Privacy Policy

Last updated: 11 March 2026

1. Who We Are

Tapref (“we”, “us”, “our”) operates the affiliate marketing platform at app.tapref.com. We act as the data controller for personal data collected through our platform. We serve a global audience and comply with applicable data protection laws including the EU/UK GDPR, CCPA, and other regional regulations.

Contact: privacy@tapref.com

2. Data We Collect

Account Data (Developers & Affiliates)

  • Name, email address
  • Role (developer or affiliate)
  • Account creation date

Financial Data

  • Stripe Connect account ID (affiliates)
  • Commission amounts, payout history, and transaction records
  • Subscription event data (revenue amounts, product IDs, currencies)

Technical & Tracking Data

  • IP address hashes — we hash IP addresses before storage; we do not store raw IPs
  • Device fingerprints — hashed device identifiers for attribution
  • Browser user agent strings
  • Country of origin (derived from IP by Cloudflare)
  • Referrer URLs
  • Click timestamps and attribution data

Data We Do Not Collect

  • We do not collect end-user (subscriber) personal data directly — we only receive anonymised event data from developer integrations
  • We do not use third-party advertising cookies

3. Lawful Basis for Processing

We process personal data under the following lawful bases under UK GDPR:

PurposeLawful Basis
Account creation & managementContract performance (Art. 6(1)(b))
Commission calculation & payoutsContract performance (Art. 6(1)(b))
Fraud detection & preventionLegitimate interest (Art. 6(1)(f))
Click & attribution trackingLegitimate interest (Art. 6(1)(f))
Legal & tax compliance (HMRC)Legal obligation (Art. 6(1)(c))
Service communicationsLegitimate interest (Art. 6(1)(f))

4. How We Use Your Data

  • To operate the affiliate platform and process commissions
  • To attribute subscription events to affiliate referrals
  • To detect and prevent fraud (click fraud, self-referral, cookie stuffing)
  • To process payouts via Stripe Connect
  • To communicate service updates and payout notifications
  • To comply with legal and tax obligations
  • To maintain platform security and prevent abuse

5. Who We Share Data With

We share personal data only with the following categories of recipients:

RecipientPurposeLocation
Stripe, Inc.Payment processing & payoutsUS (SCCs in place)
Supabase, Inc.Database hosting (EU region)EU (DPA in place)
Cloudflare, Inc.CDN, Workers, edge processingGlobal (SCCs in place)
Resend, Inc.Transactional email deliveryUS (SCCs in place)

We do not sell personal data. We do not share data with advertisers or data brokers.

6. International Transfers

Some of our service providers are based outside the UK. Where personal data is transferred to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the UK ICO, or the provider's participation in a recognised certification scheme.

7. Data Retention

Data CategoryRetention Period
Account dataDuration of account + 12 months after deletion
Financial records (commissions, payouts)6 years (HMRC requirement)
Click & attribution data13 months
IP hashes & device fingerprints13 months
Fraud detection logs24 months

8. Your Rights

Under UK GDPR, you have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your data (subject to legal retention requirements)
  • Restriction — request that we limit processing of your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest

To exercise any of these rights, email us at privacy@tapref.com. We will respond within 30 days.

9. Cookies & Tracking Technologies

We use the following cookies:

CookiePurposeDuration
authjs.session-tokenAuthentication session30 days

We do not use analytics cookies, advertising cookies, or third-party tracking pixels. Affiliate link clicks are tracked server-side without setting cookies on end-user devices.

10. Automated Decision-Making

We use automated systems for fraud detection. These systems analyse patterns such as click-to-install timing, geographic consistency, device install counts, and refund rates to flag potentially fraudulent activity.

Automated fraud checks may result in a commission being blocked (for self-referral or high refund rates) or flagged for manual review. You have the right to request human review of any automated decision that significantly affects you by contacting privacy@tapref.com.

10b. Device Fingerprinting & PECR

Under the UK Privacy and Electronic Communications Regulations (PECR), accessing information stored on a user's device (including device fingerprinting) requires consent unless it is strictly necessary for the service requested.

Our SDK collects device identifiers for attribution purposes. App developers integrating our SDK are responsible for obtaining appropriate consent from their end users before the SDK transmits device data. We provide configuration options to disable fingerprint collection where consent is not obtained.

11. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect and how it is used
  • Right to request deletion of your personal information
  • Right to opt-out of the sale of personal information — we do not sell your data
  • Right to non-discrimination for exercising your rights

12. Complaints

If you are unhappy with how we handle your data, please contact us first at privacy@tapref.com. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction:

  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • EU: Your local Data Protection Authority
  • UAE: UAE Data Office — dataoffice.ae

13. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by posting a notice on our platform. The “last updated” date at the top reflects the most recent revision.