Boost Sales in the New Year: Save up to 30% with code BOOST30

Valid until January 31 • Special offer

00
Days
:
00
Hrs
:
00
Min
:
00
Sec

AFIVIO PRIVACY POLICY

Last updated: 01.12.2025

In this Privacy Policy, references to "Afivio", "we", "us" or "our" mean the operator of the Afivio platform currently available at afivio.com (the "Platform"). References to "you" or "your" mean the individual using the Platform on behalf of a business or other organization, or otherwise interacting with us.

This Privacy Policy explains how we collect, use, disclose and otherwise process personal data in connection with the Platform, and sets out your rights under Applicable Data Protection Laws. "Applicable Data Protection Laws" means the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and any other mandatory data protection laws that apply to our processing of personal data.

1. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to personal data that we collect and process in connection with:

  • your use of the Platform (including visiting our website, creating or managing an account, running or participating in campaigns, interacting with dashboards and other product features);
  • your communications with us, for example via email or support channels; and
  • our marketing, sales and business development activities.

This Privacy Policy does not apply to processing of personal data carried out independently by Partners or Affiliates in their own systems or channels outside of the Platform. Such processing is governed by the privacy policies of the relevant Partner or Affiliate.

2. PERSONAL DATA WE COLLECT

2.1 Data you provide to us

We may collect the following categories of personal data that you provide to us directly:

  • Account and profile data: name, business email address, password, position, company or organization name, country of operation, preferred language and other profile information you choose to provide.
  • Business and billing data: business address, VAT / tax identification numbers, billing contact details, payment method details (in tokenized form where processed by a payment provider) and related records.
  • Campaign and relationship data: details of campaigns, programs and offers created by Partners, information about Affiliates, performance metrics, and communications exchanged via the Platform.
  • Support and communication data: information you provide when you contact us (for example via email, chat or support forms), including the content of your messages and any attachments.
  • Crypto wallet and payout data: company-level wallet address generated for you on a supported blockchain network, information about your wallet balance, and on-chain transaction history linked to that address (for example inbound and outbound USDC transfers).
  • Marketing preferences: your preferences regarding receiving marketing communications from us.
  • Feedback: suggestions, ideas and other feedback you choose to share about the Platform.

2.2 Data we collect automatically

When you access or use the Platform, we may automatically collect certain information, including:

  • Technical data: IP address, browser type and version, device identifiers, operating system, referral URL, time zone setting and other technical information.
  • Usage data: information about how you interact with the Platform, such as pages viewed, buttons clicked, features used, time and date of visits, and session duration.
  • Cookie and similar technology data: information collected through cookies, pixels and similar technologies as described in our Cookie Policy.

2.3 Data from third parties

We may receive personal data about you from third parties, such as:

  • Partners or Affiliates who invite you to use the Platform or add you to their programs or campaigns;
  • third-party platforms and integrations that you choose to connect to the Platform;
  • payment processors, analytics providers and other service providers; and
  • publicly available sources (for example professional networking sites) where permitted by law.

2.4 Commerce platform, order and storefront data

If you connect a Shopify store or another supported commerce platform to Afivio, we may process data made available through platform APIs, webhooks, app proxy requests, theme app extensions, embedded app authentication flows and related storefront technologies.

Depending on the integration and the permissions granted, this may include:

  • Merchant and store data: shop domain, shop identifiers, theme or app embed status, store owner or staff account details needed for installation, authentication, billing, support and administration.
  • Customer and prospect data: customer identifiers and, where made available to us by the merchant's platform permissions, contact and profile details such as name, email address or marketing status.
  • Order and transaction data: order identifiers, line items, order totals, currency, discount information, note attributes, fulfillment or payment status and other order metadata relevant to attribution, reporting, reconciliation, fraud prevention and support.
  • Referral and attribution data: campaign identifiers, affiliate or partner identifiers, referral identifiers, discount codes, timestamps, limited browser or device information, and other metadata used to attribute conversions and calculate commissions.

We use this data only to install and authenticate the app, provide referral attribution, campaign management, analytics, commission calculation, merchant reporting, fraud and abuse prevention, customer support, billing, security, and compliance with legal obligations.

2.5 Excluded / sensitive data

The Platform is not designed for processing of "special categories" of personal data under GDPR (for example data concerning health, biometric identifiers, religious or political beliefs) or data relating to children. You must not submit such data to the Platform unless we have expressly agreed to this in writing.

We also do not intend to process information that is subject to sector-specific regulations such as medical or financial secrecy rules, unless agreed in writing with the relevant Partner together with appropriate safeguards.

