1

Company Information

This Privacy Policy is issued by Eastlink Affiliate Ltd ("Eastlink Affiliate", "we", "us", or "our"), a company registered in the United Republic of Tanzania.

DetailInformation
Company NameEastlink Affiliate Ltd
Country of RegistrationUnited Republic of Tanzania
Principal OfficeDar es Salaam, Tanzania
Emaileastlinkaffiliate@gmail.com
Phone / WhatsApp+255 698 790 736
Websitehttps://eastlink.africa
Data ControllerEastlink Affiliate Ltd

We operate an affiliate marketing platform connecting businesses ("Merchants") with independent promoters ("Affiliates") and individual sellers ("Vendors") across East Africa. This policy applies to all users of our platform and website.

Applicable law: This policy is written in compliance with Tanzania's Personal Data Protection Act, 2022 (Cap. 447) and its regulations, administered by the Tanzania Communications Regulatory Authority (TCRA).
2

What Data We Collect

We collect personal data only where necessary to operate our platform and provide our services. The categories of data we collect depend on how you use our platform.

Identity & Contact Data

  • Full name or business name
  • Email address
  • Phone number (including WhatsApp number)
  • Physical address or city of residence
  • Country and nationality
  • Profile photo (where voluntarily provided)

Business & KYB Verification Data (Merchants)

  • Company registration number and TIN
  • Director name and national ID number
  • Business licence number
  • Industry type and trading name
  • Business website and description

Financial & Payment Data

  • Mobile money account numbers (M-Pesa, Airtel Money, MTN MoMo)
  • Bank account details (for payouts or bank transfers)
  • PayPal email address (where used)
  • Transaction references and amounts
  • Subscription plan and billing history

We do not store full card numbers or payment credentials. All payment processing is handled by certified third-party providers (see Section 4).

Affiliate & Marketing Activity Data

  • Affiliate ID assigned at registration
  • Promotional channels used (social media, WhatsApp, email, website)
  • Niche or category preferences
  • Campaigns applied to and approved for
  • Click counts, conversion counts, and commission earnings
  • Tracking links generated and used

Technical & Device Data

  • IP address
  • Browser type and version
  • Operating system
  • Device type (desktop, mobile)
  • Referring URL and pages visited on our site
  • Time and date of access

Cookie & Tracking Data

  • Session cookies for authentication
  • Affiliate tracking cookies (eastlink_ref) — see Section 5 and Section 8
  • Preference cookies (e.g., language, theme)

Communications Data

  • Messages sent to us via email or WhatsApp
  • Support requests and complaint records
  • Notification preferences
3

How We Use Your Data

We use personal data only for legitimate purposes and on a lawful basis as required by the PDPA 2022.

PurposeData UsedLawful Basis
Account creation & management Name, email, phone, password hash Contract performance
Identity & KYB verification ID documents, business registration, TIN Legal obligation / Contract
Processing payments & payouts Mobile money number, bank details, transaction data Contract performance
Affiliate commission tracking Affiliate ID, click data, conversion data, cookie Contract performance / Legitimate interest
Fraud prevention & security IP address, device data, transaction patterns Legitimate interest / Legal obligation
Sending transactional notifications Email address, phone (WhatsApp) Contract performance
Sending marketing communications Email address, name Consent (you may opt out at any time)
Platform analytics & improvement Usage data, device data (aggregated) Legitimate interest
Compliance with legal obligations Any relevant data Legal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human review.

4

Who We Share Data With

We share personal data only with trusted third-party service providers ("data processors") who process data on our behalf, under contractual obligations to protect it. We do not sell personal data.

Snippe — Mobile Money Payment Processing

Processes mobile money payments (M-Pesa, Airtel Money) for subscriptions and vendor upgrades. Data shared: phone number, transaction amount, reference. snippe.io

Pesapal — Payment Gateway

Processes card and mobile money payments for merchant subscriptions. Data shared: name, email, phone, amount. Subject to Pesapal's privacy policy. pesapal.com

Google Firebase (Firestore & Auth) — Database & Authentication

Stores all platform data including user accounts, campaigns, conversions, and transactions. Operated by Google LLC. Data may be processed in the United States under Google's standard contractual clauses. Firebase Privacy

Cloudinary — Image & Media Storage

Stores and serves product images, banner creatives, and profile photos uploaded by users. Images are publicly accessible via Cloudinary's CDN. Cloudinary Privacy

Resend — Transactional Email

Sends transactional emails including verification, OTP login codes, commission notifications, and subscription confirmations. Data shared: email address, name. Resend Privacy

Netlify — Hosting & Serverless Functions

Hosts our website and runs server-side functions. May process request logs including IP addresses. Netlify Privacy

WhatsApp Business API — Notifications

Sends real-time WhatsApp notifications for new leads, order alerts, and payout confirmations. Data shared: phone number, notification content. Subject to Meta's privacy policy.

