Privacy Policy
Effective date: September 1, 2026
This Privacy Policy explains how Referly Technologies, LLC ("Referly," "we," "us," or "our") collects, uses, discloses, and protects personal data when you visit referly.so, create or use a Referly account, participate in a referral or affiliate program powered by Referly, or otherwise use our services (collectively, the "Services").
This policy should be read together with our Terms of Service. When we process personal data for a customer that operates a referral or affiliate program, our Data Processing Addendum also applies between Referly and that customer.
1. Who we are
Referly Technologies, LLC is a company established in the United States.
Referly Technologies, LLC
1207 Delaware Ave #3648
Wilmington, DE 19806
United States
support@referly.so
2. When Referly is a controller or processor
Referly's role depends on why personal data is processed.
Referly as a controller
Referly acts as a controller when we determine why and how personal data is processed. This generally includes processing for:
- Referly account administration and customer support;
- Referly's own subscriptions, billing, security, fraud prevention, legal compliance, and service improvement;
- Referly-wide affiliate accounts, profiles, marketplace or discovery features, and cross-program functionality; and
- Referly's own communications and marketing.
This Privacy Policy applies directly to those activities.
Referly as a processor
When a business, program owner, or agency uses Referly to operate a referral or affiliate program, that customer generally determines the purposes of the program and is the controller. Referly processes program data on the customer's instructions as its processor or subprocessor.
Program data can include affiliate applications and profiles, referral and conversion tracking, customer and transaction data, commissions, program communications, fraud-review signals, tax information, and payout information.
If your personal data was collected through a particular customer's referral or affiliate program, please review that customer's privacy notice and direct your privacy request to that customer. We will assist the customer with the request as required by our Data Processing Addendum and applicable law.
3. Personal data we collect
Depending on how you interact with the Services, we may collect the following categories of personal data.
Information you or a Referly customer provides
- Account and contact information: name, email address, login information, company name, role, website, and account preferences.
- Affiliate and profile information: profile details, social handles, program membership, application answers, uploaded files, and other information submitted through customer-configured forms.
- Support and communications: support requests, emails, feedback, and other messages sent to Referly or through the Services.
- Billing, payout, and tax information: billing address, transaction and payment status, payout destination, bank or payment account details, invoices, tax classification, tax identification information, and tax forms where the relevant feature is used.
- Business configuration information: program settings, integration settings, API and webhook configuration, and credentials a customer provides to enable an integration.
Please do not submit special-category or highly sensitive personal data through custom forms or support channels unless it is necessary, lawful, and expressly requested for an available feature.
Information collected from use of the Services
- Device and usage information: IP address, approximate location, browser, operating system, device type, language, screen or viewport information, pages viewed, timestamps, session identifiers, and diagnostic logs.
- Referral and attribution information: referral or affiliate identifiers, cookies or local-storage identifiers, landing and referring URLs, campaign parameters, advertising click identifiers, and click or conversion events.
- Network and fraud-review information: internet service provider or network information, proxy or VPN indicators, device signals, and information used to identify possible self-referrals, duplicate activity, abuse, or fraud.
- Program and transaction information: referred-customer identifiers and contact details, purchases, subscriptions, refunds, sales values, commissions, payout status, performance information, and related program events.
- API, integration, and webhook information: data received from or sent to customer-selected integrations and endpoints, together with delivery, retry, authentication, and audit logs.
- Connected-account information: social account identifiers and handles, profile information, account-verification status, OAuth access and refresh tokens, selected Google Analytics property identifiers, audience and performance metrics, and information derived from connected services.
Information from other sources
We may receive personal data from Referly customers and their websites, ecommerce and payment integrations, affiliates and other users, identity providers, publicly available sources, and service providers that help us operate the Services.
4. How we use personal data and our legal bases
Where the European Economic Area ("EEA") or United Kingdom data protection laws apply and Referly is the controller, we rely on the following legal bases:
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide and administer the Services | Create accounts, authenticate users, provide features, calculate subscriptions, deliver support, and send service notices | Performance of a contract or steps requested before entering a contract |
| Operate and protect Referly | Secure accounts and infrastructure, debug errors, prevent abuse and fraud, maintain logs, and enforce our terms | Legitimate interests in operating a secure and reliable service |
| Improve and understand the Services | Analyze product use, test features, measure performance, and improve usability | Legitimate interests in improving our products; consent where required for non-essential cookies |
| Process billing, payments, tax, and legal matters | Collect fees, facilitate payouts, keep required records, respond to lawful requests, and establish or defend legal claims | Contract, legal obligation, or legitimate interests, depending on the activity |
| Communicate with you | Respond to requests, send operational messages, and provide marketing where permitted | Contract, legitimate interests, or consent, depending on the message and local law |
| Provide Referly-wide profiles and discovery features | Operate affiliate profiles, discovery, marketplace, and cross-program functionality | Contract, legitimate interests, or consent where required |
Where Referly acts as a processor, the relevant customer determines the purpose and legal basis for the processing.
