Privacy Policy
What Partnely collects from brands, from creators and affiliates, and from shoppers who click a tracked link; why and on what legal basis; how long it is kept; who processes it; and your rights.
1.Who we are and what this covers
This policy explains what personal data Partnely collects, why, on what legal basis, how long we keep it and what your rights are. It covers the website, the application, the API, the tracking redirect and snippet, and the emails we send.
Partnely is operated by SoMe Innovation ApS, Thulevej 12, 3. th, 9210 Aalborg SØ, Denmark (CVR 42673684). For account data and for the service itself we are the controller. You can reach us at hello@partnely.app, and about privacy at privacy@partnely.app.
For the data a brand's program processes about its partners and shoppers, the brand is the controller and we are its processor under the Data Processing Agreement; questions about a brand's program go to that brand first.
2.What we collect from brands
- Account data: name, email address, a hashed password or the identity a social sign-in provider gives us (provider id, name, email, picture), and the time of sign-up.
- Acceptances: which of our documents you accepted, at which version and when, with the IP address and browser (user agent) the acceptance came from.
- Store data: the store's name, address, platform, category, logo, currency, program terms, program page content, catalog (products, prices, images, links), store connection details, and hashed API keys.
- Orders: for each order matched to a partner, the order id and number, subtotal, currency, line items where the platform sends them, coupon code, a hashed customer identifier, and the platform fee. We do not store the shopper's name, address or payment details. For orders that no partner brought in, the tracking log keeps only the order id, amount and currency (and the currency the shopper paid in, when it differs), no customer details.
- Billing: the plan, trial dates, invoices, and a label for the card on file. Card numbers are handled by the payment provider and never reach us.
- PayPal connection, if a brand connects its PayPal account to pay partners: the PayPal app's client id and secret (the secret encrypted at rest), whether it is live or a test app, the webhook PayPal notifies us through, and each payout batch sent from it with its status, PayPal's ids, the fee PayPal reports and any error.
- Payout details you open or export: a record of each time someone on the brand's account opened or exported a partner's full payout details, with the person and the time.
- Usage and security: sign-ins, actions in the application, the inbound tracking and webhook log, and short-lived counters of sign-in and request attempts per email address or IP address that protect against abuse.
3.What we collect from creators and affiliates
- Account data: name, email address, a hashed password or a social sign-in identity, and the time of sign-up.
- Acceptances: which of our documents you accepted, at which version and when, with the IP address and browser (user agent) the acceptance came from.
- Profile: display name, handle, bio, channels, verification tokens and results, and, if you enter one, a shipping address for gifted products. Where the marketplace is offered: your discovery profile (headline, categories, country, languages, audience sizes as you state them, rates, what you are open to).
- Payout details: the payout method you choose and the details it needs, encrypted at rest, with a masked label of them and the time they last changed. For a bank transfer: the account holder's name, the IBAN or account number, the sort code, routing number or bank registration number and the account type where they apply, the BIC or SWIFT code and the bank's name, and the holder's town and country, with the street and postcode if you give them. For PayPal: your PayPal email address and, if you connect PayPal with Log in with PayPal, the email address, PayPal account id (payer id) and account verification status PayPal returns. For Wise or Venmo: the email address, handle or phone number you give; for another method, the text you write.
- Payout accounts, where funded payouts are offered: the identifier of the payout account you set up with the payment provider, which collects and holds your bank and identity documents.
- Your page and posts: the content of your public page and the posts you add by address, with the title, author and thumbnail the platform returns.
- Instagram connection, where Instagram Replies is offered: when you connect a professional account, the account id, username and an access token, the comments and messages that trigger your automations (the commenter's id and username and the text), and every reply sent with its outcome.
- Program records: memberships, the agreements you sign (the typed name, time, IP address, browser and a frozen copy of the text), the dated copies kept when you accept a program's changed terms by staying in it and the notices of those changes, links, clicks, orders, payouts, program emails sent to you and whether you have stopped a brand's program emails.
4.What we collect from shoppers who click a tracked link
When a person clicks a tracked link they pass through our redirect. We record a click id, the time, the link, a one-way hash of the IP address, the browser's user agent, the referring page, a country derived from the address, and the landing page we sent them to. The click id is carried to the store in the landing URL and, where the store uses our snippet, kept in the browser's storage on the store's domain (local storage and first-party cookies) for the length of the brand's attribution window so an order can be matched to the click.
