Legal
Privacy Policy
Last updated: September 22, 2026
Sprout Affiliate ("Sprout Affiliate," "we," "us") is an affiliate-marketing app for Shopify, operated by O10 Media LLC. This policy explains what data the app processes when a merchant installs it, how we use that data, and the choices you have. It covers the Sprout Affiliate app for Shopify, the Sprout Affiliate apps for iPhone, iPad and Android, and the sproutaffiliate.com website.
Information we process
Merchant & store data
- Your store's domain and the Shopify access token issued at install, used to call the Shopify API on your behalf.
- Order data needed to calculate commissions and run the store's fraud checks: order numbers, dates, totals, discount codes, order attributes, the buyer's name, Shopify's fraud risk rating and any chargeback on the order, and the IP address Shopify records for the browser the order was placed from. We do not need or store customer payment card data.
- App settings you enter: support email, program rules, payout timing, and your PayPal API credentials (see Security).
Affiliate data
- Information affiliates submit when they join a program: name, email, their chosen discount code, payout method, and payout details (for example a PayPal email or bank information).
- A per-affiliate ledger of referred orders and commission amounts, so payouts are accurate and never doubled.
- The IP address the application was submitted from. A store can use it to hold applications for review when many accounts arrive from one address, to block an address outright, and to spot an affiliate buying through their own link. The store chooses which of those checks run: the own-link check is on by default for new stores, and the other two are off unless the store turns them on. The account limit and the own-link check hold an application or an order for a person to look at rather than rejecting it; a blocked address cannot apply. The address is stored for as long as the affiliate's record exists.
Storefront referral data
- When a shopper arrives with an affiliate's referral link, the app stores the affiliate's referral code in the browser and on the resulting cart/order (as the "Sprout Affiliate Ref" attribute) so the sale is credited.
- For those visits only, the app records the pages visited and the visitor's IP address, so the store can see the journey behind a referral and check whether an affiliate is buying through their own link. Shoppers who did not arrive through a referral link are not recorded at all. These visit records are deleted automatically after a limited period, and the address goes with them.
- We collect no other browsing data: no device fingerprint, no advertising identifier, and no tracking across other websites.
Website data
- If you contact us through the website, we receive the details you send (such as your name, email, and message).
Mobile app data
- The Sprout Affiliate apps for iPhone, iPad and Android are for affiliates who already belong to a program, and for the merchants who run those programs. An affiliate signs in with their email address and either their password or a one-time code we email them; a merchant signs in with a pairing code generated in their own Shopify admin.
- On iPhone, iPad and Android, if you allow notifications, we store the device's push token so we can tell you when a referred order is credited to you. On iPhone and iPad this is an Apple push token; on Android it is a Firebase Cloud Messaging token, and the message is delivered by Google. Signing out deletes it, and turning notifications off in the app stops the messages.
- The apps show you the same commission, payout, and messaging data as the web portal. It collects no location, contacts, photos, advertising identifiers, or usage analytics, and there is no third-party tracking in it.
API, webhooks, and AI assistants
- When a merchant creates an API key or an MCP key in Settings > Developer, we store its name, its access (read only, or read and write), the first few characters to tell keys apart, and a one-way hash of the key. The key itself is shown once and never stored. We also record when it was last used and, for an MCP key, which assistant used it.
- When a merchant connects an AI assistant such as Claude or ChatGPT with its Connect button, we store the connection: the assistant's name and website, the access the merchant approved, when it was connected and last used, and one-way hashes of the tokens it signs in with. Its access token lasts an hour; the connection lasts until the merchant revokes it in Settings > Developer.
- When a merchant adds a webhook endpoint, we store its address, the events chosen, and its signing secret, encrypted at rest. We keep a record of each delivery: a successful one for 30 days, and a failed one until it is sent again successfully or the endpoint is deleted.
How we use it
- To run the app's core functions: tracking referrals, calculating commissions, and paying affiliates.
- To provide support and respond to your messages.
- To operate, secure, and improve the service, and to meet legal obligations.
We do not sell personal information, and we do not use your store's data to build advertising profiles.
IP addresses are used only for the fraud checks described above. They are never used to profile or track anyone, are never shared with anyone else, and are deleted when the store's data is deleted or when an affiliate asks us to remove their information.
Sharing and third parties
We share data only with the services required to deliver the app:
- Shopify, the platform the app runs on and reads order data from.
- PayPal, for automatic payouts. The payout amount and the recipient's PayPal identifier are sent to PayPal to complete the payment.
- Apple and Google, only if you turn on notifications in the iPhone, iPad or Android app. The alert's title and text pass through Apple's or Google's push service to reach your device, which is the only way any app can deliver a notification. Neither is used for advertising, and the apps contain no advertising or analytics SDK.
- Our hosting and database provider, which stores the app's data on our behalf under confidentiality obligations.
- Integrations and AI assistants a merchant connects. When a merchant uses an API key, connects an assistant, or adds a webhook endpoint, the store data that integration asks for or subscribes to (affiliates, referral orders, commission figures, payouts, and bonuses of that one store) is sent to it at the merchant's direction. The provider of that integration or assistant, for example Anthropic for Claude or OpenAI for ChatGPT, handles it under its own terms and privacy policy. Sprout Affiliate does not receive the conversation with the assistant, and no key, token, or connection reaches more than the one store that created or approved it.
We may also disclose information if required by law, or as part of a merger or sale of the business, in which case we will notify affected merchants.
Security
Data is transmitted over TLS. Sensitive secrets (your PayPal API secret and affiliates' payout details) are encrypted at rest using AES-256-GCM before they are stored. Access to production systems is restricted.
Data retention and deletion
We keep data only as long as needed to run your program:
- When you uninstall the app, we retain your data briefly in case you reinstall, then honor Shopify's
shop/redactrequest (about 48 hours later) by permanently deleting all of your store's data. - On a Shopify
customers/redactrequest, we anonymize the affiliate's personal information while keeping the anonymized commission records needed for your financial history. - On a
customers/data_request, we compile the data we hold about that person for you to share with them.
You can also email us to request access to, correction of, or deletion of your data at any time.
Your rights
Depending on where you live, you may have rights under the GDPR, UK GDPR, or CCPA/CPRA, including the right to access, correct, delete, or port your data, and to object to certain processing. To exercise these rights, contact us using the details below. Affiliates should contact the merchant whose program they joined; we will assist that merchant in responding.
International transfers
Sprout Affiliate is operated from the United States, and the application and its database run in Ashburn, Virginia. Personal data from the European Economic Area, the United Kingdom or Switzerland is therefore transferred to the United States. Those transfers are made under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module Two), the UK Information Commissioner's International Data Transfer Addendum, and the Swiss amendments to the same clauses. They are set out in full in our Data Processing Agreement, which is in force for every merchant from the moment they install the app. The third parties involved are listed on our sub-processors page.
Children
Sprout Affiliate is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated in the app.
Contact
Questions or requests: support@sproutaffiliate.com.