We may also disclose data to law enforcement, regulators, or courts where required by Tanzanian law, a court order, or to protect the legal rights of our users or company.

Where data is transferred outside Tanzania, we ensure appropriate safeguards are in place, including standard contractual clauses, as required by the PDPA 2022.

5

Affiliate Tracking

Our platform operates an affiliate marketing system that tracks referrals, clicks, and conversions to correctly attribute and pay affiliate commissions. This section explains how tracking works.

Tracking Links

Each approved affiliate receives unique tracking links for the campaigns and products they promote. These links contain an affiliateId parameter (e.g., ?ref=ABC123) that identifies the referring affiliate.

The eastlink_ref Cookie

When a visitor clicks an affiliate tracking link, we set a first-party cookie named eastlink_ref in the visitor's browser. This cookie stores:

  • The affiliate's unique ID
  • The product ID being promoted
  • The campaign ID associated with the link
Cookie duration: The eastlink_ref cookie persists for the duration set by the merchant's campaign (typically 7–90 days). This means if a visitor clicks an affiliate link today but purchases later, the affiliate still receives credit for the conversion.

Conversion Tracking

When a visitor completes a qualifying action (purchase, lead form, sign-up, or application), our system reads the eastlink_ref cookie and records a conversion event. This conversion is stored in our database and links the affiliate to the sale, enabling accurate commission calculation.

What Merchants Can See

Merchants can view aggregate analytics about their campaigns, including total clicks, conversions, commission paid, and top-performing affiliates. Merchants do not receive individual end-customer personal data through the affiliate tracking system.

What Affiliates Can See

Affiliates can view their own performance data: click counts, conversion counts, pending and approved commissions. Affiliates do not receive personal data about end customers.

Your Choices

You can prevent the eastlink_ref cookie from being set by disabling cookies in your browser settings or using a browser extension to block tracking cookies. Note that disabling cookies will not prevent you from using our website, but affiliates will not receive commission credit for referrals made without a valid cookie.

6

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data TypeRetention PeriodReason
Account data (active)Duration of account + 2 years after closureContract performance, legal claims
KYB documents5 years from account closureAnti-money laundering legal obligation
Payment & transaction records7 yearsTanzania Revenue Authority tax compliance
Affiliate conversion data3 yearsDispute resolution, commission audit
Click & tracking logs12 monthsFraud prevention, analytics
Email communication logs2 yearsSupport records, legal claims
OTP codes5 minutes (auto-expired)Security
Session cookiesDeleted on browser close or logoutAuthentication
Tracking cookies (eastlink_ref)Campaign cookie duration (7–90 days)Affiliate attribution
Deleted account data30 days (then permanently deleted)Accidental deletion recovery

After the relevant retention period, data is securely deleted or anonymised so it can no longer be associated with an individual.

7

Your Rights Under Tanzania PDPA 2022

Under the Personal Data Protection Act 2022, you have the following rights regarding your personal data. To exercise any right, contact us at eastlinkaffiliate@gmail.com. We will respond within 30 days.

Right to Access

You have the right to request a copy of the personal data we hold about you, including what data we have, how we use it, and who we share it with.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data. You can update most information directly in your account dashboard.

Right to Erasure ("Right to be Forgotten")

You may request deletion of your personal data where we no longer have a lawful basis to process it. Note: we may retain certain data where required by law (e.g., tax records, fraud prevention).

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds that override your interests.

Right to Restrict Processing

You may request that we restrict processing of your data (e.g., while accuracy is contested or an objection is being considered). Restricted data is stored but not actively processed.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and to transmit it to another controller.

Right Not to Be Subject to Automated Decisions

You have the right not to be subject to decisions made solely by automated processing, including profiling, that significantly affect you. We do not use purely automated decision-making for consequential decisions.

How to exercise your rights: Email us at eastlinkaffiliate@gmail.com with the subject line "Data Rights Request" and your account email address. We will verify your identity before processing the request and respond within 30 days.
8

Cookies Policy

We use cookies and similar technologies on our website. A cookie is a small text file stored on your device by your browser.

