Last updated: May 25, 2026
When you install OptimizeAffiliate, we collect and store:
When you install OptimizeAffiliate, Shopify asks you to approve the following permissions. Here is exactly why each one is needed:
| Permission | Why we need it |
|---|---|
| Read products | We read your product catalog to match affiliate-driven traffic to the products being promoted and calculate accurate commission values. |
| Read orders | We read your orders to track which sales were driven by affiliate partners, measure conversion rates, and report on program performance. We never modify orders. |
| Read & manage price rules | We create and manage price rules to power affiliate-specific discount codes so each partner's sales can be tracked separately. |
| Read & manage discounts | We generate unique discount codes assigned to individual affiliate partners. This is the core mechanism that attributes sales back to the partner who drove them. |
| Read & manage draft orders | We use draft orders to handle manual affiliate order workflows and custom commission scenarios where a standard discount code isn't sufficient. |
We only use these permissions to operate the affiliate program management features you signed up for. We never read or write any data outside of what's described above.
We use your data exclusively to provide the OptimizeAffiliate service:
We do not sell your data, use it for advertising, or share it with third parties except as required to provide the service.
All data is stored in a PostgreSQL database. Data is encrypted in transit using TLS and encrypted at rest. Access to your data is restricted to authenticated requests using your Shopify session token. API credentials are encrypted at rest using industry-standard encryption.
When you uninstall the app, we receive a Shopify app/uninstalled webhook and delete your shop record and all associated data within 48 hours. We also support Shopify's mandatory GDPR webhooks for customer data requests and redaction.
We use the following third-party services to provide the OptimizeAffiliate service:
| Service | Purpose and data handling |
|---|---|
| Shopify | Authentication, billing, and store data access. Your store data is handled per Shopify's privacy policy. |
| Impact | Affiliate network API integration (if connected). Your Impact API credentials and program data are used solely to sync your affiliate performance data. |
| AvantLink | Affiliate network API integration (if connected). Your AvantLink credentials and program data are used solely to sync your affiliate performance data. |
| Anthropic | AI model inference for action generation and recommendations. Your affiliate performance data and brand context are sent to Anthropic's API to generate recommendations. Data is processed per Anthropic's privacy policy and is not used to train their models. |
| SendGrid | Email delivery for daily digests and system notifications. Only your configured email address is shared with SendGrid for delivery purposes. |
OptimizeAffiliate uses Shopify session tokens for authentication within the Shopify admin. We do not use third-party tracking cookies or advertising cookies of any kind.
You may request deletion of your data at any time by uninstalling the app or contacting us directly. Uninstalling triggers automatic deletion of all stored data within 48 hours. You may also request a copy of your stored data by contacting us at the address below.
We may update this privacy policy from time to time. The "Last updated" date at the top of this document reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.
For privacy questions, data requests, or to exercise your rights:
Operated by Windy Point Media LLC