Version: v1 · Effective date: 2026-08-24 · Last updated: 2026-08-24

1. Who we are and what this policy covers

This Privacy Policy explains how Prish Partners, Inc. (a Delaware corporation), doing business as Partner Partner, registered at 8 The Green, STE B, Dover, DE 19901, United States (“Partner Partner,” “we,” “us”) handles personal data for which we are the controller.

This is our controller-side policy, and its scope is deliberately narrow. It governs Customer Account Data only — the identity, login, subscription, billing, and usage information of the agencies and individual users who hold or administer a Partner Partner account. For that data, Partner Partner decides the purposes and means of processing and is the controller (and, under U.S. state privacy laws, the business).

What this policy does not cover. When an agency uses Partner Partner, it uploads or generates information about its own clients, customers, contacts, and end users, together with related agreement and financial context (“Client Personal Data”). Partner Partner does not process Client Personal Data for its own purposes. We process it only on the agency’s documented instructions, solely to produce that agency’s own outputs, as a processor / service provider under a separate Data Processing Addendum (DPA). For Client Personal Data, the agency is the controller and is responsible for lawful basis, notices, and consent. If you are an individual whose data an agency uploaded to Partner Partner and you want to exercise your rights, please contact that agency directly — see Section 8. This policy does not expand, narrow, or override the DPA, and nothing in it makes Partner Partner a controller of Client Personal Data.

Partner Partner’s Data Processing Addendum describes the agency’s outputs as the agency’s own outputs / attestation and carries the full sub-processor annex referenced in Sections 5–6.

2. About our service (plain-language context)

Partner Partner is an independent software service. Agencies use it to organize evidence about their own standing in third-party partner programs and to have that evidence computed and held by Partner Partner. The agency — not Partner Partner — is the party that attests to its own standing. Where an agency chooses to share an external record of that standing, the record states:

[Agency] attests to its compliance against [Program]’s published [track] requirements — as of [date], based on [Agency]’s own evidence, computed and held by Partner Partner.

Where the service names a partner program:

Partner Partner is an independent service and is not affiliated with, authorized by, or endorsed by [Program], Klaviyo, Shopify, or any partner program. Program names are used only to identify the published requirements assessed.

This context is provided so you understand what the account you hold is for; the data practices that follow are what this policy actually governs.

3. The personal data we collect as controller, and why

We collect the following categories of Customer Account Data. We do not list Client Personal Data here, because we do not act as controller of it.

Sources. We collect this data from the following sources: directly from you when you create, administer, or use your account; automatically from your use of the service (log-in events, in-product actions, device and network signals); and from our payment processor in connection with billing and subscription payments.

Category Examples Why we process it Lawful basis (GDPR, where applicable)
Identity & account Name, work email, password/credential, role, agency name Create and secure your account; authenticate you Performance of a contract; legitimate interests in securing the service
Subscription & entitlement Plan, plan status, cap/entitlement state, renewal and cancellation records, consent logs for renewal disclosures Provide the plan you signed up for; operate billing and auto-renewal disclosures; keep required consent records Performance of a contract; necessary for a legal obligation (Art. 6(1)(c))
Billing metadata Billing contact, transaction and invoice records, partial payment-method identifiers held by our payment processor Take payment; meet tax and accounting duties; prevent fraud Performance of a contract; legal obligation (Art. 6(1)(c)); legitimate interests in fraud prevention
Usage & device Log-in events, feature usage, IP address, browser/device metadata, in-product actions Operate, secure, and improve the service; diagnose problems; prevent abuse Legitimate interests in a secure, functioning service
Support & communications Messages you send us, support tickets, product notices you receive Respond to you; send service and legal notices Performance of a contract; legitimate interests; consent where required for non-essential messages

We do not sell your Customer Account Data, and we do not use it to train, fine-tune, or improve any AI model.

