# Affiliate program

> How the Privatus Analytics affiliate program works, from your referral link to the 30-day hold, Wise payouts and account credit, with cookieless attribution.

Earn **25% of every payment** from the customers you refer, for **24
months** from each customer's first payment.

## Apply

**Account settings → Affiliate program.** Tell us your website or
channel and how you'll promote Privatus Analytics, pick a referral code
(or let us suggest one) and choose how you want to be paid. We review
applications within two business days and email you the result. If we
can't approve it, the email says why and you can apply again.

## Share your link

Once approved, your page shows a link like
`https://privatusanalytics.com/r/your-code`. It opens the sign-up page.
People can also enter your code in "How did you hear about us?" when they
create their first workspace.

## Signup box

A signup form for your own site. Visitors get a Privatus Analytics
tracking code for their site without leaving your page, and each new
account is credited to you like a link referral.

**Account settings → Affiliate program → Signup box** has a live preview
and your code. Pick a theme (match the visitor's device, light or dark),
then paste one of these where the box should appear.

The script fits the box to its content, supports prefill and tells your
page when someone signs up:

```html
<div data-privatus-signup="your-code" data-theme="auto"></div>
<script async src="https://privatusanalytics.com/js/signup-box.js"></script>
```

A plain iframe works on sites that don't allow scripts. It has a fixed
height and no prefill:

```html
<iframe src="https://privatusanalytics.com/embed/signup/your-code?theme=auto"
        title="Privatus Analytics signup" allow="clipboard-write"
        style="width:100%;max-width:480px;height:640px;border:0"></iframe>
```

### What the visitor does

1. They enter their first name, email and the domain of their site, accept
   the Terms and the Privacy Policy, and choose whether they want product
   emails.
2. The box shows their tracking code with a copy button and a **Check
   installation** button. Pageviews are counted from this moment.
3. We email them a one-time link to their dashboard. Opening it creates
   their account (or signs them in if they already have one) and puts the
   site in it.

A signup that nobody opens the link for is removed after 7 days, with
everything it collected. Until then it never stops someone else from
adding the same domain to their own account.

### Prefill for signed-in visitors

If your visitors are signed in on your site, add what you already know to
the element. They can still change every field, and they always tick the
terms themselves.

| Attribute | Fills in |
|---|---|
| `data-first-name` | First name |
| `data-email` | Email address |
| `data-domain` | The domain of their site, like `example.com` |

The script hands these values to the box inside the visitor's browser.
They are never put in a URL, and we store nothing until the visitor
submits the form.

### React on your page

The script fires these events on the element, and they bubble:

| Event | Fires when |
|---|---|
| `privatus:signup:submitted` | The form was submitted and the tracking code is shown |
| `privatus:signup:installed` | The tracking code was found on the visitor's site |
| `privatus:signup:receiving` | The first pageview arrived |

```js
document.addEventListener("privatus:signup:submitted", () => {
  // show your next step
})
```

The events carry no name, email, domain or site id.

## What counts

- 25% of each **net payment**: after discounts, excluding tax.
- Pro and Business payments from a workspace created by someone who signed
  up through your link or your signup box, or entered your code, for 24
  months from that workspace's first payment.
- A signup box credits you for **new accounts**. Someone who already had a
  Privatus Analytics account and uses your box gets their site, but is not
  a referral.
- Refunds and chargebacks are taken back from the commission. A reversed
  chargeback restores it.
- Self-referrals don't count. Sign-ups from your own email domain are
  reviewed before they earn (shared webmail domains like gmail.com are
  fine).

## Getting paid

Each commission is **on hold for 30 days**, then becomes **payable**.

- **Wise:** once you have **$50 or more** payable we send it to the Wise
  account email you gave us (payouts go out monthly) and email you the
  transfer reference.
- **Account credit:** payable commissions come off the **next renewal of
  your own subscription** automatically, with no minimum. We add as much as
  the renewal can absorb and the rest waits for the following one. A
  subscription can hold only one discount, so a workspace in a
  [discount program](/docs/billing/plans#discounts) can't take credit: choose Wise
  or another workspace. Credit also waits while the subscription bills in
  a different currency than your commissions. Your affiliate page tells
  you when credit is waiting and why. Switch to Wise at any time.

Your page and the API show signups, paying customers, what's on hold,
payable and paid, and every commission and payout. The Signup box page
shows the box's own numbers: signups waiting to confirm, confirmed signups
and paying customers.

## API and MCP

- `GET /account/affiliate.json` (MCP tool `affiliate_get`): status,
  referral link, stats and balances.
- `GET /account/affiliate/commissions.json` (MCP tool
  `affiliate_commissions_list`): commissions, paginated, with an optional
  `status` filter.
- `GET /account/affiliate/signup-box.json` (MCP tool
  `affiliate_signup_box_get`): your signup box code for a `theme` (`auto`,
  `light` or `dark`) and the box's numbers.

Applying and changing payout details need a signed-in browser.

## How referrals are attributed (privacy)

The program follows the same rules as the product: no tracking cookies,
no fingerprinting, no click logs.

- `/r/your-code` sets **no cookie** and **records nothing**. It only
  redirects to the sign-up page with the code in the address.
- The sign-up page keeps the code in its own session cookie (the one it
  already needs for the form), which ends when the browser closes. The
  code is dropped when the account is created.
- We then store which affiliate referred the new account and, later, its
  workspace. That's all. We never store the visitor's IP address, device
  or the pages they viewed.
- You see counts (signups and paying customers) and commissions, never
  who your referrals are.

The signup box follows the same rules:

- It sets **no cookie** on your site or ours, and uses no storage.
- Until the visitor opens their emailed link we keep **no account, no
  email address and no name**: only the site they asked for, and a keyed
  hash of the address so the right person can claim it. The first name and
  the email choice travel inside the signed link.
- The visitor's IP address is used in memory for the bot check and rate
  limits, and never stored.
- Your page learns that a signup happened, never who signed up.
