AffiliateFactoryWP

Privacy Policy

Last updated: August 27, 2026

This policy covers this website and the license services operated by Affiliate Factory WP, the data controller. The short version: we collect the minimum needed to sell and service licenses, we run no advertising trackers, and the plugin sends us nothing about your website’s visitors, affiliates, or orders.

What we collect, and why

  • Order & account data — your email address, name, billing details you enter (company, address, tax ID), plan, order history, and license keys. Purpose: delivering your purchase, invoicing and tax compliance, refunds, and support. Legal basis: contract performance and legal obligation.
  • License activation data — when a WordPress site activates, deactivates, or checks a license, our server receives the license key, the site URL, and version numbers (plugin, WordPress, PHP), and records the time. Purpose: enforcing activation limits, delivering the right updates, and support diagnostics. Legal basis: contract performance.
  • Payment data — card payments are processed by Stripe: your card details go directly to Stripe and never touch our servers. We receive and keep only what is needed to service the order — payment status, a payment reference, and the billing details you entered at checkout. Legal basis: contract performance and legal obligation (tax records).
  • Support correspondence — emails you send us, kept so we can help you and see history.
  • Security & server logs — IP address, user agent, and requested URLs, retained briefly for abuse prevention and debugging. Checkout and other forms are protected by Cloudflare Turnstile, which processes connection data to tell humans from bots. Legal basis: legitimate interest in keeping the service secure.
  • Usage analytics — we use Google Analytics and Microsoft Clarity on this website to understand which pages help visitors and where the site can improve: pages visited, referral source, approximate location (country/city), device and browser type, and interactions such as clicks and scrolling. Clarity may also produce anonymized session replays and heatmaps with typed text masked. This data is aggregated, is not used for advertising, and is never joined to your license account. Legal basis: legitimate interest in improving the service, or consent where required.
  • Demo environment — anything entered into the shared demo site is test data by definition (see Terms §11), visible to other demo users, and erased automatically at every reset.

What we do not do

  • No advertising or retargeting trackers, and no sale or sharing of personal data for advertising — the analytics above measure the website itself, nothing more.
  • No collection of your website’s visitor, affiliate, customer, or order data — the plugin is self-hosted and that data never reaches us.
  • No marketing email without your consent; transactional email (receipts, license and renewal notices, security notices) is part of the service.

Processors

We use a small number of service providers to run the service, limited to what is listed here: Amazon Web Services (server hosting), Cloudflare (network security, CDN, and Turnstile bot protection), Stripe (payment processing — a PCI-compliant provider that receives your card details directly; we never store card numbers), Brevo (delivery of transactional email such as receipts, license keys, and support replies), Google (Google Analytics — aggregated website usage statistics; Google Ads conversion measurement, which records that a purchase happened after an ad click; and, only when you use the optional address-search box at checkout, Google Maps address suggestions, which process the address text you type there), and Microsoft (Clarity — anonymized usage heatmaps and session insights). Each processor acts under a data processing agreement, and we share with each only the data it needs for its role.

Retention

Order and invoicing records are kept as long as applicable tax law requires (typically seven to ten years); license and activation records for the life of your account plus 24 months; support email for 24 months; security logs for 30 days; demo data until the next hourly reset. You can ask us to delete your account data earlier wherever a legal retention duty does not apply.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to access, correct, export, restrict, or delete your personal data, to object to processing, and to complain to a supervisory authority. Exercise any of them by emailing [email protected] from your account address — we answer within 30 days. We do not discriminate for exercising privacy rights.

International transfers

Where data crosses borders (for example via Cloudflare’s global network), transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision.

Cookies

This website sets a small number of cookies: a session cookie for the admin area; Cloudflare’s challenge cookies where Turnstile runs; and first-party analytics cookies set by Google Analytics (such as _ga) and Microsoft Clarity (such as _clck) that distinguish returning visits for the aggregated statistics described above. No cross-site advertising or retargeting cookies. You can block or delete cookies in your browser at any time — every part of the website keeps working without them.

Changes & contact

Changes to this policy appear on this page with an updated date; material changes are emailed to license holders. Questions and requests: [email protected].