Privacy
Last updated 16 September 2026
Draft — not yet reviewed by a lawyer
This describes how AffGo actually works today, written from the product itself, and every [PLACEHOLDER] below needs filling in. It is not legal advice and must be reviewed before launch. Until then these pages are excluded from search engines.
Who we are
AffGo is an affiliate tracking platform operated by [LEGAL ENTITY NAME], registered in [COUNTRY] at [REGISTERED ADDRESS]. For anything in this policy, write to [PRIVACY CONTACT EMAIL].
Two kinds of people use AffGo: brands, who run an affiliate program, and creators, who promote those programs. A third group never signs up at all: the visitors who click an affiliate link. This page covers all three.
What we collect
If you have an account (brand or creator): your name, email address and password hash; your workspace or creator profile, including the categories, links and audience figures you choose to add; and a record of what you did in the product, such as approving an affiliate or recording a payment.
If you are paid through AffGo as a creator: the payment details you give so a brand can pay you — for example a bank account, UPI ID or PayPal address. These are encrypted before they are stored, and every time they are shown or exported that access is written to an audit log.
If you clicked an affiliate link: we record that the click happened so the right creator is credited. We store the country and region, the kind of device, browser and operating system, and the website you came from. We do not store your IP address or your browser's user agent: both are turned into a one-way hash with a secret key before anything is written down, which lets us spot the same visitor clicking twenty times without keeping anything that identifies you.
Cookies and how a sale is credited
When you click an affiliate link, AffGo's link service sets a first-party cookie on the link's own domain and adds a click identifier to the address you land on. The brand's website passes that identifier back to us when you buy something, which is how the commission reaches the right creator.
How long a click stays creditable is set by each brand — commonly 90 days. There is no third-party advertising cookie, no cross-site tracking network, and none of this is used to build a profile of you or to show you adverts.
What we never do
- We never hold your money. Brands pay creators directly. AffGo calculates what is owed and records the payment reference; the funds never pass through us.
- We do not sell personal data, and we do not share it for advertising.
- We do not show your payment details to anyone but you and the brand paying you, and every such view is logged.
Who else processes it
We use a small number of services to run AffGo. They only receive what they need for their part of it:
- Stripe — subscription billing for AffGo's own plans. Card details go to Stripe, never to us.
- Resend — sending email such as invitations, payout notices and trial reminders.
- OpenAI — creator/program matching on paid plans. Profile and program text is sent to generate the match; payment details and click data never are.
- Sentry — error reports when something breaks, so we can fix it.
- [HOSTING PROVIDER] — the servers and database AffGo runs on, in [HOSTING REGION].
A full, current list with each provider's own privacy terms is available on request at [PRIVACY CONTACT EMAIL].
How long we keep it
- Account and program data: for as long as the account exists, and afterwards only where we must keep it — for example records of commissions and payments, for accounting and tax purposes.
- Click and conversion records: kept while they can still matter to a commission or a dispute.
- Export files: the download link expires after 7 days, and the file is deleted.
- Sent email: removed from our queue 7 days after it is sent.
- Audit logs of sensitive access, such as viewing payment details: kept as the record of who saw what.
How it is protected
Payment details are encrypted with AES-256-GCM before they are stored, and can only be read by the parts of the product that need to show them to you or to the brand paying you. Passwords are hashed with Argon2id. Access between workspaces is refused at the database layer, so one brand cannot read another's data even if the product has a bug.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Brands can export their own program data from the dashboard at any time. Where we must keep something — a commission record that belongs to a paid invoice, say — we will tell you what and why.
Depending on where you live you may also have the right to object to processing or to complain to a data protection authority: [SUPERVISORY AUTHORITY]. Write to [PRIVACY CONTACT EMAIL] and we will answer within [RESPONSE WINDOW].
Changes
If this policy changes in a way that matters, we will say so in the product and by email before it takes effect. The date at the top always reflects the current version. The terms of service cover the rest of the relationship.