Privacy Policy
Effective Date: March 30, 2026
Disclaimer: This Privacy Policy is a placeholder suitable for a beta launch. It is not a substitute for professional legal advice. You should consult a qualified attorney to ensure compliance with all applicable privacy laws before production use.
1. Introduction
Refuel Payments (“Refuel,” “we,” “us,” or “our”) operates the affiliate marketing platform at refuelpayments.com (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, company name, and domain when you register for an account.
- Payment information: Payment details processed through Stripe Connect, including bank account or card information. Refuel does not directly store your full payment credentials; these are handled by Stripe in accordance with their security standards.
- Communications: Information you provide when contacting our support team or communicating with us via email.
2.2 Information Collected Automatically
- Click and conversion data: We track referral link clicks, page visits, and conversion events to attribute affiliate commissions accurately.
- IP address hashes: We collect hashed (anonymized) IP addresses for fraud detection and geographic analytics. We do not store raw IP addresses long-term.
- Device information: Browser type, operating system, and device identifiers used for fraud detection and analytics.
- Cookies: We use cookies for attribution tracking and session management. See Section 8 for details.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: Operating the platform, processing affiliate registrations, tracking clicks and conversions, calculating commissions, and processing payouts.
- Fraud prevention: Detecting and preventing fraudulent activity such as click fraud, self-referrals, and cookie stuffing using IP hashes, device fingerprints, and behavioral analysis.
- Analytics and improvement: Understanding how users interact with the Service to improve features, performance, and user experience.
- Communications: Sending transactional emails (account verification, payout notifications, security alerts) and, with your consent, marketing communications.
- Legal compliance: Complying with applicable laws, regulations, and legal processes.
4. Third-Party Sharing
We do not sell your personal information. We share data with third parties only in the following circumstances:
- Stripe: We use Stripe Connect for payment processing, KYC verification, and payout distribution. Your payment information is shared with Stripe in accordance with their Privacy Policy.
- Resend: We use Resend for transactional and marketing email delivery. Your email address and name may be shared with Resend for this purpose.
- Between Companies and Affiliates: Limited information (such as affiliate performance data) is shared between Companies and their Affiliates as necessary for the operation of the affiliate program.
- Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained for the duration of your account plus 30 days after deletion request.
- Click and conversion data: Retained for up to 24 months for analytics and commission reconciliation purposes.
- Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
- Fraud detection data: Hashed IP addresses and device fingerprints are retained for up to 12 months.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
6.1 Rights Under GDPR (European Economic Area)
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to restrict processing: Request that we limit how we use your data.
- Right to object: Object to processing of your data for direct marketing purposes.
6.2 Rights Under CCPA (California)
- Right to know: Request information about the categories and specific pieces of personal information we have collected about you.
- Right to delete: Request deletion of your personal information.
- Right to opt-out: We do not sell personal information, so this right does not currently apply.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, please contact us at hello@refuelpayments.com. We will respond to your request within 30 days.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Secure API key management with separate publishable and secret keys.
- IP address hashing to minimize storage of identifiable network data.
- Regular security reviews and monitoring.
While we strive to protect your data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.
8. Cookies Policy
We use cookies to enable core functionality of the Service, specifically affiliate attribution tracking. The cookies we use are:
| Cookie | Purpose | Expiry |
|---|---|---|
| _rfl_ref | Stores the affiliate referral code to attribute conversions to the correct affiliate. Set when a visitor arrives via an affiliate link. | 30 days |
The _rfl_ref cookie is a first-party cookie essential to the operation of the affiliate tracking Service. It does not track you across websites and is not used for advertising purposes.
You can configure your browser to refuse cookies, but doing so may prevent affiliate attribution from functioning correctly.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from your jurisdiction. When we transfer data internationally, we implement appropriate safeguards to protect your information in compliance with applicable law.
10. Children’s Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at hello@refuelpayments.com and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Service. The “Effective Date” at the top of this page indicates when the policy was last revised. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: