Information we handle
- Brand and creator identity, contact, account, and program information.
- Approved creator codes, commercial terms, order attribution, refund adjustments, and payout records.
- Shopify store identifiers, installation state, required access scopes, and encrypted access credentials.
- Security, audit, webhook-delivery, and support records needed to operate and protect the service.
- Bank details submitted for payout review, stored in encrypted and masked form with role-restricted access.
How we use it
We use this information to authenticate users, operate creator programs, synchronize discounts, attribute eligible orders, calculate and adjust commissions, record external payouts, answer support requests, prevent duplicate or abusive activity, and meet legal obligations.
Affiliate1A does not sell personal information. We do not use order or bank information for unrelated advertising profiles.
Shopify data
For connected stores, Affiliate1A requests only the Shopify access scopes needed for supported discount and order workflows. Order ingestion is limited to attribution and commission operations. Shopify privacy and redaction webhooks are handled separately from ordinary order processing.
Test orders are marked as test data and do not trigger ordinary transactional notifications to real recipients.
Sharing and processors
We share information only with infrastructure and service providers used to host, secure, monitor, or deliver Affiliate1A, with the connected Shopify merchant as required for its program, or when required by law. Providers receive only the access needed for their function.
Retention and deletion
We retain program and financial records while an account is active and for a reasonable period afterward where needed for reconciliation, security, dispute handling, or legal compliance. Shopify deletion and redaction requests are processed through dedicated workflows. Encrypted credentials and sensitive exports follow shorter operational retention where possible.
Your choices
You may ask to access, correct, export, or delete personal information, subject to identity verification and records we must retain. Brand administrators can also pause creator codes and disconnect supported integrations through the product.
Send privacy requests to hello@book1a.com. Include the relevant brand handle and the email used for Affiliate1A, but do not send passwords or full bank details.
Changes
We may update this policy as the early-access product and applicable law evolve. Material changes will be reflected on this page with a revised update date.