3. PURPOSES AND LEGAL BASES FOR PROCESSING

We process personal data only where we have a legal basis to do so under Applicable Data Protection Laws. Depending on the context, we may rely on one or more of the following legal bases:

  • Contractual necessity: where processing is necessary to enter into or perform a contract with you or the organization you represent (for example to provide access to the Platform, manage your account and deliver support).
  • Legitimate interests: where processing is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your interests or fundamental rights and freedoms.
  • Consent: where you have given us your consent for specific processing activities (for example certain marketing communications or the use of non-essential cookies).
  • Legal obligations: where processing is required to comply with our legal obligations (for example accounting, tax or regulatory requirements).
  • Providing and operating the company crypto wallet (contractual necessity / legitimate interest / legal obligation): to generate and assign a wallet address to your company, to store encrypted private keys on our infrastructure, to retrieve and display balances and on-chain transaction history from blockchain networks or third-party providers, and to support the payout flows you choose to implement via such wallet.

In particular, we may process personal data for the following purposes:

  • Providing and operating the Platform (contractual necessity / legitimate interest): to create and manage accounts, authenticate users, provide features, host and maintain the Platform, and provide customer support.
  • Enabling campaigns and relationships between Partners and Affiliates (contractual necessity / legitimate interest): to allow Partners to create and manage programs and campaigns, and allow Affiliates to participate in such programs.
  • Billing and account management (contractual necessity / legal obligation): to process fees, issue invoices, manage subscriptions, handle collections and comply with accounting and tax requirements.
  • Improving and securing the Platform (legitimate interest): to monitor performance, troubleshoot issues, analyze usage patterns, develop and test new features, improve user experience, and maintain the security and integrity of the Platform.
  • Developing algorithms and models (legitimate interest): to develop, test and improve algorithms, recommendation systems and other technical models used in the Platform.
  • Marketing and communications (legitimate interest / consent): to send you product and service-related communications, newsletters and event invitations, in accordance with your preferences and Applicable Law. You can opt out of marketing at any time.
  • Compliance, risk management and legal claims (legal obligation / legitimate interest): to comply with legal obligations, enforce our Terms of Service, monitor compliance of Partners and Affiliates with Applicable Law and our policies, and establish, exercise or defend legal claims.

4. CONTROLLER AND CONTACT DETAILS

For purposes of Applicable Data Protection Laws, Afivio generally acts as an independent data controller in relation to personal data processed about Users in connection with the operation of the Platform.

The data controller is Yuliia Lukiashchenko, an individual entrepreneur (indywidualna działalność gospodarcza) registered in Poland, with registered office at ul. Sw. Wincentego 130 lok. 15, 03-291 Warszawa, Poland, NIP 5242998855, REGON 527832126.

Where Partners or Affiliates use the Platform to collect or otherwise process personal data relating to their own customers, prospects or audience, such Partners or Affiliates act as independent controllers (or, where applicable, joint controllers) for that processing. Afivio does not control and is not responsible for the lawfulness, accuracy or sufficiency of any such processing carried out by Partners or Affiliates.

Where Afivio acts as a processor on behalf of a Partner or Affiliate, Afivio's processing will be governed by a separate data processing agreement, and Afivio's responsibilities will be limited strictly to those set out in that agreement.

If you have any questions about this Privacy Policy or our processing of personal data, you can contact us at:

Email: contact@afivio.com
Subject line: Privacy request

5. COOKIES AND SIMILAR TECHNOLOGIES

We use cookies, pixels and similar technologies to operate and improve the Platform, to understand how it is used and, where permitted, to support marketing activities.

Where Afivio technologies are enabled on a merchant storefront, the relevant merchant remains responsible for providing any notices and obtaining any consents required under Applicable Data Protection Laws for that storefront. Afivio processes related attribution or storefront data only for the purposes described in this Privacy Policy and the applicable merchant configuration.

For more information about the types of cookies we use, the purposes for which we use them and your choices, please see our Cookie Policy.

6. SHARING OF PERSONAL DATA

We may share personal data with the following categories of recipients:

  • Service providers: third-party providers that help us operate the Platform and deliver our services (for example hosting providers, analytics providers, payment processors, communication tools and security services). These providers process personal data on our instructions and are subject to appropriate contractual safeguards.
  • Partners and Affiliates: where necessary to operate campaigns and programs on the Platform, we may share limited personal data between Partners and Affiliates in accordance with the relevant configuration and Applicable Law.
  • Professional advisors: lawyers, auditors and consultants who provide us with professional services.
  • Authorities: competent courts, law enforcement, regulators or other public authorities where we are legally required or permitted to do so.
  • Business transferees: in connection with any merger, acquisition, financing, reorganization, sale of assets or similar transaction involving Afivio, your personal data may be transferred to the relevant third parties as part of that transaction.
  • Blockchain networks and explorers: when you use the company crypto wallet, certain information (including your wallet address and transaction details) is processed on public blockchain networks and may be visible via blockchain explorers. We do not control such networks or explorers and cannot remove or modify on-chain data once it has been recorded.

We do not sell personal data in the sense of the term "sell" under certain privacy laws.

7. INTERNATIONAL TRANSFERS

Afivio may store and process personal data in countries other than the country in which the data was originally collected. These countries may have data protection laws that are different from those in your country.

