Privacy Policy
Last updated: August 19, 2026
1. Information We Collect
Gilad Moyal, an individual operating Wand Referrals ("we", "our", "the App"), collects the following information when you install and use our Shopify app:
- Shop data: Store name, domain, email address, and Shopify plan information.
- Affiliate data: Names, email addresses, phone numbers, physical addresses, discount codes, and commission history of affiliates you add to your program.
- Order data: For paid orders Shopify sends to the App, order identifiers, amounts, currency, discount codes, relevant product and referral signals, and limited shipping-region information used for attribution, commissions, eligibility, fraud prevention, and reconciliation. When Shopify includes the customer's browser IP address, the App uses it for an optional merchant-configured blocklist and derives a one-way hash for optional velocity checks. Successful processing removes the encrypted raw-payload snapshot immediately. After a processing failure, a minimized encrypted retry snapshot can remain until the separately scheduled purge removes it; automated seven-day purge enforcement is a launch gate and is not yet operational. The raw IP is not saved in the commission record or application logs.
- Customer data: Limited customer identifiers and contact or location data needed for configured attribution and invitation methods, including email, Shopify customer identifier, country, region, city, postal code, and an order count used when a merchant reviews customer-to-affiliate invitation candidates. Historical compatibility records can still contain customer name and phone until their documented scrub and read-retirement gates complete; new paid-order writes do not intentionally add those fields or street-address lines.
- Storefront click and attribution data: When a merchant enables the Wand tracking theme app embed and Shopify reports the required analytics consent, a referral visit can set first-party attribution cookies and send the App the affiliate code, page path, browser-session identifier, referrer, and user agent. The tracking endpoint transiently reads the network IP address and stores only a one-way IP hash with the click/journey record. Optional Meta Pixel and Facebook click-id processing runs only when the merchant configures that feature and Shopify separately reports marketing and sale-of-data consent.
- Public referral-link redirect data: When a visitor follows a generated Wand referral link, the server resolves the tenant and affiliate and records a one-way source-IP hash, user agent, referrer, and landing URL before redirecting to the merchant. This public server-side collector does not currently read Shopify Customer Privacy signals; its service-processing or consent posture remains a launch gate.
- Merchant Event API data: An authenticated merchant can separately send click, page-view, or conversion events through the server-side Event API. Depending on the event, this can include an affiliate code, session identifier, page path, referrer, user agent, customer email or identifier, order data, and a transient request IP converted to a stored one-way hash. This API does not depend on the theme app embed or read Shopify storefront consent signals. The merchant is responsible for using it only with an appropriate lawful basis and for providing any required notice or consent; conversion events are processed for attribution and commission calculation.
- Merchant automation webhook data: When a merchant configures Zapier, Make, a custom endpoint, or the legacy webhook URL, the App can send a
commission.createdpayload containing commission and affiliate identifiers, affiliate email, Shopify order ID/display name, commission amount, order subtotal, currency, tracking method, and discount code. The App can also sendaffiliate.approved,affiliate.rejected, andaffiliate.status_changedpayloads containing affiliate ID, email, name, previous status, and new status. Matching active endpoints receive their configured events; the legacy endpoint receives all supported event classes. - Registration and payout communications: After a successful affiliate registration, the App can automatically record a merchant in-app notice, send the same minimized notice to up to ten valid tenant-configured merchant notification addresses, and send a pending or approved receipt to the registering affiliate. The merchant notice contains the affiliate's display name, status, program, shop context, and authenticated-admin link; contact, company, location, referral, and discount details stay in the authenticated admin. The pending affiliate receipt contains the affiliate's own identity, pending/program and shop/portal context. The approved receipt contains the affiliate's identity, approval/shop and portal context, plus that affiliate's available referral link and discount code; the approved path does not receive program data. Registration does not use a global administrative fallback address. A payout-sent notice can separately contain the affiliate name and selected payout/profile email, net amount and currency, method, shop branding/domain, portal link, and approved merchant-authored template content.
