Privacy Policy

Your privacy.
Your control.
Our commitment.

At Partneralytics, safeguarding your personal information isn't simply a legal requirement, it's a strong promise to the publishers, advertisers, and partners who depend on us to manage their data responsibly.

Effective: 1 January 2025
Version 3.2
GDPR ยท CCPA ยท LGPD
๐Ÿ”’ PROTECTED
Your data stays private
Never sold with no exceptions
Essential data collection
Only what the service needs
Your rights, handled fast
30-day response guarantee
SOC 2 Type II verified
Annual external audit
Global compliance
GDPR ยท CCPA ยท LGPD ยท PDPA
Table of Contents

Jump to the section you need.

SOC 2 Type II certified GDPR compliant CCPA compliant We never sell your data AES-256 encryption at rest TLS 1.3 in transit Annual penetration testing SOC 2 Type II certified GDPR compliant CCPA compliant We never sell your data AES-256 encryption at rest TLS 1.3 in transit Annual penetration testing
01
Data We Collect

Information We Collect

We gather information to operate the Partneralytics platform and deliver partnership management services. We are thoughtful about what we collect - if we don't need something to run our service, we don't collect it.

Plain-language overview

We collect account details when you sign up, technical data to track conversions, usage data to improve the platform, and payment information to process commissions. We do not collect sensitive personal categories (health, political views, biometrics) unless you explicitly provide them for a specific business purpose.

Information you submit directly

Data TypeExamplesPurposeBasis
Account identityName, email, company, roleAccount creation and authenticationContract
Publisher profileWebsite URLs, audience demographics, content categoriesPartner matching and program eligibilityContract
Advertiser detailsBusiness name, industry, product catalogue, brand assetsProgram setup and publisher discoveryContract
Payment informationBank details, PayPal, tax ID (W-8/W-9), billing addressCommission processing and tax complianceLegal obligation
Support communicationsMessages, attachments, ticketsCustomer support and dispute resolutionLegitimate interest
Verification documentsGovernment ID, business registration (where required)Identity verification for high-value payoutsLegal obligation

Data gathered automatically

When you use Partneralytics, we automatically collect technical data required to deliver the service - particularly the tracking and attribution infrastructure that is the core of what we do.

Data TypeDetailsWhy We Need It
Tracking eventsClicks, conversions, referral source, device type, browserAccurate attribution and commission calculation
Log dataIP address (truncated), timestamp, page visited, actions takenSecurity monitoring, fraud detection, and debugging
Platform usageDashboard features used, reports generated, partner actionsProduct improvement and account health monitoring
Device identifiersDevice fingerprint, screen resolution, installed fonts (hashed)Fraud detection โ€” we do not use this for advertising
IP address protection

We truncate the last octet of IPv4 addresses (and the last 80 bits of IPv6 addresses) before storage. Full IP addresses are held in memory for fraud detection processing only - they are never written to persistent storage in full.

02
Using Your Data

How We Use Your Data

Every use of your data maps to a defined purpose and a lawful basis under applicable data protection law. We do not use your data for purposes beyond what is listed below without seeking fresh consent or establishing a new lawful basis.

Providing the Platform

Operating tracking infrastructure, attribution systems, payout processing, fraud detection, and all core partnership management features. Lawful basis: Contract performance.

Analytics & Development

Understanding how features are used so we can fix problems and build better tools. Data is aggregated and anonymised before analysis. Lawful basis: Legitimate interests.

Fraud Protection

Detecting and blocking invalid clicks, fake conversions, and abuse patterns that harm both advertisers and publishers on the network. Lawful basis: Legitimate interests.

Legal Requirements

Meeting tax reporting obligations, responding to lawful requests, and maintaining records required by applicable financial regulation. Lawful basis: Legal obligation.

Platform Communications

Sending payout notifications, program updates, security alerts, and platform announcements. Lawful basis: Contract performance / legitimate interests.

Marketing (with consent)

Sending newsletters, product updates, and partnership insights โ€” only to users who have explicitly opted in. You can withdraw consent at any time. Lawful basis: Consent.

What we will never do

We will never sell your personal data, use it to build advertising profiles for third-party platforms, share it with data brokers, or process it for purposes unrelated to operating the Partneralytics platform and the partnership programs you are part of.

03
Data Recipients

Data Sharing & Disclosure

We share data only where necessary to operate the platform, fulfil legal obligations, or where you have given explicit consent. We never sell personal data. The categories of recipients below cover all current sharing arrangements.

