Privacy Policy
- Scope and who we are
- Information we collect
- Where the information comes from
- How we use information
- Legal bases (EEA, UK, Switzerland)
- AI processing and model training
- TikTok and platform data
- How we share information
- Service providers and sub-processors
- Cookies and analytics
- Marketing, email and SMS
- How long we keep information
- How we protect information
- International transfers
- Your privacy rights
- US state privacy disclosures
- Global Privacy Control and opt-out signals
- Automated decision-making and profiling
- Children
- Third-party links and platforms
- Changes to this policy
- How to reach us
1. Scope and who we are
This Privacy Policy explains how Breez Global Group LLC (“Breez Global Group,” “we,” “us”) handles personal information in connection with the Afili website at affili.club, our web and mobile applications, and related services (together, the “Service”). It applies to visitors, account holders and workspace members.
For people in the European Economic Area, the United Kingdom and Switzerland, Breez Global Group is the controller of the personal information described here. Where you use Afili to process information about other people — for example team members you invite, or customers whose orders appear in your commission reports — you act as the controller of that information and we act as your processor.
This policy does not cover TikTok, TikTok Shop, or any other third-party platform you connect. Their handling of your data is governed by their own policies.
2. Information we collect
The table below lists the categories of personal information we have collected in the last 12 months, the examples in each category, where it comes from, and the types of parties we disclose it to for a business purpose.
| Category | Examples | Source | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email address, account and workspace IDs, IP address, device identifiers, TikTok account handles and open IDs | You, your device, TikTok | Service providers, TikTok |
| Commercial information | Plan, subscription status, credit balance and ledger, invoices, transaction history, products you research and promote, commissions attributed to your posts | You, Stripe, TikTok | Payment processor, hosting |
| Financial information | Billing contact and the last four digits and brand of your payment card. Full card numbers are collected and stored by Stripe — never by us | Stripe | Payment processor |
| Internet or network activity | Pages viewed, features used, clicks, session duration, referring URL, browser and OS, error traces | Your device | Analytics and error-monitoring providers |
| User content | Uploaded footage and images, generated videos and audio, scripts, hooks, captions, prompts, schedules, notes, and emails you forward to us for parcel parsing | You | AI providers, storage, TikTok at publish time |
| Approximate location | Coarse city/region inferred from IP address for security and fraud prevention | Your device | Security and hosting providers |
| Inferences | Predicted conversion scores, product-fit ranking, and performance priors derived from your workspace results | Derived by us | Not disclosed externally |
Sensitive personal information. We do not intentionally collect government identifiers, precise geolocation, biometric identifiers, health data, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or the contents of your private communications. Please do not upload footage or forward emails containing those categories. If you upload video that shows an identifiable person, you are responsible for having that person’s permission — including any consent required for biometric or likeness laws in your jurisdiction.
Payment cards. We never receive or store full card numbers. Stripe collects card details directly and returns only a token, the brand, and the last four digits.
3. Where the information comes from
- Directly from you — registration, onboarding questionnaire, uploads, prompts, schedules, support messages, emails you forward for shipment parsing.
- Automatically from your device — IP address, browser and device metadata, product analytics events, cookies and similar technologies.
- From platforms you connect — when you authorise a TikTok, TikTok Shop Affiliate or TikTok Business account, we receive the profile, video, order and campaign data those APIs return within the scopes you approve.
- From service providers — Stripe (payment and subscription status), carriers via 17TRACK (parcel checkpoints), and our infrastructure providers (security and delivery logs).
- Derived by us — conversion scores, velocity rankings and workspace performance priors we compute from your results.
We obtain product research data from licensed data partners and from official platform APIs. We do not scrape TikTok or any other platform, and we do not buy personal information from data brokers.
4. How we use information
- Provide the Service — create and secure your account, connect and refresh platform tokens, generate scripts and videos, assemble and publish posts, run and pause ad campaigns, ingest and attribute commissions.
- Billing — process subscriptions and credit purchases, place and settle credit holds, produce invoices, meet tax and accounting obligations.
- Support and communication — respond to you, send service notices (failures, reauth prompts, cap warnings, billing receipts) and, with your consent where required, product news.
- Safety, security and abuse prevention — authenticate sessions, apply rate limits, detect fraud and account takeover, enforce our Terms, and keep an audit trail of compliance actions such as disclosure toggles and AI-content labels.