- Merchant-created affiliate invitation email: When a merchant creates a pending affiliate during onboarding, through the new-affiliate form, or by promoting a discovery candidate, the App can send that affiliate's email/name, shop domain, referral or discount URL, and the shared merchant-address/shop/affiliate-settings footer through Resend. The invitation states that the storefront URL does not verify email, activate the profile, or sign the recipient in. This class remains gated on independent review and exact-release recipient authorization, minimization, preference/suppression, retry/idempotency, retention/redaction, and disabled-state evidence.
- Merchant-approved affiliate profile-change email: After an authenticated merchant updates a tenant-owned affiliate and separately selects the notification checkbox, the App can send the affiliate display name, the updated email or prior profile email, labels for changed fields but not their values, and the shared merchant-address/shop/affiliate-settings footer. The profile update remains committed if delivery is absent or rejected. This separate class remains gated on tenant authorization, recipient selection, minimization, preference/suppression, retry/failure, retention/redaction, and disabled-state evidence.
- Merchant onboarding and administrative emails: The first authenticated app load can enqueue a welcome only for the current Shopify associated user when Shopify asserts
email_verified: true. It contains recipient name, shop domain, onboarding content, and a direct Shopify Admin app URL selected from the trusted runtime Shopify client identity for production or QA, with no recipient identity or tracking proof in the query string. A tenant-lifecycle- and Shopify-auth-generation-bound transaction claims one durable email job; the legacy welcome marker records that claim, not confirmed delivery. The former global fallback, tracked click route, and process-local follow-up are retired. The welcome footer can still append merchant company/street/country from settings, a configured sender-address fallback or visible unconfigured-address placeholder, shop domain, and an affiliate-settings preference/unsubscribe URL even though the recipient is merchant staff. Staff support-ticket changes and affiliate erasure requests can separately notify the tenant's configured merchant contact with ticket/status/staff or affiliate/privacy-request details. These message classes remain gated on associated-user recipient authorization, footer security/minimization, meaningful merchant preference/suppression, queue/provider retry/failure, retention/redaction, deployment, and disabled-state evidence. - Affiliate authentication communications: Magic-link login, self-service or administrator password reset, and reactivation confirmation can send the affiliate's email/name, shop branding/domain, and a raw single-use bearer link through Resend. Their shared footer also sends the merchant company/street/country from settings, a configured sender-address fallback or visible unconfigured-address placeholder, the shop domain, and the affiliate-settings preference/unsubscribe URL. The links expire after 15 minutes for magic-link and self-service reset, one hour for an administrator reset, or 30 minutes for reactivation. The App stores only a hash but activates the exact credential when Resend synchronously accepts the submission—not after confirmed final delivery—so an asynchronous bounce/rejection can leave it active until use or expiry. Confirmed reactivation can separately notify a configured merchant recipient of the affiliate email, prior status, and footer.
- Public registration anti-abuse data: When reCAPTCHA is configured, the public registration page loads Google's script and exposes ordinary browser/network and interaction metadata. Verification uses a token, site key, expected action, hostname, validity or risk signals and, for Enterprise verification, the trusted client IP when available plus user agent. Wand does not persist the provider risk response.
- Registration logos: Remote registration-logo URLs are disabled for the launch release. Logos must be embedded PNG, JPEG, GIF, or WebP data under 2MB with a matching image signature. Legacy remote values, SVG, mismatched content, and oversized values are removed before authenticated or public pages receive them.
- Merchant settings branding images: Remote logo, favicon, and banner URLs are disabled for the launch release. The authenticated settings loader does not release persisted values to the browser, Branding and Marketplace render no remote settings image, crafted non-empty values are rejected, and saving Branding clears legacy stored URLs. Text and color branding remain available.
- Affiliate support tickets: The affiliate ticket form accepts text fields only. Its endpoint rejects multipart before parsing and enforces a 16 KiB declared and streamed request limit, so this surface does not accept file bytes, filenames, MIME types, sizes, or scan metadata. Any future attachment feature requires the approved fail-closed validation, scanning, tenant storage/download, retention, and deletion controls.
- Merchant territory configuration: The launch release uses a list-based country, state/province, city, and postal-code editor. The map enhancement is disabled, so territory editing does not contact Mapbox, geoBoundaries, or a provider-selected geometry host. Merge, deployment, and exact-release no-request proof remain pending.
