Skip to main content
CREG+
How it worksProgram termsPortal preview
Visit CREG+

Effective August 27, 2026 · Version 1.2

Creator Program Privacy Notice

This notice explains the information processed for creator applications, portal security, referral tracking, commission, fraud prevention, support, and payouts.

Information we process

We process application details, public creator profile information, creator login email, salted password hashes, security-session records, creator codes and links, aggregated and privacy-reduced click information, attributed Shopify order identifiers and merchandise amounts, refunds, commission records, and security audit events. For payouts, we process the selected method, country, currency, legal account-holder details, contact or payout email, billing address, and the bank identifiers required for the creator's selected local payout rail.

What we do not store

The creator portal does not store readable passwords, online-banking passwords, debit or credit card numbers, CVV codes, PINs, or customer payment-card data. Sensitive payout destinations are encrypted before storage and normal creator and admin dashboards display masked details only. Customer checkout and payment data remains in Shopify and its authorized providers.

Why we use information

We use information to review applications, administer the program, authenticate creators, attribute referrals, calculate commission, account for refunds, issue payouts, prevent abuse, resolve disputes, meet tax and legal obligations, and improve program performance.

Tracking and attribution

A referral visit records the creator, time, destination, and privacy-reduced technical signals needed for aggregate reporting and fraud controls. Attribution can last up to 30 days. A creator discount code can take priority over link attribution. Shopify or browser settings may limit tracking.

Sharing

Information is shared only as needed with Shopify, hosting and database providers, payout providers selected by the creator, professional advisers, and authorities where legally required. We do not sell creator application or payout information.

Retention and security

Applications, contracts, ledger entries, and payout records are retained for the period needed to operate the program, resolve disputes, prevent fraud, and meet accounting or legal obligations. Sensitive payout fields use authenticated encryption at rest, changes trigger a 72-hour security hold and owner review, payout exports are restricted to the owner and are not cached, passwords are processed with slow salted hashing, sessions use secure HTTP-only cookies, failed sign-ins are rate-limited, access is restricted by role, Shopify requests are cryptographically verified, and material account actions are audited.

Your choices

You may request access, correction, or deletion where applicable, update payout contact information, or leave the program. Some ledger, tax, fraud, or legal records may need to be retained. Contact info@cregplus.com.