| Analytics (Google Analytics, anonymised IP) — only after consent | Understand which pages are useful | 6(1)(a) consent (withdraw any time in Cookie settings) | GA default 2 months / 14 months aggregated |
| E-mail delivery (Resend) for alerts and receipts | Send what you subscribed to | 6(1)(b) contract / 6(1)(a) consent | Delivery logs 30 days |
We do not process special-category data, do not profile you for automated decisions with legal effect, and do not knowingly collect data from children under 18.
3. Personal data inside the dataset
The registry lists affiliate programmes. What an account can see and export is the programme’s official contact channels — role mailboxes such as affiliates@…, partners@… or support@…, sign-up and tracking links — which identify a function, not a person, and are not personal data.
Where a source page also published the details of a named individual (a manager’s name, a personal work mailbox, a Skype or Telegram handle, a direct phone number), those are not shown, not exported and not supplied to any customer, on any plan, at any price. Anything of that kind still held from earlier collection is withheld from every account and is reachable only by the operator, for the sole purpose of identifying and actioning correction and removal requests; it is processed on the legitimate interest of answering those requests (art. 6(1)(f)) and is not enriched from other sources. Any person named may request removal or correction via the request form; requests are handled to the extent and within the time applicable law requires.
4. Processors and recipients
| Provider | Role | Location / transfer basis |
|---|---|---|
| Vercel Inc. | Hosting and functions (region Frankfurt), privacy-friendly analytics without cookies | USA · EU-US Data Privacy Framework + SCCs |
| Cloudflare, Inc. | DNS, CDN, bot and abuse protection, Turnstile | USA / EU edge · DPF + SCCs |
| Oracle Cloud (EU Frankfurt) | Database hosting | EU |
| Microsoft Corporation (Clarity) | Session recordings and heatmaps, loaded only after analytics consent; text and inputs masked | USA · DPF + SCCs |
| Google LLC | Sign in with Google; Google Analytics (only with consent) | USA · DPF + SCCs |
| Merchant of record for paid plans | Payment, invoices and tax for paid plans — independent controller for billing data. Identified at checkout and on the invoice. | Named at checkout |
| Resend, Inc. | Transactional e-mail | USA · SCCs |
We disclose data to authorities only when legally required, and to successors of the Service with notice. We do not sell personal data. Account, billing, usage and contact-form data are never sold or shared for advertising, and the personal contact details of individuals named in the registry are not supplied to customers under any plan — what a subscription buys is programme terms and official channels, licensed under the Data Licence.
5. Your rights
EU/UK GDPR: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing), withdrawal of consent, and a complaint to your supervisory authority. Requests are handled within the period the applicable law prescribes. Account holders can delete their account from Account; otherwise use the request form. We may verify identity before acting.
6. California and other US state privacy laws
If the CCPA/CPRA or a similar state law applies to you: the categories above are the personal information we collect. We do not sell or “share” personal information within the meaning of these laws — not the information of our users and visitors for cross-context behavioural advertising (analytics is opt-in), and not the contact details of people named in the registry, which are supplied to no customer for payment or for anything else. We do not sell the personal information of anyone we know to be under 16.
You have the rights to know, delete, correct, and to opt out of sale/sharing, without discrimination. The “Do not sell or share my personal information” link in the footer switches analytics off and records that choice; we also honour the Global Privacy Control browser signal automatically. To have contact details listed in the registry corrected or removed, use the request form — that route reaches the entry itself, which the footer link does not. Authorised agents may submit requests the same way; responses follow the statutory period.
7. Cookies
Essential cookies (session, human-check, consent choice, Cloudflare security) need no consent; analytics cookies are set only after you accept them. Full list in the Cookie Policy; change your choice any time via “Cookie settings” in the footer.
8. Security and breaches
We apply technical and organisational measures appropriate to the risk, as applicable law requires. Breach notifications are made to the extent and within the time applicable law requires.
9. Changes
Changes are versioned at the top of this page and take effect when posted, subject to any notice applicable law requires.
These documents are written in good faith for a small data business and reviewed against the rules that apply in the EU/UK and the US. They are not legal advice; where mandatory law in your country grants you more rights than stated here, those rights apply.