Privacy Policy
What we collect, how we use it, and the choices you have — across our dashboard, SDKs, and attribution links.
Last updated: July 2026
1. Introduction
MyAppAffiliate (“MyAppAffiliate,” “we,” “us,” or “our”) provides an attribution and commission platform for subscription mobile apps and web SaaS products (the “Service”). This Privacy Policy explains what information we collect through the Service — including our dashboard, our SDKs (iOS, Android, React Native, Flutter, Web, and Node), our tracking links, and our public website — how we use it, who we share it with, and the choices available to you.
It applies to two groups of people: founders who install MyAppAffiliate in their app or website (“Founders”), and the creators, affiliates, and partners those Founders pay through the Service (“Creators”). If you are an end user of a Founder’s app or website — someone who clicked a creator’s link and installed or subscribed — this policy also describes the limited data we process about you on the Founder’s behalf.
2. Information We Collect
We collect the following categories of information:
- Account and contact information: name, email address, hashed password, company or app name, and billing details when you create a Founder or Creator account.
- Product configuration data: app IDs, API keys, webhook configuration, and the attribution window, hold window, and commission rates a Founder sets for their app.
- Event data:click events (timestamp, referring link, device signal), install events, identify() calls linking an install to a Founder’s own user ID, and paid-conversion, renewal, and refund events forwarded to us by RevenueCat and Stripe webhooks.
- Payout information: for Creators who opt into automated payouts, we store a Stripe Connect account identifier and payout status. We do not store full bank account or card numbers — those are held directly by Stripe.
- Device and log data:IP address, user agent, referrer, and timestamps recorded at the point of a link click, used for attribution matching and fraud detection. We do not collect Apple’s IDFA.
- Cookies: see Section 4 below.
3. How We Use Your Information
We use the information above to:
- Provide the Service — match clicks to installs and signups, calculate commissions, and render dashboards for Founders and Creators.
- Process payments and, where enabled, automated payouts.
- Detect and prevent fraud or abuse, such as duplicate clicks or self-referral schemes.
- Send transactional emails and, where you’ve opted in, product updates.
- Debug and improve the Service, generally using aggregated data.
- Comply with legal and tax obligations.
We do not sell personal information, and we do not use click or install data to build advertising profiles for third parties.
4. Cookies and Tracking Technologies
We use a small number of first-party cookies: a short-lived cookie tied to a click ID, used to match a later install or signup back to the correct attribution record, and a session cookie for the dashboard. We do not use third-party advertising cookies or pixels. See Section 16 for how we handle Do Not Track signals.
5. Third-Party Service Providers
We share information with a limited set of infrastructure providers (“sub-processors”) who help us operate the Service, bound by agreements requiring them to protect your data consistently with this policy:
- RevenueCat — receives and forwards mobile subscription events (trials, conversions, renewals, refunds) via webhook.
- Stripe, including Stripe Connect — processes web SaaS billing events via webhook and, where enabled, automated Creator payouts.
- Neon — hosts our managed Postgres database.
- Vercel — hosts our dashboard, marketing site, and docs.
- Fly.io — hosts our API.
Any additional sub-processor we add will be listed here before it begins processing data.
6. Legal Basis for Processing
Where GDPR applies, we process personal data on the following legal bases: performance of a contract (operating the Service for Founders and Creators), legitimate interests (fraud prevention, product analytics), consent (marketing emails, non-essential cookies), and legal obligation (tax and financial recordkeeping).
7. Data Sharing and Disclosure
Founders and Creators necessarily see limited data about each other through the Service — a Founder sees which Creator link drove a given conversion, and a Creator sees aggregated performance data for their own links, not the underlying customer’s personal details. We also share data with the sub-processors listed in Section 5, with law enforcement when legally compelled, and in connection with a merger or acquisition, with notice to affected users where required.
8. Data Retention
We retain account data for as long as an account is active, and for a limited period after closure as needed for tax and legal recordkeeping. Event data (clicks, installs, conversions) is retained for as long as needed to support a Founder’s configured attribution and hold windows and related reporting. You may request deletion under Section 10, subject to any legal retention obligations we’re bound by.
9. Data Security
We encrypt data in transit (TLS) and at rest, hash passwords, and scope API keys to a single app. We never store full payment card or bank account numbers — those are handled entirely by Stripe. No system is 100% secure, and we can’t guarantee absolute security, but we design and operate the Service with these protections as a baseline.
10. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, to withdraw consent, and to opt out of marketing emails at any time. To exercise any of these rights, contact us at hello@myappaffiliate.com.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion or correction of that information, to opt out of the sale or sharing of personal information (we do not sell or share personal information as defined by the CCPA), and to not be discriminated against for exercising these rights. Contact us at hello@myappaffiliate.com to make a request.
12. European Economic Area, UK, and Switzerland
For end-user event data processed on behalf of a Founder, MyAppAffiliate acts as a data processor and the Founder is the data controller. For Founder and Creator account data, MyAppAffiliate acts as a data controller in its own right. If you are located in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local supervisory authority. Founders who require a Data Processing Agreement may request one at hello@myappaffiliate.com.
13. International Data Transfers
Our infrastructure providers may process data in the United States or other countries where they operate. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or an equivalent safeguard with our sub-processors.
14. Children’s Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children through our own dashboard or website. Founders using the Service in an app or website that reaches a broader consumer audience are responsible for their own compliance with children’s privacy laws (such as COPPA) with respect to their own end users; MyAppAffiliate acts as a processor of the event data a Founder’s app sends us.
15. Creator and Affiliate Data
Creators who enable automated payouts provide payout and, where required by Stripe, tax identification information. A Creator’s dashboard only shows performance data for links tied to their own account — it is isolated from other Creators’ data.
16. Do Not Track
There is no common industry standard for how to respond to browser Do Not Track signals, so we do not currently change our behavior based on them. As described in Section 4, our own tracking footprint is already limited to first-party, attribution-purpose cookies.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We’ll post the updated “Last updated” date at the top of this page, and we’ll notify Founders by email of any material change. Continued use of the Service after an update takes effect constitutes acceptance of the revised policy.
18. Contact Us
Questions about this Privacy Policy can be sent to hello@myappaffiliate.com.
[Company legal entity name and mailing address — to be added before public launch.]