Decolinker

Privacy Policy

Effective date: July 9, 2026

This Privacy Policy explains how Decolinker ("Decolinker", "we", "us") collects, uses, shares, and protects personal data when you use our website, marketplace, dashboards, and tracking services (the "Platform"). It applies to merchants, affiliates, and visitors worldwide, and is written to meet the requirements of the EU and UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), and GCC data protection laws including Qatar's PDPPL, Saudi Arabia's PDPL, and the UAE's PDPL.

1. Data we collect

In plain terms: We collect what you give us (account and payout details), what the Platform records as you use it (clicks, sales, log data), and a small number of cookies needed to make tracking and login work.

1.1 Information you provide

1.2 Information collected automatically

1.3 Information from third parties

If you sign in with Google, we receive your name, email address, and profile image from Google , nothing more. We never receive your Google password.

2. Cookies and tracking technologies

We use a deliberately small set of cookies:

We do not use third-party advertising cookies or cross-site behavioral tracking.

3. How and why we use your data

Under the GDPR, every use of personal data needs a legal basis. Ours are:

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising as defined by the CCPA/CPRA.

4. YouTube API Services

In plain terms: We use YouTube's official API to find creators whose channels match a merchant's product category, so we can invite them to join our network. We only read information those channels already publish publicly. If you are a creator and want us to delete what we hold about your channel, email us and we will.

Decolinker's creator-discovery tool uses YouTube API Services. By using the Platform in connection with that functionality you are also agreeing to the YouTube Terms of Service, and to the Google Privacy Policy (https://policies.google.com/privacy), which governs Google's handling of any data collected through those services.

4.1 What we retrieve from YouTube

We retrieve publicly available channel metadata only: channel name and ID, channel description, country, subscriber and video counts, and the view counts of recent public uploads. Where a creator has chosen to publish a business contact address in their own channel description, we store that address so we can contact them once about joining the network.

We do not retrieve, host, embed, download, or reproduce YouTube video content. We do not access private or restricted channel data, we do not use OAuth or ask anyone to sign in with a Google account, and we do not attempt to obtain email addresses that YouTube protects behind verification on a channel's About page.

4.2 How we use it and how long we keep it

The data is used internally to decide which creators to invite to apply as affiliates. It is never sold, shared with third parties, or used for advertising. We contact a creator once, with a clear opt-out, and do not contact them again unless they reply.

Stored YouTube data is refreshed or deleted within 30 days in line with the YouTube API Services Developer Policies. Data for a creator who asks not to be contacted, or who does not respond, is removed from our records.

4.3 Deleting your data, and revoking access

If you are a creator and want the information we hold about your channel deleted, email [email protected] or use our contact form. We will delete it and add your channel to a permanent do-not-contact list. No account with us is required to make this request.

You can also review and revoke Decolinker's access to any Google or YouTube data at Google's security settings page: https://myaccount.google.com/permissions. Note that because our tool reads only public data and does not use OAuth, Decolinker will not normally appear in that list.

5. How data is shared

In plain terms: Merchants and affiliates see the transaction data they need to work together. Service providers host our infrastructure. Nobody buys your data from us.

6. International transfers

Our infrastructure providers may store data in the United States and the European Union. Where data moves across borders from the EU, UK, or GCC, we rely on recognized safeguards, including the EU Standard Contractual Clauses and equivalent UK and GCC mechanisms, and on our processors' own certified compliance programs.

7. How long we keep data

8. Your rights

In plain terms: Wherever you live, you can ask to see, correct, or delete your data. You can close your account yourself at any time from your dashboard, which removes your personal details immediately. For anything else, email us and we'll act on it, verification required, no fee, no retaliation.

7.1 EU and UK (GDPR)

You have the right to access, rectify, and erase your data; to restrict or object to processing; to data portability; and to withdraw consent. You may lodge a complaint with your local supervisory authority (or the UK ICO).

7.2 California and other US states (CCPA/CPRA)

You have the right to know what personal information we collect and how it is used, to delete it, to correct it, and to non-discrimination for exercising these rights. Because we do not sell or share personal information for behavioral advertising, there is nothing to opt out of, but you may still send us a "Do Not Sell/Share" request and we will honor and record it.

7.3 Gulf region (Qatar PDPPL, Saudi PDPL, UAE PDPL)

You have equivalent rights of access, correction, and erasure, and the right to withdraw consent to processing based on consent. We honor these on the same terms as GDPR requests.

To exercise any right, email [email protected] from the address on your account (or provide equivalent verification). We respond within 30 days (45 for complex CCPA requests, with notice).

9. Security

We protect data with industry-standard measures: passwords stored only as bcrypt hashes, encrypted connections (HTTPS/TLS) throughout, tokenized database access, role-based access to dashboards, and rate limiting against abuse. No system is perfectly secure, if a breach affects your data, we will notify you and the relevant authorities as the law requires (including within 72 hours where GDPR applies).

10. Children

The Platform is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it. Contact us if you believe a minor has created an account.

11. Changes to this Policy

We will post any changes here and update the effective date. For material changes we will notify you by email or in-Platform notice at least 14 days before they take effect.

12. Contact

Privacy questions and rights requests: [email protected], or use our contact form. See also our Terms of Service.