5. Referral and affiliate tracking
Referly enables customers to attribute visits, referrals, sales, subscriptions, refunds, and commissions to affiliates or referral partners. Tracking may use links, cookies, local storage, APIs, webhooks, or server-to-server integrations and may involve the technical, attribution, transaction, and fraud-review information described above.
The customer operating the program is responsible for providing appropriate notices, selecting a valid legal basis, and obtaining any consent required for tracking on its websites or services. Referly processes this data on the customer's behalf and according to the customer's configuration and instructions.
6. Google sign-in and connected Google accounts
Referly offers two distinct Google-related features: Google sign-in for affiliate dashboards and optional Google account connections for affiliate-profile verification and audience metrics.
Google sign-in
Program owners may configure Google sign-in for their affiliate dashboards by providing their own Google OAuth client ID and client secret. Referly stores these credentials so the configured sign-in feature can operate. A client secret is treated as a confidential integration credential and is not displayed to affiliates.
When an affiliate chooses to sign in with Google, Referly may receive limited authentication information made available by Google, such as a Google account identifier, name, email address, email-verification status, and profile image, depending on the scopes configured by the program owner. We use this information only to authenticate the affiliate, associate the sign-in with the relevant dashboard account, and protect the account.
Referly does not receive the affiliate's Google password through this sign-in feature.
YouTube and Google Analytics connections
An affiliate may separately choose to connect a YouTube channel or Google Analytics property to verify ownership of a channel or website and to add audience and performance information to the affiliate's Referly profile. Connecting an account is optional unless a particular program owner has made verified social or website information a condition of joining or participating in its program.
Depending on the feature selected, Referly requests read-only access to:
- YouTube (
youtube.readonly): channel identifiers, name, handle, profile image, description, subscriber count, total views, and video count; - YouTube Analytics (
yt-analytics.readonly): aggregate channel performance and audience metrics, which may include views, watch time, and audience demographic or geographic percentages; and - Google Analytics (
analytics.readonly): Google Analytics properties available to the affiliate and data for the property the affiliate selects, which may include active users, page views, engagement, top countries and cities, traffic sources and referrers, top pages, and device, browser, and operating-system breakdowns.
Referly uses this Google user data only to:
- verify ownership or authorized access to the connected channel or website;
- create and maintain the connected social or website profile;
- display selected aggregate audience and performance information to businesses whose programs the affiliate joins or applies to; and
- refresh the profile information while the connection remains active.
To support these features, Referly stores the OAuth access token and, where Google provides one, the refresh token associated with the connection. Referly also stores the selected account or property identifier and the profile, audience, and performance information retrieved from or derived from Google APIs.
We retain these credentials and connected-account data while the account remains connected and the feature is being provided. If the affiliate removes the connected account or deletes the Referly account, the corresponding active record is deleted. Residual copies in backups are deleted within 30 days. An affiliate may also revoke Referly's access through the security settings of the relevant Google account.
Referly does not receive the affiliate's Google password and does not use these permissions to access Gmail, Google Drive, contacts, private videos, or Google data outside the scopes disclosed during the connection flow. We do not sell Google user data, share it with advertising platforms or data brokers, use it for targeted advertising, or use it to develop, improve, or train generalized artificial-intelligence or machine-learning models.
Referly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. Cookies and similar technologies
We use cookies and similar technologies that are necessary to authenticate users, remember settings, maintain security, and operate the Services. We may also use analytics technologies to understand and improve product use.
Where required by law, we obtain consent before using non-essential cookies or similar technologies. You can manage cookies through the choices we make available and through your browser settings. Disabling necessary technologies may prevent parts of the Services from working.
Referral or affiliate tracking on a customer's website is controlled by that customer. Please consult the customer's privacy and cookie notices for information about its choices and legal basis.
8. How we disclose personal data
We may disclose personal data only as reasonably necessary for the purposes described in this policy, including to:
- Customers and authorized users: program owners, agencies, team members, and affiliates where necessary to operate a program or where the customer has configured that disclosure.
- Service providers and subprocessors: providers of hosting, databases, storage, analytics, email delivery, payment processing, and webhook infrastructure.