Product-marketing email. We use your Identity & account data (name and work email) to send you product-marketing email about Partner Partner — for example, new features, product updates, and related offers. Where required, we rely on your consent or on our legitimate interests in marketing our own similar services to existing account holders. You can opt out at any time by using the unsubscribe link in any marketing email or by contacting us at support@yourpartnerpartner.com; opting out of marketing does not affect service and transactional messages (such as billing, security, and legal notices), which you continue to receive while you hold an account. We do not use any third-party product-analytics tool to process Customer Account Data.

4. A note on AI-assisted processing

Some outputs in the service are produced with AI assistance operating on the agency’s uploaded evidence. That processing concerns Client Personal Data and is governed by the DPA, not by this policy. We mention it here only for transparency and to be clear about two things: (a) we do not use Client Personal Data, or your Customer Account Data, to train, fine-tune, or improve any model; and (b) service outputs are informational and are not legal, financial, tax, or accounting advice. The agency is the party that attests to its own standing; Partner Partner computes and holds the underlying evidence.

5. How the two data populations stay separate

To keep this policy correctly scoped:

Any external record an agency chooses to share (defined in Section 2) reflects the agency’s own first-person attestation — expressed as PASS / NEUTRAL / EVIDENCED stamps and tier names — and does not publish the agency’s clients’ personal data or confidential agreement terms.

6. Sub-processors and other recipients

We use a small number of vetted service providers (“sub-processors”) to run the service. All are US-hosted. The current, versioned sub-processor list — with purpose, data categories, and location for each — is maintained in the DPA and published at https://yourpartnerpartner.com/subprocessors. That list is the authoritative, change-notified record; we reference rather than duplicate it here so the two never drift.

The recipients below are the subset of that list that receives Customer Account Data specifically:

We may also disclose Customer Account Data to professional advisers, to a successor in a merger or acquisition, or to authorities where required by law — in each case limited to what is necessary. We do not sell or “share” (as those terms are defined under U.S. state privacy laws) your Customer Account Data.

We add or replace a sub-processor only under the governance and advance-notice process described in the DPA.

7. How long we keep it (retention)

We keep Customer Account Data only as long as needed for the purposes above, then delete or de-identify it. Our default schedule:

Data Retention default
Account & profile data (identity/login) While your account is active; deleted 12 months after account closure, or on a valid erasure request, whichever is first (excluding billing and tax records, which follow the row below)
Billing and tax records (Stripe metadata) Retained as long as required for tax, accounting, and legal obligations — 7 years under U.S. / Delaware requirements — then deleted
Usage & product-analytics data Retained only as long as needed to operate, secure, and improve the service, then deleted or de-identified — as a default, within 24 months of collection, except where a specific record must be preserved for an active security investigation or legal hold
Support & communications Retained for the life of the account and for 24 months after the related request is closed, then deleted, except where preservation is required for a legal hold or to establish, exercise, or defend legal claims
Security, debug, and access logs Purged within 30 days, except where a specific record must be preserved for an active security investigation or legal hold
Backups Cleared on the standard rotation cycle — approximately every 35 days; deletion is complete once backups have rotated

Deletion reaches every place the data lives — our primary store, our compute artifacts, our logs, and our payment processor’s account metadata — subject to the backup-rotation window above.

(Retention of Client Personal Data is governed by the DPA, not this table.)

8. Your privacy rights

The rights below apply to your own Customer Account Data. If you are an individual whose data an agency uploaded to Partner Partner, that agency is the controller — please direct your request to the agency, and we will support the agency as its processor under the DPA.

8.1 Notice at collection (California — CCPA/CPRA)

At or before collection, we tell you what we collect and why (Section 3). We collect the categories listed in Section 3, from the sources listed there, for the business purposes stated there. We do not sell your personal information and do not share it for cross-context behavioral advertising. We do not knowingly process the personal information of minors.

Sensitive personal information. Certain Customer Account Data is “sensitive personal information” (SPI) under the CPRA — specifically your account log-in credentials and financial-account / payment identifiers. We collect and use this SPI only for the purposes identified in Section 3 (to create and secure your account, to authenticate you, and to take payment) — that is, only for purposes the CPRA treats as permitted business purposes that do not trigger a consumer right to limit. We do not use or disclose SPI to infer characteristics about you, and we do not use it for any purpose that would require us to offer a “Limit the Use of My Sensitive Personal Information” method.

8.2 California rights (CCPA/CPRA)

Subject to our confirming your identity, you may request to: know / access the personal information we hold about you and details of our processing; correct inaccurate personal information; delete your personal information; opt out of sale or sharing (not applicable — we do neither); and limit the use and disclosure of sensitive personal information (as described in Section 8.1, we use SPI only for permitted business purposes, so no limit method is required, but you retain this right). We will not discriminate against you for exercising these rights. You may use an authorized agent to submit a request.

8.3 GDPR / UK GDPR rights

Where EU, UK, or Swiss data-protection law applies to your Customer Account Data, you have the rights to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting prior processing. You also have the right to lodge a complaint with your supervisory authority.

Automated decision-making (Art. 22). We do not make decisions about you that produce legal or similarly significant effects and are based solely on automated processing of your Customer Account Data. Metering, cap-state, and entitlement-state are determined by automated processing, but they do not produce legal or similarly significant effects, so Article 22 is not engaged.

8.4 How to exercise your rights

Send requests to support@yourpartnerpartner.com. We will confirm your identity and respond within the timeframes required by applicable law. We do not charge a fee unless a request is manifestly unfounded or excessive, as permitted by law.

9. International data transfers

Our infrastructure and sub-processors are located in the United States, and Customer Account Data is processed there. If you access the service from the EEA, UK, or Switzerland, your Customer Account Data will be transferred to the United States.

We have EEA, UK, and Swiss account holders, so these transfers are in scope. Where such a transfer requires a safeguard, we rely on the EU Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum / IDTA, as further papered in the DPA and its annexes.

10. How we protect your data

We maintain administrative, technical, and organizational safeguards appropriate to the risk. Live today: secrets-management and credential hygiene, and encryption of data in transit. As committed controls we are implementing (target dates tracked in our DPA Annex II), we are rolling out encryption at rest, administrator multi-factor authentication (MFA), role-based access control and least-privilege, tested backup restoration, and security monitoring across our data stores. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents.

Breach commitment. If a security incident affects personal data, we will act promptly and in accordance with applicable law. Our processor-side breach commitments to agencies — including the notification timeline and the information we provide — are set out in the DPA; this policy incorporates that commitment by reference for Customer Account Data and does not restate a separate or conflicting standard.

11. Cookies and tracking

We use cookies and similar technologies of two kinds. Strictly necessary cookies run the service — they keep you logged in, keep the application secure, and remember your preferences; these do not require consent. We also use non-essential cookies for marketing and analytics. We set non-essential cookies only with your consent, which we collect through our cookie-consent banner when you first visit and which you can review or withdraw at any time using the “Manage consent” option on our website.

Cookie table. A full, current list of the cookies we use — with each cookie’s name, provider, purpose (necessary vs. marketing/analytics), and duration — is maintained in our Cookie Policy.

Opt-out and Global Privacy Control. In addition to the preference center, you can control cookies through your browser settings, though disabling strictly necessary cookies may prevent the service from working. Where required by law, we honor opt-out preference signals, including the Global Privacy Control (GPC), and treat a valid GPC signal as a request to opt out of the sale/sharing of personal information and of non-essential tracking to the extent applicable.

12. Contact us

Controller: Prish Partners, Inc. (a Delaware corporation), dba Partner Partner — 8 The Green, STE B, Dover, DE 19901, United States
Privacy contact: support@yourpartnerpartner.com

13. Changes to this policy

We may update this policy from time to time. When we do, we will change the version number and “Last updated” date at the top. For material changes, we will provide additional notice before they take effect — by email to the account’s registered address and/or an in-product notice — and, where the law requires it, we will seek your consent. Continued use of the service after a change takes effect means the updated policy applies to you. Prior versions are available on request.