- Product and application telemetry: When separately approved and enabled, allowlisted usage classifications, session-scoped pseudonyms, scrubbed errors and performance timings, and an optional trusted-edge country code from authenticated merchant, affiliate, and Wand-staff surfaces. We do not put raw account, tenant, user, route, IP address, city, postal code, coordinates, free text, or customer/order data in provider event payloads. Browser connections to Sentry transiently expose the network source IP, which Sentry must be configured not to retain or use for geography.
2. How We Use Your Information
We use collected information to:
- Provide affiliate program management functionality
- Track and attribute sales to affiliates via discount codes
- Calculate and process affiliate commissions
- Let merchants review eligible customer invitation candidates and send customer-to-affiliate invitations
- Send transactional emails (registration confirmations, merchant-approved affiliate profile-change notices, magic link logins, commission notifications, and payout-sent notices)
- Generate reports and analytics for your affiliate program
- Understand authenticated feature adoption and improve the App, using privacy-minimized product telemetry when enabled
3. Third-Party Services
We use Shopify to provide the App, may use the following service providers, and may deliver configured events to merchant-controlled recipients. Optional providers and recipients receive data only when the related feature is enabled:
- Shopify: App platform, merchant authentication, billing, and order/customer source
- Fly.io: Application hosting and compute
- Neon (PostgreSQL): Managed database hosting
- Resend: For sending transactional emails, including magic-link login, self-service and administrator password-reset, and reactivation messages containing affiliate identity, shop context, raw single-use bearer links, and the merchant-address/shop/settings-link footer described above; automatic registration notices; merchant-created affiliate invitation messages whose referral/discount CTA is explicitly described as non-verifying and non-activating; merchant-approved affiliate profile-change notices containing recipient identity, changed-field labels, and the shared footer; the first-load merchant welcome described above; administrative-change notices for staff ticket actions and affiliate erasure requests; payout-sent notices; minimized unread-message alerts; affiliate support tickets containing identity, shop context, and user-authored subject/description but no file metadata; eligible weekly reports; and separately approved affiliate campaigns. Each class requires separate recipient authorization, preference/suppression where applicable, minimization, retry/idempotency, retention/redaction, tenant isolation, and enabled-or-disabled evidence. Credential messages additionally require footer/fallback, provider tracking/retention, expiry, replay, replacement, synchronous acceptance/failure, and asynchronous bounce/rejection proof; provider acceptance is not confirmed final delivery.
- Twilio: Optional SMS delivery and opt-out handling
- Merchant support: The launch release uses Wand's authenticated first-party ticket workflow and a user-directed email fallback. The Chatwoot widget and raw client-error forwarding are disabled. Merge, deployment, and exact-release no-request proof remain pending.
- Google Places: When an applicant requests address suggestions, Wand sends the entered address text and selected US/Canada country filter to Google Places when configured. Google Place Details is requested only after the applicant selects a prediction. The request is bound to an expiring registration context, limited by client network address, and is not reused for advertising or customer/order enrichment. Google processes this request under the Google Privacy Policy. If Google is unavailable or not configured, address suggestions stop and manual entry remains available.
- Location data: Merchant territory-city suggestions use Wand's bundled city dataset, and merchants may enter cities manually. Wand does not send those city searches or applicant street-address searches to Nominatim/OpenStreetMap.
- QR code generation: Wand generates referral, registration, and login QR codes locally without sending their target URLs to a separate QR-image provider.
- Program exports: The launch release keeps program exports local through clipboard, CSV, Excel-compatible, and PDF outputs. The Google Sheets OAuth/API export is disabled, so these exports do not send program data to Google Sheets. Merge, deployment, and exact-release no-request proof remain pending.
- Google Fonts: Disabled for the launch release. The registration builder uses system or embedded uploaded fonts, hosted registration and marketplace emit no Google Fonts link, the generated API snapshot strips its generator-added link, and document CSP omits both Google Fonts origins. Merge, deployment, and exact-release no-request proof remain pending.
