Skip to main content

Privacy Policy

Effective Date: February 6, 2025 · Last Updated: February 6, 2025

Welcome to Pomlink (the “Site”), operated by Pomlink, Inc. (“Pomlink”, “we”, “us”, and/or “our”). Pomlink provides an influencer marketing and affiliate management platform that connects brands with creators through tracking, automated commissions, and seamless payouts (the “Services”). We value your privacy and are dedicated to protecting your personal data. This Privacy Policy covers how we collect, handle, and disclose personal data on our Platform.

We use your data to provide and improve the Services. By using the Services, you agree to the collection and use of information in accordance with this policy. Our Terms of Service (“Terms”) govern all use of our Services and together with this Privacy Policy constitute your agreement with us.

1. Definitions

TermDefinition
Servicepomlink.com website and app.pomlink.com web application operated by Pomlink.
Personal DataData about a living individual who can be identified from those data.
Usage DataData collected automatically, generated by use of the Service or from Service infrastructure (e.g., page visit duration).
CookiesSmall files stored on your device (computer or mobile device).
Data ControllerA person who determines the purposes and manner in which personal data is processed.
Data ProcessorAny person who processes data on behalf of the Data Controller.
UserThe individual using our Service, corresponding to the Data Subject.

2. Information Collection and Use

We collect several different types of information for various purposes to provide and improve our Service to you.

Account Data

  • Name
  • Email address
  • Profile picture (if provided)
  • Hashed password (if using email/password authentication)
  • Two-factor authentication data (if enabled)
  • Signup source and login history

Social Media and Creator Data

If you join as an influencer or creator, we may additionally collect:

  • Social media handles (e.g., Twitter/X, YouTube, Instagram, TikTok)
  • Subscriber and view counts from connected platforms
  • Website URL
  • Company name
  • Country

Financial Data

To process payments, commissions, and payouts, we collect:

  • Stripe Connect account information
  • Payout preferences and history
  • Commission earnings and balance data
  • Customer billing information (e.g., Stripe Customer ID)

Usage Data

We may also collect information that your browser sends whenever you visit our Service, including your IP address, browser type, browser version, the pages you visit, the time and date of your visit, time spent on those pages, unique device identifiers, and other diagnostic data.

Cookies Data

We primarily use first-party cookies to operate our Service, including session cookies, preference cookies, and security cookies.

Third-party services we integrate with (such as Google for OAuth authentication, Stripe for payments, and Sentry for error monitoring) may also set their own cookies when you interact with those services through our platform.

Customer Data

If you use Pomlink for conversion tracking or partner management, we collect customer information (name, email, avatar, external ID) and technical information (browser, device, geographic location, referrer URL, IP address) via our SDKs. This data is stored securely and only accessible to you and your authorized team members.

3. Use of Data

Pomlink uses the collected data for the following purposes:

  • To provide and maintain our Service
  • To process payments, commissions, and payouts
  • To notify you about changes to our Service
  • To provide customer support
  • To gather analysis so that we can improve our Service
  • To monitor the usage of our Service
  • To detect, prevent, and address fraud, abuse, and technical issues (including fraud risk scoring and account suspension for suspicious activity)
  • To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection
  • To provide you with notices about your account and/or subscription
  • To provide you with news, special offers, and general information about other services we offer unless you have opted not to receive such information
  • For any other purpose with your consent

You may opt out of marketing communications by following the unsubscribe link or emailing us at privacy@pomlink.com.

4. Retention of Data

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

Usage Data is generally retained for a shorter period, except when used to strengthen security or improve functionality, or when we are legally obligated to retain it for longer.

5. Transfer of Data

Your information, including Personal Data, may be transferred to and maintained on computers located outside of your jurisdiction where data protection laws may differ. If you are located outside the United States and choose to provide information to us, we transfer the data to the United States and process it there.

Pomlink will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

6. Disclosure of Data

We may disclose personal information that we collect or you provide:

  • If required by law or in response to valid requests by public authorities
  • In connection with a merger, acquisition, or asset sale
  • To subsidiaries, affiliates, contractors, and service providers
  • To fulfill the purpose for which you provide it
  • With your consent
  • If we believe disclosure is necessary to protect the rights, property, or safety of the Company, our customers, or others

7. Security of Data

The security of your data is important to us but no method of transmission over the Internet or method of electronic storage is 100% secure. We implement measures including password hashing, two-factor authentication, fraud detection and risk scoring, and secure API authentication.

8. Your Data Protection Rights Under GDPR

If you are located in the EU or EEA, you have the right to access, correct, delete, restrict processing, port, or withdraw consent for your personal data. Contact us at privacy@pomlink.com.

Your Role and Ours

When you use Pomlink's platform (such as installing our tracking script), we act as a data processor while you serve as the data controller. As a controller, you are responsible for obtaining consent, informing your users about data collection, and responding to privacy requests. As a processor, we process data on your behalf, protect your users' data, and help you comply with GDPR.

9. Your Rights Under CalOPPA

According to CalOPPA we agree to the following:

  • Users can visit our site anonymously
  • Our Privacy Policy link includes the word "Privacy" and can easily be found on our website
  • Users will be notified of any privacy policy changes on this page
  • Users can change their personal information by emailing us at privacy@pomlink.com

10. Your Rights Under the CCPA

If you are a California resident, you are entitled to learn what data we collect about you, ask to delete your data, and request that we not sell it. We do not sell or rent your personal information to any third parties. To exercise your California data protection rights, email privacy@pomlink.com.

11. Service Providers (Subprocessors)

We employ third-party companies to facilitate our Service. These third parties have access to your Personal Data only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.

ServicePurpose
SupabasePostgreSQL database hosting
VercelApplication hosting and edge infrastructure
StripePayment processing, commissions, and payouts
ResendTransactional email delivery
TinybirdAnalytics and event processing
UpstashRedis caching and background job queues
Cloudflare R2File and image storage
SentryError monitoring and diagnostics
GoogleOAuth authentication
BoxyHQ (Jackson)SAML/SSO authentication
ShopifyE-commerce integration (when enabled by user)
SlackInternal team notifications

12. Links to Other Sites

Our Service may contain links to other sites not operated by us. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites.

13. Children's Privacy

Our Services are not intended for use by children under 18. We do not knowingly collect personally identifiable information from children under 18. If you become aware that a child has provided us with Personal Data, please contact us.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “effective date” at the top.

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at privacy@pomlink.com.