Skip to content
AffCheck

Draft, not yet in force. Some details on this page are still being finalised.

Privacy Policy

Version 1.1 · Effective 19 September 2026

This policy explains what personal data TBD — fill before launch (legal name as registered) ("we", "us") collects when you use AffCheck (https://affcheck.com) and its website, why we collect it, how long we keep it, and what rights you have.

Summary.

  • We collect only what we need to run the product and bill you. We do not sell personal data, and we do not use it for advertising.
  • Our website uses no tracking or advertising cookies. We measure visits with self-hosted, cookieless analytics.
  • Data you put into the product belongs to your organisation. We process it on your organisation's instructions (we are its "processor"), under our Data Processing Addendum.
  • Our servers are in Germany (EU). The few services we use are listed on our Subprocessors page.
  • Email privacy@affcheck.com to access, correct or delete your data.

Contents

  1. Who we are
  2. Our two roles: controller and processor
  3. What we collect and why
  4. Data in the product
  5. Cookies and analytics
  6. AI features
  7. Who we share data with
  8. Where your data is stored and international transfers
  9. How long we keep data
  10. How we protect data
  11. Your rights
  12. US state privacy notice
  13. Children
  14. Changes to this policy
  15. Contact and complaints

1. Who we are

AffCheck is provided by TBD — fill before launch (legal name as registered), a sole proprietor registered in TBD — fill before launch, at TBD — fill before launch (registered address). For privacy questions email privacy@affcheck.com.

Representatives. Because we are not established in the EU or the UK, we have appointed representatives you can also contact about data protection:

  • EU representative: TBD — fill before launch (name and address, or remove the line)
  • UK representative: TBD — fill before launch (name and address, or remove the line)

We are a one-person company, so we have not appointed a data protection officer; the founder is responsible for privacy.

2. Our two roles: controller and processor

  • Controller. We decide how and why we use data about visitors to our website, people who use our free tools, people who sign up for an account, people we contact about our products, and people who contact us. This policy mainly covers that data.
  • Processor. When your organisation uses AffCheck, it decides what data goes into the product (for example, content from a connected system, or details submitted by its own customers). For that data your organisation is the controller and we act on its instructions under our DPA. If you are one of those people (for example, a customer of a business that uses AffCheck), please contact that business first; we will help it respond. Section 4 describes this data.

3. What we collect and why

Who Data Why Legal basis (EU/UK)
Website visitors Pages viewed, referrer, approximate country, browser and device type, derived from your request. Your IP address is used transiently and not stored by our analytics. To understand which pages are useful and to keep the site secure (rate limits, abuse prevention). Legitimate interests (running and improving a website; security)
Free-tool users What you enter in the tool (see section 4 and the product section below), your email address if you ask us to email you the result, and technical data as for visitors. To run the tool and send you the result you asked for. Performance of your request (contract); legitimate interests (preventing abuse)
Account holders Name, email address, organisation name, sign-in data (a Google account ID if you sign in with Google), team members you invite, settings, and records of your acceptance of our terms. To create and secure your account, provide the service, and send service emails (for example email confirmation and password reset, alerts, reports, billing and security notices). Contract; legitimate interests (security, keeping records)
Customers (billing) Plan, subscription status, invoices and the country for tax. Paddle collects your payment details; we never see or store full card numbers. To manage your subscription. Contract; legal obligation (tax and accounting records)
Product usage Which features are used and when, error reports, and logs (IP address, time, request path). To operate, fix, secure and improve the service. Legitimate interests
People who contact us Your messages to support (email or chat) and any information you include. To answer you and improve support. Legitimate interests; contract (if you are a customer)
People we contact about our products Business contact details that are publicly available (for example a business name, website, business email address and city) that we gathered from public business listings and websites. To tell businesses about a product that may be useful to them, by email, with an opt-out in every message. Legitimate interests (B2B direct marketing). We don't send marketing email to individuals where the law requires prior consent.
Product news Your email address, if you opt in (checkbox at sign-up or on a waitlist). To send occasional product updates. You can unsubscribe at any time. Consent

We don't knowingly collect special-category data (such as health data) about you, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.

If you don't provide data. We need your email address to create an account. Everything else is optional or comes from your use of the product.

4. Data in the product

For data in AffCheck your store is the controller and we are its processor (see section 2 and our DPA). Shoppers and publishers should contact the store first.

4.1 Data from Shopify

When a store installs the AffCheck app, we receive through Shopify's APIs, read-only:

Data Why
Store details: shop domain, store name, currency, time zone, plan, the email of the staff member who installed the app To set up the account, show amounts in the right currency and send reports
Orders: order ID and number, dates, totals, currency, financial and fulfilment status, discount codes used, line-item totals, a customer ID number, and, where the store uses them, landing-page and referring-site fields and order tags To match orders to affiliate transactions
Refunds and cancellations: IDs, dates, amounts, reasons To find commissions on refunded or cancelled orders
Discount codes and price rules To check voucher-code use by publishers

We do not request shoppers' names, email addresses, phone numbers or addresses (Shopify "protected customer data" level 2 fields), and we don't use Shopify data for anything other than providing AffCheck to that store.

