Privacy & data handling
Last updated July 2026 · Affern, Inc.
What data we collect
Server-side click records on your first-party tracking links: a timestamp, the creator link that was used, and a one-way fingerprint hash of the visitor’s browser and IP address for basic deduplication and fraud checks. Order and refund metadata from Shopify webhooks: amounts, currency, order status, and the discount codes tied to your creators. When a shopper is signed in to your store, we also store a hashed customer key so a later purchase can be matched back to the click that drove it. We never store raw IP addresses, and we do not collect end-customer names, email addresses, or payment details.
How we handle customer identity
Attribution needs to recognize a returning shopper, so we take the customer identifier Shopify provides and run it through a keyed one-way hash before storing it. The result is a pseudonymous key that connects a click to an order inside your account and cannot be reversed back into the original identifier. The same hashing is applied on the click side and the order side, and the raw identifier is never written to our database.
How data is used
Solely to attribute orders to your creators and compute the tiering, trends, and payout figures shown in your dashboard. We do not sell data, we do not use it for advertising, and we do not share it with other merchants. Authorized Affern staff may access your store’s data to provide support and investigate issues you report, and every such access is written to an append-only audit log.
Data retention and deletion
We keep raw click and funnel-event data only for a short rolling window, roughly 45 days for clicks and 90 days for funnel events, and remove anything older. Order, refund, and attribution records are kept for the life of your subscription so your historical reporting stays intact. On uninstall or written request, we delete your store’s data within 30 days.
Merchant and end-customer rights
Under GDPR and CCPA you may request access to, correction of, or deletion of the personal data we process on your behalf. Because we store hashed keys rather than raw customer identifiers, we fulfill an end-customer deletion request by removing the order and attribution records linked to that customer. Merchants can raise end-customer data requests through us as a processor.
Contact for data requests
Email us and we’ll respond within the timelines required by applicable law. We act as a data processor for the merchant, who remains the data controller.
