Company Information
This Privacy Policy is issued by Eastlink Affiliate Ltd ("Eastlink Affiliate", "we", "us", or "our"), a company registered in the United Republic of Tanzania.
| Detail | Information |
|---|---|
| Company Name | Eastlink Affiliate Ltd |
| Country of Registration | United Republic of Tanzania |
| Principal Office | Dar es Salaam, Tanzania |
| eastlinkaffiliate@gmail.com | |
| Phone / WhatsApp | +255 698 790 736 |
| Website | https://eastlink.africa |
| Data Controller | Eastlink Affiliate Ltd |
We operate an affiliate marketing platform connecting businesses ("Merchants") with independent promoters ("Affiliates") and individual sellers ("Vendors") across East Africa. This policy applies to all users of our platform and website.
What Data We Collect
We collect personal data only where necessary to operate our platform and provide our services. The categories of data we collect depend on how you use our platform.
Identity & Contact Data
- Full name or business name
- Email address
- Phone number (including WhatsApp number)
- Physical address or city of residence
- Country and nationality
- Profile photo (where voluntarily provided)
Business & KYB Verification Data (Merchants)
- Company registration number and TIN
- Director name and national ID number
- Business licence number
- Industry type and trading name
- Business website and description
Financial & Payment Data
- Mobile money account numbers (M-Pesa, Airtel Money, MTN MoMo)
- Bank account details (for payouts or bank transfers)
- PayPal email address (where used)
- Transaction references and amounts
- Subscription plan and billing history
We do not store full card numbers or payment credentials. All payment processing is handled by certified third-party providers (see Section 4).
Affiliate & Marketing Activity Data
- Affiliate ID assigned at registration
- Promotional channels used (social media, WhatsApp, email, website)
- Niche or category preferences
- Campaigns applied to and approved for
- Click counts, conversion counts, and commission earnings
- Tracking links generated and used
Technical & Device Data
- IP address
- Browser type and version
- Operating system
- Device type (desktop, mobile)
- Referring URL and pages visited on our site
- Time and date of access
Cookie & Tracking Data
- Session cookies for authentication
- Affiliate tracking cookies (
eastlink_ref) — see Section 5 and Section 8 - Preference cookies (e.g., language, theme)
Communications Data
- Messages sent to us via email or WhatsApp
- Support requests and complaint records
- Notification preferences
How We Use Your Data
We use personal data only for legitimate purposes and on a lawful basis as required by the PDPA 2022.
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Account creation & management | Name, email, phone, password hash | Contract performance |
| Identity & KYB verification | ID documents, business registration, TIN | Legal obligation / Contract |
| Processing payments & payouts | Mobile money number, bank details, transaction data | Contract performance |
| Affiliate commission tracking | Affiliate ID, click data, conversion data, cookie | Contract performance / Legitimate interest |
| Fraud prevention & security | IP address, device data, transaction patterns | Legitimate interest / Legal obligation |
| Sending transactional notifications | Email address, phone (WhatsApp) | Contract performance |
| Sending marketing communications | Email address, name | Consent (you may opt out at any time) |
| Platform analytics & improvement | Usage data, device data (aggregated) | Legitimate interest |
| Compliance with legal obligations | Any relevant data | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review.
Who We Share Data With
We share personal data only with trusted third-party service providers ("data processors") who process data on our behalf, under contractual obligations to protect it. We do not sell personal data.
Snippe — Mobile Money Payment Processing
Processes mobile money payments (M-Pesa, Airtel Money) for subscriptions and vendor upgrades. Data shared: phone number, transaction amount, reference. snippe.io
Pesapal — Payment Gateway
Processes card and mobile money payments for merchant subscriptions. Data shared: name, email, phone, amount. Subject to Pesapal's privacy policy. pesapal.com
Google Firebase (Firestore & Auth) — Database & Authentication
Stores all platform data including user accounts, campaigns, conversions, and transactions. Operated by Google LLC. Data may be processed in the United States under Google's standard contractual clauses. Firebase Privacy
Cloudinary — Image & Media Storage
Stores and serves product images, banner creatives, and profile photos uploaded by users. Images are publicly accessible via Cloudinary's CDN. Cloudinary Privacy
Resend — Transactional Email
Sends transactional emails including verification, OTP login codes, commission notifications, and subscription confirmations. Data shared: email address, name. Resend Privacy
Netlify — Hosting & Serverless Functions
Hosts our website and runs server-side functions. May process request logs including IP addresses. Netlify Privacy
WhatsApp Business API — Notifications
Sends real-time WhatsApp notifications for new leads, order alerts, and payout confirmations. Data shared: phone number, notification content. Subject to Meta's privacy policy.
