Privacy Policy
Last Updated: August 17, 2026 | Effective Date: August 17, 2026
1. Introduction
This Privacy Policy explains how Afyore ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our SaaS marketplace platform. By using Afyore, you agree to the collection and use of your information as described in this policy.
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
Account Information:
- Name and email address
- Profile picture (preset or custom upload)
- Country of residence
- LinkedIn profile URL
- Website URL
- Role (Founder or Promoter)
Founder-Specific Information:
- Company name
- Position/title
- Company overview
- Product details (name, description, website, logo)
- Partnership reward structures
Promoter-Specific Information:
- Headline and professional summary
- Specializations and skills
- Portfolio links
- Partnership history and performance
Authentication Data:
- Login credentials (stored securely via Supabase)
- Authentication tokens
- Session information
2.2 Usage Information
We automatically collect information about your use of the Service:
- Pages visited and features used
- Time and frequency of use
- Device information (browser, operating system)
- IP address and approximate location
- Clickstream data
2.3 Communication Data
- Partnership chat messages (sender, recipient partnership, message text, timestamp) — automatically and permanently deleted 144 hours after sending
- Partnership requests, pitches and responses
- The founder's chosen contact method (in-platform chat, email, LinkedIn, X, Instagram or Reddit) and affiliate program details, unlocked to a promoter only after acceptance
- Support communications
- A local record on your own device that you accepted the chat policy for a conversation (stored in your browser, not on our servers)
2.4 Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Remember your preferences
- Analyze platform usage
- Improve user experience
- Authenticate your session
3. How We Use Your Information
3.1 Primary Purposes
We use your information to:
Service Provision:
- Create and manage your account
- Facilitate partnerships between founders and promoters
- Provide product discovery and matching
- Enable communication between users
- Track partnership activities and rewards
Platform Improvement:
- Analyze usage patterns to improve features
- Develop new features and services
- Optimize user experience
- Prevent fraud and abuse
Communication:
- Send service-related notifications
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
- Provide updates about new features
Security and Compliance:
- Detect and prevent fraudulent activity
- Enforce our Terms of Service
- Comply with legal obligations
- Protect platform security
3.2 Legal Basis for Processing (GDPR)
If you are in the European Union, we process your data based on:
- Contractual Necessity: To provide the services you've requested
- Legitimate Interests: To improve our platform and prevent fraud
- Legal Obligation: When required by law
- Consent: For marketing communications and optional features
4. Information Sharing and Disclosure
4.1 User-to-User Sharing
Your profile information is shared with other users for:
- Product discovery and partnership matching
- Partnership evaluation and decision-making
- Communication between founders and promoters
4.2 Third-Party Service Providers
We share information with trusted third parties who assist in operating our platform:
Supabase (Database & Authentication):
- Stores user account data
- Manages authentication
- Provides database services
- Privacy Policy: https://supabase.com/privacy
Cloud Hosting Providers:
- Host our application and data
- Provide infrastructure services
Analytics Services:
- Analyze platform usage
- Improve user experience
- May include tools like Google Analytics (future implementation)
Email Service Providers:
- Send transactional emails
- Manage email communications
4.3 Legal Disclosures
We may disclose your information when:
- Required by law or legal process
- To protect our rights, property, or safety
- To enforce our Terms of Service
- To prevent fraud or illegal activity
- With your explicit consent
4.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred to the new owner.
5. Data Security
5.1 Security Measures
We implement reasonable security measures including:
Technical Security:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest where applicable
- Secure authentication mechanisms
- Row Level Security (RLS) in our database
- Regular security updates and patches
Organizational Security:
- Access controls for employee data access
- Security training for personnel
- Regular security audits
- Incident response procedures
Storage Security:
- Private storage buckets for user uploads
- Signed URLs with time limits for image access
- User-specific folder structures
- File size and type restrictions
5.2 Data Retention
We retain your information for:
- Active Accounts: As long as needed to provide services
- Deleted Accounts: Up to 30 days for backup and recovery purposes
- Legal Requirements: As required by applicable laws
- Business Records: As necessary for legitimate business purposes
5.3 Data Deletion
You may request deletion of your personal data by:
- Using account deletion features in Settings
- Contacting our support team
We will delete your information within a reasonable time, except where:
- Required for legal compliance
- Necessary for legitimate business purposes
- Needed to resolve disputes or enforce agreements
6. Your Privacy Rights
6.1 General Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request transfer of your data to another service
- Objection: Object to certain processing activities
- Restriction: Request restriction of processing
6.2 GDPR Rights (EU Residents)
If you are in the European Union, you have additional rights:
- Right to withdraw consent
- Right to lodge a complaint with supervisory authority
- Right to information about processing activities
- Right to data protection impact assessment in certain cases
6.3 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect
- Know if we sell or disclose your information
- Request deletion of your information
- Opt-out of the sale of personal information
- Non-discrimination for exercising privacy rights
6.4 DPDP Rights (India Residents)
If you are in India, under the Digital Personal Data Protection Act, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for processing
- Nominate another individual to exercise rights in case of death/incapacity
6.5 Exercising Your Rights
To exercise your rights, contact us at:
- Email: privacy@afyore.com
- Subject: Privacy Rights Request
We will respond within the timeframes required by applicable law (typically 30 days).
