Privacy Policy
Pre-launch draft for this local project. The operating legal entity, privacy contact, applicable jurisdiction, and final retention schedule must be confirmed before public launch.
Information collected
The application and contact forms collect the details you enter, such as your name, business contact information, websites, campaign requirements, and traffic-source information. Do not submit sensitive personal information, credentials, or customer-level data.
How this local version handles information
Submissions are sent to the server running on this computer and saved as individual files outside the public website folder. They are not emailed or sent to a CRM. The browser does not save application drafts. The server temporarily uses the connection’s IP address to limit repeated submissions; it does not include that address in submission records.
Purpose and access
The intended purpose is to assess partnership requests, answer messages, and discuss campaign suitability. Anyone with access to the project’s private data folder may be able to read submissions. Authorized administrators can review submissions, publisher profiles, support messages, campaign activity, and validation decisions in the admin workspace.
Cookies, analytics and tracking
The partner portal uses an essential HttpOnly session cookie that expires after 24 hours. Passwords are stored as salted scrypt hashes. Partner profiles, sessions, support conversations, saved offers, clicks, conversions and administrative actions are stored in a private SQLite database. Tracking links record an offer ID, publisher ID, click ID, optional campaign sub-ID, payout snapshot and timestamp. Signed advertiser callbacks associate conversions with click IDs. Sub-IDs must not contain personal data. Tracking redirects send these campaign identifiers to the configured advertiser. No third-party analytics pixels or fonts are used. Cookie consent and advertiser data-sharing arrangements must be reviewed for the intended public operation.
Additional account features
Depending on your role and use, the platform stores email verification records, authenticator secrets and hashed recovery codes, payment destination references, withdrawal requests, private creative files, campaign proposals, reward attempts, review cases and disputes. Verification and reset emails are queued for the configured provider. Publisher postbacks send conversion identifiers and validation status to an approved publisher endpoint. No email or payment provider is configured by default. The local development mailbox is for testing only and is disabled when a public origin is configured.
Retention and deletion
Local submissions remain until the operator deletes them. No automatic expiry is configured. Before public use, the operator must set and implement a retention period and a process for access, correction, and deletion requests. For a local test, ask the person running this project to remove your submission.
Future public operation
Before public launch, this notice needs the operator’s legal name and contact details, applicable processing grounds, actual service providers, international transfer information where relevant, and a description of rights and complaint channels that apply to the business and its visitors.
Questions
The contact form can record a privacy question locally. It is not a monitored public privacy inbox in this preview.