- Google Translate: Disabled for the launch release. Legacy registration values normalize to off, merchant controls are removed, the hosted registration route emits no Translate script or widget, and the document policy no longer permits Translate hosts. Merge, deployment, and exact-release no-request evidence remain pending.
- Google reCAPTCHA: Optional public affiliate-registration abuse prevention. When configured, Google receives browser/network and interaction metadata and the verification fields described above; this path remains publication-gated on provider terms, notice/lawful posture, minimization, retention, failure/replay, and disabled-no-request evidence.
- Mapbox and geoBoundaries: Disabled for the launch release. The program editor retains its list-based territory workflow, does not expose a map token, and does not load Mapbox styles, tiles, telemetry, geoBoundaries metadata, or provider-selected geometry. Merge, deployment, and exact-release no-request proof remain pending.
- VirusTotal: Optional malware scanning only for attachment paths implemented through the approved scanner. The text-only affiliate ticket surface accepts no files and therefore makes no VirusTotal request; it must not be described as a scanned upload path.
- PayPal: Optional merchant-configured payout settlement using affiliate payout email, a reviewed USD amount, payout note, and deterministic batch/item identifiers. PayPal-eligible non-USD or missing-conversion items block before provider egress; other-method items are skipped and a partially handled batch returns to open rather than being marked paid. Accepted nonterminal outcomes retain reconciliation state. The authenticated Check PayPal status action reads only the exact stored provider batch reference with bounded pagination and atomically applies exact terminal sender-item outcomes; missing, held, unclaimed, or other nonterminal items remain claimed, and changed accounting fails closed. A batch with provider-settlement history cannot be voided or manually finalized. Evidence must use sandbox data, never a live payout as UAT.
- Stripe Connect: Optional merchant-configured transfers using the affiliate Connect account, a reviewed net USD amount, and minimized deterministic batch/affiliate metadata. Stripe-eligible non-USD or missing-conversion items block before transfer egress; other-method items are skipped and a partially handled batch returns to open rather than being marked paid. Ambiguous or partial outcomes require reconciliation. Evidence must use test mode, never a live transfer as UAT.
- Wise: Optional affiliate payout rail selected by a merchant and subject to its own configuration, recipient, minimization, retry/reconciliation, contract, and test-environment evidence.
- Optional marketing and commerce connectors: Services such as Klaviyo, Mailchimp, Omnisend, Salesforce, Chargebee, or TikTok Shop when a merchant connects them
- Merchant-controlled automation recipients: Zapier, Make, custom webhook endpoints, or a legacy webhook URL configured by the merchant. These recipients are not Wand sub-processors and must remain disabled unless the merchant owns or authorizes them and documents the purpose, notice/consent or opt-out posture, security/signing, retention/redaction, and applicable downstream terms.
- Merchant-controlled branded-email logo host: Disabled for the launch release. Branded emails use merchant text and color branding without embedding a merchant-selected remote image URL. New queue entries and previously persisted pending jobs pass through a logo-specific sanitizer before provider delivery.
- Merchant-controlled settings image hosts: Disabled for the launch release. Persisted remote logo, favicon, and banner URLs are not returned to the settings browser or rendered on the Branding or Marketplace tab, crafted non-empty values are rejected, and a normal Branding save clears both legacy logo locations plus favicon and banner values.
- Merchant-controlled registration-logo hosts: Disabled for the launch release. The registration builder accepts only bounded embedded raster image data, rejects crafted unsupported values, and normalizes legacy remote values to empty before builder, campaign-list, hosted-registration, or embedded-registration browser output.
- User-selected share recipients: Facebook, X, Pinterest, LinkedIn, Reddit, WhatsApp, or the user's mail handler can receive the full registration or affiliate referral URL after a user deliberately selects that destination. The URL contains its referral/tracking identifier; applicable social surfaces also disclose non-discount share text/title/description and ordinary browser/network request metadata. X or WhatsApp affiliate-share text and affiliate Email actions can also contain the discount code. If sent by email, the selected mail provider and recipient receive that content. These paths are separate from the optional Meta Pixel and Resend and remain publication-gated on exact-surface minimization, applicable provider/transfer/retention evidence, notice, and synthetic activation/cancel/failure verification.