If the person orders, the store's platform sends us the order; we match it to the click, record the order against the partner and keep only the order data listed above. We do not build profiles of shoppers, we do not use the data for advertising, and we do not sell it.
On a Shopify store that has added our custom pixel, the store's checkout also sends us a report when an order is completed in a browser that holds a click from a tracked link. The report carries only the order id, the order's subtotal and currency, the discount codes on the order, and the click id and link reference stored in the browser. It carries no customer details: no name, email address, postal address, phone number or payment details. We match it to the click the same way and keep only the order data listed above.
A shopper who wants to know what a brand's program holds about them should contact that brand; we will help the brand answer.
5.Why we use it and the legal basis
Each purpose below names the legal basis under the EU General Data Protection Regulation (GDPR) we rely on for it:
- Providing the service to account holders (accounts, stores, programs, links, the ledger, pages, program emails and support): performance of our contract with you (Article 6(1)(b)).
- Recording clicks and matching orders to partners in a brand's program: done for the brand as its processor, on the brand's legal basis, usually its legitimate interest in paying partners for the sales they bring, or consent where the law requires it for storage in the shopper's browser.
- Detecting bots, self-referrals and other fraud (risk flags), limiting sign-in attempts and keeping the service secure: our legitimate interest, and the brand's, in an honest ledger and a secure service (Article 6(1)(f)). Risk flags are shown to the brand, which decides what to do; we make no decision with legal or similarly significant effects by automated means alone.
- Billing brands, recording payouts to partners (and, where funded payouts are offered, paying them through the service) and keeping bookkeeping records: performance of the contract, and our legal obligations under bookkeeping and tax law (Article 6(1)(c)).
- Keeping a partner's payout details and showing them to the brands whose programs the partner joined so those brands can pay: performance of our contract with the partner (Article 6(1)(b)). Recording each time a brand opens or exports those details: our legitimate interest, and the partner's, in knowing who had them (Article 6(1)(f)).
- Sending PayPal payout requests from a brand's own PayPal account when the brand has connected it: done for the brand as its processor, on the brand's legal basis, its program agreement with the partner.
- Recording acceptances of our documents and signatures on program agreements, with the time, IP address and browser: our legitimate interest, and that of the parties to a program, in being able to show what was agreed, when and by whom (Article 6(1)(f)).
- Service emails such as sign-in links, password resets, notices and invoices, including the notice of a change to the terms of a program a partner belongs to, which is sent even to a partner who stopped that brand's program emails: performance of the contract (Article 6(1)(b)).
- Program emails a brand sends its partners: sent for the brand as its processor; every such email carries a link to stop that brand's program emails. Bounce and spam-complaint reports from the email provider are used to stop sending to an address that cannot receive mail, and a complaint stops that brand's program emails to the partner.
- Instagram reply automation, where offered: performance of the contract with the account holder who connected it; for the people who comment, done for the account holder as its processor, on the account holder's legitimate interest in answering people who ask for a link (Article 6(1)(f)).
- Handling reports of illegal content, requests from authorities and legal claims: our legal obligations (Article 6(1)(c)) and our legitimate interest in defending legal claims (Article 6(1)(f)).
- Improving the service with aggregated, de-identified usage data: our legitimate interest in a better service (Article 6(1)(f)).
Where we rely on legitimate interest you may object, as described under your rights below.
No law requires you to give us personal data, but some of it is needed for the contract: without account data (a name, an email address and a password or a social sign-in) we cannot open or run an account, without a typed name a partner cannot sign a program agreement and join a program, and without a card on file a store cannot stay on a paid plan after its trial. Payout details are needed only to be paid, and a discovery profile only to be shown to brands where the marketplace is offered. Everything else you add is optional.
6.Retention
- Account and profile data: for the life of the account. When an account closes, its profile is deleted or anonymised at once, after we have sent any copy of the data you asked for with your request; the records below that the law requires us to keep stay for their own periods.
