Legal
Privacy policy
Last updated 28 September 2026
In plain English
This page is about the data we hold on you, our customer. Your name, your email, your company, your subscription. Your affiliates' data is a different thing: that is yours and we hold it for you, under the data processing agreement. We do not sell data, we run no advertising trackers, and the product stores nothing in your browser that needs your consent, which is why you have never seen a cookie banner here.
This notice covers AffiliateRail only. RecruitAffiliates.ai has its own privacy notice, which explains how it uses YouTube data.
1. Who is responsible
For this website and for your AffiliateRail account, the controller is James Barkway trading as AffiliateRail, a sole trader established in England and Wales. Office 4382, 182-184 High Street North, London, E6 2JA, United Kingdom. Contact support@affiliaterail.com.
There is no data protection officer, because the business is not required to appoint one. The address above reaches a person who can act.
2. The two hats, because it changes who you ask
- Your own data: we are the controller. Your account, your subscription, your invoices, your support emails. This policy covers it.
- Your program's data: you are the controller and we are the processor. Your affiliates, the people who applied, and the customers your program referred. You decide why it is held and we hold it for you, under the data processing agreement, which is part of the terms and is already in force.
If you are an affiliate or a referred customer and you found this page looking for your own data, the data request page is the one you want. It explains who to ask and routes you there.
3. What we collect about you, and why
| What | Why | Lawful basis |
|---|---|---|
| Name, email, company, country | To create your account, sign you in and reach you about it | Performance of a contract |
| Your plan, subscription and payment history | To bill you, apply your plan's limits and answer a billing question | Performance of a contract |
| Your billing address and the country your card was issued in | To work out the right tax and to keep the evidence tax law requires | Legal obligation |
| Two-factor secrets and backup codes, encrypted | To protect your account | Performance of a contract |
| What you send us by email | To answer you | Legitimate interest in replying |
| Which screens of the dashboard get used | To know what to fix. Counted without identifying anyone, see section 6 | Legitimate interest in a working product |
| Server logs: IP address, browser, the page requested | Security and keeping the service up | Legitimate interest |
| Error reports when something breaks | To fix it. Personal data is stripped before the report is sent | Legitimate interest |
We never see your card number. Card details go straight into Stripe's own checkout. We get a confirmation, the last four digits and the card brand.
4. Signing in with Google or Apple
If you sign in that way, the provider tells us your name, your email address and that the sign-in succeeded. We do not get your password and we do not get access to anything else in your account with them. You can also use an email address and a password instead.
5. What we do not do
- We do not sell personal data, and we never have.
- We do not use your data, or your program's data, to train an AI model.
- We run no advertising trackers and no cross-site trackers, on this site or in the product.
- We do not buy data about you from anyone.
- We do not profile you, and nothing here makes an automated decision with a legal effect on you.
6. Cookies, and what is actually in your browser
Specific, because a vague answer here is worth nothing.
This marketing site
Since 26 August 2026 this site counts visits, so we can tell which pages are worth keeping and which of the places we write about AffiliateRail actually send anyone. It asks first. Nothing is stored in your browser until you answer the banner, and if you say no we count the visit with nothing stored at all: no cookie, no local storage, no session storage, and identity from a hash worked out on the analytics provider's servers rather than a marker kept on your device. Saying no does not cost you anything and does not change the site.
If you say yes, the analytics keeps a cookie so that a visit here and a later signup at app.affiliaterail.com are recognisably the same person rather than two strangers.
Your answer is itself kept in one cookie, rail.consent, which is how we avoid asking you twice across the site and the dashboard. Keeping a record of a preference you expressly gave us is the one thing the law does not ask consent for. You can change it from Cookie choices in the footer of any page.
Fonts are loaded from Google Fonts, which means Google receives your IP address when the font file is fetched.
The dashboard at app.affiliaterail.com
Three things, all of them needed to make it work:
- Your session, so you stay signed in.
- Which program you are looking at, if you run more than one.
- Your security settings, such as a device you have already verified.
Since 9 September 2026 there is a fourth: the live chat in the bottom corner. Crisp keeps its own record of the conversation in your browser, so a reply you have not read yet is still there when you come back. That is the chat working rather than the chat watching you, which is why it is not behind the banner. It is told nothing about you until you open it, and if you never open it, nothing about you is ever sent. Open it and it is given your name, your email address, your plan, your program and the screen you were on. Your affiliates never see it: the partner portal does not load it at all.
