Legal

Privacy Policy

What we collect, what we do with it, and the choices you have.

Updated 2026-09-19

1. What we collect

Account data: name, email, organization details. Billing data: payment method (managed by Stripe; we do not see card numbers). Affiliate program data: affiliate names, emails, payout history. Tracking data: clicks, conversions, IPs (hashed for fraud detection). Imported data: when a Brand migrates from another affiliate platform, the historical affiliate, conversion, commission, and customer-attribution records they upload (which can include customer emails and Stripe customer/subscription identifiers). Usage data: which features you use, error reports. Fraud signals: on tracking clicks and on signup, lead, and proposal forms we collect a hashed IP address, user agent, and device fingerprint, and we obtain automated risk scores (such as proxy, VPN, data-center, and bot indicators) from our fraud-detection provider; these signals are used only to detect fraud and invalid traffic, never for advertising. For affiliate accounts we also keep a person-level risk score, computed from identity facts (whether your payout account and, where you chose to run it, your identity check are verified), the state of your payout account, the quality of the traffic you send, refund and chargeback outcomes on your commissions, and links between your account and other accounts (a shared device, address, or payout destination, kept as counts); as part of it we obtain a reputation score for your login mailbox from our fraud-detection provider, and we record the IP address of your sign-up request and, where our fraud-prevention tag is present, an opaque device identifier from that provider; both are kept for as long as the related account records under Section 6. Automated decisions: a high risk score can place an affiliate application into manual review by the Brand, or mark a lead as invalid pending review. The affiliate risk score can hold a payout for Rekomi’s review before it is sent, apply a short waiting period to a first payout, and, at the highest risk band only, decline a new payout method until a reviewer has looked, leave an application to the Brand’s decision instead of approving it automatically, leave a creator page out of the directory, and pause participation in a campaign until a reviewer has looked. It never closes an account or reverses an earned commission on its own; those are decisions a named Rekomi reviewer makes, and that reviewer can change every outcome the score produces. If you think a score got it wrong, use Ask Rekomi to look in your payout settings, ask the Brand, or write to support@rekomi.com and a person will check it.

Verification data: when a brand asks to be verified for instant payouts we confirm control of its website (a DNS record or our tracking snippet), confirm a business email address by a link we send, and take one of three proofs: the connection date and volume of a sales platform the brand connected, the account holder name of a bank account the brand links through Stripe Financial Connections (read once for the name match; the account is not saved and never debited), or an identity check run by Stripe Identity (government ID and selfie are processed by Stripe under its privacy policy; we store only the session reference and the outcome). When Rekomi requires an identity check (a brand above our fraud score threshold, or one a reviewer flags), Stripe Identity verifies a government ID and a matching selfie; Stripe holds the images under its own privacy terms, and Rekomi stores only the outcome and the name on the document, which we compare with the account holder name on the brand’s funding bank account. Reviewers see this evidence together with the trust signals below.

Payout safety signals: to keep the affiliate payout rail safe, we record the IP address and, where our fraud-prevention tag is present, a device identifier for the request that creates a Brand account (sign-up), the request that creates an affiliate login (sign-up), and the request that creates an Affiliate account with a Brand (accepting an invite or applying), and for actions taken on a Brand account. For affiliates, Stripe also reports the state of the payout account to us (whether it is enabled, what Stripe still needs, the bank name, the account holder name and the last four digits of the linked bank account, and a fingerprint of that account; never the full account number), and we keep these to check that the person being paid is the person who signed up. When a Brand links a bank account for payout funding through Stripe Financial Connections, Stripe shares the account holder name(s) and a balance indication with us, alongside the tokenized account details; we store the holder names to check them against the account’s own details. We compare these signals across accounts to detect self-dealing and fraudulent payout runs, we show them to our own operators in a review console, and where we find fraud we keep the identifiers (email, IP, device, payment-instrument fingerprint) on an internal block list. These signals are used only for fraud prevention and security, never for advertising, and are retained for as long as the related account records under Section 6.

2. How we use it

To provide the Service. To send transactional email (account, payouts, billing). To improve the product (aggregate analytics only). To detect fraud and abuse. To comply with legal obligations. We do not sell your data. We do not use your data to train AI models without your explicit consent. Rekomi staff can access your account to provide support or investigate fraud; every such access is recorded in the audit log.

Email communications. Service emails (account, security, payout, billing, and legal notices) are always sent while you have an account. Optional emails such as tips, setup reminders, and payout nudges can be turned off in Settings or through the unsubscribe link in any of them.

