YOUR INFORMATION

Privacy notice

Last updated .

Who we are

Our merchant service terms describe the agreement and data-processing instructions for using Referlane.

SPIKE HEALTH LLC operates Referlane, an app that helps Shopify merchants manage affiliate programs. Contact us at support@referlane.app or write to SPIKE HEALTH LLC, 8 The Green, Suite B, Dover, DE 19901, United States.

This notice covers Referlane and its affiliate portals. The merchant decides its program terms, membership, commission rules and payments. We process program information on that merchant’s behalf and use service and support information to operate and protect Referlane. The merchant’s own privacy notice also applies to its store and its use of downloaded records.

Information we use and why

Store and program information. Shopify store identifiers, domains, name, currency, installation and access records, subscription status, program settings, support contact and affiliate terms help us connect the store, authenticate access and operate its program.

Affiliate information. Applications and invitations can contain email, name, company, website and promotional information. Program records include approval status, accepted terms, referral codes, earnings and payouts. Where supplied, payment instructions include the account holder, routing and account numbers and address; tax details include legal or business name, tax identifier, address and certification. These support program administration and payment preparation.

Order and refund information. Shopify supplies order references, products and line items, quantities, prices, discounts, taxes, shipping totals, refund and payment status, and dates. Normal order and refund processing limits retained payloads to the financial fields used for commissions and removes customer contact and address details from those payloads. This processing rule does not mean every older stored record has already been cleaned.

If a merchant enables self-referral checks and Shopify supplies customer email, we compare a store-specific keyed digest with the affiliate identity. We remove the original customer email before persistence and discard the digest after the attribution decision. Missing identity requires merchant review. Eligible link-based referrals use an opaque proof and a keyed cart identifier matched to a verified paid Shopify order.

Optional storefront activity. A random visitor identifier, referral code, time, selected page and campaign information, and a hashed IP address measure referral activity. Browser information helps identify likely automated traffic. A visit alone does not create a commission.

Access, support and privacy records. We process sign-in and security information, account actions, notification content and delivery records, support messages and privacy requests. Servers receive connection information, including IP and browser details, to serve requests and limit abuse. Shopify privacy requests can include a customer ID, email and requested order references to locate the correct records.

These records support affiliate, account, support, security and privacy functions. Commissions can be calculated or approved using the merchant’s configured rules. The merchant can review records and makes affiliate payments outside Referlane; approving or exporting a payout does not move money. Shopify handles merchant subscription billing, and Referlane checks the plan’s status. Contact the merchant or our support address to question a calculation or request human review.

Cookies and referral tracking

Affiliate portals use an essential signed, HTTP-only session cookie (__aff_session) lasting up to 14 days. It keeps a user signed in to the appropriate store’s portal. Signing out clears that portal session, and account status checks can end access sooner.

The storefront visitor cookie is normally _aff_visitor; an existing store configuration may use a _referlane_ name. With link attribution, a companion cookie ending in _proof retains referral proof for the selected attribution window, from 1 to 90 days; normally 30 days. The visitor cookie follows that same expiry when proof is issued. Referlane’s embed creates it and sends referral activity when Shopify’s privacy settings report that marketing tracking is allowed. It does not send that activity when permission is denied or unavailable. When Shopify reports withdrawn permission, the embed clears both cookies, removes cart proof and revokes further use of the saved referral session.

Use the store’s privacy controls to change tracking choices. Withdrawal stops future optional tracking; it does not erase an existing financial record. The referral redirect applies the requested discount without creating a Referlane visit record. Shopify and the store operate their own storefront and checkout cookies.

Referlane’s tracker excludes account, checkout and order-page URLs, removes URL fragments and keeps selected referral and campaign query parameters. Hashed identifiers are not treated as anonymous information.

Access and service providers

Merchants can access their program records, including affiliate payment instructions in manual payout exports. Affiliates can access their own accounts and earnings through the relevant portal. Referlane operators access information to administer, support and secure the service and handle requests.

Shopify provides store APIs, authentication, app billing and privacy-request delivery. Railway runs the application and background processing services. Supabase holds program records and the processing queue.

Resend processes recipient addresses, message content and delivery information for essential app notifications. Contact support at support@referlane.app. Fastmail handles correspondence sent to that support address.

Application processes run in Virginia, United States, and the program database is in Ohio, United States. These application regions do not establish the location of every provider’s email, support, log or backup system. Information may be processed outside the country where you live.

