Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Redgard Affiliate Marketing ("Redgard", "we", "us") processes personal data in connection with the Redgard affiliate platform, including the Redgard app for Shopify. We are based in the Netherlands and process personal data in accordance with the General Data Protection Regulation (GDPR / AVG).
Redgard Affiliate Marketing
Korenstraat 6, 9712 LX Groningen, Netherlands
KvK: 81336659
Contact: our contact form
1. Who this policy covers
We process personal data of three groups:
- Platform users: Publishers and Advertisers with a Redgard account, including merchants who connect a store through the Redgard app for Shopify;
- End users: visitors who click an affiliate tracking link and may complete a conversion on an Advertiser's website or store;
- Website visitors: visitors of the Redgard website itself.
2. Data we process and why
2.1 Platform users (Publishers and Advertisers)
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, company details, KvK/VAT number | Account creation, identification, invoicing | Contract performance |
| Payment details (bank account / payout method) | Paying out commissions; invoicing platform fees | Contract performance; legal obligation |
| Promotion descriptions, program activity, dashboard usage | Operating the platform; quality monitoring | Contract performance; legitimate interest (fraud prevention, platform integrity) |
| Communications with support | Handling questions and disputes | Contract performance; legitimate interest |
| Invoices and transaction records | Tax and accounting obligations | Legal obligation (7-year retention under Dutch tax law) |
Where you sign up for a specific program, the Advertiser (or external program owner) sees your publisher name and performance data for that program. If there is a well-founded suspicion that you are violating our Terms to the detriment of an Advertiser, we may share your contact details with the aggrieved party or with competent authorities.
2.2 End users: attribution measurement ("matching data")
Redgard's core service is measuring that a visitor who clicked a Publisher's link later completed a conversion on an Advertiser's website, so the right Publisher can be rewarded. We deliberately designed this to identify the journey, not the person.
What we process when you click a tracking link:
- A pseudonymized click identifier, stored in a first-party cookie (or comparable identifier) on the destination domain;
- Timestamp, referring channel, destination, country, and device category;
- Your IP address in truncated and hashed form only: parts of the IP address are removed and the remainder is hashed to create an identifier used solely for attribution matching and fraud detection. We do not store your full IP address for attribution purposes, and we cannot reverse this identifier back to you;
- Conversion data reported by the Advertiser: an order or booking reference, order value, and conversion status, but not your name, email address, or payment details, which remain with the Advertiser.
What we do not do:
- We do not know who you are, and we cannot re-identify you from the matching data we hold;
- We do not build interest or marketing profiles of end users;
- We do not use matching data for retargeting or for advertising to you on other websites;
- We do not sell end-user data.
The Advertiser or Publisher may be able to link a conversion to you through information they hold themselves (for example, your order in the Advertiser's shop, or a cashback account with a Publisher). That processing is governed by their own privacy policies. Where Redgard processes conversion data on behalf of an Advertiser in that context, a data processing agreement applies, and you can exercise your GDPR rights against either party; we will coordinate as required.
Purposes: attributing conversions to the correct Publisher, calculating commissions, providing aggregated statistics to Advertisers and Publishers, and detecting fraudulent or artificial traffic.
Legal basis: legitimate interest. We have carried out a balancing test, weighing the interests of everyone in the affiliate ecosystem: Advertisers have a legitimate interest in paying for marketing on a performance basis; Publishers in monetizing their content; Redgard in operating the platform; and all parties, including society at large, in preventing fraud. Because the data is minimized and cannot be traced back to an individual by Redgard, the impact on end users' rights and freedoms is negligible, and no less intrusive means exists to achieve performance-based attribution.
2.3 Advertisers using the Redgard app for Shopify
When a merchant installs the Redgard app on their Shopify store, the app reads a deliberately minimal set of order data so a completed order can be attributed to the referring Publisher and the commission calculated:
- Order identifier, order value, currency, and the time the order was processed;
- An order note attribute containing the pseudonymized affiliate click identifier described in section 2.2;
- Order status signals needed to reverse commission on a refund or cancellation.
The app does not request or receive customer name, email, phone number, or address. It is configured, at the Shopify permission level, to exclude those fields from the data Shopify sends us. In Shopify terms, the app holds an access level that covers order data but no protected customer contact fields.