3. Sub-processors and international transfers

We share personal data with vetted sub-processors that help us run the platform, including Stripe (billing and payouts), IPQualityScore (fraud and identity risk scoring of IP addresses, devices, email addresses, and subscription billing details, and reporting of identifiers tied to confirmed fraud), Paddle and Braintree (conversion tracking for brands who connect those accounts), Lemon Squeezy (conversion tracking for brands who connect their stores), Chargebee (conversion tracking for brands who connect their Chargebee sites), Polar (conversion tracking for brands who connect their Polar organizations), Recurly (conversion tracking for brands who connect their Recurly sites), Gumroad (conversion tracking for brands who connect their Gumroad seller accounts), Creem (conversion tracking for brands who connect their Creem stores), Dodo Payments (conversion tracking for brands who connect their Dodo Payments accounts), Mollie (conversion tracking for brands who connect their Mollie accounts), Shopify (conversion tracking and, for merchants who install our Shopify app, billing of their Rekomi subscription and commission fee), Wix (conversion tracking and, for brands who install our app from the Wix App Market, billing of their Rekomi subscription through Wix), BigCommerce (conversion tracking and, for brands who install our app from the BigCommerce App Marketplace, billing of their Rekomi subscription through BigCommerce), PayPal (affiliate payouts in some regions), Clerk (authentication), Cloudflare (DNS, CDN, and edge), Vercel (website and web application hosting), Resend (email), DigitalOcean (hosting and private file storage), our managed PostgreSQL and Redis providers, Sentry (error monitoring, with masked session replay on errors and IP addresses scrubbed), IPQualityScore (fraud and invalid-traffic detection, including IP reputation, device fingerprinting, and scanning of landing-page and proposal URLs), Anthropic (AI features when you invoke one, where a prompt can include the recipient names and emails you put into outreach and creator profile text while performance stats are sent in aggregate, and the automated fraud review of new brand accounts, which sends the brand dossier our reviewers see, including the owner and cardholder names, the owner and billing email addresses, the sign-up IP address and device id, the last four digits, expiry, billing postcode and country and check results of the subscription card, campaign settings, the names, email addresses and sign-up IP addresses of the brand’s affiliates, funding account holder names, website text and the text the brand typed into its description and verification replies, so the model can write a risk summary, and the automated fraud review of affiliate accounts, which sends the person’s own facts (score, signals, payout account state without account numbers, traffic and money outcomes, overlaps as counts, creator page text) so the model can write a risk summary a human reads; nothing sent is used to train models), Zapier (the Zapier page in the brand dashboard embeds Zapier, which receives the signed-in brand user’s name and email), Gravatar by Automattic (the brand dashboard shows an avatar for each referred customer, which sends an MD5 hash of that customer’s email to Gravatar from the viewer’s browser, so Gravatar also sees the viewer’s IP address), Google Fonts (fonts served at page load on brand portal signup pages and creator about pages, so Google sees the visitor’s IP address), Calendly (embedded on our demo booking page; what you enter in the booking form goes to Calendly), Google Analytics (loads on every visit with storage denied and sends only cookieless pings until you accept analytics cookies, after which full measurement runs), PostHog (product analytics, only with analytics-cookie consent), and Intercom (support chat, only with marketing-cookie consent; signed-in users are identified to Intercom by id, name, email, and signup date). The full, dated list is at /legal/subprocessors.

Webhooks and Zapier.When a Brand subscribes to outbound webhooks or connects Zapier, Rekomi delivers affiliate names and emails (and the event details) for the events the Brand chooses to the endpoints the Brand configures. Those endpoints are chosen and controlled by the Brand, so they are the Brand’s own processors, not Rekomi sub-processors.

Connected CRMs.When a Brand connects a CRM or email platform to Rekomi, we sync the affiliate and customer records the Brand selects to that platform at the Brand’s direction. That provider is the Brand’s own processor, chosen and controlled by the Brand, not a Rekomi sub-processor, and its handling of the data is governed by the Brand’s agreement with it.

Our default processing region is the United States. Where we transfer personal data out of the EEA or UK, we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum, as described in our DPA.

Shopify Protected Customer Data.When a merchant installs our Shopify app, we receive order and customer data from their store through Shopify’s Admin API and webhooks. We process the minimum we need to attribute affiliate sales, calculate commissions, bill the merchant, and report program performance. We do not sell this data, we limit its use to those purposes, we encrypt it in transit and at rest, and we honor Shopify’s mandatory data-subject requests (customer data-request, customer redaction, and shop redaction) by returning or deleting the data we hold, in line with Shopify’s Protected Customer Data requirements.

4. Connected social accounts

Creators can link social accounts (YouTube, Instagram, Facebook, TikTok, X, Twitch, Pinterest, Threads, Discord, Bluesky, LinkedIn, beehiiv) to their Rekomi profile to prove they own them and to show verified audience stats. Linking uses each platform’s official sign-in (OAuth) or, for platforms without one (Bluesky, beehiiv), a credential you create for the purpose and can revoke at the platform any time; Rekomi never sees your account password. The access credentials each platform issues are stored encrypted and used only to read your public profile identity (name, handle, avatar) and audience statistics (for example, follower or subscriber counts and aggregate view metrics), refreshed about once a day. Disconnecting a platform in your dashboard immediately deletes our stored credentials and, where the platform supports it, revokes them at the platform too; removing the connection also deletes the stored stats history. We never post on your behalf, and we do not use social account data to train AI or machine-learning models.

Public creator profiles. Once you publish your creator page, it is public at rekomi.com/@handle and visible to anyone, including the verified follower and subscriber counts from the accounts you choose to connect, and published, reviewed pages are also listed in the creator directory that Brands browse inside Rekomi. Brands can likewise connect social accounts to display verified follower counts on their public campaign pages. You control which accounts are connected and whether your page is published; disconnecting an account removes its stats from your page, and unpublishing takes the page and its directory listing offline.