Cookie NameTypePurposeDuration
__session / Firebase auth Strictly Necessary Keeps you logged in to your account Session / until logout
eastlink_ref Functional / Tracking Stores affiliate ID, product ID, and campaign ID for commission attribution Campaign-defined (7–90 days)
Netlify edge cookies Strictly Necessary Load balancing, DDoS protection, performance optimisation Session
Google Fonts / CDN Third-party Serves fonts and icons (Font Awesome). Google may set performance cookies. Up to 1 year

Strictly Necessary Cookies

These cookies are essential for the platform to function. They cannot be disabled without preventing you from using core features such as logging in or completing payments.

Functional & Tracking Cookies

The eastlink_ref cookie is set when you click an affiliate tracking link. It is necessary to operate the affiliate commission system. If you arrived at our platform via an affiliate link, this cookie enables the affiliate to be compensated. You may decline this cookie by adjusting your browser settings.

How to Manage Cookies

You can manage or delete cookies through your browser settings. Guides for major browsers:

  • Chrome: Settings → Privacy and security → Cookies
  • Firefox: Options → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Cookies
  • Edge: Settings → Privacy, search, and services → Cookies

Deleting cookies may log you out of your account and will reset your affiliate referral attribution.

9

Children's Privacy

⚠ Age Restriction: The Eastlink Affiliate platform is intended for users who are 18 years of age or older. We do not knowingly collect, process, or store personal data from individuals under the age of 18.

By creating an account on our platform, you represent and warrant that you are at least 18 years old. If you are a parent or guardian and believe that a minor has created an account or submitted personal data to us without your consent, please contact us immediately at eastlinkaffiliate@gmail.com.

Upon receiving a verified notification, we will promptly delete the relevant account and all associated personal data. We reserve the right to suspend or terminate any account where we have reasonable grounds to believe the account holder is under 18.

10

Betting & Gaming Campaigns

⚠ Regulated Category: Betting, gambling, and gaming campaigns are a regulated category on our platform. Additional requirements apply to merchants and affiliates participating in these campaigns.

Age Verification

Merchants operating betting or gaming campaigns must confirm that their service complies with the Tanzania Gaming Board Act and any applicable licensing requirements. Our platform requires that all betting/gaming merchants:

  • Hold a valid licence from the Gaming Board of Tanzania (or equivalent regulatory authority in their jurisdiction)
  • Implement age verification measures to prevent users under 18 from accessing their services
  • Clearly display responsible gambling information on their landing pages

Affiliates Promoting Betting Campaigns

Affiliates approved to promote betting or gaming campaigns must not:

  • Target or promote gambling services to individuals under 18
  • Make misleading claims about odds, winnings, or returns
  • Use tactics that exploit vulnerable individuals

Responsible Gambling

We support responsible gambling. Landing pages linked from betting campaigns must include messaging directing users to support resources, such as the National Council for Responsible Gambling or equivalent local services.

Data Collected for Betting Campaigns

Where conversions are tracked for betting campaigns, the same affiliate tracking data described in Section 5 applies. No additional sensitive data (such as gambling history) is collected or stored by Eastlink Affiliate — such data remains with the merchant's own platform.

11

Contact & Complaints

Contact Us

For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, please contact us:

ChannelDetails
Emaileastlinkaffiliate@gmail.com
WhatsApp+255 698 790 736
OfficeDar es Salaam, Tanzania
Response TimeWithin 5 business days for general enquiries; within 30 days for data rights requests

Filing a Complaint with TCRA

If you are not satisfied with our response to a data rights request or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Tanzania Communications Regulatory Authority (TCRA), which is the supervisory authority responsible for enforcing the Personal Data Protection Act 2022.

TCRA ContactDetails
Postal AddressP.O. Box 474, Dar es Salaam, Tanzania
Physical AddressMawasiliano Towers, 20 Sam Nujoma Road, Dar es Salaam
Websitewww.tcra.go.tz
Emaildg@tcra.go.tz
Phone+255 22 2199760

We encourage you to contact us directly first so we can attempt to resolve your concern before escalating to TCRA.

12

Changes To This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send an email notification to all registered users at their account email address at least 14 days before the changes take effect
  • Display a prominent notice on our platform dashboard for at least 14 days

For minor changes (such as typographical corrections or clarifications that do not affect your rights), we may update this policy without prior notice, but the "Last updated" date will always reflect the current version.

Your continued use of the Eastlink Affiliate platform after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with any changes, you must stop using the platform and may request account deletion under your rights in Section 7.

We recommend reviewing this policy periodically. Previous versions of this policy are available on request by emailing eastlinkaffiliate@gmail.com.

Current version: 1.0  ·  Effective date: 16 May 2026  ·  Governing law: Personal Data Protection Act 2022 (Tanzania, Cap. 447)