- Meta Platforms (merchant-controlled, optional): When a merchant supplies its Meta Pixel identifier and Shopify reports the required marketing and sale-of-data consent, the storefront sends Meta PageView and Lead events that can include the affiliate code. Meta acts under the merchant's configuration and applicable Meta terms; Wand does not treat this merchant-controlled recipient as a Wand sub-processor.
- PostHog (United States, when enabled): Privacy-minimized product analytics with person profiles, GeoIP, autocapture, and session replay disabled
- Sentry (when enabled): Scrubbed application error and performance monitoring; session replay is code-disabled for the pilot
4. Data Retention
We retain operational data while the app is installed. When you uninstall the app:
- Sessions, access credentials, payout credentials, and processing are disabled or removed.
- Non-financial personal data is deleted or anonymized through Shopify's redaction workflow.
- Financial and tax records required for accounting, audit, and legal obligations are retained in pseudonymized form for seven years.
After that period, permanent deletion follows our separately authorized retention process and applicable legal obligations.
When PostHog product analytics is enabled, its allowlisted events are retained for up to 12 months under the current hosted-project setting. The provider identifier changes with every browser session and is not linked across sessions. Removing local session telemetry removes Wand's mapping; any remaining provider event is no longer attributable through Wand's records. We will shorten this period if our legal and privacy review requires it.
Sentry is enabled only after its provider region, retention, deletion, access, IP-storage, and transfer controls are separately approved for the target environment. Session replay is code-disabled for the pilot and cannot be enabled through environment configuration.
5. Your Rights (GDPR & CCPA)
You and your affiliates have the right to:
- Access: Request a copy of your personal data (affiliates can download their data from the portal settings)
- Deletion: Request deletion of your personal data (affiliates can request account deletion from the portal settings); legally required financial and tax records may be retained in pseudonymized form
- Portability: Export your data in JSON or CSV format
- Opt-out: Unsubscribe from non-essential emails via the unsubscribe link in every email, and object to or request that we stop product analytics associated with your use
To exercise these rights, contact us at privacy@wandreferrals.com.
6. Data Security
We protect your data with:
- SSL/TLS encryption for all data in transit
- Managed database access controls and encryption of sensitive application credentials and session tokens
- Hashed authentication tokens (never stored in plaintext)
- Role-based access control (RBAC) for admin operations
- Rate limiting on authentication endpoints
- Content Security Policy (CSP) headers
7. Cookies
We use the following cookies:
- Session cookie: Required for affiliate portal authentication (7-day expiry)
- Storefront attribution cookies: When the merchant enables the Wand tracking theme app embed and Shopify reports analytics consent,
wr_aff_refandwr_program_idremember the affiliate/program for the merchant-configured attribution window of 1–90 days (30 days by default), andwr_cart_syncedlimits cart synchronization for one day. - Storefront session storage:
wr_sessionprovides a browser-session identifier for consented click/journey attribution. When automatic referral discounts are enabled,wr_discount_appliedprevents the same storefront session from reapplying the discount. Both clear with the browser session. - Optional marketing attribution:
wr_fbclidand an optional Facebook Pixel run only when Shopify reports marketing and sale-of-data consent. - Cookie consent: Stores the storefront cookie-consent preference in localStorage where that separate storefront feature is used
We do not use these technologies to sell personal data or for unrelated cross-context behavioural advertising. The storefront attribution and optional marketing technologies above remain subject to Shopify's consent signals.
Product-analytics session identifiers and the immediate in-page objection state, when enabled, are held only in page memory and are not written to cookies, localStorage, or sessionStorage. They reset on a full page reload. The server stores the authoritative durable merchant-shop, tenant-and-affiliate, or staff-scoped objection so later analytics writes are blocked for that authenticated scope without carrying one account's preference into another account that reuses the browser.
8. Contact
For privacy-related inquiries, contact us at privacy@wandreferrals.com.
Operator: Gilad Moyal, an individual operating Wand Referrals
Business mailing address: 4880 Lower Roswell Rd Ste 165-202, Marietta, GA 30068, USA
Wand Referrals is developed and operated by Gilad Moyal in his individual capacity.