For this order data, Redgard acts as a processor on behalf of the merchant (the Advertiser), who is the controller of their own order records. A data processing agreement governs that relationship. Redgard supports Shopify's mandatory privacy webhooks: on a customer data request or deletion request we confirm we hold no Shopify customer contact data for that person, and on store removal we delete the store's connection data within 48 hours (append-only financial records required for tax and accounting are retained as set out in section 7).
2.4 Website visitors
We process limited technical data (IP address, browser data) in server logs for security purposes, based on legitimate interest. Where we use cookies beyond strictly necessary ones on our own website, we ask consent via a cookie banner.
3. Automated analysis
We use automated systems, including AI-based analysis, to:
- Monitor traffic and conversion patterns for fraud and spam;
- Provide Publishers with insights into their traffic and suggestions to improve results.
Decisions with significant consequences (such as withholding commissions or account suspension) are not taken solely by automated means: a human reviews the case before a final decision is made. You may contest such decisions via our contact form.
4. Cookies and the consent requirement
Redgard's tracking uses a first-party cookie (or comparable identifier) on the Advertiser's domain, used exclusively to attribute a conversion to a prior click. The cookie duration is set per program (for example, 30 days) and is shown in the program details.
This attribution cookie is strictly functional for the affiliate service: it contains no profiling data, is not used across unrelated websites, and the associated data is minimized and anonymized as described in section 2.2. Under the Dutch Telecommunications Act, cookies whose processing of personal data is limited to non-existent, and which are necessary for the requested service or for audience measurement of this kind, can fall outside the consent requirement. Redgard's tracking is designed to meet that standard.
Advertisers remain responsible for the cookie and consent implementation on their own websites. Redgard provides Advertisers with the technical documentation needed to classify our tracking correctly in their consent management platform.
5. Sharing personal data
We share personal data only where necessary:
- Between platform users: Advertisers see aggregated and conversion-level performance data of Publishers in their program (Publisher name/ID, traffic and conversion statistics). Publishers see their own performance data per program.
- External program owners: for Aggregated Programs, conversion and attribution data is exchanged with the external program's system, with the program owner's written approval and under appropriate agreements.
- Service providers: hosting, payment processing, email, and accounting providers, bound by data processing agreements and not permitted to use the data for their own purposes.
- Enforcement: to investigate breaches of our Terms, to enforce agreements, or to protect the rights and safety of Redgard, our users, or third parties.
- Authorities: where we are legally required to do so.
We do not sell personal data.
6. International transfers
We store data within the EEA where possible. If a service provider processes data outside the EEA, we ensure appropriate safeguards such as EU Standard Contractual Clauses or an adequacy decision.
7. Retention
- Account and program data: for the duration of the account, plus up to 24 months after closure for dispute handling;
- Invoices and transaction records: 7 years (Dutch tax law);
- Click and matching data: 25 months after the click, after which it is deleted or retained only in fully aggregated, statistical form;
- Shopify store connection data: deleted within 48 hours of the app being removed from the store;
- Fraud investigation records: as long as necessary for the investigation and any follow-up.
8. Security
We follow a privacy-by-design approach: the most important security measure is storing as little identifying data as possible, as described in section 2.2. In addition, we apply appropriate technical and organizational measures, including encryption in transit, encryption at rest, role-based access controls, API key management, logging, and separation of production data. Despite these measures, no system is 100% secure; we will report data breaches in accordance with the GDPR.
9. Your rights
Under the GDPR you have the right to access, rectify, erase, and restrict the processing of your personal data, the right to data portability, and the right to object to processing based on legitimate interest.
To exercise these rights, contact us via our contact form. We respond within one month. We may ask you to verify your identity. Note for end users: because Redgard cannot identify you from the matching data it holds, we may be unable to link a request to specific data (art. 11 GDPR); in that case the Advertiser or Publisher you interacted with is usually the right party to approach, and we will assist where we can.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
10. Changes
We may update this policy. Material changes will be announced via the dashboard or email before they take effect. The current version is always available at https://www.redgard.nl/privacy.
11. Contact
Korenstraat 6, 9712 LX Groningen, Netherlands
KvK: 81336659
Contact us via our contact form