Affluence
PrivacyTerms

Privacy Policy

Affluence is a business tool used by brands and their agencies to run creator affiliate programmes. This policy explains what we hold about creators, storefront visitors, Shopify buyers, and the people who use the product; why we hold it; and how to get it removed.

Who we are

Affluence is operated by Avenue Z Technology (“we”, “us”). A brand or agency that uses Affluence to run its programme is the controller of the creator data in its own workspace; we process that data on their behalf.

What we collect

About creators in a programme

  • Name and public social handles — the display name and the TikTok or Instagram handle a creator publishes, plus their public follower count.
  • Contact address — an email address, where the creator gave one to the brand when applying or enrolling. Managed outreach stores the address encrypted and keeps a one-way keyed reference for duplicate prevention, suppression, and verified account matching.
  • Sample shipping address — a creator’s name and delivery address when they request or accept a physical product sample. We use it only to create and fulfil that sample order with the programme’s connected merchant store.
  • Programme records — which campaigns they are enrolled on, the discount or affiliate code issued to them, when they enrolled, and whether partnership-ad access has been granted.
  • Performance and earnings — posts attributed to the programme and their public view counts, orders and revenue attributed to their code, and commission accrued and paid.

We do not collect creator phone numbers, payment card details, government identifiers, or private messages.

About people who use Affluence

An email address for sign-in, the workspace they belong to, and ordinary server logs (IP address, user agent, timestamps) kept for security and debugging.

About storefront visitors and Shopify buyers

  • Attribution events — the creator code, Affluence launch identifier, approved UTM fields, advertising click identifier, a pseudonymous session or client identifier, event time, user agent, a daily salted hash of the IP address, and sanitized landing and referring URLs. Unrecognized URL fields are discarded.
  • Storefront activity — page, product, cart and checkout event names; relevant product identifiers; and the Shopify privacy choices observed with the event. Affluence does not receive the raw browser event or checkout object.
  • Order records — Shopify order identifier and time, currency, totals, line items, discount codes, refunds, returns, and the limited attribution fields needed to connect an order to a creator or paid-social launch.

Our current Shopify order import does not request or store a buyer’s name, email address, telephone number, delivery or billing address, payment details, or IP address. Older raw order records, if any, remain subject to Shopify’s customer-redaction process described below.

Consent and opt-out

A creator can separately choose whether to receive relevant campaign invitations by email. Each managed invitation includes a one-click opt-out. An opt-out cancels messages still waiting to send and creates a global suppression so the same address is not re-added by a later import. Brands and agencies receive delivery totals and status, not an exportable contact database. Provider delivery IDs, bounce or complaint status, provenance, and the suppression receipt are retained without copying message bodies into the activity ledger.

On Shopify stores, the merchant controls its consent banner and privacy settings through Shopify. The Affluence theme attribution component starts only when Shopify reports that analytics, marketing and sale-of-data choices allow it. The Web Pixel runs within Shopify’s privacy-controlled pixel environment and records the consent snapshot supplied by Shopify. A visitor can change or withdraw those choices through the store’s privacy controls. Affluence does not sell storefront data or use it for automated decisions that have legal or similarly significant effects.

What we do not do

We do not sell personal data. We do not use it to train machine-learning models. We do not buy creator data from brokers, and we do not build profiles of people who are not enrolled in a programme run through the product.

Where it comes from

  • The brand or agency, when they enrol a creator or import an existing roster.
  • The creator, when they apply to a programme through a link the brand shared.
  • Connected platforms, where the brand has authorised the connection: Shopify (orders and refunds), TikTok and TikTok Shop, Meta, Snapchat, AppLovin, and partner platforms the brand already uses such as Growi and Refunnel.
  • The brand’s storefront, when its Affluence attribution components are active.

Why we use it

We use the minimum data needed to operate the programme requested by the brand: connect authorised accounts, enrol creators, fulfil samples, generate affiliate links and discounts, attribute orders, calculate commission, launch approved advertising, report performance, prevent fraud, secure the service, and answer privacy requests. We do not reuse connected platform data for an unrelated purpose.

TikTok data

Where a brand connects TikTok, we request only the access needed for the features they turned on, and we use it only for those features:

  • user.info.basic — a creator’s TikTok identifier, avatar and display name, so they can be recognised on their roster row.
  • user.info.profile — their @username, bio, verified status and profile link, to match a connected account against the handle already on the brand’s roster.
  • user.info.stats — follower, following, likes and post counts, which set the creator’s tier and the commission rate that follows from it.
  • video.list — the creator’s public posts with their publish date, view, like, comment and share counts, to count what they published for a campaign and report how it performed.
  • TikTok Shop affiliate orders and commission — to attribute sales to the creator who drove them and calculate what they are owed.
  • Advertising and reporting — where the brand runs Spark or Partnership Ads on creator posts, to launch those ads and report their spend and return.