Product analytics follows the answer you gave the banner, and refusing it leaves the dashboard working exactly as it did. Refuse and it runs in cookieless mode: no cookie, no local storage, no session storage, and no profile for anonymous traffic, with visits counted from a hash computed on the analytics provider's servers rather than an identifier kept in your browser.
Two things are true either way, and they are the ones that matter on a screen showing your affiliates' details. Autocapture is off, so the text of whatever you click is never collected. And the session recording is fully masked: it records where the pointer went, what was clicked and where the page was scrolled, and every piece of text and every form field is blanked before it leaves your browser. Nobody here can read an affiliate's email address off a recording, because the recording never contained it.
The partner portal your affiliates use
Their session and their chosen language. Nothing else.
The banner, and why it looks the way it does
For most of 2026 there was no banner here, because there was nothing stored to ask about. That changed on 26 August, when this site started counting visits, and we said on this page that if it ever changed we would ask first. This is us asking.
It is built the way the guidance actually asks for rather than the way most sites do it. Accept all and Reject all sit side by side, the same size and the same colour, so neither is the easy answer. Nothing is pre-ticked. The detail is one click away, never instead of the choice. It is a bar at the bottom with no overlay, so you can read the whole page and ignore it. Nothing is written to your browser before you answer, and you can change your mind at any time from Cookie choices in the footer.
7. Who else sees your data
The companies that process data on our behalf are listed at affiliaterail.com/subprocessors, with what each does, where it processes and the transfer mechanism. We give 30 days' notice before adding one.
Otherwise we share personal data only where the law requires it, or where we have to defend a legal claim.
8. Sending data outside the UK
Nearly all of it goes to the United States. Our database, our hosting, our email and our analytics all process there. The one exception is the live chat in the dashboard, which is run by a French company and stores its messages inside the EU. Nothing is processed inside the UK.
Each of those transfers relies on a mechanism UK law recognises: the UK International Data Transfer Addendum, the EU Standard Contractual Clauses with the UK Addendum, or a provider's certification under the UK Extension to the EU-US Data Privacy Framework. Which one applies to which provider is in Annex 3 of the data processing agreement, provider by provider, with the date each was checked. Two entries there say "not confirmed" rather than naming a mechanism we have not seen, and both are being chased. The live chat needs no mechanism at all, because the EEA is covered by the UK adequacy regulations.
9. How long we keep it
| What | How long | Why |
|---|---|---|
| Your account | While it is open, then 30 days | Long enough to undo a mistake |
| Invoices and payment records | 5 years after the 31 January filing deadline for that tax year | HMRC record keeping |
| Tax location evidence: billing country, card country, IP country | 10 years | Required by the EU VAT One Stop Shop rules. It is the longest period on this page and it is not ours to shorten |
| Support emails | 3 years | Long enough for a billing dispute |
| Server logs | Our hosting provider's own retention | Security. We do not add to it or query it |
| Error reports | 90 days | Fixing things |
Your program's data is kept on a different schedule, which is described in the data processing agreement and set out in full in the retention schedule we will send you on request.
10. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how it is used, hand it to someone else in a machine-readable form, or withdraw consent where consent was the basis.
Email support@affiliaterail.com and we respond within one month. It is free.
Some records survive a deletion request because the law requires us to keep them, and the two rows above with a legal basis are the ones that do. Where that applies, we keep the record, use it only for that purpose, and tell you which records and why rather than quietly keeping them.
You can also complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but you do not have to.
11. If there is a breach
If a breach is likely to be a risk to your rights, we tell you without undue delay, and we tell the ICO within 72 hours where the law requires it. Where your program's data is involved, you are the controller and the data processing agreement sets out what we tell you and how quickly, which is within 48 hours of finding out.
12. Children
AffiliateRail is for businesses and is not for anyone under 16. We do not knowingly collect data about children. If you think we have, tell us and we will delete it.
13. RecruitAffiliates.ai
This notice covers AffiliateRail only. RecruitAffiliates.ai has its own privacy notice at recruitaffiliates.ai/privacy. That is where it explains how it uses YouTube API Services and how long it keeps YouTube data.
14. Changes
Changes are posted here with a new date at the top. For anything material we email you first.