Privacy policy
Last updated 21 August 2026
Who is responsible for what
Ascendz operates Advoro and is the data controller for account data: the people who sign in to run a workspace, their email addresses and their activity in the product. For the leads, customers and partners a business tracks inside Advoro, that business is the controller and Ascendz is a processor acting on their instructions.
What is stored about a lead
When someone opts in through a referral link, Advoro records their email address, an optional first name and phone number, which partner referred them, which programme it belonged to, the source label and whether they gave marketing consent along with the exact wording they agreed to. A salted hash of their IP address is stored to spot abuse. The raw IP address is never stored.
If you are a partner
Your Advoro login is yours and spans every business you work with, so Ascendz is the controller for it: your name, your email address and how you sign in. Each business you partner with is the controller for their own arrangement with you, which is your referral code with them, your terms, what you have earned and where they send it.
That is why closing a business’s workspace does not delete your account, and why one business cannot remove you from another. To change your name or your login, use Your account in the portal. To leave a particular business, ask them.
Artificial intelligence
Advoro does not use AI. There was a copy drafting feature and it was removed in August 2026. Nothing in the product sends anything to a model provider, and nothing about attribution, commission or payouts has ever been decided by one.
Where your data is held
The application runs in London and the database, authentication and file storage are on Supabase in Ireland. Transfers between the UK and the European Economic Area are covered by the UK’s adequacy regulations.
Transactional email is sent through Postmark and payment data is read from Stripe. Those two process in the United States, under the UK addendum to the Standard Contractual Clauses. They are the only two.
What a partner can see
The business owns the lead, the partner earns from it. A partner sees that they generated a lead, its first name, a masked email such as b...@example.com, its source and its status. Full email addresses and contact details stay with the business. A partner can also opt out of the public leaderboard and appear as Anonymous to other partners, while the business always sees who they are.
Cookies
Advoro sets one first-party cookie on a business’s own website, remembering which partner a visitor came through so the right person is credited if that visitor buys later. It is not a third-party cookie, it is not shared, and it is not used for advertising or profiling.
The business decides how consent is handled on their own site, because it is their site. Advoro can be told to wait for a consent signal before writing anything, and reads Google Consent Mode where a banner sets it.
Payment data
Advoro never sees or stores card details. It connects to a business’s own Stripe account to read the sales it needs to attribute, and Stripe remains responsible for processing. In this version Advoro also never moves money to partners: a partner raises an invoice and the business pays it directly.
Cross-account access
Businesses are isolated from one another by row level security in the database, so one cannot read another’s data. Ascendz staff can open a read-only support session against a workspace to troubleshoot. Every such session is time-boxed, is recorded in the operator audit log, and is also written into the affected business’s own audit log so they can see that someone looked and when.
Retention
Commission entries are kept for as long as the business needs them for their accounts, because the ledger is append-only and is the record both sides rely on. Email bodies are scrubbed after 30 days, raw payment provider payloads after 14, and delivered webhook attempts after 30.
The hashed IP, browser and referring page recorded against a click are erased once no cookie window at that business could still credit a partner from it. The click itself stays, because it is what a count of visits is made of and it then holds no person. Leads are the business’s own records and are kept until they erase them, unless that business has set a limit, in which case leads that never bought are erased once past it.
Erasure
A business can erase any lead or customer from their own workspace, and can close the workspace entirely, which deletes everything in it. Erasing somebody deletes their name, email address, phone number and consent record. Any sale they produced keeps its amount and stops pointing at anybody, because the business needs that figure for their accounts and it says nothing about who bought.
A partner erases their own account, from Your account in the partner portal, because a partner works with several businesses through one login and that identity is not any one business’s to erase. Closing a workspace therefore does not delete a partner. Leaving a single business is separate and is on that business’s settings page in the portal.
Erasing a partner account removes their name, email address, login, payout address, company details and billing address. Where the partner never earned anything, the record is deleted outright. Where they did, each business keeps the commission entries and payouts its own accounts depend on, and those name a referral code and an amount rather than a person. The referral code stays so that links already shared credit nobody, rather than being reissued and quietly crediting somebody else. Erasure is refused while a business still owes a partner money, because settling it needs the record on both sides; once paid, it proceeds.
Requests to access, correct or delete personal data should go to the business running the programme, since they are the controller for it.
Contact
clientsupport@ascendz.co