AlgoRift Privacy Policy
This Privacy Policy explains how AlgoRift collects, uses, shares, and safeguards personal data across our marketplace, affiliate intelligence, and automated payout services for sellers, partners, and affiliates worldwide.
1. Overview
AlgoRift ("AlgoRift", "we", "our", or "us") provides marketplace discovery, partner analytics, and automated payout services for brands, agencies, and affiliates. We design our privacy program to meet and often exceed the requirements enforced by leading partner marketing platforms such as Levanta.io, PartnerBoost, WayWard, and ArcharAffiliates while preserving agility across development, test, and production environments.
This Privacy Policy describes the categories of personal data we collect, how we process and secure that data, the third parties with whom we share it, and the rights available to individuals under global regulations including GDPR, UK GDPR, ePrivacy, CCPA/CPRA, VCDPA, LGPD, and Australian Privacy Principles.
2. Definitions
- Account: A dedicated profile enabling access to the Platform, its APIs, and sandbox or production environments.
- Controller: The entity determining the purposes and means of processing personal data. AlgoRift acts as controller for core services and as processor where we handle data under our clients' instructions.
- Personal Data: Any information relating to an identified or identifiable natural person, including device identifiers and online profile data.
- Platform: AlgoRift marketplace, analytics dashboards, messaging hub, payout automation, and related APIs.
- Sensitive Data: Personal data subject to enhanced protection (e.g., government IDs, financial information, precise geolocation, demographic or biometric data) as defined by applicable laws.
- Services: The Platform and any professional services, onboarding, consulting, support, or beta features we provide.
- Usage Data: Metrics generated by interacting with the Platform, including device metadata, session logs, and event analytics.
3. Data We Collect
3.1 Identity & Contact Data
Includes names, usernames, job titles, company affiliation, addresses, phone numbers, email addresses, and account IDs required to provision access and facilitate communication.
3.2 Professional & Marketplace Data
Includes seller store details, affiliate vertical preferences, marketplace listings, campaign briefs, commission terms, and creative approvals similar to the data sets processed by Levanta.io and PartnerBoost for matchmaking purposes.
3.3 Financial & Transaction Data
Includes billing contacts, subscription information, payment card tokens, payout instructions, tax identifiers, commission schedules, and reconciliation records. Financial data is encrypted and managed in alignment with PCI DSS standards.
3.4 Authentication & Security Data
Includes hashed passwords, multi-factor tokens, API keys, OAuth tokens, role assignments, audit logs, and verification documents collected for Know Your Business (KYB) and Anti-Money Laundering (AML) compliance.
3.5 Usage, Device & Network Data
Includes IP addresses, browser fingerprints, operating system and device type, session timestamps, feature usage analytics, error logs, performance telemetry, and referral URLs.
3.6 Social & Integrations Data
Includes data retrieved with your consent from integrated services (e.g., Amazon Attribution, Google, Meta, TikTok, Pinterest, YouTube), such as profile IDs, campaign metrics, and engagement analytics required to validate affiliate eligibility and measure performance.
3.7 Support & Communications Data
Includes chat transcripts, ticket history, onboarding notes, feedback surveys, and recorded calls where permitted by law.
3.8 Sensitive Data
We limit collection of sensitive data and only process it where necessary for regulatory obligations (e.g., tax numbers for payouts) or with explicit consent.
4. Sources of Data
- Direct interactions: Form submissions, onboarding workflows, marketplace listings, contract negotiation, and support channels.
- Automated technologies: Cookies, SDKs, server logs, device fingerprinting, and security monitoring tools.
- Third-party integrations: Advertising platforms, ecommerce marketplaces, CRM systems, payment processors, and fraud prevention partners.
- Public sources: Government registries, professional directories, and publicly available social profiles to verify business credentials.
5. Legal Bases & Regional Grounds
We rely on different legal grounds depending on jurisdiction and context:
- Consent: For optional integrations, marketing communications, or sharing sensitive data.
- Contract performance: To deliver services under our Terms of Service, order forms, or partner agreements.
- Legitimate interests: To secure the Platform, analyze usage, improve products, prevent fraud, and benchmark program performance as common among platforms like WayWard and ArcharAffiliates.
- Legal obligations: To comply with tax, AML, sanctions, accounting, and consumer protection laws.
- Vital and public interests: To investigate suspected abuse or comply with lawful requests impacting safety.
For Australian users we follow the Australian Privacy Principles. For European users we operate under GDPR/UK GDPR. For US residents we comply with CCPA/CPRA, VCDPA, CPA, and other state privacy laws.
6. How We Use Data
- Provide, activate, and monitor access to the Platform across development, test, and production environments.
- Facilitate seller-affiliate matchmaking, campaign messaging, approval workflows, and payout calculations.
- Deliver analytics dashboards, benchmarking, and performance alerts while maintaining aggregated and anonymized insights.
- Process billing, collections, commissions, disbursements, refunds, and chargeback management.
- Verify compliance with policies, conduct fraud detection, and enforce agreements.
