Back
Privacy Policy for RefWaffle
Last Updated: February 13, 2026
Welcome to RefWaffle, operated by Merlinsbeard Pty Ltd ("we," "our," "us"). This Privacy Policy explains how we collect, use, and protect your information when you use our website at https://refwaffle.com (the "Site") and the RefWaffle platform (the "Service"). By using the Site or Service, you agree to this Privacy Policy.
1. Information We Collect
1.1 Personal Data
We collect the following personal information:
- Name: To personalise your experience and communicate with you.
- Email Address: To send account-related communications, notifications, and updates.
- Payment Information: To process subscription payments. We do not store payment details on our servers. Payments are processed by Paddle, our merchant of record.
- PayPal Email (Program Owners and Affiliates): Stored to facilitate direct commission payments between Program Owners and Affiliates. RefWaffle does not process these payments.
1.2 Program and Affiliate Data
- Program Configuration: Program names, slugs, website URLs, commission structures, welcome messages, custom terms, and resource links provided by Program Owners.
- Affiliate Data: Coupon codes, conversion records, commission amounts, and payout history.
- Payment Processor API Keys: Encrypted at rest and used solely for conversion tracking and coupon generation as defined by Program Owners.
1.3 Non-Personal Data
We use web cookies and similar technologies to collect non-personal information such as your IP address, browser type, device information, and browsing patterns to improve our Service.
2. Purpose of Data Collection
We collect and use data for:
- Providing and operating the Service.
- Processing subscription payments via Paddle.
- Tracking affiliate conversions and generating reports.
- Communicating with you about your account, programs, or affiliate activity.
- Improving our Service and user experience.
- Complying with legal obligations.
3. Data Collection Practices
We only collect personal information when it is necessary to provide the Service. We collect information by fair and lawful means, with your knowledge and consent.
4. Cookie Consent Management
To comply with GDPR regulations, we provide a cookie consent banner to visitors from the European Union and United Kingdom. You can choose to accept or decline non-essential cookies. Your choice is stored in your browser and can be changed at any time.
Regardless of consent choice, we may still process basic data server-side under our legitimate business interest for service operation and financial reporting.
5. Tracking Technologies and Analytics
5.1 DataFast Analytics:
We use DataFast (datafa.st) to track website usage, including page views and user interactions. When you accept cookies, DataFast uses cookies for visitor tracking and attribution. For more information, please review DataFast's privacy policy at https://datafa.st/.
5.2 End Customer Data (GDPR Compliance):
RefWaffle's coupon-based affiliate tracking does not use cookies or collect personal data about end customers visiting Program Owner websites. Coupon codes are entered by customers at checkout and tracked through payment processor webhooks. No personal data about end customers is stored by RefWaffle.
When Program Owners use RefWaffle's optional link-based tracking, a consent modal is displayed to the end customer before any tracking occurs, ensuring GDPR compliance.
6. Third-Party Services
6.1 Paddle: Our merchant of record for subscription billing. Paddle processes your payment information in accordance with their privacy policy: https://www.paddle.com/legal/privacy.
6.2 Supabase: Our database and authentication provider. User data is stored securely on Supabase infrastructure. For more information: https://supabase.com/privacy.
6.3 Stripe and Paddle (Program Owner Integrations): Program Owners may connect their own Stripe or Paddle accounts. RefWaffle accesses these accounts only to track conversions and generate coupon codes as defined by Program Owners, using encrypted API keys. We do not access end customer payment details.
7. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We only share data:
- With third-party service providers as described above, solely to operate the Service.
- Between Program Owners and their Affiliates (e.g. conversion data, coupon code attribution).
- When required by law or to protect our legal rights.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Upon account deletion, we will remove your personal data within a reasonable timeframe, except where retention is required by law or for legitimate business purposes (e.g. financial records).
9. Data Security
We protect your data using industry-standard security measures, including:
- Encryption of sensitive data at rest (e.g. payment processor API keys).
- Secure authentication via Supabase Auth.
- HTTPS encryption for all data in transit.
While we take reasonable precautions, no method of electronic storage or transmission is 100% secure.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data.
- Correct inaccurate data.
- Request deletion of your data.
- Object to or restrict processing of your data.
- Data portability.
To exercise any of these rights, contact us at jake@refwaffle.com.
11. Children's Privacy
RefWaffle is not intended for children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with their information, please contact us at jake@refwaffle.com.
12. External Links
Our Site may link to external websites not operated by us. We have no control over the content or privacy practices of these sites and accept no responsibility for them.
13. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. Users will be notified of material changes via email. Continued use of the Service after such updates constitutes acceptance of the revised policy.
14. Contact Information
For questions or concerns about this Privacy Policy, please contact us at:
Email: jake@refwaffle.com
Thank you for using RefWaffle!