afflyr
  • Features
  • Pricing
  • Docs
  • Help
  • vs AffiliateWP
  • Changelog
  • ★ Refer & Earn
Account Get Afflyr →

Privacy Policy

Last updated: May 15, 2026

Afflyr ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information when you visit our website at afflyr.com ("Site") or use the Afflyr WordPress plugin ("Plugin"). It also describes our compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws.

1. Information We Collect

1.1 Through the Site (afflyr.com)

When you visit our Site or make a purchase, we may collect:

  • Purchase information: Name, email address, billing address, and payment details. Payment is processed by Freemius — we do not store credit card numbers.
  • Account information: Email address and name associated with your Freemius customer account.
  • Usage data: Pages visited, time on site, referral source, browser type, device type, and IP address (collected via standard web server logs and analytics).
  • Communication data: Any information you provide when contacting support (email address, message content, attachments).
  • Refer & Earn data: If you join our affiliate program (Refer & Earn), we collect your tracking link slug, click and conversion counts, and the payout address (PayPal email or subscription credit preference). This is handled by Freemius.

1.2 Through the Plugin

The Afflyr plugin operates entirely within your own WordPress installation. We do not have access to, collect, or store any data from your website or your affiliates. Specifically:

  • Affiliate data (names, emails, earnings) is stored in your WordPress database only.
  • Referral and commission data is stored in your WordPress database only.
  • Visitor tracking data (clicks, IP addresses, cookies) is stored in your WordPress database only.
  • Payout records are stored in your WordPress database only.

The Plugin includes the Freemius SDK, which may collect limited technical data for license validation and update delivery:

  • WordPress version, PHP version, and server environment
  • Plugin version and activation status
  • Site URL (for license validation)
  • Admin email (if opted in)

This data is sent to Freemius, not to Afflyr. See the Freemius Privacy Policy for details. You can opt out of non-essential data collection during plugin activation.

2. How We Use Your Information

DataPurposeLegal Basis (GDPR)
Email, nameDeliver your license key, provide support, send important product updatesContract performance
Payment detailsProcess your purchase (via Freemius)Contract performance
Usage dataImprove the Site, understand visitor behavior, diagnose technical issuesLegitimate interest
Support messagesRespond to your inquiries and resolve issuesContract performance
Plugin technical dataLicense validation, deliver updates, compatibility tracking (via Freemius SDK)Legitimate interest / Consent
Marketing emails (product announcements, tips)Send occasional product news to existing customers; unsubscribe anytime via the link in every emailLegitimate interest / Consent
Refer & Earn dataAttribute referrals, calculate credits/payouts, prevent fraudContract performance

3. Information Sharing & Sub-Processors

We do not sell, rent, or trade your personal information. We share data only with the following sub-processors, each of which is contractually bound to protect your data:

Sub-ProcessorPurposeLocation
Freemius, Inc.Licensing, billing, customer accounts, plugin distribution, affiliate program managementUnited States
Stripe, Inc.Payment processing (via Freemius)United States
PayPal, Inc.Payment processing and payouts (via Freemius)United States
Bluehost / EIGWeb hosting for afflyr.comUnited States
Cloudflare, Inc.Content delivery network, DDoS protection, edge securityUnited States (global edge)

We may also disclose information to law enforcement, regulators, or in response to valid legal process (subpoena, court order, etc.) where we believe in good faith that disclosure is required by law.

4. Cookies

4.1 On the Site (afflyr.com) — we use the following cookies:

CookiePurposeDuration
fp_refRecords the slug of the affiliate who referred you so we can credit them if you subscribe (Refer & Earn program)60 days
afflyr_purchasedGranted after a successful purchase to unlock the post-purchase download & setup page (/welcome/)24 hours
WordPress session cookiesLogin session, comment forms, security tokensSession — 14 days
Analytics cookies (if enabled)Aggregate visitor counts and page popularityUp to 26 months

No third-party advertising or cross-site tracking cookies are used. We do not participate in advertising networks.

4.2 In the Plugin — the Plugin sets a first-party cookie (afflyr_ref) on your customers' browsers to track affiliate referrals on your store:

  • Contains only the referring affiliate's ID (a number).
  • Expires after the duration configured by the store owner (default: 30 days).
  • Is set with the Secure and SameSite flags on HTTPS sites.
  • Is a first-party cookie set by your domain, not by Afflyr.

Note for Plugin Customers: You are responsible for disclosing the use of this cookie in your own site's cookie/privacy policy if required by applicable law (e.g., GDPR, ePrivacy Directive, UK PECR).

