AppThunder
PricingBenefitsNative PowerTestimonialsStepsAbout
Referrals↗Log inGet Started
PricingBenefitsNative PowerTestimonialsStepsAboutAppThunder Referrals ↗
Log inGet Started

Data Processing Agreement — AppThunder Referrals

Last updated: September 30, 2026

This Data Processing Agreement ("DPA") is concluded between the customer using AppThunder Referrals ("Customer", controller) and AMDMarketing (sole proprietor: Alejandro Morillo Diaz), Am Markt 14, 23769 Fehmarn, Germany ("Processor", "We"). It forms part of the AppThunder Referrals Additional Terms (https://appthunder.io/referrals-terms) and is concluded when the Customer accepts them.

1. Subject matter and duration

The Processor processes personal data on behalf of the Customer in order to provide AppThunder Referrals: generating referral codes, attributing referred users to referrers, recording purchase and refund events, calculating commissions and providing them in the dashboard and as exports. This DPA applies for as long as the Processor processes personal data for the Customer in Referrals and ends automatically thereafter.

2. Nature and purpose of the processing

Collection (via webhooks from the Customer's subscription platform or Stripe account, the REST API, the code templates and the web snippet), storage, matching, calculation, display, export and deletion — exclusively for running the Customer's referral program as configured by the Customer.

3. Categories of data subjects

  • Referrers: end users of the Customer who share a referral code.
  • Referred users: end users of the Customer who apply a referral code, and whose purchases and refunds are reported to Referrals.

4. Types of personal data

  • Identifiers chosen by the Customer: its own user IDs (e.g. an app user ID, a subscription-platform user ID and its aliases, or a Stripe customer ID).
  • E-mail addresses, if the Customer chooses to send them: stored only as a SHA-256 hash and used for the self-referral check.
  • Referral data: referral codes, which referrer referred which user, the source of the referral and timestamps.
  • Purchase and refund data: amount, currency, store/platform, product ID, transaction and event IDs, environment, period type and timestamps. From the Customer's Stripe account or subscription platform, only these booking fields are kept — names, e-mail addresses, postal addresses, payment-method details and other attributes contained in those webhooks are discarded and not stored.
  • Commission data: amounts, status, hold and void information, payout batches.
  • Payout address: free text the Customer may enter for a referrer (e.g. a PayPal e-mail address or Wise ID).
  • Technical data: when an app or website validates a referral code with Our API, the request (code, public key) necessarily reaches Our hosting provider together with the device's IP address and user agent. We do not store IP addresses or user agents in Referrals; the hosting provider's infrastructure logs may contain them for a limited time.

The web snippet stores the referral code and the time it was captured in the visitor's browser (localStorage key "at_aff_ref") for up to 90 days and removes it once expired. It sets no cookies and sends nothing to Us unless the Customer's page calls its code-validation function. Whether a consent is required for this storage (e.g. under § 25 TDDDG or Art. 5(3) of the ePrivacy Directive) is assessed and, where necessary, obtained by the Customer.

The Customer must not send special categories of personal data (Art. 9 GDPR) or data of children to Referrals, and should use pseudonymous identifiers instead of names.

5. Instructions

The Processor processes the personal data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by Union or Member State law; in that case the Processor informs the Customer before processing, unless the law prohibits this. The Customer's instructions are given by this DPA, by the configuration of its programs and Integrations, and by its use of the dashboard and API. Further instructions must be given in text form (e.g. e-mail to support@appthunder.io). The Processor informs the Customer without delay if it considers an instruction to infringe data protection law.

6. Confidentiality

The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. At the time of writing, only the Company's owner has access.

