Promio processes account data, Company data, Affiliate data, referral data, click data, Conversion data, payout data, invoice data, device data, usage data, and related information to provide the Service, prevent fraud, process payments, support users, improve the Service, and comply with law.
Users must not upload, send, or collect personal data through Promio unless they have the legal right to do so.
Companies are responsible for providing legally required notices and obtaining legally required consents for their websites, checkout flows, tracking integrations, cookies, pixels, webhooks, referral programs, and marketing activities.
Affiliates are responsible for complying with privacy, advertising, email, and platform rules that apply to their own promotional channels.
Promio may use third-party providers for hosting, analytics, communication, payment processing, fraud prevention, identity verification, tax compliance, payout processing, and other operational purposes.
16.1 Data Processing Agreement (Company customer data)
This section forms the data processing agreement ("DPA") between Promio and each Company and takes effect when the Company accepts these Terms or connects a store or integration. Where Promio processes personal data of a Company's own customers, prospective customers, or site visitors (for example order email, name, order totals, order identifiers, referral codes, and related tracking data received through a store integration such as Shopify or WooCommerce), the Company is the data controller and Promio is the data processor.
Scope and purpose. Promio processes that customer personal data only on the Company's documented instructions and only to provide the Service — attributing referrals and conversions, calculating and reversing commissions, preventing fraud, generating reports and invoices, and meeting related legal obligations. Promio does not sell customer personal data and does not use it for its own independent purposes or for advertising.
Duration and data subjects. Processing lasts for the term of the Company's use of the Service, subject to the retention periods in Promio's Data Retention Policy. Data subjects are the Company's customers, prospective customers, and site visitors; data categories are limited to what is described above.
Security. Promio maintains appropriate technical and organizational measures, including encryption of data in transit, encrypted backups, access controls limiting staff access, an append-only audit log of sensitive actions, and a documented incident response process.
Sub-processors. Promio uses vetted sub-processors (including its hosting provider, Stripe for payments/payouts, and Brevo for transactional email), each under their own data protection terms, and remains responsible for their compliance. Promio will inform Companies of material changes to its sub-processors.
Assistance and breach notification. Promio will reasonably assist Companies in responding to data-subject requests and honors Shopify's customers/data_request, customers/redact, and shop/redact webhooks. Promio will notify affected Companies without undue delay after becoming aware of a personal data breach affecting their data.
Return or deletion. On termination, or on a valid erasure request, Promio deletes or anonymizes the Company's customer personal data except where retention is required by law (for example invoicing records), in which case that data is minimized and access-restricted.