Tossed Leaf Affiliate Privacy Policy

Effective date: September 18, 2026

This Affiliate Privacy Policy explains how Tossed Leaf collects, uses, shares, protects, and retains information connected with affiliate applications, accounts, referral tracking, commissions, and payouts.

1. Information collected

  • Application and identity data: name, username, email, phone or WhatsApp number, country, city, website or social profile, promotion channels, audience, promotion plan, consent records, and review history.
  • Account and security data: password hash, account status, secure session and password-reset tokens, login and security events, and fraud-prevention signals. Plain-text passwords are not stored.
  • Referral data: referral code, landing page, referring domain, visit time, signed first-party referral cookie, and a daily salted visitor hash. The plugin does not store raw visitor IP addresses in referral-click records.
  • Order and commission data: eligible direct-order reference, subtotal, currency, commission rate and amount, status, adjustments, hold period, and payout association. Partner-kiosk orders are excluded.
  • Payout data: payout method, masked destination, encrypted payout instructions, requested amount, status, administrative notes, and transaction reference.
  • Communications: messages, support requests, application decisions, and policy or account notices.

2. Why information is used

Information is used to review applications, create and secure accounts, operate referral attribution, calculate and pay commission, prevent self-referral and fraud, provide support, enforce program terms, maintain accounting and audit records, meet legal obligations, and improve program reliability.

3. Legal grounds

Depending on applicable law, processing may be based on steps requested before entering the affiliate agreement, performance of that agreement, legitimate interests in operating and securing the program, consent where required, and compliance with legal, tax, accounting, fraud-prevention, or dispute obligations.

4. Cookies and referral tracking

A signed first-party referral cookie may be stored for up to 30 days, subject to the configured attribution period and browser settings. The cookie identifies the referring affiliate and issue time. Visitors can block or remove cookies, but attribution may then be unavailable. Essential affiliate login and security cookies are used to maintain secure sessions.

5. Sharing and service providers

Information may be shared with authorized Tossed Leaf staff and service providers supporting hosting, email, security, analytics, payment, accounting, legal compliance, and program operations. Information may also be disclosed where required by law, to protect rights or safety, to investigate abuse, or as part of a business reorganization. Personal data is not sold by this plugin.

6. International processing

Service providers may process information in other countries. Where required, Tossed Leaf uses appropriate contractual, organizational, and technical safeguards for international transfers.

7. Retention schedule

  • Pending applications: retained while under review and for reasonable follow-up.
  • Rejected or withdrawn applications: normally deleted or anonymized after 24 months.
  • Referral-click records: normally deleted after 395 days.
  • Active affiliate profiles and consent records: retained while the account is active and afterward as needed for contract, dispute, fraud-prevention, and audit purposes.
  • Orders, commissions, payouts, tax, and accounting records: normally retained for at least 7 years after the relevant transaction, or longer when law, an investigation, a dispute, or an outstanding payment requires it.
  • Password setup tokens: expire after 24 hours. Session tokens expire or are revoked when the user signs out or the account is frozen, disabled, or deleted.
  • Backups: deleted information may remain in restricted backups until the normal backup cycle completes.

8. Security

Tossed Leaf uses access controls, password hashing, signed tokens, encrypted payout instructions where supported, limited administrative permissions, and operational logging. No system is completely secure; affiliates should use a unique password and report suspicious activity promptly.

9. Individual rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Some information may be retained where necessary for accounting, legal claims, fraud prevention, security, or other lawful obligations. Identity verification may be required before a request is completed.

10. Children

The affiliate program is not intended for children or individuals who cannot legally enter the affiliate agreement. Applicants must meet the applicable legal age and capacity requirements.

11. Changes and contact

This policy may be updated as the program, law, or service providers change. The current version and effective date will appear on this page. Privacy questions or rights requests may be sent to admin@tossedleaf.com.