1. Introduction
This Privacy Policy describes how OneVa.ai ("we," "us," or "our") collects, uses, and protects information in connection with the OneVa.ai Affiliate Program. By participating in the Affiliate Program, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Affiliate Account Information
When you sign up for the Affiliate Program, we collect:
- Full name
- Email address
- Phone number (optional)
- Company name (optional)
- Website URL (optional)
- Password (stored securely using industry-standard hashing)
- Payout preferences (e.g., PayPal email, bank details, Venmo handle)
2.2 Tracking & Analytics Data
Our internal tracking system collects data related to affiliate referral activity. This includes:
- Clicks on your referral link (timestamps, referrer URLs, landing pages)
- Page views during referred sessions
- Session identifiers (randomly generated, non-personal)
- UTM parameters (source, medium, campaign, content, term)
- Device type, browser, and operating system
- General geographic information (country, region, city — derived from IP address)
- IP addresses (used for analytics and fraud prevention)
- Conversion events (signup, trial, active client status)
2.3 Financial Data
We track commission amounts, payout history, and related financial records necessary for calculating and disbursing your affiliate earnings.
3. How We Use Your Information
We use the information we collect to:
- Operate and administer the Affiliate Program
- Track referrals, clicks, and conversions to calculate commissions
- Process and disburse commission payouts
- Communicate with you about your account, earnings, and program updates
- Detect and prevent fraud, abuse, or policy violations
- Improve the accuracy and reliability of our tracking system
- Comply with legal obligations, including tax reporting requirements
4. Internal Tracking System
Our affiliate tracking system is built and maintained internally by OneVa.ai. It is not a third-party affiliate network. You acknowledge and agree that:
- The tracking system uses cookies with a 30-day expiration window to attribute referrals.
- Tracking relies on browser cookies and session identifiers, which may be affected by user browser settings, ad blockers, privacy extensions, VPN usage, or device switching.
- While we use commercially reasonable efforts to ensure tracking accuracy, no tracking system is infallible. Occasional discrepancies may occur.
- We are not liable for tracking inaccuracies caused by factors outside our control, but we will investigate and make good-faith efforts to resolve any discrepancies you report.
- Tracking data is used solely for affiliate program purposes and is not sold to third parties.
5. Cookies
We use the following cookies in connection with the Affiliate Program:
- oneva_ref — Stores the affiliate referral code for attribution. Expires after 30 days.
- oneva_user_type — Identifies whether a logged-in user is an affiliate or client for proper dashboard routing. Session-based.
- Authentication cookies — Standard session cookies used by Supabase Auth to maintain your logged-in state.
These cookies are essential to the operation of the Affiliate Program and are not used for third-party advertising or cross-site tracking.
6. Data Sharing
We do not sell your personal information. We may share your information with:
- Service providers — Third-party services that help us operate the platform (e.g., hosting, email, payment processing). These providers are contractually obligated to protect your data.
- Legal compliance — When required by law, court order, or government request.
- Business transfers — In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
7. Data Security
We implement industry-standard security measures to protect your personal information, including encryption in transit (TLS/SSL), secure password hashing, and access controls. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
8. Data Retention
We retain your affiliate account information and related tracking data for as long as your account is active and for a reasonable period thereafter for legal, tax, and business purposes. Click and page view data may be aggregated and anonymized for analytics after 12 months. If you request account deletion, we will remove your personal information within 30 days, except where retention is required by law.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Object to or restrict certain processing of your data
- Request a copy of your data in a portable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at support@oneva.ai. We will respond to your request within 30 days.
10. Children's Privacy
The Affiliate Program is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through your affiliate dashboard. The "Last updated" date at the top of this page reflects the most recent revision. Continued participation in the Program after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at support@oneva.ai.