1. General provisions
This Privacy Policy describes what User data the AffiliateProgramOS.com platform (the “Platform”, “we”) collects, how we use, store, and protect it, and what rights Users have regarding their data.
By using the Platform, you agree to this Policy. The Policy is an integral part of the Terms of Service.
2. What data we collect
2.1. Data provided by the User
- Username, email address, password (hashed);
- First and last name (optional in the profile);
- Profile bio (optional);
- Avatar (optional upload);
- Wallet addresses for withdrawals;
- Telegram ID (if linked voluntarily);
- Data from Google OAuth (when using Google sign-in): name, email, Google ID;
- Contents of dialogs (tickets), support messages, and materials attached to tickets.
- Channel URLs (TikTok, Instagram, YouTube, etc.), channel IDs and public metrics, feed snapshots;
- A temporary channel verification code (the User places it in the public bio);
- Niche, audience languages, timelines, formats, prices, and refused topics — if the User provided them.
- Visit-card data: headline, bio, country and city, portfolio examples, which channels to show, barter readiness (if that feature is on).
- Exchange orders: brief, price, deadlines, decline reason, pre-publish draft materials.
2.2. Data collected automatically
- IP addresses on sign-in and other actions that require authentication;
- Device and browser data (User-Agent), active sessions;
- Registration date/time, last sign-in, last activity;
- User country (approximate, from IP) — country code only.
2.3. Data related to activity on the Platform
- Information about Projects and Tasks created by the Advertiser;
- Submitted Works (clips): URL, status, views, engagement;
- Financial history: top-ups, payouts, withdrawals, tips;
- Account event log — User actions and administration actions regarding the account;
- Registration source (referrer page, UTM tags) — for analytics.
- Visit-card status (payment, moderation, pause) and work offers sent from the visit card.
- Exchange orders, fund reserves and returns, placement and payout statuses.
3. Purposes of processing
- Account registration, authentication, and session maintenance;
- Platform functionality: creating Projects and Tasks, accepting Works, making payouts;
- Processing financial operations;
- Checking Works against Task terms;
- Detecting abuse and violations;
- Resolving disputes and support requests;
- Sending notifications on the site and (if linked) via Telegram;
- Internal analytics and Platform improvement.
- Verifying channels from publicly available platform data;
- Showing a visit card in the catalog;
- Fulfilling exchange orders and reserving funds;
- Automated moderation of texts to detect abuse.
4. Sharing data with third parties
4.1. We do not sell or share Users’ personal data with third parties for commercial purposes.
4.2. Data may be shared with the following recipient categories:
- Payment systems — to the extent needed to process transactions;
- Telegram — ID when the bot is linked voluntarily, notification contents;
- Google — when using Google OAuth sign-in.
- Social platforms and public-data providers — to retrieve publicly available data about a linked channel (verification, metrics);
- Automated moderation providers — texts of messages and support requests may be sent to check for abuse; we do not use them for ad targeting;
- Anti-bot services — on sign-in, registration, and password-reset pages (IP, verification token).
4.3. Data publicly visible to other Users is limited to: username, avatar, online status (if enabled), account type, public bio. Email and wallet addresses are not visible to other Users.
If the visit-card catalog is enabled, Advertisers may see the visit card, channels, public metrics, and rates — to the extent the Creator made them visible in the interface.
If the ad exchange is enabled, Advertisers may see the channel, public metrics, price, and placement terms — to the extent the Creator made them visible in the interface.
With guest access, an active visit card opens via a direct link without sign-in in a limited view (no working channel links and no work-offer form).
5. Data storage
5.1. Only administrators and moderators can access User data from the Platform interface — in the minimum volume needed for their duties.
5.2. Passwords are stored hashed only. We do not have access to passwords in plain text.
6. User rights regarding their data
- View and edit — available in “Settings”.
- Hide public profile — toggle in profile settings.
- Session management — list of active devices with the ability to end any session is available in settings.
- Remove Telegram link — via settings or the bot management page.
- Account deletion request — contact support (“Dialogs”). Deletion is performed by an administrator subject to legal requirements and unfinished financial operations.
7. Cookies and analytics
7.1. The Platform uses session cookies for authentication and form protection. Cookies are removed when the browser is closed or the session expires.
The selected interface language may be stored (a separate language cookie).
7.2. Platform pages may include a web analytics counter for aggregated visit statistics.
7.3. We do not use analytics data for targeted advertising.
7.4. Sign-in, registration, and password-reset pages may use a third-party “I am not a robot” check: technical data (IP, token) are sent to that provider only for this check.
8. Data retention period
Account data is stored until deletion at the User’s request or by administration decision. Financial records (transactions, payouts) are kept for the period required by law (generally at least 5 years). Event logs are kept for a technically justified period.
9. Changes to the Policy
We may update this Policy. The new version is published on the site with the effective date. For material changes we will notify Users via the Platform notification system. The current version is always available at https://affiliateprogramos.com/privacy.
10. Contact
For questions about personal data processing, contact us via the built-in support system: “Dialogs” → “Message the administration”.