- Offer support, respond to inquiries, and manage incident response.
- Conduct research and product development, including beta testing.
- Send transactional, security, and marketing communications within your preferences.
7. Data Sharing & Disclosure
7.1 Service Providers
We engage vetted processors for hosting, cloud infrastructure, analytics, communications, payment operations, identity verification, and security monitoring. Each provider is bound by data processing agreements and confidentiality obligations.
7.2 Platform Counterparties
When you use collaborative features, we share necessary profile data, program terms, and performance metrics with counterparties (e.g., a seller and an affiliate) consistent with match-and-measure capabilities offered by competitors.
7.3 Corporate Transactions
If AlgoRift undergoes a merger, acquisition, investment, or restructuring, we may transfer personal data to involved parties subject to appropriate safeguards.
7.4 Legal & Compliance
We disclose data to regulators, tax authorities, law enforcement, or courts when legally required or necessary to protect rights, safety, or enforce agreements.
7.5 Aggregated or De-Identified Data
We may publish aggregated insights that no longer identify individuals, such as industry benchmarks or trend reports.
8. Cookies, Analytics & Tracking
We use cookies and similar technologies to authenticate users, remember preferences, analyze traffic, personalize experiences, and optimize campaigns.
- Strictly necessary: Required for security, session management, and core Platform features.
- Performance & analytics: Help us measure feature adoption and fix issues.
- Functional: Store preferences such as language or notification settings.
- Marketing: Power retargeting or attribution services, including integrations with advertising networks.
You can manage cookies via browser settings, consent banners, or by contacting us. Some features may not function without essential cookies.
9. Retention & Deletion
We retain personal data for as long as necessary to fulfill the purposes outlined in this policy, meet legal obligations, resolve disputes, and enforce agreements. Typical retention periods include:
- Account records: duration of the relationship plus up to seven years for audit and compliance.
- Billing and payout data: minimum of seven years to satisfy accounting and tax regulations.
- Usage logs: up to twenty-four months for security and analytics unless extended for investigations.
Upon termination or verified deletion request, we delete or anonymize personal data unless retention is legally required or technically necessary for legitimate business purposes.
10. Security & Incident Response
We maintain administrative, technical, and organizational measures comparable to those showcased by leading partner ecosystems:
- Encryption in transit and at rest for sensitive fields.
- Role-based access control, least privilege, and mandatory MFA for internal and external admin accounts.
- Continuous monitoring, threat detection, and automated anomaly alerts.
- Secure development lifecycle covering dev, test, and prod environments.
- Vendor risk assessments and annual penetration testing.
We investigate potential incidents promptly. If an incident materially affects your data, we notify affected customers and regulators as required, outlining remediation steps.
11. International Transfers
AlgoRift operates globally using infrastructure located in Australia, the United States, the European Union, and other regions. When transferring personal data internationally we implement safeguards such as Standard Contractual Clauses, UK Addenda, and intra-company agreements. We also review local data residency requirements and offer regional data hosting where feasible.
12. Your Privacy Rights
Depending on your jurisdiction, you may exercise the following rights:
- Access: Request confirmation whether we process personal data about you and obtain a copy.
- Correction: Request updates to inaccurate or incomplete information.
- Deletion: Request deletion of personal data subject to legal exceptions.
- Restriction: Request temporary limitation of processing under certain circumstances.
- Portability: Receive data in a structured, commonly used format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Opt-out: Opt out of targeted advertising, sale, or sharing of personal data pursuant to CCPA/CPRA and similar laws.
- Withdraw consent: Withdraw consent at any time where processing relies on consent.
To exercise rights, contact us using the channels in section 16. We authenticate requests to prevent unauthorized access and respond within required timeframes.
13. Marketing Preferences & Communications
We send transactional communications (e.g., security alerts, payout notices) without requiring additional consent. Promotional messages are delivered based on your subscription preferences. You may opt out through email links, account settings, or by contacting us. We honor statutory opt-out requests such as Do Not Sell/Share signals and Global Privacy Control signals where required.
14. Children's Privacy
The Platform is not directed to individuals under 18, and we do not knowingly collect personal data from children. If we learn that a minor registered without verifiable parental consent, we will delete the account and related data.
15. Third-Party Links & Integrations
Our Platform contains links to external websites or services. We are not responsible for the privacy practices of third parties. Review their policies before sharing data. Integrations (e.g., payment processors, social platforms, CRMs) are subject to separate agreements and may collect data directly per their terms.
16. Changes to This Policy
We may update this Privacy Policy to reflect product developments, legal requirements, or industry best practices. Material updates will be communicated via email or in-app notices at least 30 days before they take effect. Continued use after the effective date signifies acceptance of the revised policy.
17. Contact
If you have questions or wish to exercise privacy rights, please contact:
- Email: privacy@algorift.io
- Support: https://underjungle.com/contact/
- Mail: Sweet Round Pty Ltd, 4 Selborne St, Mount Gravatt East QLD 4122, Australia