Partner Program — Privacy Notice
Effective date: 2026-05-25 · Version: 1.0.0
This notice covers data we collect about partners. For end-user data, see the general Privacy Policy.
What we collect
At application: legal entity name, trading name, country, entity type, year established, employee bucket, website, industry, business description, tax residency, tax ID (last 4 only; full ID on uploaded form), VAT/GSTIN where applicable, partnership intent (channels, target customers, references), primary contact details, IP and User-Agent at submission, captcha pass/fail.
During participation: transaction records (Flow A referrals, Flow B purchases), payout records, portal session metadata, HMAC-hashed click-tracking, optional co-brand logo.
We don't collect banking credentials beyond payout-method details, browsing outside the partner portal, or sensitive personal data (race, religion, biometric, health, sexual orientation, politics, criminal record).
Legal basis (EU / UK GDPR)
- Contract performance — application review, payouts, support.
- Legal obligation — tax records, sanctions screening, AML.
- Legitimate interest — anti-fraud, security logging, program operations.
- Consent — marketing emails about the Program.
Retention
- Declined or withdrawn applications: 12 months identifiable, then anonymised.
- Approved partner records: duration + 7 years post-termination.
- Tax forms: 4 years post-final-payout (US 1099-NEC retention).
- Transaction records: 7 years.
- Audit log: 7 years.
- Portal sessions: 90 days post-expiry.
- Magic-link login tokens: 30 days.
- Referral click logs: 90 days.
Sharing
- Payment processors (Stripe, PayPal, Stripe Connect) — only what's needed to pay you.
- Email delivery (Brevo) — your email, name, and the message body of partner-program emails.
- Tax authorities — as required by law.
- Professional advisors — accountants, lawyers, bound by professional confidence.
- Cloudflare — our infrastructure provider.
We do not sell partner data and do not share it with advertising networks.
Your rights
GDPR / CCPA / similar: access, rectify, erase (where law permits), restrict, object, port, withdraw consent, complain. Email <privacy@storagestudio.us> from your registered contact. 30-day response (extendable by 60 days for complex requests with notice).
Security
- TLS 1.2+ in transit, encrypted at rest by Cloudflare.
- Magic-link authentication only — no passwords stored on our side.
- Portal sessions: 7-day expiry, single cookie, revocable.
This page at <https://storagestudio.us/legal/partner-privacy-notice> is the canonical published version of the Partner Privacy Notice.
Contact: <privacy@storagestudio.us>.