5. Data Retention

  • Purchase records: Retained for the duration of your subscription plus 7 years for accounting, tax, and legal purposes.
  • Support correspondence: Retained for 2 years after your last interaction.
  • Usage analytics: Aggregated and anonymized after 26 months.
  • Refer & Earn records: Retained for the duration of your participation plus 3 years.
  • Plugin data on your site: Retained in your database until you delete it or uninstall the Plugin. Uninstalling the Plugin deletes all associated data from your database.

6. Data Security

We implement reasonable technical and organizational measures to protect your information, including:

  • HTTPS encryption on all Site pages and API endpoints (TLS 1.2 or higher).
  • Secure payment processing through PCI-DSS-compliant providers (Freemius / Stripe / PayPal).
  • Access controls limiting personal data access to authorized personnel only, with role-based permissions.
  • Regular security reviews of the Plugin codebase and infrastructure.
  • Encryption at rest for sensitive records held by our sub-processors.

No method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify affected users and supervisory authorities of a personal-data breach within 72 hours of discovery where required by law.

7. Your Rights (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure ("right to be forgotten"): Request deletion of your personal data (subject to legal retention requirements).
  • Portability: Request your data in a structured, machine-readable format.
  • Restriction: Request that we limit our processing of your data.
  • Objection: Object to processing based on legitimate interest, including direct marketing.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.
  • Lodge a complaint: File a complaint with your local data-protection authority. EEA residents can also contact the Irish DPC; UK residents can contact the ICO.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or 45 days where permitted with notice).

8. Your Rights (California — CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know: Request that we disclose the categories and specific pieces of personal information we collect, use, disclose, and sell.
  • Delete: Request deletion of personal information we collected from you, subject to legal exceptions.
  • Correct: Request correction of inaccurate personal information.
  • Opt out of sale / sharing: We do not sell or share your personal information for cross-context behavioral advertising. There is nothing to opt out of, but you may confirm this at any time by emailing us.
  • Limit use of sensitive personal information: We do not collect or use sensitive personal information beyond what is necessary to provide our Service.
  • Non-discrimination: We will not deny service, charge different prices, or provide a different level of service because you exercised your privacy rights.

To exercise these rights, email [email protected] with the subject line "California Privacy Request." We will verify your identity before responding. Authorized agents may submit requests on your behalf with written authorization.

California "Shine the Light" Law: California residents may request information about disclosures of personal information to third parties for direct-marketing purposes. We do not disclose personal information to third parties for their direct-marketing purposes.

9. Data Controller / Processor Relationship

For Site visitors and Refer & Earn affiliates: Afflyr is the data controller of personal information you provide to us directly.

For Plugin customers: When you use the Plugin on your WordPress site, you are the data controller for the personal information you collect about your own affiliates, customers, and visitors. Afflyr is not a processor of that data — we never receive, see, or store it. You are solely responsible for compliance with applicable law regarding personal data on your site, including providing a privacy policy, securing consent for cookies where required, honoring data-subject rights, and disclosing data sharing with your affiliates.

10. International Data Transfers

Your data may be processed in the United States or other countries where our service providers operate. Where data is transferred from the EEA, UK, or Switzerland to the United States, we and our sub-processors rely on Standard Contractual Clauses (SCCs), the EU-U.S. Data Privacy Framework where applicable, or other lawful transfer mechanisms. By using the Service, you understand that your information may be transferred to and processed in jurisdictions with different data-protection laws than your country of residence.

11. Marketing Communications

If you are an Afflyr customer, we may send you occasional product news, feature announcements, and educational content based on legitimate interest. Every marketing email contains a one-click unsubscribe link. You can also unsubscribe at any time by emailing [email protected]. Transactional emails (license keys, billing, support replies, security notices) are not subject to opt-out as long as you have an active account or subscription with us.

12. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you. License validation and payment fraud screening involve automated systems but always include human review when a decision adversely affects your account.

13. Do Not Track

Some browsers send a "Do Not Track" (DNT) signal. There is no industry consensus on how DNT signals should be honored, and we do not currently respond to them. We do not engage in cross-site tracking regardless of DNT signal status.

14. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will delete it promptly. Parents or guardians may contact us at [email protected] to request deletion of a child's data.

15. Third-Party Links

The Site may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policies of any third-party sites you visit.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to active customers or a prominent notice on the Site, with at least 30 days' advance notice where required. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

17. Contact

For privacy-related questions, data-subject requests, or to exercise any of the rights described above, contact us at:

  • Email: [email protected]
  • Website: afflyr.com/support
  • Subject lines we honor: "GDPR Request," "California Privacy Request," "Data Deletion Request," "Marketing Unsubscribe."
afflyr

The affiliate tracking plugin WooCommerce stores actually want to use.

Product

  • Features
  • Pricing
  • Changelog
  • Documentation
  • ★ Refer & Earn

Support

  • Getting Started
  • Submit a Ticket
  • FAQ

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
© 2026 Afflyr. All rights reserved. Built for WooCommerce stores that mean business.