Privacy Policy

Effective Date: September 1, 2026
Last Updated: August 21, 2026

Affily, Inc. ("Affily," "we," "us," or "our") provides an affiliate marketing platform that connects businesses with creators and provides campaign management, attribution, commission, reimbursement, payment, payout, reporting, and related services.

This Privacy Policy explains how we collect, use, disclose, and retain personal information when you use the Affily mobile application, affilyapp.com, our store connection and attribution services, and related services.

1. Scope

This Privacy Policy applies to:

  • creators, affiliates, and promoters who use Affily;
  • businesses, merchants, brands, and their authorized personnel;
  • visitors to Affily websites and store-setup pages;
  • individuals who contact Affily or participate in waitlists or support processes;
  • customers and visitors of participating merchant stores whose transactions or interactions are processed for attribution; and
  • other individuals whose information is processed through Affily's services.

Affily's services are intended for individuals who are at least 18 years old.

2. Information We Collect

The information we collect depends on how you interact with Affily.

Account and Profile Information

We may collect:

  • name;
  • username;
  • email address;
  • business name;
  • business domain;
  • account role;
  • profile photo, avatar, or business logo;
  • account status and access status;
  • onboarding and waitlist status;
  • preferences; and
  • authentication and account-security information.

Creator Information

Creators may provide information such as:

  • social media platform;
  • social media handle;
  • self-reported follower count;
  • category preferences;
  • product interests or keywords;
  • referral information;
  • campaign memberships;
  • creator performance information;
  • payout preferences; and
  • other profile information.

Social-media handles and follower counts provided through Affily may be visible to businesses whose campaigns the creator has joined or previously participated in and to Affily administrators. Unless expressly stated otherwise, Affily does not independently verify creator-reported follower counts.

Business, Storefront, Product, and Campaign Information

We may collect or process:

  • business descriptions and branding;
  • store domains;
  • product names, identifiers, prices, images, descriptions, availability, and variants;
  • campaign names and descriptions;
  • campaign product selections;
  • commission structures;
  • commission hold periods;
  • promotional guidelines;
  • campaign media;
  • creator participation and removal records;
  • reimbursement program settings;
  • inventory and product-availability information; and
  • campaign activity and analytics.

Attribution and Usage Information

Affily may process information used to determine whether a visit or purchase should be attributed to a creator or campaign, including:

  • Affily links and link identifiers;
  • click identifiers;
  • campaign and creator identifiers;
  • visitor or client identifiers;
  • URL and referral information;
  • page-view events;
  • checkout-start events;
  • purchase events;
  • timestamps;
  • browser or device information;
  • IP address or network information available through requests and logs;
  • attribution status;
  • conversion records; and
  • related fraud, security, and diagnostic information.

Commerce and Transaction Information

When a business connects a store or otherwise provides commerce data to Affily, we may process:

  • store and business identifiers;
  • external order identifiers;
  • order timestamps;
  • currencies;
  • product and variant identifiers;
  • quantities;
  • product prices;
  • discounts and post-discount amounts;
  • order totals and subtotals;
  • cancellation status;
  • refund information;
  • product-update and product-deletion information;
  • inventory or availability information; and
  • other transaction information needed to operate attribution, commission, reimbursement, refund, and accounting workflows.

Affily's current Shopify integration is designed primarily around transaction, product, refund, and attribution information rather than maintaining independent full customer profiles.

Creators are not intended to receive merchant customer names, email addresses, shipping addresses, payment credentials, or customer order histories through Affily.

Product Reimbursement Information

If a business offers product reimbursement and a creator participates, we may process:

  • the reimbursement link used;
  • the eligible creator purchase;
  • the eligible campaign product;
  • the reimbursement sales target in effect when the offer is used;
  • the recorded reimbursement amount;
  • qualifying sale progress;
  • refund or cancellation information;
  • reimbursement hold status;
  • collection status; and
  • reimbursement payment and ledger records.

Payment, Banking, Settlement, and Payout Information

Affily and our payment providers may process information relating to:

  • connected bank accounts;
  • bank name and last four digits;
  • payment method identifiers;
  • verification status;
  • Stripe account identifiers;
  • payment and payout status;
  • payment-provider requirements and capabilities;
  • business collection amounts;
  • creator payout amounts;
  • settlement attempts;
  • ACH return or failure information;
  • outstanding balances;
  • payment recovery activity;
  • refunds or credits owed to businesses;
  • payout schedules;
  • negative balances; and
  • related accounting records.

Full bank credentials may be collected directly by payment providers rather than stored by Affily.

Identity, Tax, and Compliance Information

Affily or its service providers may process:

  • identity-verification status;
  • identity-verification metadata;
  • payment eligibility information;
  • fraud and risk indicators;
  • taxpayer information where required;
  • tax-document availability;
  • electronic delivery preferences;
  • compliance records; and
  • information relating to legal, regulatory, payment-network, or tax requirements.

Some identity, banking, and tax information may be submitted directly to Stripe or another service provider. Affily may receive verification results, account status, identifiers, or other limited information rather than the underlying documents.