- Improve the Service — measure feature usage, diagnose errors, and tune ranking and scoring models using aggregated or workspace-scoped signals.
- Legal — comply with law, respond to lawful requests, and establish or defend legal claims.
We do not use your content to build or improve products for other customers except in aggregated or de-identified form that cannot reasonably be linked back to you or your workspace. Where we de-identify data, we maintain it in that form and do not attempt to re-identify it.
5. Legal bases (EEA, UK, Switzerland)
| Purpose | Legal basis (UK/EU GDPR Art. 6) |
|---|---|
| Providing the Service, generating and publishing content you request, billing | Performance of a contract — Art. 6(1)(b) |
| Security, fraud prevention, rate limiting, service improvement, aggregate analytics | Legitimate interests — Art. 6(1)(f) |
| Non-essential cookies, marketing email where required, optional integrations | Consent — Art. 6(1)(a), withdrawable at any time |
| Tax records, responding to lawful requests, retention obligations | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have assessed that our interest in running a secure, reliable service is not overridden by your rights. You may object at any time — see Your privacy rights.
6. AI processing and model training
Afili uses third-party AI models to do the work you ask for. Understanding exactly what leaves our systems matters, so here it is plainly:
- What we send. Product titles, descriptions and images; the hooks, scripts and prompts you write or accept; footage you upload for captioning or critique; and the text of shipping emails you forward to your workspace parsing address.
- Who we send it to. Anthropic (language), Higgsfield, fal.ai, Google AI and HeyGen (video and speech). Each is listed in section 9 with the data it receives.
- Training. We do not use Your Content to train foundation models, and we use these providers under terms and API configurations that direct them not to train their models on our API inputs or outputs. We cannot control a provider’s own retention for abuse-monitoring, which is typically short-lived; we list current providers so you can review their policies.
- Human review. We do not read your prompts or media except when you ask for support, when we are investigating a specific abuse or security report, or when the law requires it. Those accesses are logged.
- Outputs. AI outputs can be inaccurate and are not unique to you — identical or similar prompts may produce similar results for other users. You must review generated video, claims and captions before publishing. Videos generated in Afili are labelled as AI-generated at publish time.
- Scoring. Conversion scores and rankings are statistical estimates. They do not produce legal or similarly significant effects about you — see section 18.
7. TikTok and platform data
Afili connects to three separate TikTok identity systems — content posting, Shop affiliate, and Business (ads). For each account you connect, we store an encrypted access and refresh token and the identifiers, metrics and order data the relevant API returns.
- Tokens are encrypted at rest with authenticated encryption and are never displayed back to you.
- We request the narrowest scopes that make the features work, and we only act on an account when you or a schedule you created tells us to.
- You can disconnect any account at any time in the app. Disconnecting revokes our tokens and stops all further calls for that account; content already published on TikTok remains on TikTok and is governed by TikTok.
- Commission and order data we ingest for attribution is limited to what the affiliate API exposes. We do not receive buyer payment details.
- Your use of TikTok through Afili is also subject to TikTok’s own terms and privacy policy. Afili is an independent product and is not affiliated with, endorsed by, or sponsored by TikTok Pte. Ltd. or ByteDance Ltd.
8. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:
- Service providers and sub-processors that host, process, generate, deliver or monitor on our instructions — listed in section 9.
- Platforms you direct us to — TikTok, when you publish a video, add a showcase product, or run a campaign.
- Members of your workspace — anyone you invite can see workspace content, schedules and performance according to their role, and workspace owners can see and remove member activity.
- Professional advisers — auditors, accountants and lawyers under confidentiality obligations.
- Legal and safety — where we reasonably believe disclosure is required by law or necessary to protect rights, safety or the integrity of the Service. Where legally permitted, we will notify you of a request for your data before responding.
- Corporate transactions — in a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply to the transferred information.
9. Service providers and sub-processors
Each provider below is bound by a written agreement limiting its use of personal information to providing the service to us. We update this list when it changes; material additions are announced in-app or by email before they take effect.
