Legal
Privacy Policy
Effective August 3, 2026
1. Who we are
AffiliateKit ("AffiliateKit," "we," "us") operates this site. If you have questions about this policy or your data, contact us at chris@affiliatekit.co.
2. What we collect from account holders
When you create a AffiliateKit account, we collect your email address, a hashed password, your profile name, your campaign configuration, and payout settings for your affiliates — specifically their payout email, payout method, currency, and tax ID.
3. What we process on merchants' behalf
In running your affiliate program, we process two things about your customers on your behalf: signups (which affiliate earned them, and an optional identifier you choose) and purchase events from Stripe (charge amount, currency, charge id, and Stripe's customer id). We do not collect your customers' email addresses, names, or IP addresses. For this data, we act as a processor — you, the merchant, are the controller.
4. Cookies
On affiliatekit.co, we set a standard session cookie called _affiliate_kit_session, which is required for signing in. On merchant sites, the AffiliateKit snippet sets a first-party cookie called _ak_ref, which carries the affiliate's referral code and the time it was set, for as long as that merchant's attribution window. It holds nothing that identifies the visitor. We don't set any third-party advertising cookies.
5. Payments
Payments are processed by Stripe. We never see your card numbers — Stripe handles that directly. Stripe acts as a subprocessor for payment data.
6. Retention & deletion
We keep account data for as long as your account is active, and referral data for as long as the relevant merchant's campaign needs it. To request deletion, email chris@affiliatekit.co.
7. Your rights
You can request access to, correction of, or deletion of your data by emailing chris@affiliatekit.co.
8. Changes
If we make changes to this policy, we'll post the update here with a new effective date.