AffiliateStar — Privacy Policy
Last updated: 1 September 2026
AffiliateStar ("the app") is operated by Appify Market ("we", "us"). This policy explains what the app stores, why, and how to have it deleted.
It is written to be accurate rather than reassuring. Where the app holds personal data, it says so plainly, because a privacy policy that undersells what an app stores is worse than none.
1. Who the data is about
The app handles data about three different groups, and they are treated differently:
| Group | Who they are |
|---|---|
| Merchants | Shopify store owners and staff who install the app |
| Affiliates | People who sign up to a merchant's affiliate program |
| Shoppers | Customers of the merchant's store |
2. What we store about merchants
- The store's
.myshopify.comdomain, display name, currency and country - An access token allowing the app to call the Shopify Admin API on the store's behalf
- The store's subscription plan
- Program configuration: commission rates, payout settings, portal branding and terms text
We do not store merchant names, email addresses, or passwords. The app has no login of its own for merchants — identity comes from Shopify itself each time the app is opened.
3. What we store about affiliates
Affiliates provide this directly when they sign up:
- Name and email address
- Their acceptance of the merchant's program terms, and when
- A payout email address, if they give one
- Their referral and discount codes
- Their commission history and payouts
Email addresses are also the login mechanism. The app sends a single-use sign-in link rather than using passwords, so no affiliate password is ever created, transmitted or stored.
Sign-in links are stored hashed, never in their original form. A copy of our database would not yield a usable login link.
4. What we store about shoppers
We do not store shopper names, email addresses, phone numbers or addresses. The app is designed not to request them, and the permissions it asks Shopify for do not include access to customer contact details.
When an order is attributed to an affiliate, the app records:
- The Shopify order ID and order number
- The order subtotal and the commission calculated from it
- Line item titles, quantities and prices
- The affiliate code the order was attributed by
- The shopper's Shopify customer ID only where it is needed to detect an affiliate buying through their own link
Consent. Where the law requires permission before storing non-essential cookies, the tracking script asks Shopify's Customer Privacy API before setting its attribution cookie, and clears that cookie if consent is later withdrawn.
We also record clicks on affiliate links:
- A one-way hash of the visitor's IP address and browser user-agent
- The page the link pointed to, and the referring page
- The time of the click
The IP address itself is never stored. It is hashed with a secret unique to each store, so the hashes cannot be compared across stores or reversed with a precomputed table. Hashes exist so that a burst of orders from one address can be flagged as suspicious; they are not used to identify anyone.
5. What we never do
- We do not sell data, and we do not share it with advertisers or data brokers.
- We do not use shopper data to build profiles, or use it for any purpose beyond attributing an order to an affiliate.
- We do not track shoppers across different merchants' stores. Each store's data is isolated and hashed with its own secret.
- We do not read shopper email addresses, names, phone numbers or addresses.
6. Third parties
| Service | What it receives | Why |
|---|---|---|
| Shopify | Order, discount and gift card requests | To read orders and create discounts and payouts on the merchant's store |
| Our hosting and database provider | All data described above, encrypted in transit | To run the app |
| Our email provider | An affiliate's email address and the message sent to them | To deliver sign-in links and program notifications |
We do not add analytics, advertising or session-recording services to the app.
7. How long we keep it
- While the app is installed: for as long as the merchant's program needs it.
- When the app is uninstalled: access tokens are deleted immediately. Program data is kept briefly so that a merchant who reinstalls does not lose their affiliates and commission history.
- 48 hours after uninstall: Shopify sends a deletion request and we delete everything for that store — affiliates, codes, clicks, commissions, payouts, sign-in tokens and sessions.
8. Deleting an individual's data
Shoppers. Send a data deletion request through the merchant's store, as you would for any Shopify app. Shopify forwards it to us automatically and we act on it without further action from you.
Where the person is also an affiliate of that store, we erase their name, email address and payout details, and clear the hashes recorded against their clicks. The commission amounts themselves are retained: they are the merchant's financial records, and are not the individual's to erase. What remains cannot be connected back to a person.
Affiliates. Contact the merchant whose program you joined, or us directly at the address below. We will erase your personal details on the same basis.
9. Security
- All traffic is encrypted in transit.
- Sign-in links and sessions are stored only as one-way hashes.
- Affiliate payout codes issued as store credit are sent by email and never stored by us — not even we can retrieve one after it has been sent.
- The app requests the narrowest set of Shopify permissions that lets it work, and deliberately does not request access to customer contact details.
See also our Terms of Service, section 10 of which is a Data Processing Agreement covering our obligations as a processor.
No system is perfectly secure. If you believe you have found a vulnerability, please contact us before disclosing it publicly.
10. Contact
Appify Market
16 Longview Ave
Valley Stream, NY 11581
United States
For questions about this policy or to request deletion of your data, contact us at the address above. We aim to respond within five working days.
11. Changes
We will update this page when the app's data handling changes, and update the date at the top. Material changes affecting merchants will also be sent to the email Shopify holds for the store.