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Neon | Managed Postgres database hosting | All application data | United States |
| Hetzner Online GmbH | Application and background-worker compute | All application data in processing | United States / Germany |
| Cloudflare, Inc. | CDN, DNS, WAF and R2 object storage | Uploaded and generated media, request metadata | Global edge |
| Stripe, Inc. | Payments, subscriptions and tax | Billing contact, payment method (held by Stripe), transaction history | United States |
| Anthropic PBC | Language model for scripts, critique, concierge and shipping-email parsing | Prompts derived from your product, script and forwarded email content | United States |
| Higgsfield | Image-to-video generation | Product images and generation prompts | United States |
| fal.ai | Video generation fallback and speech-to-text captioning | Product images, prompts, generated audio | United States |
| Google LLC (Google AI) | Veo video generation | Product images and generation prompts | United States |
| HeyGen | Avatar and product-in-hand video generation | Product images, scripts, avatar selections | United States |
| TikTok / ByteDance Ltd. | Shop Affiliate, Content Posting and Business (ads) APIs | Account identifiers, video files, captions, campaign and order data | United States / Singapore |
| Postmark (ActiveCampaign) | Transactional email and inbound shipping-email parsing | Email address, content of messages you forward | United States |
| 17TRACK | Parcel tracking for product samples | Tracking numbers and carrier checkpoints | Hong Kong / Global |
| Sentry | Error monitoring | Error traces, workspace and user identifiers | United States |
| PostHog | Product analytics | Pseudonymous usage events, device and page metadata | United States |
10. Cookies and analytics
We use a small number of cookies and similar technologies:
- Strictly necessary — session and authentication cookies, CSRF protection, and load balancing. These cannot be switched off without breaking sign-in.
- Preferences — remembering your theme (light/dark) and workspace selection.
- Analytics — PostHog, to understand which features are used and where people get stuck. We configure it to record pseudonymous usage events; we do not use it for advertising and we do not permit it to be used for cross-site tracking.
- Error monitoring — Sentry, which captures error traces along with a workspace and user identifier so we can reproduce and fix bugs.
Where consent is required (for example in the EEA and UK), non-essential cookies are set only after you accept, and you can change your choice at any time from the cookie settings link in the footer. Most browsers also let you block or delete cookies; blocking necessary cookies will prevent you from signing in.
11. Marketing, email and SMS
We send transactional messages — receipts, job failures, reauthorisation prompts, security alerts — as part of the Service; these are not marketing and cannot be turned off while your account is active.
Marketing email is sent only where permitted or with your consent, and every message has an unsubscribe link.
SMS. If you opt in to text alerts (for example, the manual-post fallback notification), you consent to receive automated messages at the number you provide. Message and data rates may apply; frequency varies. Reply STOP to cancel or HELP for help. Consent to marketing texts is never a condition of purchase. We do not sell or share phone numbers.
12. How long we keep information
| Data | Retention |
|---|---|
| Account and workspace records | For the life of the account, then 30 days after deletion request |
| Uploaded and generated media | Until you delete it, or 30 days after account deletion |
| Platform access and refresh tokens | Deleted immediately on disconnect or account deletion |
| Credit ledger, invoices and tax records | Up to 7 years, as required by tax and accounting law |
| Compliance audit trail (disclosure and AI-label decisions) | Up to 3 years, to evidence advertising compliance |
| Security and access logs | Up to 12 months |
| Error traces and analytics events | Up to 90 days (errors) / 12 months (pseudonymous analytics) |
| Encrypted backups | Rolling window, expires within 35 days |
After a deletion request we remove or irreversibly de-identify personal information within 30 days, except where a longer period is legally required or necessary to resolve a dispute or enforce our agreements. Data in encrypted backups is removed as those backups expire.
13. How we protect information
- TLS 1.2+ in transit; encryption at rest for the database, object storage and backups.
- Platform tokens and advertising authorisation codes are additionally encrypted at the application layer with authenticated encryption, using keys held outside the database.
- Every record is scoped to a workspace and enforced by server-side authorisation on every request — not by the client.
- Least-privilege administrative access, unique credentials, and logging of privileged actions.
- Rate limiting, CSRF protection, secure session cookies and signature verification on all webhooks.
- Regular dependency scanning and prompt patching; backups tested by restore.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators without undue delay and, where required, within 72 hours of becoming aware. Report a vulnerability to security@affili.club — we will not pursue legal action against good-faith research that respects user privacy and avoids service disruption.
14. International transfers
We are based in the United States and our providers operate globally, so your information may be processed outside your country, including in the United States. Those countries may not offer the same level of protection as your own.
For transfers from the EEA, UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), together with supplementary technical measures such as encryption in transit and at rest. You can request a copy of the relevant transfer mechanism at privacy@affili.club.