Protection of information

Protected requests are authenticated and access is scoped to the correct store and app registration. Database connections use TLS, and the managed database encrypts stored data. The app applies field-level encryption when storing new Shopify access tokens, tax information and bank or payment instructions. Affiliate passwords use Argon2id hashing.

Shopify privacy-request processing is limited to the identifiers needed for the request. Those identifiers can remain in the processing queue until the worker creates the encrypted access-request record and clears the original payload. Recorded fulfillment or applicable erasure removes the encrypted request identifiers. Application logging redacts selected personal and credential fields.

Retention and deletion

Scheduled cleanup uses the following processing rules. A threshold is when a record becomes eligible for cleanup, not an exact deletion instant or confirmation that all historical records have been cleaned. Privacy requests can trigger earlier erasure.

Storefront activity details: the threshold is the longest of 30 days, the program’s attribution window and its cookie-lifetime setting, plus 30 days; normally 60 days. Older clicks lose visitor links, network and browser hashes, and page and referrer URLs. Inactive visitor records past the threshold are deleted. Campaign labels are also cleared; basic click counts and dates remain.

Referral and verification proofs: expired referral sessions are removed after a 30-day delivery grace period. Customer/cart evidence is cleared after the attribution decision; unresolved old evidence follows tracking retention. Email-verification links expire after one hour. Expired verification secrets are cleared by maintenance, and sent verification messages lose their stored link token.

Notifications: recipient, subject, body, metadata and error details are eligible for redaction after 365 days. Delivery and status records remain.

Audit records: IP and browser fields are eligible for cleanup after 180 days and detail payloads after 730 days. Access-attempt records expire after 90 days. Agreement version and acceptance evidence remain while needed for the merchant agreement. Other basic action records remain. An affiliate account’s latest sign-in IP is cleared when its recorded last login is older than 180 days, or when no login time is recorded. Expired sign-in and password-reset token records are cleared during scheduled cleanup; a token with no expiry is also cleared.

Closed affiliate profiles: a closed profile unchanged for 30 days is eligible for identifying-data cleanup when it has no pending, approved or adjusted commission or open payout. This also clears its credentials and related identifying notification and audit details.

Privacy access requests: required encrypted identifiers remain while the request is pending and are cleared on recorded fulfillment or erasure. Request references, dates and status records remain.

Financial history: commission, ledger and payout history is retained to preserve the record of amounts owed, adjustments and settlement. The current app has no automatic age-based deletion for this history or the remaining basic records described above. A verified whole-store erasure can remove that history after outstanding obligations and any legal retention requirement have been reviewed.

Active account information remains available for program administration until it is changed or erased. Cancelling a subscription does not delete program records. Uninstall revokes the relevant app access; Shopify’s subsequent shop-deletion request starts separate identifying-data cleanup. Customer deletion requests have a tracked 30-day deadline. We first clear unnecessary details and revoke access. Where final settlement is needed, the account can only settle existing obligations; we temporarily retain the payee details needed for that purpose. We then remove the reviewed customer-linked records. A separate review covers remaining copies. Minimal keyed identifiers prevent erased orders from being restored; these safeguards are not anonymous data. An outstanding balance does not by itself establish a legal exception to deletion.

We keep encrypted recovery copies on operator-controlled local storage. New managed copies have a seven-day expiry and are verified through an isolated restore. Backup rotation and deletion of older copies require the operator’s separate backup process. Provider logs and email records, support mail and downloaded exports also require separate handling. A merchant is responsible for the copies it downloads and any payment service it chooses.

Questions and privacy requests

You can request access, correction, deletion or a copy of your information, ask to restrict or object to processing, and ask for human review of a program decision. These request channels are available wherever you live. Contact the merchant for its program and order records, or email support@referlane.app for Referlane’s handling. Include the store domain and enough information to locate the request. Do not send passwords, Shopify tokens, tax identifiers or bank details in ordinary support email.

We may need to verify the requester and work with the merchant. Shopify data requests enter a merchant queue with a 30-day deadline. The merchant exports the relevant records and separately records their secure delivery; downloading an export is not completion. A request may require retaining particular records where an applicable legal obligation prevents erasure. Raise unresolved concerns through our support contact; any statutory right to contact a privacy regulator is unaffected.

Help and support