Privacy notice
How Affiliate Guardian handles personal data
Who is responsible
Outliyr LLC ("Outliyr," "we," "us," or "our"), based in Austin, Texas, operates Affiliate Guardian. We act as controller of personal data used to administer accounts, billing, security, support, and our own business. For Customer Data that a customer directs us to process through Affiliate Guardian, the customer is the controller or business and Outliyr acts as its processor or service provider. This Notice applies to Affiliate Guardian websites, applications, alerts, reports, support, and Recovery Concierge (together, the "Service").
Data we collect
We collect identifiers and account data, including name, email address, user and account identifiers, authentication records, role, and account preferences. We also collect billing and commercial data, including plan, subscription and invoice status, Stripe customer references, acceptance receipts, and Recovery Concierge fee records. Stripe, not Outliyr, collects and stores full payment-card details.
We process Customer Data that a customer provides or authorizes us to collect: affiliate accounts and programs, reports and transactions, balances and payout information, links and tracking codes, sites and pages, findings, alert and recovery records, connector settings, and encrypted connector credentials. Reports may contain identifiers or commercial information about the customer, its personnel, or transaction contacts.
We collect service, device, and security data such as IP address, browser and device type, requested pages, timestamps, session and authentication events, rate-limit information, errors, audit logs, support messages, and actions taken in the Service. We store a theme choice in local storage. We use necessary session and security cookies. The Service does not currently include advertising pixels or cross-site analytics trackers.
Where data comes from
We receive data directly from you; from personnel who administer your account; from sites you ask us to scan; from reports, email routes, and files you provide; from affiliate services you connect; from Stripe about subscription and payment status; and automatically from use, security, and operation of the Service.
How and why we use data
We use data to create and authenticate accounts; provide and secure the Service; crawl authorized sites; ingest and normalize authorized affiliate reporting; identify potential revenue problems; label evidence and confidence; deliver requested alerts; prepare and execute separately approved recoveries; provide exports and support; administer trials, subscriptions, invoices, cancellation, and fees; prevent abuse and fraud; troubleshoot and improve reliability; keep audit and acceptance receipts; comply with law; and establish, exercise, or defend legal claims.
Where law requires a legal basis, we process data to perform our contract with you, based on our legitimate interests in operating and securing the Service, to comply with legal obligations, and with consent where the law requires consent. You may withdraw consent for future processing at any time, but withdrawal does not affect prior lawful processing.
We do not use nonpublic Customer Data to publish cross-customer benchmarks. We do not sell personal information or share it for cross-context behavioral advertising. We do not use personal information for targeted advertising.
Sharing and service providers
We disclose data only as needed to: Cloudflare for network delivery and security; our hosting, storage, database, backup, and error-monitoring infrastructure providers; Stripe for checkout, subscriptions, invoices, refunds, disputes, and payment status; EmailIt for transactional email; affiliate networks, merchants, websites, and email routes that you direct us to contact or connect; professional advisers under duties of confidentiality; and government authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or handle a legal claim.
Service providers may process data only for contracted services and under applicable confidentiality and data-protection duties. When we process Customer Data for a customer, we use that data only to provide the services the customer directs, subject to the agreement and applicable law. We may also transfer data in a merger, financing, reorganization, bankruptcy, or sale of all or part of the business, subject to this Notice and appropriate confidentiality protections.
We operate from the United States, and providers may process data in the United States or other countries. If applicable law requires a particular safeguard for an international transfer, we will put the required safeguard in place before making that transfer.
Retention and deletion
Anonymous terminal scans are scheduled for deletion after a 48-hour adoption window. For customer scans, the Service retains the ten newest full completed crawls per site and may preserve limited older evidence needed to explain findings. Rate-limit records and completed queue records are short-lived operational records. Founding applications receive an operational delete-or-retain review after 90 days.
Other account and affiliate records remain while the account is active and until removed through account deletion, a supported deletion request, or an applicable retention rule. A signed-in sole owner can download a JSON export and permanently delete the account in Settings after any Stripe subscription is confirmed canceled. Shared accounts require Support so one member cannot erase another member's records.
Account deletion removes the active tenant account, connected-network records and credentials, sites, monitoring history, findings, recoveries, and ledger data. A privacy-minimized receipt proving affirmative consent to automatic renewal may be retained for at least three years after consent or one year after the subscription ends, whichever is longer, as required by applicable law. Limited data may also remain temporarily in protected backups until rotation, or longer where reasonably needed for security, fraud prevention, payment and tax records, audit integrity, dispute resolution, legal holds, or other legal obligations. We delete or de-identify data when its applicable purpose and retention period end.
Your choices and privacy requests
You may update account details in the Service, export account data in Settings, cancel a subscription through Billing, and delete an eligible sole-owner account in Settings. You may also ask us to access, correct, delete, or provide a portable copy of personal data, or to object to or restrict processing, through the Support page or at [email protected]. We will verify the requester and respond as applicable law requires. An authorized agent may submit a request, but we may require proof of authority and identity.
Depending on where you live, you may have additional rights, including the right to appeal a refusal or complain to a data-protection authority. We will not discriminate against you for exercising a privacy right. We do not sell personal information or use it for targeted advertising, so there is no sale or targeted-advertising opt-out needed for the Service's current practices.
Cookies and do not track
We use necessary authentication, session, security, and rate-limiting technologies. Blocking them may prevent the Service from working. A theme preference is stored locally in your browser. We do not currently use cookies to serve targeted advertisements or collect a person's activity over time across unrelated third-party websites.
Because the Service does not currently engage in that cross-site tracking, it does not take a separate action in response to browser "do not track" signals. Other parties may collect activity when you leave the Service, use Stripe Checkout, follow a link, or connect a third-party affiliate service; their notices govern their collection.
Security
We use administrative, technical, and physical safeguards designed for the nature of the data, including encrypted transport, encrypted connector credentials, role and tenant access controls, audit records, backups, and operational monitoring. No transmission, storage, or system is completely secure, and we cannot guarantee absolute security. Do not send passwords, API secrets, raw exports, or sensitive attachments through the general Support form.
Children
The Service is for people age 18 or older and is not directed to children. We do not knowingly collect personal data from anyone under 13. If you believe a child provided data, contact us so we can investigate and delete it as appropriate.
Changes to this Notice
We may update this Notice as the Service or law changes. We will post the new version and effective date here. For a material change, we will provide reasonable advance notice by email or in the Service when required and describe the change. We will request consent if applicable law requires it for a new use.
Contact
Outliyr LLC is based in Austin, Texas. For privacy questions or requests, contact [email protected] or use the Affiliate Guardian Support page. For account security, do not include a password, API key, connector secret, or raw affiliate export in the message.