Privacy Policy

Last updated: August 30, 2026.

Overview

Conduit is partnership infrastructure that helps businesses run referral programs. This policy explains what data we collect and why, in plain language.

Account and workspace data

When you create an account we store your email address, workspace details, program configuration, partner records, and any data you or your partners enter into Conduit (such as commission rules and conversion records).

Click and attribution data

When someone clicks a referral link, we store data needed to attribute that click to the right partner and later match it to a conversion. This includes:

  • A hashed identifier for the visitor (not raw personal identifiers)
  • A hashed or truncated IP address
  • Approximate country, derived from the request
  • Device and browser type
  • Referrer URL and UTM parameters, if present
  • Timestamp of the click and, later, the associated conversion

We use first-touch attribution: the first referral click within the attribution window is credited. This approach has real limitations — it can be affected by cross-device journeys, private browsing, cookie expiry, and direct traffic after a referral. See the docs for details.

Economic and integration data

We store conversions, provider webhook records, customer and subscription references, revenue events, commission rules, commission amounts and adjustments, payout records, and related metadata so businesses can operate and audit their partner programs. Provider payloads may contain identifiers supplied by the business or its billing provider.

RevenueCat and Stripe

If a business enables an integration, Conduit receives subscription lifecycle data from RevenueCat or exchanges connected-account and payout data with Stripe. Stripe hosts partner financial onboarding and may collect identity, tax, or bank information under its own terms and privacy policy. Conduit stores provider account references and eligibility status rather than partner bank details.

Data sharing

We do not sell personal data. We use infrastructure providers (such as hosting and database providers) to operate the service. When enabled by a business, RevenueCat and Stripe also process relevant integration and payout data under their respective terms.

Compliance

Conduit does not currently hold any compliance certifications (such as SOC 2 or ISO 27001). We do not claim certifications that have not been independently verified.

Data retention and deletion

We retain workspace, attribution, economic-event, webhook, commission, and payout records while an account is active and as reasonably necessary for security, accounting, dispute resolution, and legal obligations. Append-only financial records may require a different retention period. You can request deletion by contacting us.

Contact

Questions about this policy can be sent to support@conduitreferral.com.