Privacy
What SalesUp stores, who can read it, and what it never shares.
Last updated
SalesUp is an affiliate marketing platform. Brands publish offers, affiliates promote them, and SalesUp sits between the two — which means SalesUp holds data about both sides, and keeps them apart on purpose.
This page describes what is actually stored and who can actually read it, checked against the database rather than written from intention.
1 Who holds your data
SalesUp is operated by a single company, which is the party responsible for everything described on this page.
Not published yet
The operating company's legal name, its registered address, the country whose law applies, and an address for privacy questions. SalesUp will not name a company it has not registered, so this stays blank until the owner fills it in.
2 What SalesUp stores
- Your account — display name, email address, preferred language and an avatar colour. Sign-in is by a one-time code sent to your email; where an account also has a password, it is held hashed by the authentication provider and is never visible to SalesUp.
- If you are a brand — the brand's name and handle, its tier, its review status, its settings, its social links, its subscription and invoices, and the team members you invite.
- If you are an affiliate — your handle, your tier, your review status, the niches, regions and tools you list, trust signals computed from your own activity, and a stable anonymous number ("Affiliate #101") explained in the next section.
- Activity — every click and conversion on a tracking link, as an append-only stream: which tracking asset, when it happened, and whether it was a TEST event.
- Money — an earnings ledger, payouts, brand invoices, and payment methods. Card details are tokenized: SalesUp stores the last four digits and nothing more. A full card number never reaches SalesUp's database.
- Conversations — the messages you exchange inside the app, including with the in-app assistant.
- An audit trail — an append-only record of what was done, by whom, on which face of the app, and whether an AI proposed it. This record cannot be edited, including by SalesUp.
3 A brand never learns who its affiliates are
This is the most important commitment on this page, and it is a design constraint rather than a setting — there is no switch that turns it off.
- A brand sees "Affiliate #101" and aggregate performance. It never sees an affiliate's name, email address, handle, profile or linked social accounts.
- It is enforced in the database, not in the interface. No database rule grants a brand's members any access to the affiliates table. Disabling JavaScript, reading the page source, or calling the API directly does not reveal an identity, because the identity is never sent.
- Every brand-facing figure that summarizes affiliate performance is served by a view or function that exposes the anonymous number and never joins to a name.
- Inference counts as disclosure. Screens are designed so a brand cannot work out who someone is by combining otherwise-harmless numbers: a count that could only describe one person is treated as a leak, not as a statistic.
- The exception, stated plainly: SalesUp's own operators can see both sides. Someone has to review offers, settle disputes and pay people. Operator access is limited by role, and every operator action is written to the audit trail.
4 The two sides never receive each other's details
- Brands pay SalesUp. SalesUp pays affiliates. There is no direct payment between the two sides — which is what makes the previous section possible rather than merely promised.
- A brand never receives an affiliate's bank or payout details, and an affiliate never receives a brand's.
- The payout details you provide — an IBAN or an stc pay number — are used to pay you. They are readable by you and by SalesUp's finance operators, and by nobody else.
5 TEST data and real data
SalesUp keeps TEST activity separate from real activity end to end. A TEST click or conversion carries a flag, never enters the earnings ledger, and can never turn into money. TEST payments run against a test gateway and never charge a real card. Anything TEST is badged where it appears.
Today the entire platform is in that state: the payment and payout rails are not connected to a live provider, and no real money has moved through SalesUp. When that changes, this page changes with it.
6 The in-app assistant
- The assistant can read the data of the workspace you are in, and can propose actions inside it. It cannot see another workspace.
- It proposes; a human confirms. An action taken after an AI proposal is marked as such in the audit trail, so an AI-initiated change is always distinguishable from one you made yourself.
- If a brand supplies its own AI provider key, that key is write-only: it is stored where the interface cannot read it back, and it is never displayed again after it is saved.
- Content the assistant fetches from the web is treated as data, never as instructions.
7 Where the data lives, and who else touches it
- Database, authentication and file storage: Supabase, in its eu-central-1 region — Frankfurt, Germany.
- Application hosting: Vercel, targeted at its Frankfurt region.
- Transactional email — sign-in codes and invitations: Resend.
- The in-app assistant, when it is used: Anthropic.
- SalesUp runs no advertising trackers and no third-party analytics. There is no Google Analytics, no advertising pixel and no session-replay script on any page of this product.
Not published yet
The final list of processors the owner commits to, the data-processing agreements behind them, and confirmation that the regions above are the ones SalesUp will keep. The list above is what the build actually uses today.
8 Cookies and on-device storage
- A sign-in cookie, set by the authentication provider, that keeps you signed in.
- A language cookie and a display-density cookie, so the page renders in the right language and the right direction from the first byte instead of flickering.
- If you install SalesUp as an app on your phone, a service worker keeps a copy of the application's own static files on your device so it can tell you honestly when you are offline. It stores no data of yours, and nothing from any other site.
- Nothing else. SalesUp sets no advertising cookie and no cross-site tracking cookie.
9 How long it is kept
Account and workspace records are kept for as long as the account exists.
Two kinds of record are append-only by design and are not deleted when something is corrected: the audit trail, and the click and conversion stream. A money trail that can be edited is not a money trail. Corrections are added as new entries; nothing is rewritten in place.
Not published yet
A stated retention period. Today nothing is deleted on a schedule, because no schedule has been set — and saying otherwise would be a commitment the product does not keep.
10 Asking for your data, or for its removal
You can ask SalesUp for a copy of what it holds about you, for a correction, or for deletion.
A deletion request is recorded and settled one of two ways: deletion, or anonymization — your identifying fields are removed while the append-only money and audit records survive without them, because those records are also a record about somebody else.
Not published yet
The address to send that request to. SalesUp has not published a support mailbox yet: the app deliberately shows a reference code with no contact link rather than an invented address, and this page does the same.
11 Changes to this page
The date at the top is the day this text was last written. SalesUp is pre-launch and this text will change as the platform does; every material change moves that date.