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. When this occurs, we ensure appropriate safeguards including:
- Standard contractual clauses with third-party providers
- Compliance with GDPR requirements for international transfers
- Adequate data protection measures in destination countries
- Your consent where required by law
8. Children's Privacy
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we discover we have collected such information, we will delete it immediately.
9. Cookies and Tracking Technologies
9.1 Types of Cookies We Use
- Essential Cookies: Required for basic functionality
- Performance Cookies: Analyze platform performance
- Functionality Cookies: Remember your preferences
- Targeting Cookies: Deliver relevant content (with consent)
9.2 Managing Cookies
You can control cookies through:
- Browser settings
- Cookie consent banner (when implemented)
- Platform preferences
Disabling cookies may affect platform functionality.
10. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes via:
- Email notification
- In-app notification
- Posting on our website
Your continued use of the Service after changes constitutes acceptance of the updated policy.
12. California Residents (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act:
- Right to Know: We will provide information about categories of personal information we collect, use, and share
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out: You can opt-out of the sale of your personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, contact us at privacy@afyore.com.
13. European Residents (GDPR)
If you are a resident of the European Union, the General Data Protection Regulation (GDPR) provides you with comprehensive data protection rights:
- Lawful Basis: We process your data based on contractual necessity, legitimate interests, legal obligation, or consent
- Data Minimization: We collect only data necessary for our services
- Purpose Limitation: We use your data only for stated purposes
- Storage Limitation: We retain data only as long as necessary
- Accuracy: We maintain accurate and up-to-date information
- Security: We implement appropriate security measures
- Accountability: We maintain records of our processing activities
14. India Residents (DPDP)
If you are a resident of India, the Digital Personal Data Protection Act provides you with data protection rights:
- Notice: We provide clear notice of data collection practices
- Consent: We obtain your consent for data processing
- Purpose: We collect data for specified, clear, and lawful purposes
- Access and Correction: You can access and correct your data
- Deletion: You can request deletion of your data
- Grievance Redressal: We provide a mechanism for addressing complaints
15. Data Breach Notification
In the event of a data security breach that may affect your personal information, we will:
- Notify affected users within required timeframes (typically 72 hours for GDPR)
- Provide information about the breach and its impact
- Describe steps we are taking to address the breach
- Provide recommendations for protecting your information
16. Marketing Communications
16.1 Promotional Communications
We may send you marketing communications about:
- New features and services
- Partnership opportunities
- Platform updates
- Relevant industry content
16.2 Opt-Out
You can opt-out of marketing communications by:
- Using unsubscribe links in emails
- Updating your communication preferences in Settings
- Contacting our support team
17. Platform-Specific Privacy Considerations
17.1 Profile Pictures and Images
- Custom profile pictures are stored in private Supabase storage
- Images are accessible via signed URLs with time limits
- Images are organized by user ID for security
- File size limited to 5MB to prevent abuse
17.2 Partnership Data
- Partnership requests and responses are stored securely
- Reward tracking data is used for platform functionality
- Partnership communications may be reviewed for fraud prevention
17.3 In-Platform Chat
- Chat exists only inside an accepted partnership and is readable only by those two people
- Access is enforced by database row-level security, so no other user can query the conversation
- Messages are encrypted in transit and stored in our Supabase database in the EU/US region of our project
- Every message is permanently deleted by an automated hourly job 144 hours (6 days) after it was sent — this is a hard limit, not a user setting, and expired messages cannot be restored
- We do not sell chat content, use it for advertising, or feed it to third-party marketing tools
- We may access messages within that window only to investigate an abuse report, prevent fraud, or comply with the law
- Because chat is temporary, please keep anything important (terms, links, invoices) somewhere you control
17.4 Product Listings and Deletion
- Live product information is visible to signed-in platform users; drafts and paused products are visible only to their founder
- A founder's affiliate link or chosen contact method is revealed to a promoter only once that partnership is accepted
- Founders can permanently delete a product at any time; this also deletes every partnership on that product and the chat history within them, for both sides
- Deletions are immediate and irreversible in our live database; residual copies may persist briefly in encrypted backups before rotating out
17.5 Deleting Your Account Data
- You can edit or clear your profile, company details and portfolio information at any time from Settings
- To have your account and associated records deleted entirely, email privacy@afyore.com and we will action it
18. Contact Information
For privacy-related inquiries, please contact:
Afyore
Privacy Contact: privacy@afyore.com
Website: https://afyore.com
⚠️ Legal Disclaimer
IMPORTANT LEGAL NOTICE:
This Privacy Policy is provided as a template and has not been reviewed by legal counsel. It is intended to provide basic privacy protections for the Afyore platform during its beta phase.
We strongly recommend:
- Having this Privacy Policy reviewed by a qualified attorney licensed in your jurisdiction
- Customizing this policy to comply with local data protection laws
- Regular legal review as the platform grows and regulations change
- Specific compliance measures for GDPR, CCPA, DPDP, and other applicable laws
This Privacy Policy is not a substitute for professional legal advice.
This document is a living document and will be updated as Afyore evolves and privacy regulations change. Last updated: August 17, 2026