Privacy Policy
Effective July 5, 2026
This Privacy Policy explains how affixo collects, uses, discloses, retains, and protects personal information, and the rights available to individuals under Québec’s Law 25, Canada’s PIPEDA, and — where applicable — the GDPR and CCPA/CPRA.
1. Introduction and Scope
Unleashed Labs Inc, doing business as affixo (“affixo,” “we,” “us,” or “our”), a company based in the Province of Québec, Canada, provides an affiliate- and referral-program management platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information (also called “personal data”), and describes the rights available to individuals.
This Policy is written to meet the requirements of Québec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and — for individuals in those regions — the EU/UK GDPR and the California CCPA/CPRA.
Our two roles.
- When we handle personal information about our customers, their team members, and visitors to our own websites, we act as the organization responsible for it (a “controller”).
- When our customers use the Service to run their programs, we handle personal information about their affiliates and tracked visitors on their behalf — as a service provider / processor. For that information, our customer is the responsible organization, and this Policy describes our practices as their service provider. If you are an affiliate or a tracked visitor, please also review the privacy policy of the business whose program you interacted with.
2. Person in Charge of the Protection of Personal Information
We have designated a person responsible for the protection of personal information (a “privacy officer,” as required by Law 25). You may contact them for any privacy question or to exercise your rights:
Fer Patel, Founder — Chief Privacy Officer
Unleashed Labs Inc (doing business as affixo), Côte-Saint-Luc, Québec, Canada
Email: privacy@affixo.dev
3. Personal Information We Collect
A. Information you provide (as our customer / account holder):
- Identification and contact details — name, business name, email address, and any profile details.
- Account and security data — credentials, single-sign-on identifiers, and settings.
- Billing information — plan, and payment details processed by Stripe (we receive limited data such as card brand and last four digits, not the full card number).
- Communications — messages you send us for support or otherwise.
B. Information we process on our customers’ behalf (as service provider):
- Affiliate and referral records that our customer uploads or generates — names, email addresses, referral codes, campaign membership, and payout details (e.g., PayPal, Wise, or cryptocurrency identifiers) that the customer chooses to store.
- Tax-form data that affiliates submit (e.g., legal name, country, and only the last four digits of a tax identification number).
- Tracking and attribution data collected through the affixo tracking script, links, and pixels — IP address, user-agent and device/browser information, referring URL, pages and events, click and conversion events, and attribution cookies/identifiers.
C. Information collected automatically (as controller, for operating the Service):
- Technical and usage logs — IP address, device and browser data, timestamps, and actions taken in the Service, for security, diagnostics, and product analytics.
- Cookies and similar technologies used on our own websites and dashboard (see Section 6).
We do not intentionally collect special/sensitive categories of personal information and ask that you not submit them through the Service.
4. How We Collect Personal Information
We collect personal information: (a) directly from you when you register, subscribe, or communicate with us; (b) automatically through the Service and our tracking technologies; and (c) from third parties, such as our payment processor (Stripe), authentication provider, and platforms you connect (for example, when a connected store reports a conversion).
5. Why We Use Personal Information (Purposes and Legal Bases)
We use personal information to:
| Purpose | Examples | GDPR legal basis |
|---|---|---|
| Provide and operate the Service | Account creation, tracking, attribution, commission calculation, reporting | Performance of a contract |
| Billing and payments | Charging fees, invoices, dunning | Performance of a contract |
| Security and fraud prevention | Detecting invalid clicks, self-referral, and abuse; risk and affiliate-health scoring | Legitimate interests / legal obligation |
| Support and communications | Responding to requests, sending service messages | Performance of a contract / legitimate interests |
| Product improvement and analytics | Diagnostics, aggregated usage analysis | Legitimate interests |
| Marketing (optional) | Product updates and offers, where permitted | Consent (CASL / GDPR) |
| Legal and compliance | Recordkeeping, responding to lawful requests | Legal obligation |
Where we act as a service provider, we process the relevant personal information only to provide the Service to our customer and on their documented instructions, and not for our own independent purposes.
6. Cookies and Tracking Technologies
We and our customers’ programs use cookies and similar technologies. The most significant is first-party attribution tracking: when a visitor clicks an affiliate link, the Service may set a first-party cookie or identifier to attribute a later conversion to the correct affiliate. The Service may also honour pre-existing attribution cookies from other affiliate tools during a migration (“legacy cookie bridge”). We also use limited cookies necessary to operate the dashboard and to understand product usage.
Advertising and data-partner cookies. On our own website we use OSPRY, a third-party visitor-recognition service. Where you consent, cookies and similar technologies may be used by our online data partners or vendors to associate your activity with other personal information they or others have about you, including by association with your email or online profiles, and we (or service providers on our behalf) may then send communications and marketing to those emails or profiles. These technologies load only after you accept them through our consent banner, and only for visitors in the United States. You may opt out of this advertising at any time via Your Privacy Choices.
You can also control cookies through your browser settings and, where offered, through the cookie preferences on the relevant website. We present a consent banner that blocks non-essential and advertising cookies until you accept them, and we support the Global Privacy Control (GPC) signal for applicable opt-outs where required by law.
7. Disclosure of Personal Information; Subprocessors
We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We disclose personal information only:
- to service providers / subprocessors that help us operate the Service, under contracts that limit their use of the information;
- to payment and connected platforms you use;
- as required by law or to protect rights and safety; and
- in connection with a corporate transaction (merger, acquisition, or asset sale), subject to this Policy.
Current subprocessors:
| Subprocessor | Purpose | Processing region |
|---|---|---|
| Supabase | Database, authentication, file storage | US (N. Virginia) |
| Vercel | Application hosting and delivery | US (primary); global edge delivery |
| Stripe | Payments, billing, and connected-account tracking | US / global |
| Resend | Transactional and broadcast email | US |
| WorkOS | Administrator single sign-on (SSO) | US |
| Sentry | Error monitoring and diagnostics | EU (Germany) |
8. Cross-Border Transfers
The Service and our subprocessors may store or process personal information outside Québec and Canada, including in the United States and the European Union. Before transferring personal information outside Québec, we conduct the assessment required by Law 25 and put appropriate protections in place. For transfers of EU/UK personal data, we rely on recognized transfer mechanisms such as the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework, as applicable. You may contact our privacy officer for more information about the safeguards we use.
9. Retention
We keep personal information only as long as necessary for the purposes described in this Policy or as required by law. In general: account and billing records are kept for the life of the account and for a reasonable period afterward to meet legal, tax, and audit obligations; personal information we process on a customer’s behalf is retained per that customer’s configuration and deleted or returned after termination within a reasonable period; and logs are kept for a limited diagnostic window.
10. Security Safeguards
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls and role-based permissions, and monitoring. Tax identification numbers are stored in truncated form (last four digits only). No method of transmission or storage is completely secure; we cannot guarantee absolute security. If a confidentiality incident presents a risk of serious injury, we will notify affected individuals and the relevant authorities (including the Commission d’accès à l’information under Law 25 and, where applicable, other regulators) as required by law, and maintain a register of incidents.
11. Your Rights
Depending on where you live and our role, you may have some or all of the following rights. If your personal information is processed by us on a customer’s behalf, we will refer your request to that customer (the responsible organization) and assist them as their service provider.
- Québec (Law 25): access; rectification; withdrawal of consent; de-indexing / cessation of dissemination and, in certain cases, deletion; portability of computerized personal information in a structured, commonly used format; information about automated decision-making and the right to submit observations (see Section 12); and the right to complain to the Commission d’accès à l’information (CAI).
- Canada (PIPEDA): access to your personal information and to correct it; and the right to complain to the Office of the Privacy Commissioner of Canada (OPC).
- EU/UK (GDPR): access, rectification, erasure, restriction, portability, objection, rights related to automated decision-making, the right to withdraw consent, and the right to complain to a supervisory authority.
- California (CCPA/CPRA): to know/access, delete, correct, opt out of “sale”/“sharing” (we do neither), limit use of sensitive personal information, and non-discrimination for exercising your rights.
How to exercise your rights. Contact our privacy officer at privacy@affixo.dev. We will verify your identity and respond within the timeframes required by applicable law (for Law 25 and PIPEDA, generally within 30 days). These rights are free to exercise, subject to limited exceptions permitted by law.
12. Automated Decision-Making
The Service uses automated processing to help detect fraud and abuse (for example, invalid-click and self-referral detection) and to classify affiliate engagement / health. These processes may influence how a program treats an affiliate. Where a decision is based exclusively on automated processing and produces effects concerning an individual, that individual may, as permitted by Law 25 and the GDPR, be informed of it, obtain the reasons and principal factors, request human review, and submit observations. Requests may be directed to our privacy officer or, where we act as service provider, to the relevant customer.
13. Children’s Privacy
The Service is not directed to children and is intended for business users. We do not knowingly collect personal information from a child under the age of 14 (the threshold under Québec law; other laws may apply a different age). If you believe a child has provided us personal information, contact our privacy officer and we will delete it.
14. Marketing Communications (CASL)
We send service and transactional messages necessary to operate your account. We send optional marketing messages only where permitted, and every commercial electronic message includes a working unsubscribe mechanism and accurate sender identification, consistent with CASL and other applicable laws. You can withdraw consent to marketing at any time using the unsubscribe link or by contacting us.
15. Changes to This Policy
We may update this Policy. For material changes we will provide notice (by email or in-product) and update the “Last updated” date above; where required, we will obtain consent. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
16. Contact and Complaints
For any privacy question, to exercise a right, or to make a complaint, contact:
Fer Patel, Founder — Chief Privacy Officer · Unleashed Labs Inc
Côte-Saint-Luc, Québec, Canada · Email: privacy@affixo.dev
You may also complain to a regulator:
- Commission d’accès à l’information du Québec (CAI) — for Law 25 matters.
- Office of the Privacy Commissioner of Canada (OPC) — for PIPEDA matters.
- Your local EU/UK supervisory authority or the California Privacy Protection Agency, as applicable.
Questions about privacy, or want to exercise a right? Email privacy@affixo.dev.