All documents

Privacy Policy

Version 2026-09-17Everyone

What Partnely collects from brands, from creators and affiliates, and from shoppers who click a tracked link; why and on what legal basis; how long it is kept; who processes it; and your rights.

1.Who we are and what this covers

This policy explains what personal data Partnely collects, why, on what legal basis, how long we keep it and what your rights are. It covers the website, the application, the API, the tracking redirect and snippet, and the emails we send.

Partnely is operated by SoMe Innovation ApS, Thulevej 12, 3. th, 9210 Aalborg SØ, Denmark (CVR 42673684). For account data and for the service itself we are the controller. You can reach us at hello@partnely.app, and about privacy at privacy@partnely.app.

For the data a brand's program processes about its partners and shoppers, the brand is the controller and we are its processor under the Data Processing Agreement; questions about a brand's program go to that brand first.

2.What we collect from brands

  • Account data: name, email address, a hashed password or the identity a social sign-in provider gives us (provider id, name, email, picture), and the time of sign-up.
  • Acceptances: which of our documents you accepted, at which version and when, with the IP address and browser (user agent) the acceptance came from.
  • Store data: the store's name, address, platform, category, logo, currency, program terms, program page content, catalog (products, prices, images, links), store connection details, and hashed API keys.
  • Orders: for each order matched to a partner, the order id and number, subtotal, currency, line items where the platform sends them, coupon code, a hashed customer identifier, and the platform fee. We do not store the shopper's name, address or payment details. For orders that no partner brought in, the tracking log keeps only the order id, amount and currency (and the currency the shopper paid in, when it differs), no customer details.
  • Billing: the plan, trial dates, invoices, and a label for the card on file. Card numbers are handled by the payment provider and never reach us.
  • PayPal connection, if a brand connects its PayPal account to pay partners: the PayPal app's client id and secret (the secret encrypted at rest), whether it is live or a test app, the webhook PayPal notifies us through, and each payout batch sent from it with its status, PayPal's ids, the fee PayPal reports and any error.
  • Payout details you open or export: a record of each time someone on the brand's account opened or exported a partner's full payout details, with the person and the time.
  • Usage and security: sign-ins, actions in the application, the inbound tracking and webhook log, and short-lived counters of sign-in and request attempts per email address or IP address that protect against abuse.

3.What we collect from creators and affiliates

  • Account data: name, email address, a hashed password or a social sign-in identity, and the time of sign-up.
  • Acceptances: which of our documents you accepted, at which version and when, with the IP address and browser (user agent) the acceptance came from.
  • Profile: display name, handle, bio, channels, verification tokens and results, and, if you enter one, a shipping address for gifted products. Where the marketplace is offered: your discovery profile (headline, categories, country, languages, audience sizes as you state them, rates, what you are open to).
  • Payout details: the payout method you choose and the details it needs, encrypted at rest, with a masked label of them and the time they last changed. For a bank transfer: the account holder's name, the IBAN or account number, the sort code, routing number or bank registration number and the account type where they apply, the BIC or SWIFT code and the bank's name, and the holder's town and country, with the street and postcode if you give them. For PayPal: your PayPal email address and, if you connect PayPal with Log in with PayPal, the email address, PayPal account id (payer id) and account verification status PayPal returns. For Wise or Venmo: the email address, handle or phone number you give; for another method, the text you write.
  • Payout accounts, where funded payouts are offered: the identifier of the payout account you set up with the payment provider, which collects and holds your bank and identity documents.
  • Your page and posts: the content of your public page and the posts you add by address, with the title, author and thumbnail the platform returns.
  • Instagram connection, where Instagram Replies is offered: when you connect a professional account, the account id, username and an access token, the comments and messages that trigger your automations (the commenter's id and username and the text), and every reply sent with its outcome.
  • Program records: memberships, the agreements you sign (the typed name, time, IP address, browser and a frozen copy of the text), the dated copies kept when you accept a program's changed terms by staying in it and the notices of those changes, links, clicks, orders, payouts, program emails sent to you and whether you have stopped a brand's program emails.

6.Retention

  • Account and profile data: for the life of the account. When an account closes, its profile is deleted or anonymised at once, after we have sent any copy of the data you asked for with your request; the records below that the law requires us to keep stay for their own periods.
  • Payout details, including the PayPal account data from Log in with PayPal: until you change them or ask us to remove them at privacy@partnely.app, and deleted when the account closes. The method, the reference and PayPal's ids recorded on a payout already made stay with that payout as a financial record.
  • A brand's PayPal connection: until the brand disconnects it or the store closes. The record of each time a brand opened or exported a partner's payout details is kept with the payout records.
  • Clicks and inbound tracking and webhook events: twenty-four months from when they were recorded, then deleted.
  • Sign-in sessions and the counters that limit sign-in and request attempts (which hold an email address or IP address): deleted once they expire.
  • Password reset and email confirmation links: stored only as a hash, and deleted a week after they are used or expire.
  • Orders, commission, payouts and invoices: five years from the end of the financial year they belong to, as the Danish Bookkeeping Act requires, also after an account closes.
  • Signed agreements and acceptances, including copies accepted by staying in a program after notice of a change and the notices sent, with the IP address and browser recorded with them: for the life of the relationship they record and seven years after it ends.
  • Records of program emails a brand sent through the service (recipient and delivery status): for the life of the brand's account.
  • The log of actions our administrators take on accounts and stores (who, what, when and from which IP address): for as long as the account or store exists and five years after, so we can show what was done and why.
  • Instagram access tokens, where Instagram Replies is offered: until you disconnect the account or remove its access on Instagram; the log of comments and replies for twelve months, then deleted.
  • Backups: overwritten within ninety days, so data deleted from the live system may remain in a backup for up to ninety days.

