This Privacy Policy explains how Decolinker ("Decolinker", "we", "us") collects, uses, shares, and protects personal data when you use our website, marketplace, dashboards, and tracking services (the "Platform"). It applies to merchants, affiliates, and visitors worldwide, and is written to meet the requirements of the EU and UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), and GCC data protection laws including Qatar's PDPPL, Saudi Arabia's PDPL, and the UAE's PDPL.
1. Data we collect
In plain terms: We collect what you give us (account and payout details), what the Platform records as you use it (clicks, sales, log data), and a small number of cookies needed to make tracking and login work.
1.1 Information you provide
- Account data — name, email address, password (stored only as a cryptographic hash, never in readable form), account role (merchant or affiliate), and store/business name for merchants;
- Listing and promotional content — products, descriptions, and images merchants upload;
- Payout and billing details — the information needed to pay commissions or invoice fees;
- Communications — messages you send us, including support requests.
1.2 Information collected automatically
- Tracking-link activity — when someone clicks an affiliate link we record the click, a referrer URL, and technical metadata so the sale can be attributed correctly;
- Transaction records — purchases, commission amounts, and payout status;
- Log and device data — IP address, browser type, pages visited, and timestamps, used for security, rate limiting, and debugging.
1.3 Information from third parties
If you sign in with Google, we receive your name, email address, and profile image from Google — nothing more. We never receive your Google password.
2. Cookies and tracking technologies
We use a deliberately small set of cookies:
- Session cookies (essential) — keep you signed in securely;
- Attribution cookie (essential to the service) — set when you click an affiliate tracking link, stores which link referred you, and expires after 30 days. This is how affiliates get credited for sales;
- OAuth role cookie (essential, short-lived) — remembers whether you chose to sign up as a merchant or affiliate during a Google login, and expires within 10 minutes.
We do not use third-party advertising cookies or cross-site behavioral tracking.
3. How and why we use your data
Under the GDPR, every use of personal data needs a legal basis. Ours are:
- To perform our contract with you — operating accounts, tracking clicks and sales, calculating and paying commissions, providing dashboards;
- Legitimate interests — securing the Platform, preventing fraud and abuse, improving features, and defending legal claims (balanced against your rights);
- Legal obligation — tax, accounting, and lawful requests from authorities;
- Consent — anything optional, such as marketing emails if we introduce them; you can withdraw consent at any time.
We do not sellyour personal data, and we do not "share" it for cross-context behavioral advertising as defined by the CCPA/CPRA.
4. How data is shared
In plain terms: Merchants and affiliates see the transaction data they need to work together. Service providers host our infrastructure. Nobody buys your data from us.
- Between Platform users— merchants see which affiliates drove their sales (name and performance figures); affiliates see the products, commissions, and sale amounts they earned. Neither side sees the other's payout details or login data;
- Service providers (processors) — companies that host our infrastructure under contract: website hosting (Vercel), database hosting (Turso), and our sign-in provider (Google) if you use it. They process data only on our instructions;
- Legal and safety — where required by law, court order, or to protect the Platform and its users from fraud or harm;
- Business transfers — if Decolinker is acquired or merged, data may transfer with the business under the same protections, with notice to you.
5. International transfers
Our infrastructure providers may store data in the United States and the European Union. Where data moves across borders from the EU, UK, or GCC, we rely on recognized safeguards — including the EU Standard Contractual Clauses and equivalent UK and GCC mechanisms — and on our processors' own certified compliance programs.
6. How long we keep data
- Account data — for the life of your account, then deleted or anonymized within 90 days of closure, except where law requires longer;
- Transaction and commission records — retained as long as required by tax and accounting law (typically 5–10 years depending on jurisdiction);
- Click and log data — retained in identifiable form only as long as needed for attribution, fraud prevention, and security, then aggregated or deleted.
7. Your rights
In plain terms: Wherever you live, you can ask to see, correct, or delete your data. Email us and we'll act on it — verification required, no fee, no retaliation.
7.1 EU and UK (GDPR)
You have the right to access, rectify, and erase your data; to restrict or object to processing; to data portability; and to withdraw consent. You may lodge a complaint with your local supervisory authority (or the UK ICO).
7.2 California and other US states (CCPA/CPRA)
You have the right to know what personal information we collect and how it is used, to delete it, to correct it, and to non-discrimination for exercising these rights. Because we do not sell or share personal information for behavioral advertising, there is nothing to opt out of — but you may still send us a "Do Not Sell/Share" request and we will honor and record it.
7.3 Gulf region (Qatar PDPPL, Saudi PDPL, UAE PDPL)
You have equivalent rights of access, correction, and erasure, and the right to withdraw consent to processing based on consent. We honor these on the same terms as GDPR requests.
To exercise any right, email cogrowteam9@gmail.com from the address on your account (or provide equivalent verification). We respond within 30 days (45 for complex CCPA requests, with notice).
8. Security
We protect data with industry-standard measures: passwords stored only as bcrypt hashes, encrypted connections (HTTPS/TLS) throughout, tokenized database access, role-based access to dashboards, and rate limiting against abuse. No system is perfectly secure — if a breach affects your data, we will notify you and the relevant authorities as the law requires (including within 72 hours where GDPR applies).
9. Children
The Platform is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it. Contact us if you believe a minor has created an account.
10. Changes to this Policy
We will post any changes here and update the effective date. For material changes we will notify you by email or in-Platform notice at least 14 days before they take effect.
11. Contact
Privacy questions and rights requests: cogrowteam9@gmail.com, or use our contact form. See also our Terms of Service.