7. Security of processing (Art. 32 GDPR)

The Processor implements at least the following technical and organisational measures and may replace them with measures of an equivalent or higher level of protection:

  • Encryption in transit: all connections to the dashboard, API and webhooks use TLS (HTTPS).
  • Encryption at rest: the database is hosted by Supabase on Amazon Web Services infrastructure with encrypted storage.
  • Access control: row-level security separates the data of each customer account; customers can only read their own programs. Administrative database access is limited to the Company's owner.
  • Pseudonymisation and minimisation: e-mail addresses are stored only as SHA-256 hashes; webhook payloads are reduced to booking fields before storage; secret API keys are stored only as hashes.
  • Authenticity of input: Stripe webhooks are verified with the Customer's webhook signing secret, subscription-platform webhooks with a per-program authorization secret; server-side API calls require the Customer's secret key.
  • Separation of duties: publishable keys used in apps and websites give read access only (validating a code, reading a referrer's referral count and earned commission); creating codes, referrals and events requires the secret key.
  • Availability: the hosting provider performs regular backups.
  • Review: the Processor reviews these measures when the service changes and at least once a year.

8. Sub-processors

The Customer grants general authorisation to engage sub-processors. The following sub-processor is engaged at the conclusion of this DPA:

  • Supabase Inc. (USA) — database hosting, authentication, serverless functions. Data is stored in the AWS region eu-west-1 (Ireland). Supabase uses Amazon Web Services as its infrastructure provider.

The Processor informs the Customer at least 30 days in advance by e-mail of any intended addition or replacement of sub-processors. The Customer may object on reasonable data-protection grounds within that period; if no solution is found, the Customer may terminate the Referrals subscription with effect from the date of the change. The Processor imposes on each sub-processor data protection obligations that offer at least the same level of protection as this DPA.

Not sub-processors: Stripe, for billing the Customer's own Referrals subscription (a separate processing for which the Processor or Stripe is controller), and the Customer's own subscription platform or Stripe account, which send data to Referrals on the Customer's instruction.

9. Transfers to third countries

Personal data is stored in the European Union. Where a sub-processor or its infrastructure provider may access personal data from a third country (in particular for support or security operations), the transfer is based on an adequacy decision (including the EU-U.S. Data Privacy Framework, where the recipient is certified) or on the European Commission's Standard Contractual Clauses.

10. Deletion and return

The Customer can export its referral data at any time from the dashboard. After the end of the Referrals service, or on the Customer's written request at any time, the Processor deletes the personal data processed for the Customer within 30 days, unless Union or Member State law requires storage. Deleting the Customer's Account deletes all Referrals data of that Account. Residual copies in backups are overwritten in the hosting provider's regular backup cycle.

11. Assistance

Taking into account the nature of the processing, the Processor assists the Customer with appropriate measures in responding to requests from data subjects (access, rectification, erasure, restriction, portability, objection) and in complying with Art. 32 to 36 GDPR. If a data subject contacts the Processor directly, the Processor forwards the request to the Customer without delay and does not respond itself unless instructed. Because Referrals identifies users only by the Customer's own IDs, requests are to be identified by that ID.

12. Personal data breaches

The Processor notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting the Customer's data, with the information available at that time (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed), and supplements it as further information becomes available.

13. Evidence and audits

The Processor makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, by the Customer or an auditor mandated by it who is bound to confidentiality. Audits are to be announced at least 30 days in advance, take place during normal business hours, no more than once a year unless there is a specific reason, and are at the Customer's expense. The Processor may first answer by providing documentation or written information.

14. Final provisions

Liability is governed by Art. 82 GDPR and otherwise by the liability provisions of the AppThunder Referrals Additional Terms. In the event of a conflict between this DPA and other agreements between the parties, this DPA prevails with regard to data protection. Should individual provisions be invalid, the validity of the remaining provisions is unaffected. German law applies.

Contact for data protection matters

  • By email: support@appthunder.io
  • By post: AMDMarketing, Alejandro Morillo Diaz, Am Markt 14, 23769 Fehmarn, Germany
AppThunder
AppThunder.io

Building the future, one pixel at a time.

AppThunder.io

© 2026 AppThunder.io. All rights reserved.

Terms of ServicePrivacy PolicyImpressum