Privacy policy
Effective date: August 5, 2026
RefKit is operated by Avit Tech, LLC (“RefKit,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, and share personal information when you use the RefKit website, platform, APIs, and related services.
1. Information We Collect
Information you provide
We may collect information that you provide directly, including:
- Name and email address
- Account and company information
- Profile information
- Program, commission, and referral settings
- Communications with us
- Payment and payout information
- Information submitted through forms, support requests, or surveys
Payment information may be processed directly by third-party payment providers. We may receive limited information about payments, such as payment status, transaction identifiers, and billing details.
Referral and conversion information
RefKit helps apps track referrals and conversions. We may process information such as:
- Affiliate links and link codes
- Click and conversion events
- Dates and timestamps
- IP address and approximate location
- Browser, device, and operating-system information
- Page URLs and referring pages
- Customer or transaction identifiers provided by an app
- Commission and payout information
Apps using RefKit are responsible for ensuring that they have the right to send this information to us.
Apps should not send sensitive personal information unless RefKit has specifically agreed to process it.
Automatically collected information
When you use RefKit, we may automatically collect:
- Log and usage information
- IP address
- Device and browser information
- Pages viewed and actions taken
- Error and performance information
- Cookies or similar technologies
2. How We Use Information
We use personal information to:
- Provide and operate RefKit
- Create and manage accounts
- Track referrals, conversions, and commissions
- Process payments and payouts
- Connect apps with promoters
- Provide reports and analytics
- Prevent fraud, abuse, and security threats
- Respond to support requests
- Send service-related communications
- Improve and develop RefKit
- Comply with legal and financial obligations
Where applicable, we process information based on the performance of a contract, our legitimate interests, compliance with legal obligations, or your consent.
3. Information Processed for Our Customers
When an app sends customer, referral, or conversion information to RefKit, the app generally controls why that information is collected and used.
In these cases, RefKit processes the information on the app’s behalf. Questions or requests concerning this information should normally be sent directly to the relevant app.
Our processing of this information may also be governed by a separate data processing agreement.
4. Shopify Integration
Information we receive
When a Shopify merchant installs or uses RefKit, we receive information from Shopify and the merchant through Shopify APIs, webhooks, embedded-app authentication, and the RefKit Web Pixel. Depending on the features used, this information may include:
- Store information, such as the store name, domain, currency, Shopify installation identifiers, granted permissions, and encrypted session credentials
- Merchant staff authentication and authorisation information, such as a staff identifier, owner or collaborator status, and locale
- Pseudonymous customer, order, checkout, transaction, refund, product, variant, and line-item identifiers
- Order, transaction, and refund details, such as discount codes, quantities, currency, amounts, status, test-order status, and timestamps
- Program and affiliate information entered by the merchant, such as names, affiliate email addresses, commission rules, discount settings, and payout records
We minimise the Shopify data we retain. Our stored Shopify attribution records do not include a buyer's name, email address, phone number, or postal address. We use keyed hashes to pseudonymise many Shopify identifiers and encrypt selected credentials and operational identifiers. Pseudonymous information may still be personal information.
Storefront attribution
Subject to Shopify's Customer Privacy settings and the visitor's consent choices for analytics and marketing, the RefKit Web Pixel may collect an affiliate referral code, the page origin and path with the query string and fragment removed, an event timestamp, and a randomly generated click identifier. At checkout, it may associate that click identifier with a checkout token or order identifier. Checkout and order identifiers are pseudonymised before storage.
The pixel may store a refkit_click_id cookie in the visitor's browser for up to 30 days. Its payload does not include the buyer's name, email address, phone number, postal address, IP address, or the page's query string. Shopify controls whether the pixel runs based on applicable privacy requirements and the visitor's choices.
How we use and disclose Shopify data
For Shopify buyer information processed through RefKit, the merchant generally decides why and how the information is processed, and RefKit processes it on the merchant's behalf.