7.Processors and other recipients

We use a small number of providers, each for one job, under contracts that bind them to protect the data:

  • Hosting provider: the servers, database and backups the service runs on, in the European Union.
  • Cloudflare: the domain name service for our website, and forwarding of email sent to our hello, privacy and abuse addresses to the mailbox where we read it.
  • Stripe: card billing for brands and, where funded payouts are offered, those payouts and payout accounts for partners. For payout accounts, where offered, Stripe also collects identity and tax details as a controller under its own privacy policy.
  • Resend: transactional email and the program emails brands send their partners through the service.
  • PayPal: when a partner connects PayPal with Log in with PayPal, confirming the account and returning its email address, account id and verification status.
  • Meta Platforms, where Instagram Replies is offered: receiving comments and sending replies for the Instagram accounts connected to it.
  • Store platforms and social networks you connect (order webhooks, catalog reads, discount codes, post details): each under its own terms, receiving and sending only what you authorise.

When a brand connects its own PayPal account to pay partners, PayPal receives the PayPal email address or account id and the amount of each partner the brand pays through it. PayPal receives that data under the brand's own agreement with PayPal, not as our provider.

A current list with each provider's legal name and location is available from privacy@partnely.app. We share data with authorities when the law requires, and with a successor if the company or the service is sold, under this policy.

8.Sharing between brands and partners

A brand sees the profile, channels, links, clicks, orders, commission and payouts of the partners in its program, and each partner's signed agreement with the typed name and the time of signing; the IP address and browser recorded with a signature are shown only to our administrators. A brand whose program a partner joined can also see the partner's payout details so it can pay them: in lists only as a masked label, and in full, on a separate page or in an export file, only while it owes the partner approved commission, with each view and export recorded. A partner sees the same rows for their own activity, the brand's program terms and the brand's payouts to them. Creator pages and program pages are visible to anyone, and so are media kits and discovery profiles that a creator makes public where the marketplace is offered. Nothing else is shared between accounts.

9.Your rights and how to make a request

You have the right to access the data we hold about you, to have it corrected, to have it deleted, to receive it in a portable form, to restrict its processing, to object to processing based on legitimate interest, and to withdraw a consent you gave at any time.

Most profile and store details can be corrected in your settings. To close your account and have your data deleted, to receive a copy of your data, or to exercise any other right, write to privacy@partnely.app from the email address on your account. We answer within one month; we may ask you to confirm who you are first. Closing an account deletes or anonymises its profile, but orders, commission, payouts, invoices and signed agreements are kept for the periods above, because the law requires it and the other party to a program relies on them.

Where a brand is the controller we pass the request to the brand and help it respond.

10.Complaints

If you believe we handle your data unlawfully, please tell us first at privacy@partnely.app. You also have the right to lodge a complaint with a data protection supervisory authority. You can complain to Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk, or to the data protection authority in the country where you live or work.

11.Cookies and storage

On our own site we use only what the service needs: a session cookie that keeps you signed in, a cookie that remembers which of your stores you are working in, and short-lived cookies that protect social sign-in. None of them is used for advertising or shared with third parties, so they need no consent.

Videos and posts embedded on creator pages and program pages are loaded from the social platform (for example YouTube, TikTok or Instagram) only when you press play; before that, the page may show a preview image served by that platform.

On a brand's store, the tracking redirect adds attribution parameters to the landing URL and, where the brand has installed the snippet, the click id is kept in the browser's storage (local storage and first-party cookies on the store's domain) for the attribution window. The snippet offers a consent mode in which it stores nothing until the store's consent tool reports that the shopper agreed. Whether the store needs consent, and how it asks for it, is the brand's responsibility under the law where it sells.

12.International transfers

We host the service and its backups in the European Union. Stripe, Resend, PayPal and Meta may process data in the United States and other countries outside the European Economic Area; those transfers rely on the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission's standard contractual clauses.

13.Children

The service is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.

14.Changes

This policy carries a version date. We will notify account holders by email or in the application of any material change before it applies.

15.Contact

Privacy requests and questions: privacy@partnely.app. Post: SoMe Innovation ApS, Thulevej 12, 3. th, 9210 Aalborg SØ, Denmark.

Privacy Policy, version 2026-09-17. Questions: hello@partnely.app.