Legal

Privacy policy

Last updated September 17, 2026

1. Who is responsible for what

Klibon is the data controller for account data — your email, your profile, your programs and your statements.

For visitors to a merchant's website, the relationship is different. The _klb cookie is a first-party cookie set on the merchant's own domain, on pages the merchant serves. The merchant is the controller for it and is responsible for declaring it in their cookie notice and obtaining consent where consent is required. Klibon acts as their processor for that data.

2. What we collect

From account holders

  • Email address, and a display name if you provide one.
  • Sign-in sessions (a session token, its expiry, the IP and user agent that created it).
  • Your selected payout method and encrypted payment destination, revealed only to you and merchants who owe you a statement.
  • If you use managed payouts: for a merchant, the identifier of your Stripe customer and the brand, last four digits and expiry of the card you saved; for an affiliate, the identifier of your Stripe account, its country, and whether Stripe currently allows it to be paid. The card number, identity documents, tax details and bank account you give during those setups go to Stripe and never reach Klibon.
  • A record of each managed payout: what was charged, what was transferred, to whom and when.
  • Subscription state mirrored from Creem. We never see or store card details.

From visitors who click a tracked link

  • The referral code, the destination, and the time of the click.
  • A salted hash of the IP address and of the user agent — never the values themselves. They are used to deduplicate repeated clicks and flag fraud, and cannot be reversed back to an IP address.
  • The referring page and the country derived from the request.

From people who ask for a listing to be removed

  • What you type in the form, and the email address you give us with the request.
  • A salted hash of your IP address, used only to limit abuse of that public form. Never the address itself.

From payment processors

  • Payment amount, currency, type (sale, renewal, refund) and a customer identifier.
  • Which product was bought, so the right commission rate applies.
  • A salted hash of the customer's email address, used to detect self-referral. We do not store the address itself.
  • If the merchant supplies a read-only API key: the names and prices of the products they sell. For Stripe, the key can also be how Klibon receives the payments above: it then reads the merchant's sale, renewal and refund events, and the checkout of a one-off sale to see which product was bought. Stripe's permissions let such a key read other events on the merchant's account too; Klibon does not request them. A merchant who prefers not to grant that access can send the same events by webhook instead.

3. Cookies we set on klibon.com

  • A session cookie, so you stay signed in. Strictly necessary.
  • A short-lived cookie remembering where you were headed before signing in.
  • A short-lived cookie carrying an Uneed product identifier, when you arrive through "Continue with Uneed", so we can pre-fill your product.

We use OpenPanel for privacy-friendly analytics on our own site. It sets no advertising cookies and builds no cross-site profile.

4. Who we share with

  • Merchants — an affiliate's profile and payment details, when a statement is due.
  • Creem — our merchant of record for subscription billing.
  • Stripe — only if you use managed payouts. Stripe charges the merchant, verifies the affiliate and pays them. It receives your email address and what it collects from you directly, and handles that data as an independent controller under its own privacy policy.
  • Sequenzy — transactional email delivery.
  • Supabase — database hosting, in the European Union.
  • Cloudflare and our hosting provider — serving the application.

We do not sell personal data, and we do not share it for advertising.

5. How long we keep it

Account data is kept while your account exists, then deleted within 30 days of a deletion request — except records we must retain for accounting purposes. Click records are kept for 24 months; the hashes they contain are not reversible in any case. Raw payment events are kept for the life of the program so commissions can be audited and recomputed. Records of managed payouts are financial records and are kept for the period accounting and tax law require, including after an account is closed.

6. Your rights

If you are in the EU, UK or a jurisdiction with comparable law, you may request access to your data, its correction, its deletion, or a portable copy, and you may object to processing. Write to [email protected] — we respond within 30 days. You also have the right to complain to your local supervisory authority.

7. Security

Payment-processor credentials — signing secrets and any read-only API key — are encrypted at rest with AES-256-GCM and are never returned to a browser. Personal identifiers used only for comparison are stored as salted hashes. Traffic is served over TLS. Access to the production database is limited to the operator.

8. Contact

Questions about this policy: [email protected].