15. Your privacy rights
Depending on where you live, you may have the right to:
- Know and access the personal information we hold about you, including categories, sources, purposes and recipients.
- Correct inaccurate personal information.
- Delete your personal information, subject to legal exceptions.
- Port a copy of your data in a portable, machine-readable format. Workspace exports are available in-app.
- Opt out of sale or sharing for cross-context behavioural advertising — we do neither, so there is nothing to opt out of.
- Limit the use of sensitive personal information — we do not collect it for purposes that trigger this right.
- Object to or restrict processing based on legitimate interests, and withdraw consent at any time without affecting prior processing.
- Not be discriminated against for exercising any of these rights. We will not deny service, change prices, or degrade quality because you made a request.
How to exercise them
Most actions are self-service in the app: Settings → Privacy lets you export your workspace, delete media, disconnect platform accounts and delete your account. Otherwise, email privacy@affili.club, or write to us at the postal address at the end of this policy. We respond within 45 days (extendable once by a further 45 days where permitted), or within one month for GDPR requests.
We operate exclusively online and deal with you only through the app and email, so email is our designated request channel; we do not maintain a toll-free telephone line for privacy requests.
We verify requests by matching the request to the email address on the account and, for higher-risk requests, by requiring you to complete an action from within a signed-in session. An authorised agent may submit a request on your behalf with written permission and proof of identity; we may still contact you to confirm.
If you are in the EEA, UK or Switzerland you may lodge a complaint with your local supervisory authority. We would appreciate the chance to resolve it first — write to dpo@affili.club.
16. US state privacy disclosures
This section supplements the rest of the policy for residents of California, Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia and other states with comprehensive privacy laws.
- The categories of personal information we collect, the sources, the business purposes and the categories of recipients are set out in section 2, section 4 and section 8.
- We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding 12 months — including information about consumers we know to be under 16.
- We do not process personal information for targeted advertising or for profiling that produces legal or similarly significant effects.
- Retention periods are described in section 12. Where a specific period is not listed, we retain data for as long as needed for the purpose it was collected and then delete or de-identify it.
- Some states allow you to appeal a refused request. To appeal, reply to our decision or email privacy@affili.club with “Privacy Appeal” in the subject line. We will respond within 45 days with our reasoning and, where applicable, a link to your state attorney general’s complaint process.
- California Shine the Light. We do not disclose personal information to third parties for their own direct-marketing purposes.
17. Global Privacy Control and opt-out signals
We honour the Global Privacy Control (GPC) signal. When your browser sends it, we treat it as a valid request to opt out of sale and sharing for that browser, and we disable non-essential analytics cookies. Because we do not sell or share personal information, this signal does not change how your data is used beyond cookie preferences. GPC applies per browser and device; we cannot link it to your account unless you are signed in.
18. Automated decision-making and profiling
Afili scores and ranks products and videos, not people. Conversion scores, velocity rankings, schedule optimisation and boost suggestions are recommendations that you review and approve; they do not produce legal or similarly significant effects concerning you within the meaning of Art. 22 GDPR.
We do use automated checks for security and abuse — for example rate limiting, fraud signals on payments, and blocking activity that breaches platform caps. If an automated control restricts your account, you can contact us at support@affili.club to have a person review it.
19. Children
The Service is for adults. It is not directed to anyone under 18 and we do not knowingly collect personal information from children. If we learn that we have collected information from someone under 18, we will delete it. A parent or guardian who believes their child has provided us information should contact privacy@affili.club.
20. Third-party links and platforms
The Service links to and integrates with third-party sites and platforms — TikTok, TikTok Shop, Stripe’s checkout and billing portal, and carrier tracking pages among them. We are not responsible for their content or privacy practices, and this policy does not apply to them. Review their policies before providing information.
Because there is no consistent industry standard for browser “Do Not Track” signals, we do not respond to DNT headers. We do honour GPC as described in section 17.
21. Changes to this policy
We may update this policy as the Service evolves. When a change is material we will give notice by email or in-app at least 14 days before it takes effect and update the “Last updated” date above. Continuing to use the Service after the effective date means you accept the updated policy. Prior versions are available on request.
22. How to reach us
Breez Global Group LLC
4480 South Cobb Drive SE, Suite H #738, Smyrna, GA 30080, United States
Privacy requests: privacy@affili.club
Data protection contact: dpo@affili.club
Security reports: security@affili.club
General support: support@affili.club
You can also read our Terms of Service.