We may also disclose data to law enforcement, regulators, or courts where required by Tanzanian law, a court order, or to protect the legal rights of our users or company.
Where data is transferred outside Tanzania, we ensure appropriate safeguards are in place, including standard contractual clauses, as required by the PDPA 2022.
Affiliate Tracking
Our platform operates an affiliate marketing system that tracks referrals, clicks, and conversions to correctly attribute and pay affiliate commissions. This section explains how tracking works.
Tracking Links
Each approved affiliate receives unique tracking links for the campaigns and products they promote. These links contain an affiliateId parameter (e.g., ?ref=ABC123) that identifies the referring affiliate.
The eastlink_ref Cookie
When a visitor clicks an affiliate tracking link, we set a first-party cookie named eastlink_ref in the visitor's browser. This cookie stores:
- The affiliate's unique ID
- The product ID being promoted
- The campaign ID associated with the link
eastlink_ref cookie persists for the duration set by the merchant's campaign (typically 7–90 days). This means if a visitor clicks an affiliate link today but purchases later, the affiliate still receives credit for the conversion.
Conversion Tracking
When a visitor completes a qualifying action (purchase, lead form, sign-up, or application), our system reads the eastlink_ref cookie and records a conversion event. This conversion is stored in our database and links the affiliate to the sale, enabling accurate commission calculation.
What Merchants Can See
Merchants can view aggregate analytics about their campaigns, including total clicks, conversions, commission paid, and top-performing affiliates. Merchants do not receive individual end-customer personal data through the affiliate tracking system.
What Affiliates Can See
Affiliates can view their own performance data: click counts, conversion counts, pending and approved commissions. Affiliates do not receive personal data about end customers.
Your Choices
You can prevent the eastlink_ref cookie from being set by disabling cookies in your browser settings or using a browser extension to block tracking cookies. Note that disabling cookies will not prevent you from using our website, but affiliates will not receive commission credit for referrals made without a valid cookie.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data (active) | Duration of account + 2 years after closure | Contract performance, legal claims |
| KYB documents | 5 years from account closure | Anti-money laundering legal obligation |
| Payment & transaction records | 7 years | Tanzania Revenue Authority tax compliance |
| Affiliate conversion data | 3 years | Dispute resolution, commission audit |
| Click & tracking logs | 12 months | Fraud prevention, analytics |
| Email communication logs | 2 years | Support records, legal claims |
| OTP codes | 5 minutes (auto-expired) | Security |
| Session cookies | Deleted on browser close or logout | Authentication |
Tracking cookies (eastlink_ref) | Campaign cookie duration (7–90 days) | Affiliate attribution |
| Deleted account data | 30 days (then permanently deleted) | Accidental deletion recovery |
After the relevant retention period, data is securely deleted or anonymised so it can no longer be associated with an individual.
Your Rights Under Tanzania PDPA 2022
Under the Personal Data Protection Act 2022, you have the following rights regarding your personal data. To exercise any right, contact us at eastlinkaffiliate@gmail.com. We will respond within 30 days.
Right to Access
You have the right to request a copy of the personal data we hold about you, including what data we have, how we use it, and who we share it with.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. You can update most information directly in your account dashboard.
Right to Erasure ("Right to be Forgotten")
You may request deletion of your personal data where we no longer have a lawful basis to process it. Note: we may retain certain data where required by law (e.g., tax records, fraud prevention).
Right to Object
You may object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds that override your interests.
Right to Restrict Processing
You may request that we restrict processing of your data (e.g., while accuracy is contested or an objection is being considered). Restricted data is stored but not actively processed.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and to transmit it to another controller.
Right Not to Be Subject to Automated Decisions
You have the right not to be subject to decisions made solely by automated processing, including profiling, that significantly affect you. We do not use purely automated decision-making for consequential decisions.
Cookies Policy
We use cookies and similar technologies on our website. A cookie is a small text file stored on your device by your browser.
