Effective July 17, 2026

Privacy Policy

AffiliateOS is operated by Pack6 LLC. This policy explains what data we collect when you use the service, why we collect it, and the choices you have.

1. What we collect

DataWhere it comes fromWhy we have it
Account data — email address and authentication detailsYou, at sign-upSigning you in and contacting you about your account
Network credentials — API keys and tokens for affiliate networks you connectYou, when connecting a networkCalling network APIs on your behalf; stored encrypted at rest
Synced network data — programs, transactions, commissions, paymentsThe affiliate networks you connectShowing your earnings and powering links, webhooks, and the API
Usage data — pages visited, features used, API and MCP activityYour use of the serviceOperating, securing, and improving the product
Billing data — plan, subscription status, invoice historyOur payment processorManaging your subscription; we never see full card numbers

We do not collect more than the service needs, and we do not buy data about you from third parties.

2. How we use it

We use your data to provide the service: authenticating you, syncing your network accounts, generating links, delivering webhooks, and serving the dashboard, API, and MCP server. We also use aggregate usage data to understand how the product is used and to keep it reliable and secure. We do not use your data for advertising, and we do not sell it — to anyone, for anything.

Your commission and program data is visible only to your account. We do not pool one user’s network data for another user’s benefit, and access between accounts is enforced at the database layer, not just in application code.

3. Who we share it with

We share data only with the service providers required to run AffiliateOS: cloud hosting and database infrastructure, our payment processor (for paid plans), our email provider (for account and service messages), and product analytics. Each processes data on our instructions and only as needed to provide their service to us.

Beyond that, we disclose data only if required by law, to protect the rights and safety of our users or the public, or as part of a merger or acquisition — in which case this policy continues to apply and we will notify you of any change of control.

4. How we protect it

All traffic to the service is encrypted in transit. Network credentials are encrypted at rest with keys held separately from the database. Row-level security isolates each account’s data at the database layer. Access to production systems is restricted and logged. No system is perfectly secure, but if a breach affects your data we will notify you without undue delay.

5. How long we keep it

We keep your data for as long as your account exists. When you disconnect a network, we stop using its credentials; when you delete your account, we delete your account data, credentials, and synced network data within 30 days, except for records we must retain for legal, billing, or security purposes. Backups age out on a rolling schedule.

6. Your rights

You can access and update your account information from the dashboard, disconnect networks at any time, and delete your account entirely. Depending on where you live — including under the GDPR and the CCPA — you may also have rights to request a copy of your data, correction, deletion, or restriction of processing, and to lodge a complaint with a supervisory authority. To exercise any of these, email us at the address below; we will respond within the timeframe your local law requires.

7. Cookies

We use cookies that are necessary to keep you signed in, and first-party analytics to understand product usage. We do not use third-party advertising cookies or cross-site tracking.

8. Children

The service is not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.

9. Changes and contact

If we make material changes to this policy we will notify you by email or in the dashboard before they take effect; the effective date above always reflects the current version. This policy should be read together with our Terms of Service.

Pack6 LLC · privacy questions and data requests: support@affiliateos.dev