MilesMiles/Privacy Policy

Privacy Policy

Last updated: May 20, 2026

1. Introduction

Miles ("we", "us", "our") operates the Miles Affiliate Platform (the "Service"), accessible at askmilesai.com and as an embedded application within the Shopify Admin. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

Miles is operated by Devdock Inc. By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Merchant Information (via Shopify)

When you install our Shopify app, we access and store:

  • Store name, domain, and contact email
  • Product catalogue data (names, prices, images, descriptions)
  • Order data (order IDs, amounts, dates, customer identifiers for attribution)
  • Customer data (limited to email for affiliate order attribution)
  • Discount code information (for affiliate coupon management)

2.2 Creator/Affiliate Information

When creators sign up for a brand's affiliate program, we collect:

  • Name, email address, and contact information
  • Social media handles and platform connections
  • Payment information (bank details or PayPal for commission payouts)
  • Content submissions (links to posts, videos)
  • Country of residence (for tax compliance)

2.3 Automatically Collected Information

  • IP address (for geographic detection and security)
  • Browser type and device information
  • Usage analytics (pages visited, features used)
  • Cookies for session management and authentication

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the affiliate marketing platform
  • Attribute orders to the correct affiliates and calculate commissions
  • Process affiliate payouts
  • Enable AI-powered features (creator discovery, content analysis, outreach suggestions)
  • Sync product catalogues and order data from Shopify
  • Generate analytics and performance reports for merchants
  • Detect and prevent fraud
  • Send transactional communications (payout notifications, application updates)
  • Improve and develop our Service

4. AI Processing

Our platform uses artificial intelligence to provide features such as creator discovery, content analysis, automated outreach, and performance insights. Data processed by AI systems includes:

  • Product descriptions and catalogue data (for creator-product matching)
  • Order patterns (for performance analytics)
  • Social media content (for engagement and quality analysis)
  • Communication templates (for outreach optimization)

AI processing is performed using third-party providers (Anthropic, OpenAI, Google) under their respective data processing agreements. No personally identifiable customer information is sent to AI providers — only anonymized or aggregated data.

5. Data Sharing and Disclosure

We do not sell your personal information. We may share data with:

  • Service providers: Cloud infrastructure (Google Cloud Platform), payment processors (Stripe, PayPal, RazorpayX), AI providers (Anthropic, OpenAI, Google)
  • Merchants and creators: Performance data is shared between brands and their affiliated creators as necessary for the affiliate relationship
  • Legal requirements: When required by law, regulation, or legal process

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

  • Active accounts: Data retained for the duration of the subscription
  • After app uninstall: Merchant data is retained for 30 days (for reinstall convenience), then permanently deleted
  • Financial records: Commission and payout records retained for 7 years for tax compliance
  • Audit logs: Retained for 12 months

7. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.3) and at rest
  • Access tokens encrypted at rest
  • Role-based access control with tenant isolation
  • Regular security audits and monitoring
  • Secure OAuth 2.0 authentication flows

8. Your Rights (GDPR & Global)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Restrict processing of your personal data
  • Objection: Object to processing based on legitimate interests

To exercise these rights, contact us at privacy@askmilesai.com.

9. Shopify Data Handling

When you uninstall our Shopify app, we receive an app/uninstalled webhook and:

  • Immediately revoke and delete the Shopify access token
  • Deactivate the tenant account
  • Retain data for 30 days for potential reinstallation, then delete

We comply with Shopify's mandatory GDPR webhooks:

  • Customer data request: We provide all stored data for the requested customer
  • Customer redact: We permanently delete or anonymize all customer personal data
  • Shop redact: We permanently delete all data associated with the shop

10. Cookies

We use essential cookies for:

  • Authentication session management
  • Tenant context (subdomain-based routing)
  • Affiliate link attribution tracking

We do not use third-party advertising or tracking cookies.

11. International Data Transfers

Our Service operates globally. Data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place through data processing agreements and standard contractual clauses where applicable.

12. Children's Privacy

Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

For privacy-related inquiries: