Privacy Policy

Effective 19 August 2026

This policy explains what EP Links collects when you use EP Links, why we need it, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.

1. Scope

This policy covers the EP Links website and web app. It applies to you whether you create an account, generate affiliate links, or simply click a link someone shared with you. We process personal data in accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 together with rules made under it.

EP Links is the data fiduciary for this processing.

2. What we collect

Account information

Your name, email address and mobile number, and a one-way cryptographic hash of your password. We never store your password itself and cannot recover it for you.

Links you create, and clicks on them

The product URLs you convert, the affiliate links we generate for you, and an event for each click on those links. A click event records the time, the IP address of the visitor, the browser user-agent string, the referring page where available, and an approximate region derived from the IP address.

We need this because commission attribution and fraud detection are both impossible without it. Someone clicking a link you shared is a visitor to us, not an account holder, and we do not attempt to identify them personally or build a profile of them.

Purchase and commission data

When a purchase happens through your link, our affiliate partner sends us a notification containing an order reference, the order value, the commission payable, and the status of that order. We do not receive the buyer’s name, address, payment details, or the full contents of their basket.

Payout and tax information

To pay you, we need your bank account or UPI details, and identity information required by Indian law for payouts — which may include your PAN. We collect this at the point you request a withdrawal, not at signup.

Technical and usage data

Server logs of requests to our systems, including IP address and timestamps, kept for security, abuse prevention and debugging. A session cookie so you stay signed in.

3. Why we use it

We do not sell personal data. We do not run third-party advertising on this service, and we do not share your data for anyone else’s advertising.

4. Consent, and withdrawing it

We process your data on the consent you give when you create an account and when you request a payout, and, where the law requires us to keep records, on that legal obligation. You can withdraw consent at any time by writing to grievance@eplinks.com. Withdrawing consent means we close your account, because the service cannot function without the data described above. It does not erase financial records we are legally required to retain, and it does not reverse payouts already made.

5. Who else sees your data

Our primary database sits in India. Some providers listed above operate global networks, which means limited technical data such as an IP address may be processed outside India in the course of delivering a page or an email.

6. How long we keep it

Account data is kept while your account is open. Click events are kept for as long as they are needed to attribute and audit commission, and are then aggregated.

Wallet and commission entries are permanent. Our ledger is append-only by design — a correction is recorded as a new offsetting entry rather than by editing or deleting the original. This is deliberate: it is what lets you and us reconstruct exactly how a balance was arrived at. Financial records are additionally retained for the period Indian tax and company law requires.

7. Your rights

Write to grievance@eplinks.com for any of these. We will respond within the period the law allows, and will tell you if we need to verify your identity first.

8. Cookies

We use one essential cookie to keep you signed in. There are no advertising cookies, no cross-site trackers, and no third-party analytics scripts on the pages you browse as a signed-in user. Affiliate links, by their nature, cause the destination store to set its own cookies once the visitor arrives there — that happens on the store’s site under the store’s policy, not ours.

9. Security

Passwords are stored only as one-way hashes. Traffic to our systems is encrypted in transit. Our database is not reachable from the public internet. Access to production data is limited to the people who need it to operate the service. No system is perfect; if we discover a breach affecting your data we will tell you and the Data Protection Board as required.

10. Children

EP Links is not for anyone under 18. We do not knowingly collect data from children, and we will delete an account we discover to belong to one.

11. Changes

If we change this policy we will update the effective date above, and for anything material we will notify account holders by email before it takes effect.

12. Contact and grievances

Our Grievance Officer can be reached at grievance@eplinks.com. For anything else, write to tech@eplinks.com.