Affluence does not request video.publish or video.upload, and never posts to a creator’s account. A creator may decline any individual permission at TikTok’s consent screen; Affluence records what was actually granted and simply does without the rest.

We retain TikTok data only while the connection is active. Disconnecting TikTok in Integrations deletes the TikTok-derived records for that workspace. We do not share TikTok data with any third party, and we do not use it for advertising to the creator.

Shopify data and privacy requests

Affluence subscribes to Shopify’s mandatory customers/data_request, customers/redact, and shop/redact topics. We verify Shopify’s signature before processing a request. A customer-data request creates a restricted report for a workspace owner or administrator. A valid customer-redaction request strips customer identifiers from affected legacy order payloads, and a shop-redaction request also destroys the store credential and disconnects the installation. We retain only a one-way hashed receipt and aggregate counts needed to prove that the request was handled.

We acknowledge valid Shopify callbacks immediately and complete the required action as soon as practicable, and no later than 30 days. A merchant can also disconnect Shopify from Affluence at any time; uninstall and redaction callbacks remove usable credentials even when the store is no longer connected.

Who we share it with

Only the brand and agency running the programme, and the vendors that host it: Supabase (database, United States), Vercel (application hosting), and the platform providers a brand enables, such as Shopify, TikTok, Meta, Snapchat, AppLovin, Stripe, Slack, and Resend for managed email delivery. A provider receives only what is needed for the feature the brand turned on. We disclose data to authorities only where legally required.

When a creator receives a physical sample, Affluence sends their name and shipping address to the brand’s connected Shopify store so the merchant can create and fulfil the order. Affluence does not send that address to advertising platforms.

Client and agency views

Affluence deliberately restricts what a brand-side viewer sees. Creator email addresses and other contact details are not loaded at all under the client view, and dashboards shared by link never contain them.

How long we keep it

  • OAuth handshake state is deleted when it expires and cannot be reused.
  • Pseudonymous storefront events and non-winning click events are kept for no more than 90 days. A winning click that explains a booked commission is kept with the financial record.
  • Creator shipping details are kept while an application, gifting enrolment, or sample fulfillment needs them. Application, sample and profile copies are scrubbed after a 30-day support period once that purpose ends. Delivery status, product and non-personal fulfillment dates may remain as programme records.
  • Programme, order, commission, payout, attribution-decision, audit and hashed compliance records are kept for the life of the workspace and then for seven years because they explain amounts owed and paid and our compliance actions.
  • Creator outreach routes are kept while the creator remains eligible and has not requested deletion. Suppression hashes and delivery or complaint receipts may remain as compliance records so an opted-out address is not contacted again.
  • Connected-platform credentials and provider-derived working data are deleted or made unusable when the connection is revoked, subject to the financial and compliance records described above.

A service-only nightly retention process enforces the short periods above and records only aggregate deletion counts. If a verified deletion request applies sooner, we act on the request rather than waiting for the schedule.

Security

Affluence uses encrypted transport, encrypted hosting and database services, tenant-scoped access controls, role-based views, encrypted provider credentials, signed webhook checks, and service-only retention and redaction functions. No internet service is risk-free; write to security@runaffluence.com if you believe data or an account has been compromised.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Creators can ask us directly even though the brand is the controller — write to privacy@runaffluence.com and we will respond within 30 days. Depending on where you live you may also have the right to object to processing or to complain to a data protection authority.

Storefront visitors may also use the merchant’s Shopify privacy controls or contact the merchant that operates the store. Merchants may send Shopify customer requests through the mandatory compliance webhooks or contact us directly. We do not discriminate against a person for exercising a privacy right.

Children

Affluence is not for anyone under 18. We do not knowingly enrol creators under 18, and we delete such records when we learn of them.

Changes

We will post any change on this page and update the date in the footer. Material changes will be sent to workspace owners by email.

Contact

Avenue Z Technology, 250 North Orange Avenue, #1250, Orlando, FL 32801, United States. Email privacy@runaffluence.com.

Affluence is operated by Avenue Z Technology. Last updated 16 August 2026.

Questions about this policy or a request about your data: privacy@runaffluence.com