4.1a Your Shopify orders export (web app, no Shopify app)

Without the Shopify app you upload your own orders export. The CSV is read in your browser and is never uploaded to us. Code running on your device reads only the columns below and sends us those values; every other column, including the ones Shopify fills with your customers' details, is never read and has nowhere to go in what we store.

We store from the export We never read
Order name and Shopify order ID, order date, currency, total, subtotal, total after refunds, refunded amount, financial status, cancellation date, discount codes used, the order tags you set, how many line-item rows the order had, whether the order was a test order Email, phone, billing and shipping name, company, street, address, city, postcode, province and country (except the shipping country), notes and note attributes, customer name and customer ID, employee, payment references and payment IDs

Order tags are the labels you set in Shopify (such as "staff" or "wholesale"); we read them only to spot orders that are not customer sales. If you use tags to record something about a shopper, do not upload that export.

We also keep, per upload: how many rows and orders it covered, the first and last order date, the currencies, any warnings about the file, who uploaded it and when. We do not keep the file, its name or any row we did not read. Uploading a newer export overwrites the orders it covers, because Shopify's export carries only cumulative refund totals, not individual refunds.

4.2 Data from affiliate networks

When a store uploads a network export or connects a network's API, we process pending transactions: transaction ID, order reference, dates, sale amount, commission, status, voucher code, publisher ID and publisher name, and click or channel information the network includes. Publisher names can identify individuals (many publishers are individual creators). We use them only to show the store which publisher a transaction belongs to and to prepare decline or amend files.

4.3 The free leak check

The free check on our website runs entirely in your browser. The order and network files you select are read by code on your device and are not uploaded to our servers. Our analytics records that a check ran with rounded ranges only (for example "leak $100–500", "100–999 rows" and the network name), never order numbers, amounts or file names.

We receive something from the check only when you choose to send it:

If you… We store We use it to
Answer the short survey under the result Your answers (your role, the networks you use, who validates commissions today, whether your network's app declines refunds, whether you would pay), the leak range and network of that check, and the campaign tags of the link you came from (such as utm_source). No email address, no amounts, no file contents. Decide what to build and measure demand.
Send us the column names of a file that didn't work The first line of the file (the column names) only, the network we detected and a row-count range (such as "100–999"). You see exactly what is sent before you send it; lines with data are refused. Support that file format. We read the report by email.
Ask us to email you a link for your computer, or email you the result Your email address, the source ("phone link", "result email"), and the role, networks, leak range and campaign tags you had in the check. The result email contains totals by reason and by network only, never individual orders. Send you that one email and, as you agreed in the form, occasional product news. You can unsubscribe at any time.
Reserve the founding offer by email Your email address and the campaign tags. Tell you when the founding checkout opens.
Buy the founding pre-order Your email address, the Paddle transaction ID, the amount and currency, and the status (paid or refunded). Paddle, as Merchant of Record, handles the payment and your billing details. Confirm your pre-order, handle refunds and apply the prepaid year at launch.

Abuse prevention. To stop automated submissions, these forms are rate-limited per connection. We store a keyed hash of your IP address (never the IP address itself) with the time of the request, separately from your answers, and delete it after 24 hours. Legal basis: legitimate interests (keeping the service secure).

4.3a Emails we send you about your workspace

Once you have an AffCheck workspace we send two kinds of email about it, to the verified address of every member:

Email When What is in it
The Monday deadline email Monday morning, 08:00 in your store's own time zone, and only when something is pending and your plan includes it Totals per currency, one line per network with a count and the network's next auto-approval date, and a link back to your review queue
Setup emails Three one-off emails while you set the workspace up: a welcome, a reminder if no network file has arrived after two days, and a note when your first decline file is marked as uploaded Totals only, plus links into the app

No order numbers, no customer names, no amounts belonging to individual shoppers. These emails carry totals, counts and dates, and nothing that identifies an order or a person.

Turning them off. Every one of them has an unsubscribe link that works without signing in, and an unsubscribe header your mail app can use. The setting is per person and per store: turning it off changes nothing for your colleagues. You can also change it under Account → Email settings in the app. Legal basis: legitimate interests (telling you about work waiting in a service you asked for), and you can object at any time with one click.

Account emails — email verification, password resets, invitations and billing receipts — are part of having an account and are not covered by that setting. Legal basis: performance of the contract.

