LEGAL
Privacy Policy
Last updated: June 11, 2026
1. What this policy covers
This policy explains what data Rolinko collects, why it is collected, and who it is shared with. Rolinko is an affiliate-tracking platform, so some data collection — click tracking and order attribution — is core to how the product works rather than optional analytics.
2. Data we collect
Account data: your name, email address, and a hashed password (we never store passwords in plain text). Creators additionally provide profile data such as a bio, avatar, social links, and a storefront slug.
Click and tracking data: when a shopper clicks an affiliate link, we record a click event that includes a hashed IP address, device and browser information, approximate location, referrer, and marketing parameters (such as UTM tags). On connected brand storefronts, our tracking script records similar touchpoint data so orders can be attributed to the right creator.
Order data: for brands with a connected Shopify store, we receive order webhooks containing order totals, line items, discount codes used, and attribution identifiers. This is used to calculate creator commissions.
We do not collect payment card numbers. Purchases happen on the retailer or brand checkout, not on Rolinko.
3. Cookies
Session cookie: keeps you signed in (JSON Web Token, up to 30 days).
Attribution cookie: set when a shopper arrives via a creator link on a connected store, so a later purchase can be credited to that creator. The attribution window defaults to 30 days and is configured per store.
We do not run third-party advertising cookies.
4. How we use data
To operate creator storefronts and dashboards; to attribute orders to creators and calculate commissions (including reversals on refunds); to show creators and brands analytics about their own links, codes, and sales; to secure the platform and detect attribution fraud; and to communicate with you about your account.
5. Who data is shared with
Brands see order and commission data for sales attributed through their own store, including which creator drove the sale. Creators see aggregated performance data for their own links and codes. Shoppers are identified to brands and creators only through attribution data, not by name.
Service providers that run the platform: Vercel (hosting), Neon (database), Mux (video streaming), Stripe (payment infrastructure), and Shopify (store integration for connected brands). Each receives only the data needed to provide its service.
We do not sell personal data.
6. Data retention
Account data is kept while your account is active. Click events, touchpoints, and order records are retained because they are the audit trail behind commission payments. If you delete your account, we remove profile data and retain only what is needed for financial records and fraud prevention.
7. Security
Passwords are hashed, shopper IP addresses are hashed before storage, webhooks from Shopify and Mux are signature-verified, and all traffic is served over HTTPS. No system is perfectly secure, but we design for least data and verifiable inputs.
8. Your rights
You can access and update your profile data from your dashboard settings. To request a copy of your data, correct something you cannot edit yourself, or delete your account, contact us and we will handle it.
9. Changes to this policy
Rolinko is an early-access product and this policy will evolve with it. Material changes will be posted here with an updated date.
10. Contact
Privacy questions or requests? Reach us through the contact page. The rules that govern use of the platform are in the Terms of Service.