AffiliateFactoryWP

Privacy Policy

Last updated: August 20, 2026

This policy covers this website and the license services operated by Affiliate Factory, the data controller. The short version: we collect the minimum needed to sell and service licenses, we run no advertising trackers, and the plugin sends us nothing about your website’s visitors, affiliates, or orders.

What we collect, and why

  • Order & account data — your email address, name, billing details you enter (company, address, tax ID), plan, order history, and license keys. Purpose: delivering your purchase, invoicing and tax compliance, refunds, and support. Legal basis: contract performance and legal obligation.
  • License activation data — when a WordPress site activates, deactivates, or checks a license, our server receives the license key, the site URL, and version numbers (plugin, WordPress, PHP), and records the time. Purpose: enforcing activation limits, delivering the right updates, and support diagnostics. Legal basis: contract performance.
  • Support correspondence — emails you send us, kept so we can help you and see history.
  • Security & server logs — IP address, user agent, and requested URLs, retained briefly for abuse prevention and debugging. Checkout and other forms are protected by Cloudflare Turnstile, which processes connection data to tell humans from bots. Legal basis: legitimate interest in keeping the service secure.
  • Demo environment — anything entered into the shared demo site is test data by definition (see Terms §11), visible to other demo users, and erased automatically at every reset.

What we do not do

  • No advertising trackers, no sale or sharing of personal data for advertising.
  • No collection of your website’s visitor, affiliate, customer, or order data — the plugin is self-hosted and that data never reaches us.
  • No marketing email without your consent; transactional email (receipts, license and renewal notices, security notices) is part of the service.

Processors

We use a small number of service providers to run the service, limited to what is listed here: our server infrastructure provider (hosting), Cloudflare (network security, CDN, and Turnstile), and — once online payment is enabled — a PCI-compliant payment provider, named here at that time, that processes your payment details directly; we never store card numbers. Each processor acts under a data processing agreement.

Retention

Order and invoicing records are kept as long as applicable tax law requires (typically seven to ten years); license and activation records for the life of your account plus 24 months; support email for 24 months; security logs for 30 days; demo data until the next hourly reset. You can ask us to delete your account data earlier wherever a legal retention duty does not apply.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to access, correct, export, restrict, or delete your personal data, to object to processing, and to complain to a supervisory authority. Exercise any of them by emailing [email protected] from your account address — we answer within 30 days. We do not discriminate for exercising privacy rights.

International transfers

Where data crosses borders (for example via Cloudflare’s global network), transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision.

Cookies

This website sets only what it needs to function: a session cookie for the admin area and, where Turnstile runs, Cloudflare’s challenge cookies. No cross-site tracking cookies, which is why there is no cookie banner.

Changes & contact

Changes to this policy appear on this page with an updated date; material changes are emailed to license holders. Questions and requests: [email protected].