4.4 Shopify privacy requests

AffCheck responds to Shopify's mandatory privacy webhooks:

  • Customer data request (customers/data_request): we tell the store what data we hold linked to that customer ID (order and refund records, no contact details) within 30 days.
  • Customer redaction (customers/redact): we delete or anonymise that customer's order records within 30 days, unless the store still needs them to prove a commission decision within the network's dispute period and the law allows us to keep them.
  • Shop redaction (shop/redact, sent 48 hours after a store uninstalls the app): we delete all of the store's data within 7 days.

4.5 AI

AffCheck does not currently send store or network data to an AI provider. If we add AI features, we will update this policy and our Subprocessors page first.

4.6 How long we keep AffCheck data

Data Retention
Network export files Not kept at all. The file is read on your device and only the transaction fields listed in 4.2 are sent to us
Orders read from your own Shopify export (web app) 13 months from the order date, then deleted on a rolling basis; deleted with the store when you delete it
The record of an orders upload or an import (counts, dates covered, warnings, status) 13 months
Pending transactions and your decisions 13 months from the transaction date (so you can compare with the same month last year and handle network disputes)
Flags (what we suggested and the evidence for it) With the transaction they belong to
Generated export files Not kept at all — the file is built when you download it. The record of which decisions went into which file is kept 13 months
Your activity log — who decided, imported, undid or exported what, when, and the commission it involved. Counts, ids, amounts and the Shopify order name only: never a customer, an address or anything else from an order 24 months, and deleted with the store
Order, refund and discount data from Shopify While the app is installed; orders older than 13 months are deleted on a rolling basis
All store data after uninstall Deleted within 7 days of Shopify's shop/redact request (sent 48 hours after uninstall)
Network API credentials Until you disconnect the network or uninstall (deleted immediately)
Free check: survey answers 24 months after you answer, then deleted
Free check: column-name reports 24 months after you send them, then deleted
Free check: rate-limit IP hashes 24 hours
Email addresses from the free check and the waitlist, with the role, networks, leak range and campaign tags given with them Until you unsubscribe or ask us to delete them; deleted after 24 months without any email from us
One-off email keys (so the same email is never sent twice) 90 days. The key names the purpose and a row id, never an address
Your email settings (which workspace emails you want) With the store: deleted when the store or your account is deleted. We keep it for as long as the store exists rather than expiring it by age — deleting it would start the emails again
Founding pre-orders As long as tax and accounting law requires for billing records (see section 9)

When you delete a store or your account. Deleting a store deletes everything above that belongs to it — orders, refunds, transactions, flags, decisions, imports, export records and its activity log — immediately, not on a schedule. Deleting your account deletes the workspaces nobody else is a member of, and their stores with them. Backups are kept for 30 days and then expire (see section 8), so a deleted store disappears from those within 30 days. Deleting a store does not cancel a paid plan: cancel it on the Billing page first.

Ask for a copy first. "Download my data" in the app gives you every row of the table above for your own workspaces, as one JSON file, at any time.

4.7 International transfers

AffCheck data is hosted in Germany (EU). See section 8 and our Subprocessors page for the services outside the EU and the safeguards we use.

5. Cookies and analytics

We don't use advertising, social-media or cross-site tracking cookies, and we don't use Google Analytics. That is why you don't see a cookie banner.

What we do use:

Name / type Where Purpose Duration
Session cookie (for example better-auth.session_token) App, after you sign in Keeps you signed in. Strictly necessary. Until you sign out, or up to 30 days
Sign-in security cookies (state / CSRF) Sign-in pages Protects sign-in and "Sign in with Google" against forgery. Strictly necessary. Minutes
Cloudflare security cookies (for example __cf_bm, Turnstile) Website and app Bot and abuse protection. Strictly necessary. Up to 30 minutes
Paddle checkout Checkout window only, when you choose to buy Processes your payment and prevents fraud. Set by Paddle as the seller. See Paddle's privacy notice. Set by Paddle
Chat widget Only after you click "Chat with us" Keeps your support conversation open. See the Subprocessors page. Up to 6 months

Analytics. We use Umami, hosted on our own server in Germany. It does not set cookies or store anything on your device. It records the page, referrer, browser, device type and country, and counts unique visitors using a hash of your IP address and browser details combined with a secret that changes regularly; the IP address itself is not stored. We cannot identify you from this data and we don't combine it with other data. Our analytics honours your browser's "Do Not Track" setting.

If we ever add non-essential cookies (for example advertising conversion tracking), we will ask for your consent first and update this section.

6. AI features

The product section above says which features use AI and what they send — and a product that says it sends nothing, sends nothing. Where a feature does send content to an AI provider (named on the Subprocessors page) to generate results such as drafts or suggestions, we send only the content needed for the task. Under the provider's commercial terms, it does not use this content to train its models and keeps it only for a limited time for safety and abuse monitoring. We never use your content to train any AI model.

