DRAFT — this is not legal advice. Have it reviewed by qualified counsel before publishing. Bracketed values (such as the legal entity name and governing jurisdiction) are placeholders that must be completed before this page is relied upon.
Privacy Policy
For Deflect LLC (https://ambassy.io). Last updated: July 2026. Governing jurisdiction: the Commonwealth of Virginia, United States.
1. Who we are and our role
Ambassy is a Wix App Market application that lets a Wix merchant run an affiliate and customer-referral program — recruiting affiliates, issuing tracking links and coupons, automatically attributing referred sales across Wix Stores and Wix Bookings, and orchestrating commission payouts. This policy explains what personal information Deflect LLC ("Ambassy", "we", "us") handles in connection with the Ambassy website and app, and how we handle it.
Ambassy is a business-to-business tool. For the affiliate, buyer, and order data processed inside a merchant's program, the merchant is the data controller and Ambassy acts as a data processor, handling that data on the merchant's behalf and under their instructions. For our own website visitors and for the account relationship with the merchant, Ambassy is the controller. Where this policy refers to a request that only the merchant can fulfill (for example, deletion of an affiliate's record), we may route that request to the relevant merchant.
2. Information we process
Depending on how the app is used, we process the following categories of information.
2.1 Merchant and store information
- Wix app instance identifier and store URL, used to identify and isolate the merchant's account.
- Program configuration, payout settings, and tax settings the merchant chooses.
- Merchant payout-rail credentials (for example, a connected PayPal account). PayPal OAuth refresh tokens are encrypted at rest.
2.2 Affiliate information
When a person joins a merchant's program as an affiliate, we process the information needed to run that program:
- Name and email address.
- Account password, stored only as a scrypt hash — we never store or have access to the plaintext password.
- Chosen payout method and its destination (for example, a PayPal email address or a Venmo phone number).
- US tax information, when the merchant enables tax handling: a W-9 (name, address, and SSN or EIN) for US affiliates, or a W-8 for affiliates outside the US (no US SSN). The full taxpayer identification number is encrypted at rest using AES-256-GCM; other than at the moment a tax summary is generated, we retain only the last four digits plus a salted hash for matching.
- Commission, earnings, and payout records; terms-acceptance records; and answers to any custom registration-form questions the merchant configures.
- For multi-level (MLM) programs, the affiliate's upline/downline relationships within that merchant's program.
2.3 Buyer and customer information (limited)
To attribute referred sales and to detect fraud, we process a limited set of information about the merchant's customers. We do not use this information for advertising and we do not build customer profiles.
- Buyer email address, used for self-referral fraud checks, connected-email "lifetime commission" attribution, and customer-referral programs. It is lowercased for matching and is never written to our logs.
- Wix visitor identifier and contact identifier.
- Order identifier and number, subtotal, currency, and any applied coupon codes.
2.4 Click and tracking information
- The affiliate referral code associated with a tracking link.
- A visitor identifier and timestamps, used to carry a referral through from the initial click to a completed order.
2.5 Support submissions
- The category and message of a support request, and an optional contact email if you would like a reply.
2.6 Website information
When you visit https://ambassy.io, we process information you provide directly (such as your name and email if you contact us) and standard information needed to operate and secure a website.
3. What we never collect
- Payment card numbers or bank-account details of buyers. All shopper payments are processed by Wix; the app never sees or stores card data.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use advertising or analytics trackers to profile you across sites.
4. How we use information
- To operate the affiliate and referral program on the merchant's behalf: tracking links and coupons, attributing referred sales across Wix Stores and Wix Bookings, calculating commissions, and orchestrating payouts.
- To detect and prevent fraud and coupon-code leakage (for example, self-referral and velocity checks).
- To generate tax-form summaries (such as 1099 summaries) that help a merchant meet their own filing obligations.
- To send transactional messages related to an account (such as welcome, approval, password-reset, and payout notifications), where configured.
- To respond to support requests, operate and secure the website and app, and meet legal and accounting obligations.
5. Cookies and local storage
The Ambassy affiliate portal and the merchant's storefront tracking use functional browser storage only — for example, a session token to keep an affiliate signed in, and an instance/visitor identifier used to attribute a referred sale to the correct affiliate. These are necessary for the service to work. We do not set advertising cookies. You can control cookies and local storage through your browser, though some features may not work without them.
6. How we share information — subprocessors
We share information only with the service providers needed to run the app, and only as needed. These are:
- Wix — the platform Ambassy runs on. We receive order and store data through Wix APIs and webhooks.
- PayPal — a payout rail. When a merchant chooses to pay via PayPal, an affiliate's payout email/identity is shared with PayPal so PayPal can send a merchant-funded payout.
- Resend — transactional email delivery (welcome, approval, password-reset, and notification emails), when the merchant has email configured.
- Cloudflare — DNS and TLS/CDN for our website and API.
- Our hosting and infrastructure provider — the servers and PostgreSQL database that run our self-hosted backend.
7. How we protect information
We use technical and organizational measures appropriate to the data we handle, including the following:
- Encryption in transit using TLS (certificates via Let's Encrypt).
- Encryption at rest using AES-256-GCM for full taxpayer identification numbers and for merchant payout-rail credentials and PayPal OAuth refresh tokens. Tax-ID handling is fail-closed: if the encryption key is unavailable, a submission errors rather than being stored in plaintext.
- Taxpayer identification numbers are never returned by any API and are decrypted only at the moment a 1099 summary is generated, with an access log.
- Per-merchant (per-instance) data isolation, so one merchant's program data is separated from another's.
- Passwords stored only as scrypt hashes.
- Secrets and sensitive personal information (such as email addresses, tax IDs, and coupon codes tied to an identity) are kept out of our logs.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. This policy does not claim any specific third-party security certification.
8. Data retention
We retain personal information for as long as the related program or account is active, and afterward only as needed to meet legal, tax, accounting, or audit requirements — for example, payout and 1099 records may be retained for the period required by applicable tax law. When information is no longer needed, it is deleted or anonymized.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to restrict or object to certain processing, and to withdraw consent. To exercise these rights, contact us at hello@ambassy.io.
Because Ambassy acts as a processor for affiliate, buyer, and order data on behalf of the merchant, we may need to refer a request about that data to the relevant merchant, who is the controller. We will help the merchant respond as required by law.
10. International transfers
The service providers listed above may process information in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
11. Children
Ambassy is a business tool and is not directed to children. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the date below and, where appropriate, by additional notice.
13. Contact
Questions about this policy can be directed to Deflect LLC at hello@ambassy.io.