CAPITIS
Sign inCreate sandbox key

Privacy Policy

Version 2.0 · Effective 4 August 2026

This policy describes how Capitis handles information — both about the people who use our website and API, and about the shoppers whose clicks pass through our tracking links. Capitis is operated by Single.id Limited, a company registered in England and Wales under company number 17044105, with its registered office at 20 Wenlock Road, London, England, N1 7GU.

Related documents: Cookies and tracking · Subprocessors · Security · Data Processing Addendum

The one distinction that explains everything else

There are two very different kinds of data here, and we are in a different legal role for each.

Your account data — we are the controller. If you sign up for Capitis, we decide what to collect about you and why. This policy governs that, and you can hold us to it directly.

Your end-users' data — we are your processor. If you are a publisher sending us hashed identifiers, clicks and conversions about your own shoppers, you decide what to send and why. We only act on your instructions. The terms that govern it are in the Data Processing Addendum, and the privacy notice your shoppers should read is yours, not this one.

Everything below is split along that line.


Part one — if you have a Capitis account

What we collect about you

  • Account information. Your email address; your name and profile picture if you sign in with Google or GitHub; your organisation name; and the authentication records needed to keep you signed in.
  • Usage data. Which API endpoints you call and when, request volumes, error rates, dashboard actions, and an audit log of security-relevant events on your account (API keys created and revoked, webhooks changed, identifiers attached or revoked).
  • Technical data. IP address and browser information in server logs, kept for operational and security purposes.
  • Billing information. Your billing contact details, subscription tier and invoice history. Card details are handled entirely by Stripe — we never see or store them.
  • What you write to us. Support emails, compliance reports and anything you send to our published addresses.
What we doWhyLegal basis (UK/EU GDPR)
Run your account, authenticate you, serve the APITo provide what you signed up forPerformance of a contract
Send transactional email — sign-in links, account and billing noticesSamePerformance of a contract
Bill you and keep accounting recordsTo get paid, and because tax law says soContract; legal obligation
Monitor for abuse, fraud and policy breaches; keep the audit logTo protect the platform, our customers and our network relationshipsLegitimate interests
Meet the compliance duties our affiliate network agreements impose on usWe cannot supply inventory without themLegitimate interests
Improve and debug the ServicesTo make the product work properlyLegitimate interests
Respond to regulators, and to lawful requestsBecause we mustLegal obligation

We do not use your data for advertising, we do not sell it, and we do not use it to train machine learning models. There is no automated decision-making that produces legal or similarly significant effects on you.

Marketing

We send product and service email to account holders about the service they are using. If we ever send marketing that needs consent, we will ask for it, and every message will carry a one-click unsubscribe.

How long we keep it

DataKept for
Account informationWhile your account is active, then 30 days after closure
Audit log24 months
Server and operational logs90 days
Billing and accounting records7 years, as UK tax law requires
Support correspondence24 months

Part two — shoppers, clicks and identifiers

This part describes data about your end-users. You are the controller; we are your processor. We are describing it here because transparency about it is what makes your own privacy notice possible to write.

What a click records

When a shopper follows a Capitis tracking link, we record, server-side: the timestamp, their IP address, the country derived from that IP, their user agent (the browser and device string), the referring URL, the link, merchant, campaign and label involved, and the click token that lets a later conversion be matched back.

We do not set or read any cookie on the shopper, and we run no script on them. The redirect is a plain HTTP response. The full detail is on the Cookies and tracking page.

IP address and user agent are personal data. We are not going to call them anything else. They are recorded because attribution and fraud detection do not function without them, and because the affiliate networks require us to be able to evidence traffic quality.

Hashed identifiers

If you use the identity features, identifiers reach us as HMAC-SHA256 hashes computed on your side — email, phone, card token, bank link or wallet reference. We never receive the raw values; there is no API field that accepts one.

Before storage we hash the incoming hash again, using a secret held only in the API environment and never written to the database. This matters because the incoming hash is deterministic — the same input always produces the same output, which is exactly what makes matching a returning shopper possible, and equally what would let someone holding both the parameters and a guessed value test for a match. The second, secret-keyed step means a stolen database on its own cannot be tested against a list of candidate email addresses.

These are pseudonymous personal data, not anonymous data, and we treat them that way throughout. Each identifier can be revoked individually, from the dashboard or the API, which removes it from matching immediately.

Who else receives this

The affiliate networks. A click has to reach the network for the commission to be paid — that is what an affiliate link is. Awin, Admitad, Rakuten Advertising, CJ, Skimlinks, FMTC and the others receive the click and the tracking reference, and process it as independent controllers under their own privacy policies, for their own purposes. They are not our subprocessors and we cannot limit what they do with it.

The merchant receives the shopper on its own site after the redirect.

Our subprocessors are listed, with locations and transfer mechanisms, at capitis.app/legal/subprocessors. None of them touches end-user data — that data stays on our own infrastructure.

How long we keep it

Hashed identifiers: until revoked, or until the publisher's account is deleted. Click and conversion records: for the life of the account, because they are the commission audit trail and a network can reverse a conversion months after the fact. After account closure, deletion follows DPA §10.

If you are a shopper reading this

You probably arrived here from a publisher's privacy notice. To have an identifier removed, ask the publisher whose site you used — they can revoke it instantly. You can also email privacy@capitis.app; we will help, but in most cases we will need to route the request back to the publisher, because a hash on its own does not tell us who you are.


Part three — the things that apply to everyone

Where your data is

All Capitis production infrastructure runs in Manchester, United Kingdom. Production personal data is not replicated outside the UK. A small number of subprocessors handling billing, email and sign-in are elsewhere; each is listed with its transfer mechanism on the subprocessors page.

Transfers from the EEA to us rely on the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 and valid until 27 December 2031.

Security

Described in full, including what we have not yet implemented, on the Security page.

Your rights

If you are in the UK, EEA or California you have rights to access, correct, delete, restrict, object to, and receive a portable copy of your personal data, and to withdraw consent where we rely on it. California residents additionally have the right to know and to opt out of sale or sharing — we do not sell or share personal information as those terms are defined by California law.

Email privacy@capitis.app. We respond within 30 days. We do not charge, and we will not treat you differently for asking.

Account deletion is currently handled manually by our team on request; a self-service control is in development.

Complaining

Tell us first — privacy@capitis.app. We will acknowledge your complaint and tell you what we are doing about it. Under the Data (Use and Access) Act 2025 we are required to make this easy and to respond, and we would rather hear it from you than from a regulator.

If you are not satisfied, you can complain to the UK Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113), or to the data protection authority in your EU or EEA country. You can go to them without coming to us first.

Children

Capitis is not directed at anyone under 16. We do not knowingly collect their data, and publishers must not use Capitis links on properties directed at children or submit identifiers for them.

Changes

We will announce material changes by email at least 30 days before they take effect, and the version and date at the top of this page will change.

Contact

WhatWhere
Privacy and data rightsprivacy@capitis.app
Securitysecurity@capitis.app
Legallegal@capitis.app
Generalsupport@capitis.app

Capitis is operated by Single.id Limited, 20 Wenlock Road, London, England, N1 7GU — Company Number 17044105 (registered in England and Wales).