Privacy and your data
Who controls what, the DPA accepted at signup, how long each record is kept, and how a partner or customer exercises their rights.
Running an affiliate program means holding data about people who never signed up with us. This page is what happens to it.
You are the controller and we are the processor
Your affiliates and your referred customers are your data. You decide why it is held and what it is for; we hold it and act on your instructions. In UK GDPR terms you are the controller and we are the processor, and Article 28 says a processor may only act under a written contract.
That contract exists and you have already accepted it. The data processing agreement is incorporated into the terms of service, so it takes effect when you open an account and nobody has to sign anything. If your own compliance process needs a copy on file, there is a standalone one at affiliaterail.com/dpa that prints cleanly.
Your own account details, your subscription and your invoices are a different matter: there we are the controller and our own privacy policy applies.
Who else touches it
Our sub-processors are published at affiliaterail.com/subprocessors, with what each one does, where it processes and the transfer mechanism that covers it. Your acceptance of the DPA is a general authorisation for that list, and we commit to announcing a change before it takes effect so you have time to object.
Your own payment rails are not on that list, and the distinction matters. When a payout goes out, we call PayPal, Wise or Payoneer with your credentials, on your account. They are your processors, engaged by you under your own terms with them, and we are the software that presses the button.
What we store in a browser
The dashboard keeps your session, the program you are looking at and your security settings. Those three are what signing in means, so there is nothing to turn off there.
Analytics does whatever you told the banner to do. Accept and it keeps a cookie, which is what lets a visit to affiliaterail.com and your signup here be recognisably the same person. Refuse and it runs cookieless: no cookie, no local storage, no session storage, no profile for anonymous traffic, and the visit counted from a hash worked out on the analytics provider's servers instead of a marker on your device. Refusing changes nothing about how the product works.
Two things hold either way, and they are the ones that matter on screens showing your affiliates' details:
- The text you click is never captured. Autocapture is off, deliberately and permanently.
- The session recording is fully masked. It records where the pointer went, what was clicked and how far the page scrolled. Every text node and every input is blanked before anything leaves your browser, so an affiliate's email address cannot be read off a recording that never contained it.
Your answer is kept in one cookie, rail.consent, shared between the site and the dashboard so
you are only ever asked once. Change it any time from Settings, then Security, then Cookies and
analytics, or from Cookie choices in the footer of affiliaterail.com.
The partner portal your affiliates use keeps their session and their language and nothing else.
How long we keep things
The full schedule, record by record, is in the repository as docs/runbooks/retention.md. The
shape of it:
| Record | Kept |
|---|---|
| Partner and customer identity | While your program runs |
| Ledger amounts: commissions, payouts, balances, invoices | While your program runs, and at least 6 years |
| Tax forms | The statutory period, which outlives a deletion request |
| Audit log | While your program runs, and at least 6 years |
| Messages sent to partners | 2 years |
| Unsubscribes and complaints | Kept, because a suppression is the record of a refusal |
| Webhook deliveries | 30 days |
When you close your account we give you 30 days to export, then purge the program's personal data. The amounts stay with nobody's name on them, because your own books have to keep balancing.
Exporting or deleting one person
Settings, then Data requests. Search by email, handle or id.
- Export downloads everything held about that person as one JSON bundle. We do not keep a copy; the record we keep is the size, a hash and the date.
- Delete hides them immediately, waits seven days so you can change your mind, then removes their personal details and keeps the money records with nobody on them. A partner with commissions still due cannot be deleted until that is settled, and the screen tells you the count.
Someone who is not one of your merchants and wants to reach us directly has a public route at affiliaterail.com/data-request. It explains that you are the controller, routes the request to you, and does not create a second, competing mechanism.
What happens to a deleted partner's tax form
It is kept, and sealed. A submitted W-9 or W-8 is a record you may be legally required to hold whether or not the partner stays, because you are the payer of record and the retention period belongs to the tax authority, not to the person. So the deletion removes the partner's details everywhere else, and the form stays in the database restricted: off every list, every export and every screen except one. The US year-end export still shows the partner, under the legal name on the form, because that export exists to answer the tax authority. Erasure law works the same way: a record kept under a legal obligation survives the request, and may be used for that obligation and nothing else.
Breaches
If personal data you control is involved in a breach, we tell you without undue delay and with what we know: what happened, which categories of data and roughly how many people, what we have done, and who to talk to. You decide what to tell your own regulator and your own people, because you are the controller. The commitment is in the DPA.
Reaching us
support@affiliaterail.com for anything on this page. security@affiliaterail.com for a
vulnerability. The trading details, including the postal address, are in the footer of every page
on the marketing site.