AffiliateRail docs
Platform guides

Privacy and your data

Who controls what, the DPA accepted at signup, how long each record is kept, and how a partner or customer exercises their rights.

Running an affiliate program means holding data about people who never signed up with us. This page is what happens to it.

You are the controller and we are the processor

Your affiliates and your referred customers are your data. You decide why it is held and what it is for; we hold it and act on your instructions. In UK GDPR terms you are the controller and we are the processor, and Article 28 says a processor may only act under a written contract.

That contract exists and you have already accepted it. The data processing agreement is incorporated into the terms of service, so it takes effect when you open an account and nobody has to sign anything. If your own compliance process needs a copy on file, there is a standalone one at affiliaterail.com/dpa that prints cleanly.

Your own account details, your subscription and your invoices are a different matter: there we are the controller and our own privacy policy applies.

Who else touches it

Our sub-processors are published at affiliaterail.com/subprocessors, with what each one does, where it processes and the transfer mechanism that covers it. Your acceptance of the DPA is a general authorisation for that list, and we commit to announcing a change before it takes effect so you have time to object.

Your own payment rails are not on that list, and the distinction matters. When a payout goes out, we call PayPal, Wise or Payoneer with your credentials, on your account. They are your processors, engaged by you under your own terms with them, and we are the software that presses the button.

What we store in a browser

The dashboard keeps your session, the program you are looking at and your security settings. Those three are what signing in means, so there is nothing to turn off there.

Analytics does whatever you told the banner to do. Accept and it keeps a cookie, which is what lets a visit to affiliaterail.com and your signup here be recognisably the same person. Refuse and it runs cookieless: no cookie, no local storage, no session storage, no profile for anonymous traffic, and the visit counted from a hash worked out on the analytics provider's servers instead of a marker on your device. Refusing changes nothing about how the product works.

Two things hold either way, and they are the ones that matter on screens showing your affiliates' details:

  • The text you click is never captured. Autocapture is off, deliberately and permanently.
  • The session recording is fully masked. It records where the pointer went, what was clicked and how far the page scrolled. Every text node and every input is blanked before anything leaves your browser, so an affiliate's email address cannot be read off a recording that never contained it.

Your answer is kept in one cookie, rail.consent, shared between the site and the dashboard so you are only ever asked once. Change it any time from Settings, then Security, then Cookies and analytics, or from Cookie choices in the footer of affiliaterail.com.

The partner portal your affiliates use keeps their session and their language and nothing else.

How long we keep things

The full schedule, record by record, is in the repository as docs/runbooks/retention.md. The shape of it:

RecordKept
Partner and customer identityWhile your program runs
Ledger amounts: commissions, payouts, balances, invoicesWhile your program runs, and at least 6 years
Tax formsThe statutory period, which outlives a deletion request
Audit logWhile your program runs, and at least 6 years
Messages sent to partners2 years
Unsubscribes and complaintsKept, because a suppression is the record of a refusal
Webhook deliveries30 days

When you close your account we give you 30 days to export, then purge the program's personal data. The amounts stay with nobody's name on them, because your own books have to keep balancing.

Exporting or deleting one person

Settings, then Data requests. Search by email, handle or id.

  • Export downloads everything held about that person as one JSON bundle. We do not keep a copy; the record we keep is the size, a hash and the date.
  • Delete hides them immediately, waits seven days so you can change your mind, then removes their personal details and keeps the money records with nobody on them. A partner with commissions still due cannot be deleted until that is settled, and the screen tells you the count.

Someone who is not one of your merchants and wants to reach us directly has a public route at affiliaterail.com/data-request. It explains that you are the controller, routes the request to you, and does not create a second, competing mechanism.

What happens to a deleted partner's tax form

It is kept, and sealed. A submitted W-9 or W-8 is a record you may be legally required to hold whether or not the partner stays, because you are the payer of record and the retention period belongs to the tax authority, not to the person. So the deletion removes the partner's details everywhere else, and the form stays in the database restricted: off every list, every export and every screen except one. The US year-end export still shows the partner, under the legal name on the form, because that export exists to answer the tax authority. Erasure law works the same way: a record kept under a legal obligation survives the request, and may be used for that obligation and nothing else.

Breaches

If personal data you control is involved in a breach, we tell you without undue delay and with what we know: what happened, which categories of data and roughly how many people, what we have done, and who to talk to. You decide what to tell your own regulator and your own people, because you are the controller. The commitment is in the DPA.

Reaching us

support@affiliaterail.com for anything on this page. security@affiliaterail.com for a vulnerability. The trading details, including the postal address, are in the footer of every page on the marketing site.