Privacy notice
This notice describes processing through Share Master: Affiliate & Royalty, its public pages and the partner portal.
Last updated: 3 October 2026
Provider and responsibilities
Visions Studio · Samuel Marques Lucio · Sole proprietorSperlingweg 4 · 80937 München · Germany
contact@marqueslucio.com
Samuel Marques Lucio is responsible for the provider's own communications, support and operation of these public pages. Each merchant is responsible for their shop, partner program and settlement data; Share Master processes that data to provide the app according to the merchant's settings and instructions. The merchant's privacy notice also applies.
Data we process
- Shop and administration data: shop domain, currency, country, app settings, subscription and permission status, and Shopify access tokens. Shopify session data can include an administrator's name, email address and user ID.
- Partner data: name, email address, password hash, program and partner code, status, optional Shopify customer ID, tax and address details, payout details, and agreement and approval records.
- Order and attribution data: Shopify order ID and number, line items, product and collection IDs, quantities, amounts, currency, payment and refund status. Customer and checkout attribution uses hashes; complete order payloads are not stored as such. Hashes can remain personal data.
- Settlement and operational data: commissions, royalties, corrections, payout and document records, tax reviews, email contents and delivery status, API/webhook events, sessions and failed sign-ins.
- Access logs: shop, authenticated administrator, partner or API key identifier, or system actor, data categories, operation, action, time and result. Unidentified requests are recorded as anonymous. These logs contain no names, contact or payment details, document contents, passwords or access tokens.
- Opening a page transmits your IP address, time, requested URL and browser information to the servers involved. For support requests, we process your contact details and message contents.
Data comes from the merchant, Shopify, your partner portal entries or permitted storefront events. The relevant features cannot be provided without required account or settlement information.
Purposes and legal bases
Shop data is used to manage programs and partner accounts, attribute referrals, calculate commissions and royalties, correct refunds, and prepare settlements and documents. The merchant determines the legal basis for this processing. The app calculates amounts using configured rules; the merchant manages partner approvals and settlement operations.
Where applicable, our own contract and support communications rely on Article 6(1)(b) GDPR. Secure, reliable operation and prevention of abuse rely on our legitimate interest under Article 6(1)(f) GDPR. Where statutory retention duties apply to us, Article 6(1)(c) GDPR applies. Consent-dependent tracking operates only with the permissions described below; consent under Article 6(1)(a) GDPR is the relevant basis.
Cookies and browser storage
- Partner sign-in: the necessary sm_partner_session cookie contains a random session identifier and lasts up to 30 days. It enables protected portal access. Signing out ends the session.
- Referral pixel: when the Shopify pixel is enabled and both analytics and marketing are permitted, sm_ref_token is stored for up to 30 days. It associates a referred checkout with a partner. Without these permissions, the pixel does not set or send a new attribution; withdrawal removes the cookie. The signed referral token also has a validity period determined by the program settings.
- Optional link discount: with analytics permission, the theme module can keep a referral token in the tab's sessionStorage under sm_link:<shop> and set a signed proof in the sm_link_proof cart attribute. Withdrawal removes tab storage and requests removal of the cart proof.
Manage storefront permissions through the merchant's privacy choices. Blocking browser storage can affect sign-in or attribution. Withdrawal applies going forward and does not automatically remove settlement data that remains necessary.
Recipients and integrations
The merchant receives their program's data; partners receive their own account data, amounts and documents. Shopify provides the shop platform, authentication, APIs and, where enabled, store credit. Technical hosting providers process data for app operation. These pages also load a font through cdn.shopify.com, which receives your browser's technical connection data.
Emails are sent only through the merchant's own configured SMTP or Resend provider. That provider receives the recipient address and message content, which may include settlement documents. No email is sent without valid shop configuration. Enabled merchant webhooks send configured app events to the HTTPS endpoints selected by the merchant. After download, exported bank and accounting files are the merchant's responsibility.
Processing by Shopify or a provider chosen by the merchant may take place outside the EEA. Contact the merchant or our privacy contact for details of the specific providers, processing locations and any required transfer safeguards.
Storage, deletion and security
The app stores data in a server-side database scoped by shop. Portal passwords are stored as salted hashes. Integration secrets and stored email contents are encrypted.
Access logs support review and investigation of data access. The app worker deletes them after 90 days. For a specific security incident, individual entries may be held until a set end date; regular retention then applies again. This purpose-based period is not a statutory tax or Shopify retention duty. Access is restricted to authorized operators; partner data requests include only their own linked access metadata.
Retention criteria include the active app contract, processing purpose, open settlements, necessary evidence and applicable statutory duties. Shopify deletion requests remove or redact credentials, profile details and attribution data. Historical financial documents, tax reviews, necessary settlement evidence and unresolved payments require a separate retention and deletion review. Uninstalling therefore does not immediately delete all data. Cookie expiry also does not mean all associated database records are automatically deleted.
Support messages are retained for as long as handling the request and necessary records require. Contact us for specific retention questions, including backup copies.
Your rights
Subject to the GDPR's conditions, you have rights of access, correction, deletion, restriction and data portability. You can withdraw consent going forward and object to processing based on legitimate interests. Statutory retention duties may prevent immediate deletion.
For shop and partner data, contact the merchant or contact@marqueslucio.com and identify the shop. We verify authorization and coordinate handling with the merchant when needed. You may complain to a data protection supervisory authority, particularly where you normally live or work or where an alleged infringement occurred.
Further information
We update this notice when features or processing change. Program terms and tax decisions remain the merchant's responsibility and require separate review.
Provider's legal notice · General Data Protection Regulation · Shopify privacy policy