7. Who we share data with

We share personal data only:

  • With service providers (subprocessors) who help us run the product, such as hosting, email delivery and AI. They may use the data only to provide their service to us. The full list, with locations, is on our Subprocessors page.
  • With Paddle, our reseller and Merchant of Record, which processes your purchase as an independent controller under its own privacy notice.
  • With Google, if you choose "Sign in with Google" (Google tells us your name, email address and account ID; Google's privacy policy applies to your Google account).
  • With systems you connect. When you connect a third-party system, data flows between it and AffCheck because you asked for it.
  • When the law requires it, or to protect our rights, users or the public (for example in response to a valid court order). Where allowed, we will tell you first.
  • If the business is transferred, for example if the product is moved into a company the founder sets up or is sold. We will tell you, and this policy will continue to protect your data.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

8. Where your data is stored and international transfers

Our application servers and database are hosted by Hetzner in Germany (EU). Encrypted backups are kept on our Hetzner server and in Cloudflare R2 storage restricted to the EU jurisdiction. Some subprocessors are in the United States (see the Subprocessors page); for those we rely on the EU–US Data Privacy Framework where the provider is certified, or on Standard Contractual Clauses (with the UK Addendum for UK data).

The founder works from Ukraine, which the EU and UK have not recognised as providing "adequate" protection. Access from Ukraine is remote, encrypted and limited to what is needed to run and support the service. Data is not copied to local devices except where needed to handle a support request, and then deleted.

9. How long we keep data

Data How long
Account data While your account is open. Deleted within 30 days after you close it (60 more days in backups).
Customer data in the product See the product section above. Deleted within 30 days after your account closes, or earlier when you delete it.
Billing records As long as tax and accounting law requires (currently up to 7 years). Paddle keeps its own records.
Support conversations 3 years after the last message.
Server logs and error reports 30 days.
Website analytics Aggregated, without personal identifiers; kept indefinitely.
Records of outreach and opt-outs Contact details of people we contacted: 24 months after the last contact. Opt-out list: kept permanently so we never contact you again (only the email address).
Records of your consents and acceptance of terms For as long as your account exists plus 3 years, to prove what was agreed.

10. How we protect data

Data is encrypted in transit (TLS) and at rest. Secrets such as API keys are additionally encrypted in our database. Access is limited to the founder, uses strong authentication, and is logged. See our Security page for details. If a personal-data breach affects you, we will notify you (and, as your processor, your organisation) without undue delay.

11. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy;
  • correct it if it is wrong;
  • delete it;
  • restrict or object to our use of it, including objecting at any time to direct marketing;
  • port it to another service in a machine-readable format;
  • withdraw consent where we rely on consent (this doesn't affect what we did before); and
  • complain to a data protection authority (see section 15).

To exercise these rights, email privacy@affcheck.com from the address linked to your account, or use the account settings where available (export, delete account). We reply within 30 days. We may need to verify your identity. We don't charge for requests unless they are clearly unfounded or excessive.

If your request concerns data that an organisation put into AffCheck (section 2, "Processor"), we will forward it to that organisation and help it respond.

12. US state privacy notice

This section is for residents of US states with consumer privacy laws, including California.

  • Categories of personal information we collect are described in section 3: identifiers (name, email, IP address), commercial information (subscription records), internet activity (product usage and analytics), and the content of your communications with us. Sources: you, your organisation, your device, Paddle, Google sign-in and public business listings.
  • We do not sell or share personal information (as those terms are defined in California law), and we have not done so in the past 12 months. We do not knowingly sell or share personal information of people under 16.
  • We don't use sensitive personal information for purposes that would give you a right to limit it.
  • Your rights: to know, access, correct and delete your personal information, and not to be discriminated against for exercising these rights. You can use an authorised agent. Contact privacy@affcheck.com.
  • Global Privacy Control and Do Not Track. We honour GPC and "Do Not Track" signals by disabling analytics for that browser. We don't track you across third-party websites.

13. Children

AffCheck is a business tool and is not intended for anyone under 18. We don't knowingly collect personal data from children. If you believe a child has given us personal data, email privacy@affcheck.com and we will delete it.

14. Changes to this policy

We will update this policy when our practices change. The version and effective date are at the top. If a change materially affects how we use your personal data, we will email account owners at least 30 days before it takes effect (or ask for your consent where the law requires it).

15. Contact and complaints

TBD — fill before launch (legal name as registered), TBD — fill before launch (registered address), TBD — fill before launch. Email: privacy@affcheck.com.

If you are unhappy with how we handled your data, please contact us first. You can also complain to your local data protection authority, for example:

  • in the EU, the supervisory authority of the country where you live or work (list);
  • in the UK, the Information Commissioner's Office (ico.org.uk);
  • in Ukraine, the Ukrainian Parliament Commissioner for Human Rights.