We process Shopify data to:
- Connect, authenticate, and secure the merchant's store
- Operate affiliate programs, links, discounts, and Shopify marketing activities
- Attribute eligible clicks, checkouts, paid orders, and refunds
- Calculate and reconcile commissions, payments, refunds, and payout reports
- Provide merchant reporting, support, fraud prevention, and privacy compliance
We may disclose this information to the merchant, Shopify, and service providers that host and support RefKit, only as needed to provide and protect the service or comply with law. Shopify's own collection and use of information is governed by the Shopify Privacy Policy.
We do not sell Shopify buyer personal information or use it for cross-context behavioural advertising.
Retention and Shopify privacy requests
The click cookie and initial click-attribution window last for up to 30 days. Related server-side attribution records may be retained while the app remains installed and are removed or redacted when we complete Shopify's shop-redaction process. Encrypted files generated to answer a customer data request expire after 90 days.
Uninstalling RefKit stops ongoing Shopify API access and removes active session credentials. We then delete or redact store data when we process Shopify's required shop-redaction request, subject to limited retention for security, disputes, and legal, accounting, or tax obligations. A customer-redaction request removes the customer's linkage from retained records; pseudonymous transaction and financial records may remain where needed for those purposes.
Shopify storefront customers should normally submit privacy requests to the merchant from whom they purchased. We support merchants through Shopify's required customer data access and redaction processes. The privacy rights described below apply to Shopify personal information regardless of where the person lives. Merchants and customers may also contact us at privacy@refkit.net.
5. How We Share Information
We may share personal information with:
- Service providers that help us host, secure, maintain, and operate RefKit
- Payment and payout providers
- Analytics, email, and customer-support providers
- Apps and promoters where necessary to operate referral programs
- Professional advisers, such as accountants, lawyers, and auditors
- Government authorities where required by law
- A buyer or successor in connection with a merger, acquisition, financing, or sale of the business
Service providers may only use information as necessary to provide their services to us.
We do not sell personal information or share it for cross-context behavioural advertising.
6. Cookies
RefKit may use cookies and similar technologies to:
- Keep users signed in
- Remember preferences
- Track referral activity
- Protect the platform from abuse
- Understand how RefKit is used
- Improve performance
You can control cookies through your browser settings. Disabling certain cookies may prevent parts of RefKit from working correctly.
Where required, we will request consent before using non-essential cookies.
7. Data Retention
We keep personal information for as long as reasonably necessary to:
- Provide RefKit
- Maintain referral and transaction records
- Resolve disputes
- Prevent fraud and abuse
- Meet legal, accounting, and tax obligations
Retention periods depend on the type of information and why it was collected.
When information is no longer required, we may delete or anonymise it. Some information may remain temporarily in secure backups.
8. International Data Transfers
RefKit is operated from the United States and may use service providers located in other countries.
Your information may therefore be processed outside your country of residence. Where required, we use appropriate safeguards for international data transfers.
9. Your Privacy Rights
Depending on where you live, you may have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information
- Receive a copy of your information
- Object to or restrict certain processing
- Withdraw consent
- Appeal a decision concerning a privacy request
- Submit a complaint to a data-protection authority
You may exercise these rights by contacting us at privacy@refkit.net.
We may need to verify your identity before completing a request. Certain information may be retained where permitted or required by law.
We will not discriminate against you for exercising your privacy rights.
10. Security
We use reasonable technical and organisational measures designed to protect personal information.
However, no online service or storage system can guarantee complete security.
You are responsible for protecting your account credentials and notifying us if you believe your account has been compromised.
11. Children
RefKit is intended for businesses and professional users. It is not intended for children under 16.
We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so that we can review and delete it.
12. Third-Party Services
RefKit may contain links to third-party websites or integrate with third-party services.
Their privacy practices are governed by their own policies. RefKit is not responsible for the privacy practices of third parties.
13. Changes to This Policy
We may update this Privacy Policy as RefKit changes.
We will publish the updated version on our website and change the effective date above. Where appropriate, we may also notify account holders of significant changes.
14. Contact Us
For questions, requests, or complaints concerning this Privacy Policy, contact:
Avit Tech, LLC
Email: privacy@refkit.net
Website: https://refkit.net