Legal

Privacy policy

Last updated 28 September 2026

In plain English

This page is about the data we hold on you, our customer. Your name, your email, your company, your subscription. Your affiliates' data is a different thing: that is yours and we hold it for you, under the data processing agreement. We do not sell data, we run no advertising trackers, and the product stores nothing in your browser that needs your consent, which is why you have never seen a cookie banner here.

This notice covers AffiliateRail only. RecruitAffiliates.ai has its own privacy notice, which explains how it uses YouTube data.

1. Who is responsible

For this website and for your AffiliateRail account, the controller is James Barkway trading as AffiliateRail, a sole trader established in England and Wales. Office 4382, 182-184 High Street North, London, E6 2JA, United Kingdom. Contact support@affiliaterail.com.

There is no data protection officer, because the business is not required to appoint one. The address above reaches a person who can act.

2. The two hats, because it changes who you ask

If you are an affiliate or a referred customer and you found this page looking for your own data, the data request page is the one you want. It explains who to ask and routes you there.

3. What we collect about you, and why

WhatWhyLawful basis
Name, email, company, countryTo create your account, sign you in and reach you about itPerformance of a contract
Your plan, subscription and payment historyTo bill you, apply your plan's limits and answer a billing questionPerformance of a contract
Your billing address and the country your card was issued inTo work out the right tax and to keep the evidence tax law requiresLegal obligation
Two-factor secrets and backup codes, encryptedTo protect your accountPerformance of a contract
What you send us by emailTo answer youLegitimate interest in replying
Which screens of the dashboard get usedTo know what to fix. Counted without identifying anyone, see section 6Legitimate interest in a working product
Server logs: IP address, browser, the page requestedSecurity and keeping the service upLegitimate interest
Error reports when something breaksTo fix it. Personal data is stripped before the report is sentLegitimate interest

We never see your card number. Card details go straight into Stripe's own checkout. We get a confirmation, the last four digits and the card brand.

4. Signing in with Google or Apple

If you sign in that way, the provider tells us your name, your email address and that the sign-in succeeded. We do not get your password and we do not get access to anything else in your account with them. You can also use an email address and a password instead.

5. What we do not do

6. Cookies, and what is actually in your browser

Specific, because a vague answer here is worth nothing.

This marketing site

Since 26 August 2026 this site counts visits, so we can tell which pages are worth keeping and which of the places we write about AffiliateRail actually send anyone. It asks first. Nothing is stored in your browser until you answer the banner, and if you say no we count the visit with nothing stored at all: no cookie, no local storage, no session storage, and identity from a hash worked out on the analytics provider's servers rather than a marker kept on your device. Saying no does not cost you anything and does not change the site.

If you say yes, the analytics keeps a cookie so that a visit here and a later signup at app.affiliaterail.com are recognisably the same person rather than two strangers.

Your answer is itself kept in one cookie, rail.consent, which is how we avoid asking you twice across the site and the dashboard. Keeping a record of a preference you expressly gave us is the one thing the law does not ask consent for. You can change it from Cookie choices in the footer of any page.

Fonts are loaded from Google Fonts, which means Google receives your IP address when the font file is fetched.

The dashboard at app.affiliaterail.com

Three things, all of them needed to make it work:

Since 9 September 2026 there is a fourth: the live chat in the bottom corner. Crisp keeps its own record of the conversation in your browser, so a reply you have not read yet is still there when you come back. That is the chat working rather than the chat watching you, which is why it is not behind the banner. It is told nothing about you until you open it, and if you never open it, nothing about you is ever sent. Open it and it is given your name, your email address, your plan, your program and the screen you were on. Your affiliates never see it: the partner portal does not load it at all.

Product analytics follows the answer you gave the banner, and refusing it leaves the dashboard working exactly as it did. Refuse and it runs in cookieless mode: no cookie, no local storage, no session storage, and no profile for anonymous traffic, with visits counted from a hash computed on the analytics provider's servers rather than an identifier kept in your browser.

