Last updated: 13 August 2026 · affiliates.dropcommerce.com
This policy explains what personal information the DropCommerce Affiliate Program collects, why we collect it, who we share it with, and what you can do about it.
It covers the affiliate platform at affiliates.dropcommerce.com only. This is a separate system from the main DropCommerce app, with its own database. The platform is operated by DropCommerce Inc., of 7-2070 Harvey Ave. Unit 229, Kelowna, BC V1Y8P8. We are the controller of the information described here.
There are two groups of people whose information we handle, and they are handled quite differently:
We also hold information about referred merchants — the businesses that subscribe to DropCommerce. That is mostly business information rather than personal information, but we describe it in section 6 so the picture is complete.
It is easier to understand this policy if we start with what is absent from it.
We do not run advertising on this platform. We do not build profiles, we do not track anyone across other websites, and we do not sell or rent personal information to anyone. The cookies described in section 5 exist for one purpose: working out which affiliate should be credited for a referral.
We have also designed several parts of the system to hold less than we could:
When you apply for and use an affiliate account, we collect:
Stripe collects your bank details and tax information directly from you during their onboarding process. That information goes to Stripe, not to us. We never receive it, see it or store it, and we cannot retrieve it from Stripe.
This is optional. If you do not enable two-factor authentication, none of this is collected.
These exist so that you and we can see what happened on an account — which matters when money is involved, and when an account is disputed or compromised.
When someone clicks an affiliate’s tracked referral link, we record the click, set the cookies described in section 5, and redirect them to our Shopify App Store listing. The click record contains:
There is no name, no email address, no account and no login involved. In almost all cases we have no way of working out who an individual click belongs to, and we do not try to.
If someone shares a direct App Store link tagged with an affiliate’s referral code rather than the tracked link, no click record is created at all.
Depending on where you are, a hashed IP address and a user-agent string may still count as personal information even though we cannot readily identify anyone from them. We have written this policy on the basis that they do.
We set two cookies when someone clicks a tracked referral link. Both last 90 days, matching the attribution window in our Affiliate Program Terms. Both exist solely to work out which affiliate should be credited for a referral.
| Cookie | Duration | Type | What it does |
|---|---|---|---|
dc_aff | 90 days | HttpOnly | Holds an opaque token. It carries no readable information. It is what connects a later install back to the affiliate who referred it. HttpOnly means scripts running in the browser cannot read it. |
dc_ref | 90 days | Readable, scoped to .dropcommerce.com | Holds the affiliate’s referral code in readable form. It is scoped across dropcommerce.com so that the main DropCommerce app can pre-fill “referred by” during merchant setup, rather than asking the merchant to type a code they may not have. |
We do not set advertising cookies, analytics cookies or any cookie that follows a visitor to other websites.
You can delete or block these cookies through your browser settings. Blocking them does not stop you installing or using DropCommerce; it means the affiliate who referred you may not be credited.
So that we can calculate commission correctly, we hold the following about merchants who subscribe to DropCommerce through an affiliate referral:
This is business information about a store rather than information about an individual, and we treat it that way. It can overlap with personal information — for a sole trader, a store domain may be their own name — so we handle it with the same care as everything else described here.
Affiliates see a limited view of this in their dashboard: enough to understand what they have earned and why. Under the Affiliate Program Terms, affiliates may not use information about referred merchants for anything other than participating in the Program.
We send transactional email — account and application notices, payout confirmations, password resets, and notices about changes to the Program.
For each message we log the recipient address, which message was sent, when, and whether delivery succeeded. We do not store the message bodies. We keep these logs so we can tell whether an affiliate was actually notified about something, which matters for payouts and for changes to the Terms.
We do not send marketing email to affiliates from this platform.
We have set out below every purpose for which we use personal information, what we use for each, and the legal basis we rely on. We apply the same standard to every affiliate, wherever you live. Rather than giving different people different treatment depending on which privacy law reaches them, we have written this policy — and the rights in section 13 — to the highest standard that applies to any of our affiliates, and we extend it to all of them. Where we say we rely on legitimate interests, that means we have judged our reason for using the information against the effect on the person it concerns. We think our interest is not outweighed, largely because of how little we hold. If you disagree, you can object — section 13 explains how.
| Purpose | Information used | Legal basis if GDPR applies |
|---|---|---|
| Reviewing your application and deciding whether to approve it | Name, email, company name | Steps taken at your request before entering into a contract |
| Running your affiliate account and giving you a dashboard | Name, email, company name, password hash | Performance of our contract with you |
| Keeping a record of what you agreed to and when | Terms acceptance timestamp | Our legitimate interest in being able to show what was agreed, and yours in the same |
| Attributing referrals to the right affiliate | Click records, cookies, merchant install data | Performance of our contract with the affiliate. See section 5 on the separate cookie consent question. |
| Calculating commission | Merchant plan, status and charge amounts from Shopify | Performance of our contract with you |
| Paying you | Payout method, PayPal email or Stripe account ID | Performance of our contract with you |
| Keeping financial and tax records | Payout records, commission records | Compliance with a legal obligation |
| Securing accounts and detecting fraud, including self-referral and duplicate or artificial clicks | Session records, audit log, two-factor data, hashed IP, user-agent | Our legitimate interest in protecting the Program, our affiliates and our merchants from fraud and abuse |
| Sending you transactional email and proving we did | Email address, delivery logs | Performance of our contract with you, and our legitimate interest in being able to show that notice was given |
| Handling questions and disputes about an account | Whatever is relevant to the dispute | Our legitimate interest in resolving disputes fairly and defending claims |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by the effect on the individual. We think it is not, largely because of how little we hold — but you can object, and section 13 explains how.
