The Affiliate Data You Should Own (and What It's Worth When You Leave)
Partner emails, referral history, the audit trail — when your program runs on a hosted network, whose data is it? The exportability checklist that decides how expensive your next migration is.
Ask a store owner who owns their affiliate program's data and you'll get a confident "we do." Ask them to produce it — every partner's contact details, every referral with its status history, every payout with what it covered, every rejected commission with the reason — and the confidence gets quieter. On many hosted networks the honest answer is: you own a CSV of whatever the export button includes, whenever the export button works, minus everything in the categories the platform considers theirs.
This matters on exactly two days: the day you migrate, and the day something goes wrong. Both days are expensive in proportion to what you can't export.
The five datasets that constitute your program
The partner roster — names, emails, payment details, tax forms, application answers, and join dates. This is a relationships dataset; losing it means re-onboarding humans, not reimporting rows. On some networks, affiliates belong to the network's marketplace, not to you: you can message them through the platform, but walk away and the relationships stay behind.
Referral history with status lineage. Not just totals — individual referrals with amounts, timestamps, sources, and how each moved through pending, approved, rejected, or refunded, and why. This is your fraud baseline, your seasonality record, and your defense in any partner dispute. Aggregates can't reconstruct it.
The payout ledger — what was paid, when, to whom, covering which referrals. Your accountant needs it for years; tax authorities in most places assume you can produce it on request. "The old platform had it" is not an answer an auditor accepts.
Your configuration — commission rules, cookie windows, per-partner overrides, coupon assignments, terms versions. Undocumented config is why migrations produce month-one payment errors: nobody remembered that one partner negotiated 15% in 2023.
The audit trail — who changed what, when. The least glamorous dataset and the one you'll want most in a dispute, because it's the difference between "we believe" and "here's the log."
Whose customer is the affiliate?
That's the structural question underneath the data one. In a network model, affiliates are the network's users who chose your program; the network's terms usually restrict exporting their contacts or contacting them off-platform, and your program's reviews and reputation live in an account you rent. In a direct model — program running on your own site — affiliates applied to you, agreed to your terms, and appear in your database, and every one of the five datasets above is a table you can query.
Neither model is dishonest; networks trade data custody for distribution, which is sometimes a fine trade. The mistake is not knowing which trade you made until the day you want to leave.
The exportability audit (run it before you need it)
Whatever you run on, spend an hour confirming — not assuming — four things. One: you can export partners with contact details and payment info, not an anonymized list. Two: referral exports include status and reason fields, not just approved totals. Three: the payout ledger exports with referral linkage. Four: exports are self-serve, not a support-ticket lottery. Do a real test export and open the files. The gap between "the platform has export features" and "I possess a usable copy" is where migrations go to die.
Then make it a habit: a quarterly export into your own storage. It's an incremental backup of a business asset, treated with the same seriousness as your customer database — because that's what it is.
The compliance flip side
Owning data means owing duties. Partner rosters are personal data under GDPR and its cousins: minimize what you collect, secure what you keep, honor deletion requests (with the standard carve-outs for tax and fraud records you're required to retain), and mention the program's data handling in your privacy policy. Self-hosting concentrates the responsibility — there's no platform to point at. The mature posture is the same in either model: know exactly what you hold, hold it deliberately, and be able to produce or delete it on demand.
Data you can't export was never really yours. Check before the day it matters.