Communications and Support Information

We may process:

  • support requests;
  • reports and complaints;
  • business-to-creator campaign broadcasts;
  • broadcast subjects and messages;
  • notification records;
  • creator-removal reasons;
  • internal notes;
  • dispute communications;
  • email communications; and
  • push-notification preferences and tokens.

Technical and Security Information

We may collect:

  • application logs;
  • request logs;
  • authentication events;
  • device and operating-system information;
  • error reports;
  • security signals;
  • rate-limiting information;
  • fraud indicators;
  • setup verification events; and
  • synthetic or diagnostic events used to verify that store tracking is functioning properly.

3. Attribution Technologies

Affily uses links, click identifiers, browser storage, pixels, webhooks, and server-side records to attribute purchases.

Affily currently uses a standard seven-day attribution window for ordinary campaign attribution unless a different period is expressly displayed through the Service.

On participating Shopify stores, the Affily Customer Events pixel may store an Affily click identifier in local storage. The pixel may use a Shopify-provided client identifier or an Affily-generated visitor identifier and may transmit events such as page views, checkout starts, and completed purchases to Affily.

Affily may also use setup and health-check events to confirm that merchant tracking is functioning.

An attribution window does not guarantee attribution. Attribution may be affected by browser storage restrictions, customer behavior, device changes, merchant configuration, network failures, commerce-platform behavior, deleted links, fraud controls, or other technical conditions.

4. Shopify and Other Store Integrations

Affily's current Shopify connection uses merchant-configured Customer Events pixel functionality and merchant-configured signed webhooks.

The current Shopify setup may require the merchant to provide or configure:

  • the Shopify store domain;
  • an Affily pixel identifier;
  • Affily Customer Events pixel code;
  • webhook destination URLs;
  • a webhook signing secret;
  • order creation notifications;
  • order cancellation notifications;
  • refund creation notifications;
  • product update notifications; and
  • product deletion notifications.

Affily stores the merchant's webhook signing secret in encrypted form for webhook authentication.

The current Shopify connection does not require the merchant to grant Affily general Shopify Admin API authority to edit the merchant's products, prices, orders, customer accounts, or storefront. Future integrations may use different technical methods, in which case we will provide appropriate disclosures.

Shopify and other commerce platforms remain independent services governed by their own privacy practices.

5. How We Use Information

We use information to:

  • create and administer accounts;
  • operate storefront and campaign features;
  • connect businesses and creators;
  • create and operate Affily links;
  • attribute clicks, visits, and purchases;
  • calculate commissions and Affily fees;
  • administer commission hold periods;
  • process refunds and reversals;
  • administer product reimbursement programs;
  • maintain financial ledgers;
  • collect amounts owed by businesses;
  • pay creators;
  • return eligible business credits;
  • process failed-payment recovery;
  • provide transaction histories and analytics;
  • synchronize product and inventory information;
  • detect unavailable or out-of-stock products;
  • administer creator participation and removal;
  • deliver campaign broadcasts and notifications;
  • provide support;
  • verify identities and payment readiness;
  • provide tax-related functionality;
  • prevent fraud and abuse;
  • investigate suspicious activity;
  • protect Affily, users, and third parties;
  • enforce our agreements and policies;
  • comply with legal and regulatory obligations;
  • maintain accounting, tax, audit, and legal records;
  • resolve disputes; and
  • improve the reliability, security, and functionality of our services.

6. How We Disclose Information

We may disclose information as reasonably necessary to operate Affily.

Service Providers

We may use service providers for:

  • cloud hosting and databases;
  • website and application hosting;
  • payments and banking;
  • identity verification;
  • tax-document functionality;
  • email;
  • push notifications;
  • analytics and diagnostics;
  • fraud prevention;
  • customer support; and
  • security and infrastructure.

These providers may process information on our behalf subject to applicable contractual and legal requirements.

Stripe and Financial Providers

Affily uses Stripe and related services for payment methods, ACH collection, creator payouts, connected accounts, tax functionality, identity or account verification, and payment-risk workflows.

Stripe may independently collect information directly from users under Stripe's own privacy terms.

Businesses and Creators

Affily may disclose information between businesses and creators when reasonably necessary to operate campaigns.

Businesses may receive creator profile information, social-account information, campaign participation information, performance information, and related campaign records.

Creators may receive business storefront information, products, campaign terms, promotional requirements, commission information, reimbursement information, and business campaign broadcasts.

Affily does not provide merchant customer payment credentials to creators.

Commerce Platforms

We may exchange information with Shopify or other commerce platforms as necessary to operate store integrations, process events, investigate technical problems, or comply with applicable platform requirements.

We may disclose information where reasonably necessary to:

  • comply with law, legal process, or governmental requests;
  • investigate fraud, abuse, infringement, or security incidents;
  • enforce our agreements;
  • protect the rights, safety, or property of Affily, our users, or others; or
  • establish, exercise, or defend legal claims.

Corporate Transactions

Information may be transferred in connection with a merger, financing, acquisition, restructuring, asset sale, bankruptcy, or similar corporate event, subject to applicable law.

