← AttribGate

Privacy Policy

Effective September 9, 2026 ยท Version 1.0

Who operates AttribGate

AttribGate is operated by SkyMork, the public service name used by an individual software developer based in the People's Republic of China ("SkyMork", "we", "us", or "our"). SkyMork is not presented as an incorporated company. Contact us at service@skymork.com. Legal operator details are available to merchants, regulators, and other authorized parties on a valid contractual or legal request.

Scope and roles

This policy covers the AttribGate Shopify app, its public website, support communications, and the infrastructure used to provide the service. For Shopify order and affiliate-network data processed on a merchant's instructions, the merchant is the controller or business and SkyMork acts as its processor or service provider. SkyMork acts as an independent controller for account administration, security, support, and legal communications.

Data we process

We process the minimum information needed to provide affiliate attribution review and commission audit:

  • Shop and staff session information supplied by Shopify, including shop domain, staff name, email, locale, session identifiers, and access tokens needed to authenticate the embedded app.
  • Order identifiers and references, processed and updated timestamps, cancellation, test, financial and fulfillment status, discount codes, order amounts and currencies, refund amounts, and current totals.
  • Available last-visit evidence from Shopify, including source, landing and referrer paths, and UTM source, medium, and campaign. Query strings are removed from persisted landing and referrer URLs.
  • Merchant-connected Awin or Impact account identifiers, encrypted API credentials, affiliate transaction identifiers, publishers, status, dates, amounts, currencies, and allowlisted attribution references.
  • Reconciliation recommendations, supporting reason codes, merchant decisions, writeback job states, synchronization checkpoints, and tenant-scoped operational records.
  • Information a merchant sends to our support mailbox. The public site currently uses no marketing analytics vendor and has no lead form.

Data we do not store

Business audit tables do not store buyer names, buyer email addresses, buyer phone numbers, street addresses, payment credentials, full Shopify Customer records, or raw Shopify, Awin, or Impact API response bodies. AttribGate does not add storefront tracking scripts, sell personal data, or use merchant or buyer data for advertising.

How we use data

We use the data to authenticate merchants, synchronize the most recent order and affiliate evidence, produce explainable commission-review recommendations, carry out separately confirmed network actions when enabled, operate and secure the service, respond to support requests, comply with law, and enforce our Terms. We do not use the data for materially different purposes without updating this policy and, where required, obtaining instructions or consent.

Service providers and connected networks

Cloudflare provides edge compute, queues, object storage, and database connectivity. Aiven provides managed PostgreSQL. Shopify provides the application platform, authentication, APIs, and compliance webhooks. Awin and Impact receive data only when a merchant connects the applicable account or confirms an eligible action; they act under their own terms and the merchant's relationship with them. Current details are listed on our Subprocessors and connected services page.

International processing

SkyMork is based in China, while Shopify, Cloudflare, Aiven, and connected networks may process data in other countries. This means data can be transferred internationally. A merchant that requires a particular transfer mechanism must contact us before sending affected data. Our Data Processing Agreement describes the contractual baseline and the process for any required transfer addendum.

Retention and deletion

Business audit data is deleted on a rolling schedule, with a default retention period of 395 days. Generated export objects and export metadata expire after seven days. OAuth state expires after ten minutes. Encrypted affiliate credentials are deleted when the integration or app is disconnected or uninstalled. Shopify's authenticated shop/redact webhook deletes tenant-scoped database rows, Shopify sessions, credentials, and objects under the tenant's export prefix. Data in provider backups ages out under the provider's backup schedule and is protected as production data.

Security

We use TLS in transit, AES-256-GCM encryption for affiliate credentials, authenticated Shopify sessions and webhooks, tenant-scoped data access, restricted service credentials, and explicit merchant confirmation before network writeback. No online service can guarantee absolute security. Report a suspected security issue to service@skymork.com.

Requests and choices

Merchants can request access, correction, deletion, restriction, or information about processing by contacting us. Because AttribGate does not retain buyer identity fields in its business tables, buyers should normally contact the Shopify merchant with whom they transacted; we assist the merchant and respond to Shopify's mandatory privacy webhooks. We may request enough information to authenticate a request and will respond within the period required by applicable law.

Changes

We may update this policy as the service or law changes. We will update the effective date and provide additional notice when a material change requires it.

Contact

Privacy, security, support, and legal notices: service@skymork.com. Operator information is available on the Operator Information page.