- Customer-selected integrations: ecommerce platforms, payment providers, APIs, and webhook endpoints selected or configured by a customer.
- Payment and financial providers: to facilitate subscriptions, commissions, payouts, refunds, fraud controls, and legally required checks. A provider may act as its own controller for processing it independently determines, such as regulatory compliance.
- Professional advisers and authorities: auditors, lawyers, insurers, regulators, courts, law enforcement, or other authorities where necessary or legally required.
- Business transaction participants: prospective buyers, successors, or counterparties in connection with a merger, financing, reorganization, acquisition, or sale of assets, subject to appropriate safeguards.
Our principal infrastructure and service providers currently include:
| Provider | Service | Primary processing region |
|---|---|---|
| Vercel | Application and website hosting | Germany |
| Supabase | Database and image hosting | Germany |
| Stripe | Subscription and payment processing | United States |
| Mailgun | Email delivery | United States |
| PostHog | Product analytics and feature flagging | European Union |
| DigitalOcean | Frankfurt-hosted webhook infrastructure using self-hosted Svix | Germany |
Referly does not sell personal data.
9. International data transfers
Referly is established in the United States, and personal data may be processed in the United States, the European Union, or other countries in which Referly's service providers operate. Those countries may have data-protection laws that differ from those in your country.
Where EEA or UK personal data is transferred to a country that is not recognized as providing adequate protection, we use a legally recognized transfer mechanism where required, such as the European Commission's Standard Contractual Clauses and, for UK transfers, the applicable UK transfer addendum or agreement. We may also rely on another lawful transfer mechanism available under applicable law.
Contact support@referly.so if you would like more information about the safeguards relevant to your personal data.
10. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. The relevant period depends on the type of data, the relationship, legal requirements, and whether the data is needed for security or a legal claim.
Customer Personal Data that Referly processes as a processor is deleted from active systems and residual backups within 30 days after the relevant Services end or after a valid deletion instruction, unless applicable law requires longer retention.
Account, billing, tax, security, and legal records that Referly processes as a controller may be retained for longer where needed for the purposes above. We may retain aggregated or de-identified information that no longer identifies an individual.
11. Your privacy rights
Depending on your location and applicable law, you may have the right to:
- request access to personal data about you;
- ask us to correct inaccurate or incomplete data;
- request deletion of personal data;
- restrict or object to certain processing, including direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where processing relies on consent, without affecting earlier processing;
- lodge a complaint with the data-protection authority in the country where you live or work, or where you believe an infringement occurred; and
- not be discriminated against for exercising an applicable privacy right.
To exercise a right concerning processing for which Referly is the controller, email support@referly.so. We may need to verify your identity and may ask for information needed to locate your data. You may also use an authorized agent where permitted by law.
If the request concerns data processed for a particular referral or affiliate program, please submit it to the program owner. Referly will assist that customer in responding.
12. Automated processing
Referly may use automated rules or signals to support security, fraud detection, recommendations, matching, and program administration. Referly does not make decisions in its role as controller based solely on automated processing that produce legal effects or similarly significant effects for an individual.
A program owner may configure rules that flag, hold, or reject referrals or rewards. In that context, the program owner determines the rule and its consequences, and Referly processes the relevant data on the program owner's behalf. Questions or challenges about such a decision should be directed to the program owner.
13. Security
We use administrative, technical, and organizational measures designed to protect personal data. These measures include access restrictions, secure transmission, logging and monitoring, vendor controls, and measures intended to maintain the availability and resilience of the Services. No system can be guaranteed to be completely secure.
If you believe your interaction with Referly is no longer secure, contact support@referly.so promptly.
14. Children
The Services are not intended for use by anyone under 18 years of age, and we do not knowingly allow a child to create a Referly account. If you believe that a child has provided personal data to Referly, contact support@referly.so. We will investigate and take appropriate steps, including deletion where required.
Referly customers must not knowingly use the Services to collect or process children's personal data unless they have a valid legal basis, provide all required notices, obtain any required authorization, and have agreed the processing with Referly where necessary.
15. Third-party services and links
The Services may link to or integrate with third-party websites and services. Those third parties determine their own privacy practices when acting independently of Referly. Their privacy notices, not this policy, govern that independent processing.
16. Changes to this policy
We may update this Privacy Policy to reflect changes to the Services, our practices, or applicable law. We will post the updated policy on this page and revise the effective date. Where required, we will provide additional notice of material changes.
17. Contact us
For questions, complaints, or requests concerning this Privacy Policy or Referly's privacy practices, contact:
Referly Technologies, LLC
1207 Delaware Ave #3648
Wilmington, DE 19806
United States
support@referly.so