Two things are true either way, and they are the ones that matter on a screen showing your affiliates' details. Autocapture is off, so the text of whatever you click is never collected. And the session recording is fully masked: it records where the pointer went, what was clicked and where the page was scrolled, and every piece of text and every form field is blanked before it leaves your browser. Nobody here can read an affiliate's email address off a recording, because the recording never contained it.

The partner portal your affiliates use

Their session and their chosen language. Nothing else.

The banner, and why it looks the way it does

For most of 2026 there was no banner here, because there was nothing stored to ask about. That changed on 26 August, when this site started counting visits, and we said on this page that if it ever changed we would ask first. This is us asking.

It is built the way the guidance actually asks for rather than the way most sites do it. Accept all and Reject all sit side by side, the same size and the same colour, so neither is the easy answer. Nothing is pre-ticked. The detail is one click away, never instead of the choice. It is a bar at the bottom with no overlay, so you can read the whole page and ignore it. Nothing is written to your browser before you answer, and you can change your mind at any time from Cookie choices in the footer.

7. Who else sees your data

The companies that process data on our behalf are listed at affiliaterail.com/subprocessors, with what each does, where it processes and the transfer mechanism. We give 30 days' notice before adding one.

Otherwise we share personal data only where the law requires it, or where we have to defend a legal claim.

8. Sending data outside the UK

Nearly all of it goes to the United States. Our database, our hosting, our email and our analytics all process there. The one exception is the live chat in the dashboard, which is run by a French company and stores its messages inside the EU. Nothing is processed inside the UK.

Each of those transfers relies on a mechanism UK law recognises: the UK International Data Transfer Addendum, the EU Standard Contractual Clauses with the UK Addendum, or a provider's certification under the UK Extension to the EU-US Data Privacy Framework. Which one applies to which provider is in Annex 3 of the data processing agreement, provider by provider, with the date each was checked. Two entries there say "not confirmed" rather than naming a mechanism we have not seen, and both are being chased. The live chat needs no mechanism at all, because the EEA is covered by the UK adequacy regulations.

9. How long we keep it

WhatHow longWhy
Your accountWhile it is open, then 30 daysLong enough to undo a mistake
Invoices and payment records5 years after the 31 January filing deadline for that tax yearHMRC record keeping
Tax location evidence: billing country, card country, IP country10 yearsRequired by the EU VAT One Stop Shop rules. It is the longest period on this page and it is not ours to shorten
Support emails3 yearsLong enough for a billing dispute
Server logsOur hosting provider's own retentionSecurity. We do not add to it or query it
Error reports90 daysFixing things

Your program's data is kept on a different schedule, which is described in the data processing agreement and set out in full in the retention schedule we will send you on request.

10. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how it is used, hand it to someone else in a machine-readable form, or withdraw consent where consent was the basis.

Email support@affiliaterail.com and we respond within one month. It is free.

Some records survive a deletion request because the law requires us to keep them, and the two rows above with a legal basis are the ones that do. Where that applies, we keep the record, use it only for that purpose, and tell you which records and why rather than quietly keeping them.

You can also complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but you do not have to.

11. If there is a breach

If a breach is likely to be a risk to your rights, we tell you without undue delay, and we tell the ICO within 72 hours where the law requires it. Where your program's data is involved, you are the controller and the data processing agreement sets out what we tell you and how quickly, which is within 48 hours of finding out.

12. Children

AffiliateRail is for businesses and is not for anyone under 16. We do not knowingly collect data about children. If you think we have, tell us and we will delete it.

13. RecruitAffiliates.ai

This notice covers AffiliateRail only. RecruitAffiliates.ai has its own privacy notice at recruitaffiliates.ai/privacy. That is where it explains how it uses YouTube API Services and how long it keeps YouTube data.

14. Changes

Changes are posted here with a new date at the top. For anything material we email you first.