Google user data (YouTube). If you connect a YouTube channel, Rekomi uses YouTube API Services. With your consent, we access (via read-only scopes) your channel’s identity (channel id, title, thumbnail) and its statistics (subscriber count, video count, and aggregate 28-day view metrics). We use this data for exactly one purpose: verifying that you own the channel and displaying those stats on your Rekomi creator profile. These stats are informational only. Rekomi never pays, rewards, or otherwise compensates anyone for viewing, liking, commenting on, sharing, or subscribing to YouTube content, and no payout on Rekomi is based on YouTube views or engagement; commissions are earned only for referred sales and sign-ups completed on a brand’s own website. We do not sell it, do not use it for advertising, do not use it to train AI or machine-learning models, and do not share it with anyone except the infrastructure sub-processors that host Rekomi (section 3), which process it only on our instructions. It is encrypted in transit and at rest. We keep only recent stat snapshots; disconnecting YouTube immediately deletes our Google credentials and revokes Rekomi’s access at Google, and removing the connection deletes the stored stats as well. You can also revoke Rekomi’s access at any time in your Google security settings. Rekomi’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By connecting YouTube you also agree to the YouTube Terms of Service; Google’s own handling of your data is described in the Google Privacy Policy.

5. Cookies

We use first-party cookies for authentication and consent tracking. We use first-party tracking cookies on customer domains only when their affiliate program activates Rekomi tracking. Full cookie policy at /legal/cookies.

6. Data retention

Account and program data: kept while the account is active. After cancellation it is retained so you can export it or reactivate, and deleted when you ask us to or delete the account. Tracking data: kept for the lifetime of the account; aggregated indefinitely. Audit logs: kept indefinitely and never deleted, because they are the record of who changed what; an audit entry stores the before and after state of the change, so older entries can still contain the name or email of a person whose account has since been erased. Customer identifiers on conversion records (a referred customer’s name or email): removed when Shopify sends a customer or shop redaction request, and on request to support@rekomi.com for other account closures. Shopify protected customer data: kept only as long as needed to provide the service, deleted or anonymized within 30 days of an account closing or a shop-redaction request, and removed on a customer-redaction request as required by Shopify. Database backups: daily, with 7-day point-in-time recovery, so erased data can persist in a backup for up to 7 days.

What erasure does and does not reach. After we erase your account, Stripe and PayPal keep their own transaction records under their own retention rules, since they are independent controllers for the payments they processed. Your Intercom chat history is deleted on request. Audit log entries are kept as described above.

7. Data subject rights (GDPR + CCPA)

You can request access, correction, deletion, or portability of your personal data at support@rekomi.com. We respond within 30 days. Portability is handled by support within that window; Brands can also export their program data as CSV from the dashboard at any time, and affiliates can download their own earnings history. Affiliates can delete their own account from Settings without contacting us. California residents can also opt out of data sale (we do not sell data).

8. Controller, legal bases, and your rights

Controller. Uplup Inc., 382 NE 191st St, PMB 836716, Miami, FL 33179-3899, United States, is the controller for the personal data of people who hold a Rekomi account (brand users and affiliates in their direct relationship with Rekomi) and for visitors to rekomi.com. For the personal data of a Brand’s customers and affiliates that a Brand puts into its program, the Brand is the controller and Rekomi is its processor under our DPA. We have not appointed a representative in the EU or the UK.

Legal bases (GDPR and UK GDPR). We process your data to perform our contract with you (running your account, tracking, payouts, and support); for our legitimate interests in keeping the platform secure and free of fraud, invalid traffic, and abuse; to comply with legal obligations such as tax and sanctions rules; and with your consent for analytics and marketing cookies, which you can withdraw at any time in the cookie settings.

Your rights. You can access, correct, delete, restrict, or port your data, and object to processing based on legitimate interests, by writing to support@rekomi.com. You also have the right to lodge a complaint with your local data protection supervisory authority. Where an automated risk check affects a payout, a payout method, or an application of yours (Section 1), you can ask for a person to review it, tell us your side, and contest the outcome through Ask Rekomi to look in your payout settings or at support@rekomi.com; a named reviewer can change every outcome.

California (CCPA/CPRA). In the last 12 months we have collected the categories described in Section 1: identifiers (name, email, IP address, device identifiers), commercial information (program, conversion, and payout records), internet activity (clicks, usage data), and, for affiliates paid through Rekomi, financial and tax information handled by our payout providers. We do not sell or share personal information for cross-context behavioral advertising, and we do not discriminate against you for exercising your rights. Requests go to support@rekomi.com.

9. Security

Multi-tenant RLS, encryption at rest and in transit, signed webhooks. Full security model at /security.

10. Children

Rekomi is not directed at anyone under 18, and you must be 18 or older to hold an account. We do not knowingly collect data from children.

11. Changes

We notify customers of material changes via email at least 30 days in advance. Continued use after a change constitutes acceptance.

We keep this policy current as the product evolves. Questions about your data: support@rekomi.com.