- Payout details, including the PayPal account data from Log in with PayPal: until you change them or ask us to remove them at privacy@partnely.app, and deleted when the account closes. The method, the reference and PayPal's ids recorded on a payout already made stay with that payout as a financial record.
- A brand's PayPal connection: until the brand disconnects it or the store closes. The record of each time a brand opened or exported a partner's payout details is kept with the payout records.
- Clicks and inbound tracking and webhook events: twenty-four months from when they were recorded, then deleted.
- Sign-in sessions and the counters that limit sign-in and request attempts (which hold an email address or IP address): deleted once they expire.
- Password reset and email confirmation links: stored only as a hash, and deleted a week after they are used or expire.
- Orders, commission, payouts and invoices: five years from the end of the financial year they belong to, as the Danish Bookkeeping Act requires, also after an account closes.
- Signed agreements and acceptances, including copies accepted by staying in a program after notice of a change and the notices sent, with the IP address and browser recorded with them: for the life of the relationship they record and seven years after it ends.
- Records of program emails a brand sent through the service (recipient and delivery status): for the life of the brand's account.
- The log of actions our administrators take on accounts and stores (who, what, when and from which IP address): for as long as the account or store exists and five years after, so we can show what was done and why.
- Instagram access tokens, where Instagram Replies is offered: until you disconnect the account or remove its access on Instagram; the log of comments and replies for twelve months, then deleted.
- Backups: overwritten within ninety days, so data deleted from the live system may remain in a backup for up to ninety days.
7.Processors and other recipients
We use a small number of providers, each for one job, under contracts that bind them to protect the data:
- Hosting provider: the servers, database and backups the service runs on, in the European Union.
- Cloudflare: the domain name service for our website, and forwarding of email sent to our hello, privacy and abuse addresses to the mailbox where we read it.
- Stripe: card billing for brands and, where funded payouts are offered, those payouts and payout accounts for partners. For payout accounts, where offered, Stripe also collects identity and tax details as a controller under its own privacy policy.
- Resend: transactional email and the program emails brands send their partners through the service.
- PayPal: when a partner connects PayPal with Log in with PayPal, confirming the account and returning its email address, account id and verification status.
- Meta Platforms, where Instagram Replies is offered: receiving comments and sending replies for the Instagram accounts connected to it.
- Store platforms and social networks you connect (order webhooks, catalog reads, discount codes, post details): each under its own terms, receiving and sending only what you authorise.
When a brand connects its own PayPal account to pay partners, PayPal receives the PayPal email address or account id and the amount of each partner the brand pays through it. PayPal receives that data under the brand's own agreement with PayPal, not as our provider.
A current list with each provider's legal name and location is available from privacy@partnely.app. We share data with authorities when the law requires, and with a successor if the company or the service is sold, under this policy.
9.Your rights and how to make a request
You have the right to access the data we hold about you, to have it corrected, to have it deleted, to receive it in a portable form, to restrict its processing, to object to processing based on legitimate interest, and to withdraw a consent you gave at any time.
Most profile and store details can be corrected in your settings. To close your account and have your data deleted, to receive a copy of your data, or to exercise any other right, write to privacy@partnely.app from the email address on your account. We answer within one month; we may ask you to confirm who you are first. Closing an account deletes or anonymises its profile, but orders, commission, payouts, invoices and signed agreements are kept for the periods above, because the law requires it and the other party to a program relies on them.
Where a brand is the controller we pass the request to the brand and help it respond.
10.Complaints
If you believe we handle your data unlawfully, please tell us first at privacy@partnely.app. You also have the right to lodge a complaint with a data protection supervisory authority. You can complain to Datatilsynet (the Danish Data Protection Agency), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk, or to the data protection authority in the country where you live or work.
12.International transfers
We host the service and its backups in the European Union. Stripe, Resend, PayPal and Meta may process data in the United States and other countries outside the European Economic Area; those transfers rely on the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission's standard contractual clauses.
13.Children
The service is for adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.
14.Changes
This policy carries a version date. We will notify account holders by email or in the application of any material change before it applies.
15.Contact
Privacy requests and questions: privacy@partnely.app. Post: SoMe Innovation ApS, Thulevej 12, 3. th, 9210 Aalborg SØ, Denmark.
Privacy Policy, version 2026-09-17. Questions: hello@partnely.app.