7. Merchant Customer Data and Our Role

For information relating directly to Affily account holders and our own operations, Affily generally acts as a controller or business.

When a merchant provides or enables Affily to receive customer transaction information for attribution, commission calculation, product reimbursement, refund processing, fraud prevention, reporting, or related merchant services, the merchant generally determines the purposes for which that customer data is processed.

For that processing, Affily may act as a processor, service provider, or contractor on behalf of the merchant.

Our Data Processing Addendum applies where applicable.

Affily does not use merchant customer personal information to create unrelated customer profiles or for independent cross-context behavioral advertising.

8. No Sale or Cross-Context Behavioral Advertising

Based on our current practices, Affily does not sell personal information for monetary consideration and does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.

Affily does disclose personal information to service providers, payment providers, participating businesses, creators, and commerce platforms for the operational purposes described in this Privacy Policy.

9. Data Retention

We retain information only for as long as reasonably necessary for the purposes for which it was collected, including providing the Service, maintaining financial records, processing payments and payouts, administering refunds and reversals, preventing fraud, resolving disputes, complying with law, and protecting Affily.

Retention periods vary depending on the category of information.

Factors we consider include:

  • whether an account remains active;
  • whether a campaign, transaction, payout, reimbursement, or settlement remains open;
  • applicable tax, accounting, and financial-record requirements;
  • fraud and security needs;
  • legal limitation periods;
  • contractual obligations;
  • unresolved claims or disputes; and
  • backup and disaster-recovery cycles.

Transaction, accounting, payout, settlement, refund, reimbursement, tax, fraud, and audit records may be retained after account closure where reasonably necessary or legally required.

De-identified or aggregated information may be retained for longer periods.

10. Account Deletion

Users may request account deletion through available in-app tools or by contacting Affily.

We may need to verify a request before acting on it.

Deletion may not be completed immediately if financial or operational obligations remain unresolved.

For example:

  • a creator may need to wait for an in-progress payout to complete;
  • a creator with an outstanding payable balance may need an eligible payout bank account before deletion can be completed;
  • a business may be required to resolve an outstanding balance;
  • a business may need to wait for a pending settlement or collection to complete; or
  • Affily may delay final deletion for fraud, security, refund, chargeback, legal, tax, accounting, or dispute-resolution purposes.

Account deletion does not require Affily to erase records that we are permitted or required to retain.

Disconnecting a Shopify pixel, removing webhooks, or disconnecting another commerce integration generally ends new event collection through that connection but does not automatically erase historical attribution, order, refund, reimbursement, settlement, fraud, support, or accounting records.

11. Your Privacy Rights

Depending on where you live and which laws apply, you may have rights to:

  • know or access personal information;
  • obtain information about categories and sources of information;
  • correct inaccurate information;
  • delete information;
  • obtain a portable copy of certain information;
  • restrict or object to certain processing;
  • withdraw consent where processing relies on consent;
  • opt out of certain sales or sharing;
  • limit certain uses of sensitive personal information; and
  • appeal certain privacy-request decisions.

Affily will not unlawfully discriminate against you for exercising applicable privacy rights.

To make a privacy request, email admin@affilyapp.com from the email associated with your account or use an available in-app request method.

We may request information reasonably necessary to verify your identity or authority.

Where Affily processes merchant customer data only on behalf of a business, we may direct the request to the relevant merchant.

12. Communications and Notifications

Affily may send operational communications relating to:

  • authentication;
  • account activity;
  • campaign activity;
  • payments and payouts;
  • product reimbursement;
  • business collection activity;
  • creator participation;
  • support;
  • policy enforcement;
  • security;
  • tax documents; and
  • changes to our legal terms.

Users may control certain optional push-notification or communication preferences through the Service.

Some transactional, security, legal, or account-related communications cannot be disabled while the account remains active.

13. Security

Affily uses commercially reasonable administrative, technical, and organizational safeguards designed to protect information.

These safeguards may include access controls, encrypted communications, encryption of certain secrets, authentication controls, database security policies, monitoring, and restricted administrative access.

No electronic system can guarantee absolute security.

14. Children

Affily is not intended for individuals under 18 years old.

We do not knowingly permit individuals under 18 to create Affily accounts.

If you believe a minor has provided personal information to Affily, contact us.

15. International Processing

Affily and our service providers may process information in the United States and other jurisdictions.

Where applicable law requires safeguards for international transfers, we will use appropriate transfer mechanisms or other legally recognized protections.

16. Changes to This Privacy Policy

We may update this Privacy Policy as our services, integrations, legal obligations, or information practices change.

We will update the effective or last-updated date when we make changes.

Where required by law, we will provide additional notice before collecting new categories of personal information or using personal information for materially different purposes.

For material changes, we may also provide notice through email, push notification, in-app notice, or another reasonable method.

17. Contact Us

For privacy questions or requests, contact:

Affily, Inc.
43313 Woodward Ave #1152

Bloomfield Hills, MI 48302

United States

Email: admin@affilyapp.com