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
__session / Firebase auth |
Strictly Necessary | Keeps you logged in to your account | Session / until logout |
eastlink_ref |
Functional / Tracking | Stores affiliate ID, product ID, and campaign ID for commission attribution | Campaign-defined (7–90 days) |
| Netlify edge cookies | Strictly Necessary | Load balancing, DDoS protection, performance optimisation | Session |
| Google Fonts / CDN | Third-party | Serves fonts and icons (Font Awesome). Google may set performance cookies. | Up to 1 year |
Strictly Necessary Cookies
These cookies are essential for the platform to function. They cannot be disabled without preventing you from using core features such as logging in or completing payments.
Functional & Tracking Cookies
The eastlink_ref cookie is set when you click an affiliate tracking link. It is necessary to operate the affiliate commission system. If you arrived at our platform via an affiliate link, this cookie enables the affiliate to be compensated. You may decline this cookie by adjusting your browser settings.
How to Manage Cookies
You can manage or delete cookies through your browser settings. Guides for major browsers:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Options → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Privacy, search, and services → Cookies
Deleting cookies may log you out of your account and will reset your affiliate referral attribution.
Children's Privacy
By creating an account on our platform, you represent and warrant that you are at least 18 years old. If you are a parent or guardian and believe that a minor has created an account or submitted personal data to us without your consent, please contact us immediately at eastlinkaffiliate@gmail.com.
Upon receiving a verified notification, we will promptly delete the relevant account and all associated personal data. We reserve the right to suspend or terminate any account where we have reasonable grounds to believe the account holder is under 18.
Betting & Gaming Campaigns
Age Verification
Merchants operating betting or gaming campaigns must confirm that their service complies with the Tanzania Gaming Board Act and any applicable licensing requirements. Our platform requires that all betting/gaming merchants:
- Hold a valid licence from the Gaming Board of Tanzania (or equivalent regulatory authority in their jurisdiction)
- Implement age verification measures to prevent users under 18 from accessing their services
- Clearly display responsible gambling information on their landing pages
Affiliates Promoting Betting Campaigns
Affiliates approved to promote betting or gaming campaigns must not:
- Target or promote gambling services to individuals under 18
- Make misleading claims about odds, winnings, or returns
- Use tactics that exploit vulnerable individuals
Responsible Gambling
We support responsible gambling. Landing pages linked from betting campaigns must include messaging directing users to support resources, such as the National Council for Responsible Gambling or equivalent local services.
Data Collected for Betting Campaigns
Where conversions are tracked for betting campaigns, the same affiliate tracking data described in Section 5 applies. No additional sensitive data (such as gambling history) is collected or stored by Eastlink Affiliate — such data remains with the merchant's own platform.
Contact & Complaints
Contact Us
For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, please contact us:
| Channel | Details |
|---|---|
| eastlinkaffiliate@gmail.com | |
| +255 698 790 736 | |
| Office | Dar es Salaam, Tanzania |
| Response Time | Within 5 business days for general enquiries; within 30 days for data rights requests |
Filing a Complaint with TCRA
If you are not satisfied with our response to a data rights request or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Tanzania Communications Regulatory Authority (TCRA), which is the supervisory authority responsible for enforcing the Personal Data Protection Act 2022.
| TCRA Contact | Details |
|---|---|
| Postal Address | P.O. Box 474, Dar es Salaam, Tanzania |
| Physical Address | Mawasiliano Towers, 20 Sam Nujoma Road, Dar es Salaam |
| Website | www.tcra.go.tz |
| dg@tcra.go.tz | |
| Phone | +255 22 2199760 |
We encourage you to contact us directly first so we can attempt to resolve your concern before escalating to TCRA.
Changes To This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Send an email notification to all registered users at their account email address at least 14 days before the changes take effect
- Display a prominent notice on our platform dashboard for at least 14 days
For minor changes (such as typographical corrections or clarifications that do not affect your rights), we may update this policy without prior notice, but the "Last updated" date will always reflect the current version.
Your continued use of the Eastlink Affiliate platform after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with any changes, you must stop using the platform and may request account deletion under your rights in Section 7.
We recommend reviewing this policy periodically. Previous versions of this policy are available on request by emailing eastlinkaffiliate@gmail.com.