Recipient CategoryWhat They ReceivePurposeYour Control
Advertisers (your programs)Publisher profile, performance metrics, conversion dataProgram management and commission verificationControlled by program participation
Publishers (your advertisers)Program terms, creative assets, aggregated performancePartnership operationControlled by program participation
Payment processorsBank details, payout amounts, tax documentationCommission disbursementRequired for payout receipt
Cloud infrastructureAll platform data (AWS, encrypted at rest)Hosting and data storageNot optional โ€” platform dependency
Fraud intelligence providersHashed device identifiers, IP data (truncated)Network-level fraud detectionCan be opted out (affects fraud coverage)
Legal authoritiesAccount data, transaction records (when lawfully required)Compliance with court orders or regulatory requestsWe notify you unless legally prohibited

Cross-border data transfers

Partneralytics operates globally. If you are located in the European Economic Area, UK, or Switzerland, your data may be transferred to and processed in countries outside your jurisdiction. When this occurs, we ensure adequate protection through:

Standard Contractual Clauses

EU-approved SCCs covering all transfers to countries without an adequacy decision.

Adequacy Decisions

Transfers to countries with European Commission adequacy status use no additional safeguards โ€” the level of protection is deemed equivalent.

04
Data Retention

Data Lifecycle

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. After the applicable retention period, data is securely deleted or irreversibly anonymised.

Active account data
Duration of account
Transaction records
7 years
Tracking & attribution data
3 years
Support communications
2 years
Log & security data
13 months
Marketing consent records
Until withdrawn + 1 year
Closing your account

When you close your Partneralytics account, we begin deletion of personal data within 30 days. Financial transaction records and tax documentation are retained for the statutory period required in your jurisdiction (typically 7 years). Anonymised, aggregated performance data that cannot identify you may be retained indefinitely for platform benchmarking.

05
Your Choices

Your Data Rights

Based on where you live, you have several rights concerning your personal data. We respect these rights regardless of jurisdiction - we apply the most comprehensive set to all users, not the minimum required in each country.

Access Your Data

Ask for a copy of all personal data we keep about you, including how it's used, who it's shared with, and how long it will be kept. Fulfilled within 30 days.

Right to Data Correction

Ask us to correct inaccurate personal data. You can update most account data directly via your dashboard settings without contacting us.

Right to Deletion

Request deletion of personal data where we no longer have a lawful basis for processing. Financial and legal records may be exempt from erasure during their statutory retention period.

Right to Limit Processing

Ask us to pause processing of your data while a dispute is resolved, rather than deleting it immediately.

Right to Data Portability

Receive your personal data in a structured, machine-readable format (JSON or CSV) so you can transfer it to another service.

Right to Object

Object to processing based on legitimate interests, including direct marketing. We will cease processing unless we can demonstrate compelling grounds that override your interests.

How to use your privacy rights

Submit a request via your account dashboard under Settings โ†’ Privacy, or email privacy@partneralytics.com. We respond to all requests within 30 days. For complex or high-volume requests, we may extend this by up to two additional months - we will notify you within the initial 30-day window if this applies.

California residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know about the categories of personal information sold or disclosed (we do not sell personal information), the right to opt out of sale (not applicable - we do not sell), and the right to non-discrimination for exercising your CCPA rights.

06
Tracking & Cookies

Cookies & Tracking

Partneralytics uses cookies and similar tracking technologies to operate the platform, power conversion attribution, detect fraud, and (with your consent) improve the product. Our use of tracking technology is central to what the platform does - without cookies and pixels, we cannot attribute partner-driven conversions.

07
Data Protection

Security Controls

We invest significantly in keeping your data fully secure. Our security programme is independently audited and verified - not self-reported.

Encryption

AES-256 encryption at rest for all stored data. TLS 1.3 for all data in transit. Encryption keys managed by AWS KMS with automated rotation.

SOC 2 Type II

Annual audit by an independent third party covering security, availability, and confidentiality. Reports available to enterprise customers under NDA.

Access Security

Role-based access with least-privilege principles. All internal access to production data is logged, reviewed monthly, and requires multi-factor authentication.

Security Testing

Annual third-party penetration tests by certified security firms. Critical findings must be remediated within 72 hours; high findings within 14 days.

Incident Notification

In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware โ€” as required by GDPR Article 33.

Vulnerability Disclosure

We operate a responsible disclosure programme. Security researchers who find vulnerabilities can report them at security@partneralytics.com. We do not pursue legal action against good-faith researchers.

08
Contact Us

Privacy Contacts & Data Officer

If you have any questions about this policy, want to exercise a privacy right, or need to report a data protection concern, the right contacts are below. We aim to acknowledge all privacy enquiries within one business day.

Data Protection Officer

Our DPO is available for all GDPR-related enquiries, right exercises, and supervisory authority communications.

dpo@Partneralytics.com

Privacy Team

General privacy questions, data requests, and complaints about how we handle your personal information.

privacy@partneralytics.com

Registered Address

Partneralytics Inc.
150 Partnership Drive, Suite 800
San Francisco, CA 94107
United States

Supervisory authority

If you are an EEA resident and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection supervisory authority. For users in the Republic of Ireland (our EU establishment), the lead supervisory authority is the Data Protection Commission (dataprotection.ie).