Where we transfer personal data from the European Economic Area ("EEA"), the United Kingdom or Switzerland to a country that is not considered to provide an adequate level of protection, we will implement appropriate safeguards, such as standard contractual clauses approved by the European Commission or the UK authorities, or rely on other lawful transfer mechanisms.

When you interact with public blockchain networks (for example by sending or receiving USDC to or from your company wallet), personal data relating to those transactions may be processed in multiple jurisdictions outside the EEA or the UK, depending on how the relevant blockchain infrastructure and nodes are operated. Such processing is inherent to the use of public blockchain networks.

8. AGGREGATED AND ANONYMISED DATA

We may aggregate and/or anonymise personal data so that it can no longer be associated with an identified or identifiable individual. We may use such aggregated and anonymised data for any lawful purpose, including analytics, product development, benchmarking, research, statistics, marketing and improving the Platform, and we may share such data with third parties. To the maximum extent permitted by Applicable Data Protection Laws, we will have no obligation to you in relation to the use of aggregated or anonymised data.

9. DATA RETENTION

We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by Applicable Law.

As a general rule:

  • Active account data is retained while your account remains active.
  • If you close your account (or we terminate it), we will deactivate your account and delete or anonymize your personal data from our active systems within thirty (30) days, except as described below.

We may retain certain categories of information for longer periods where necessary for legitimate business or legal purposes, including:

  • Core account, billing, and transactional records – for up to ten (10) years where required by tax, accounting, audit, or anti-fraud obligations;
  • Logs, security records, and support communications – for up to five (5) years;
  • Marketing-related data – until you opt out or the data is no longer reasonably necessary;
  • Information necessary to establish, exercise, or defend legal claims – for no longer than permitted under applicable limitation periods.

What deletion means in practice:
After the applicable retention period, your personal data will no longer be accessible through the platform. It will be removed from our production systems. Residual copies may remain temporarily in secure encrypted backups for disaster recovery and security purposes, but such copies will not be actively processed and will be automatically overwritten or deleted within six months.

You may request earlier deletion at any time by contacting us at contact@afivio.com.

10. SECURITY

We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.

However, no security measures are perfect or impenetrable, and we cannot guarantee absolute security. Transmission of information via the internet and electronic storage of data always carries certain risks, and you provide information to us at your own risk.

11. YOUR RIGHTS

Depending on your location and subject to Applicable Data Protection Laws, you may have the right to:

  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of personal data in certain circumstances;
  • request restriction of processing in certain circumstances (for example if you contest the accuracy of the data);
  • object to processing on grounds relating to your particular situation;
  • request data portability in certain circumstances, where technically feasible; and
  • where we rely on consent, withdraw your consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).

You can exercise these rights by contacting us using the details above. We may request additional information from you to verify your identity before responding to your request.

We may refuse to act on or may charge a reasonable fee for requests that are manifestly unfounded, excessive or repetitive, or where we are entitled to do so under Applicable Data Protection Laws. We may also decline to comply with a request where doing so would adversely affect the rights and freedoms of others, interfere with ongoing legal or regulatory proceedings, conflict with our legal obligations or our legitimate interests in establishing, exercising or defending legal claims.

You also have the right to lodge a complaint with a competent supervisory authority, particularly in the EEA Member State or the UK where you live or work or where you consider that your rights have been infringed.

12. CHILDREN

The Platform is intended for business and professional use only and is not directed at children. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have collected personal data from a child under 16, we will take reasonable steps to delete such information.

13. CHANGES TO THIS PRIVACY POLICY

We may update or modify this Privacy Policy from time to time. Unless otherwise required by law, the updated version will take effect upon posting on the Platform. It is your responsibility to review this page regularly to stay informed about our processing of personal data.

Your continued use of the Platform after the effective date of an updated Privacy Policy will constitute your acceptance of the changes. If you do not agree to the updated Privacy Policy, you must stop using the Platform.

14. GOVERNING LAW AND DISPUTE RESOLUTION

This Privacy Policy is governed by the same governing law and dispute resolution provisions that apply to our Terms of Service. Any dispute, controversy or claim arising out of or relating to this Privacy Policy shall be resolved in accordance with the "Governing Law and Dispute Resolution" section of our Terms of Service. To the maximum extent permitted by Applicable Law, you agree to bring any such claims only on an individual basis and not as part of any class, collective or representative proceeding.

In particular, where Afivio processes Shopify or other commerce-platform customer, order or storefront data on behalf of a merchant to provide attribution, tracking, analytics, commission management or related reporting, the merchant is generally the controller (or business) for that data and Afivio acts as the processor or service provider for those activities, except to the extent Afivio uses the data for its own security, billing, contractual, legal or abuse-prevention purposes.

15. CONTACT

If you have any questions about this Privacy Policy or our processing of personal data, or if you wish to exercise your rights, you can contact us at:

Email: contact@afivio.com