Affiliate applications are reviewed by a person, not decided automatically.
Our system does flag suspected self-referrals and suspicious click patterns automatically, but a flag is not a decision. A person reviews what has been flagged before any action is taken on an account or a commission balance.
We share information with the following service providers, and only so they can perform the function described. They act on our instructions and are not permitted to use the information for their own purposes.
| Provider | What it does for us | What it processes |
|---|---|---|
| Heroku (Salesforce) | Hosts the application and the PostgreSQL database | Everything described in this policy is stored on this infrastructure |
| Twilio SendGrid | Sends transactional email | Recipient email address and the message being sent |
| Shopify | Source of subscription and billing data through the Partner API. Shopify is not acting on our instructions here; it is an independent controller of merchant data under its own terms. | Merchant subscription plan, status, install and uninstall dates, and charge amounts |
| PayPal | Pays affiliates who choose PayPal | The PayPal email address and the payment amount |
| Stripe | Pays affiliates who choose Stripe Connect, and collects their bank and tax details directly | The Stripe account identifier and the payment amount. Stripe separately holds bank and tax details that we never receive. |
Beyond those providers, we will disclose information only:
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Our application and database are hosted on Heroku infrastructure in the United States. This means that affiliate account information, click records, commission and payout records are stored in the United States, wherever in the world you live. Our other providers are also established in the United States. SendGrid, Stripe, PayPal and Shopify may each process information in the United States and in other countries where they or their own subprocessors operate.
The United States does not have a single national privacy law equivalent to those in the EU, the UK or Canada, and its authorities have powers of access to information held there that may be broader than those where you live. We think it is more useful to say that plainly than to reassure you in general terms.
Two things reduce what is actually exposed by this, and both are design decisions rather than promises:
If you would like more detail about how a particular provider handles information, each publishes its own privacy documentation, and we are happy to point you to the relevant one.
We keep information only for as long as we have a reason to, and the reasons differ a lot between the categories below.
When a retention period ends, records are deleted or irreversibly anonymised.
These are the specific measures in place, rather than a general statement of intent:
No system is completely secure, and we cannot guarantee that information will never be accessed without authorisation. What we can say is that the design deliberately avoids holding the things that would be most damaging if it were: raw IP addresses, readable passwords, and affiliates’ bank details.
You have rights over the information we hold about you. Which of them are legal entitlements depends on where you live, but we do not think that is a useful thing for you to have to work out. We offer the rights below to every affiliate, wherever you are. Where the law gives you something more than this, the law wins.
Where the CCPA or CPRA applies, you also have the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing, and not to be treated differently for exercising those rights. As set out in section 9, we do not sell or share personal information, so there is nothing to opt out of.
Email partners@dropcommerce.com from the address on your affiliate account, or contact us from within your dashboard. We will respond within the time the applicable law allows, and we may need to verify who you are before acting — usually by confirming control of the account email address.
This is the one case where we may genuinely be unable to help, and we would rather explain why than pretend otherwise.
Click records contain a hashed IP address, a user-agent string and an opaque token. There is no name and no account attached. We cannot search for “your” clicks, because we have nothing to search by, and we are not required to collect additional information about you purely in order to identify you.
If you still have the dc_aff cookie in your browser, its value identifies your click record
directly, and you can send it to us and we can act on it. Otherwise, deleting the two cookies in your
browser removes the link between you and any future attribution, which achieves the practical outcome in
most cases.
The affiliate platform is for people old enough to enter into a binding contract where they live, and it is not directed at children. We do not knowingly collect information from children. If you believe a child has created an affiliate account, contact us and we will remove it.
Privacy questions and requests are handled directly by our team, at the address in section 17. We have not appointed a Data Protection Officer, because the nature and scale of what we do does not require one — we do not monitor people systematically, we do not profile anyone, and we do not handle sensitive categories of information.
That is not a reason to expect a slower answer. Requests go to a person who can act on them, and the response times in section 13.2 apply.
We may update this policy — for example if we add a payout method, change hosting provider, or if the law changes.
When we make a material change, we will email affiliates at the address on their account and post the updated policy at affiliates.dropcommerce.com with a “last updated” date. Minor corrections take effect when posted.
We will not start using information we already hold for a materially different purpose without telling affiliates first and, where the law requires it, asking for consent.
Questions about this policy, or about information we hold: