Privacy Policy
Last updated: 27 July 2026
Ambassly provides affiliate tracking, a commission ledger, and payout tooling for companies and their affiliates. This policy explains what we process and why. It is written to be genuinely readable, not to bury the important parts — but it is not a substitute for legal advice.
What we collect
- Account data: your name and email for authentication, held in our authentication database.
- Program & ledger data: programs, affiliates, referrals, commissions, and payouts you create or that result from tracked conversions.
- Tracking data: when the tracking snippet runs on a merchant’s site, we record clicks with a referral code. IP addresses and user-agent strings are stored only as one-way hashes, never in the clear.
- Email addresses of buyers are stored only as one-way hashes, used to detect self-referrals and to match refunds.
- Cookies: a strictly-necessary session cookie for signing you in, and a first-party referral-code cookie the tracking snippet sets on the merchant’s site so a later purchase can be attributed. We don’t use third-party advertising or cross-site-tracking cookies.
Why we collect it, and our legal basis
We process this data to run the affiliate program you configured (contract), to keep tracking and attribution accurate (legitimate interest), to bill you (contract), and to comply with tax and accounting law where applicable (legal obligation). We don’t use your data for anything beyond running Ambassly.
Payments
Subscription billing is processed by Stripe. We store a Stripe customer identifier and your current plan; we never store card details.
Transactional messages (sign-in links, receipts) are required to use the service. Notification emails (such as payout alerts) include a one-click unsubscribe link in every message, and you can unsubscribe at any time at /unsubscribe.
Subprocessors
We use the following third-party processors to run Ambassly. Each processes data only as needed to provide their service. We don’t sell your data, and we don’t share it for advertising.
- Stripe — subscription billing and payment processing.
- Resend — transactional and notification email delivery.
- Supabase — authentication database and application data storage.
- Sentry — application error monitoring and performance diagnostics.
We may also disclose data if legally required to (e.g. a valid court order), or to protect the rights, safety, or property of Ambassly, our users, or the public.
Data retention & deletion
Commission and payout records are financial records and are retained for accounting integrity. When an account is closed we archive rather than erase these ledgers; the audit trail is append-only. Contact us to request account archival. Data that isn’t part of the financial audit trail (account data, session data) is deleted within 30 days of a deletion request.
Your rights
Wherever you’re located, you can ask us to: access the personal data we hold about you; correct it if it’s wrong; delete what isn’t part of the financial audit trail; export it in a portable format; or object to / restrict certain processing. If you’re in the EU/UK, these are your rights under GDPR; if you’re in California, similar rights exist under the CCPA/CPRA. To exercise any of these, email [email protected] — we’ll respond within 30 days.
Children’s privacy
Ambassly is a B2B tool, not directed at children, and we don’t knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we’ll delete it.
International data transfers
Our infrastructure and subprocessors may process data outside your country of residence, including in the United States. Where required, we rely on standard contractual clauses or equivalent safeguards recognized under applicable data-protection law for these transfers.
Security
We use industry-standard measures — encryption in transit (HTTPS/TLS), access controls, and one-way hashing for sensitive tracking identifiers — to protect your data. No system is 100% secure, but we take reasonable steps appropriate to the sensitivity of what we hold.
Changes to this policy
We may update this policy as Ambassly evolves. The version at ambassly.com/privacy always governs, and we’ll update the “Last updated” date above when we make a change. For material changes, we’ll make reasonable efforts to notify active accounts by email.
Contact
Questions, requests, or complaints about this policy? Email [email protected].