Skip to content
Referral API
Privacy PolicyTerms and ConditionsCookies PolicyDisclaimerRefund Policy

Legal

Privacy Policy

Effective
September 20, 2026
Last updated
September 20, 2026

Plain-language summary

Scalith, LLC operates Referral API as a business-to-business service. We use account information to run our business, and we process referral and related information for our Customers so the service can attribute referrals, reconcile events and payments, calculate commissions, and support payout records.

All information handled through the Services is stored and processed in the United States. We do not offer Customer-specific data residency. We do not sell personal information or share it for cross-context behavioral advertising.

A person whose information was submitted by a Customer must send privacy requests to that Customer. Verified Referral API Customers may contact us at support@referralapi.dev.

The detailed terms below control if this summary and the detailed terms differ.

On this page

  1. Scope and who we are
  2. Definitions
  3. Our privacy roles
  4. Information we process
  5. Where information comes from
  6. Why we process information
  7. Legal bases
  8. How information is disclosed
  9. No sale or behavioral advertising
  10. Cookies and similar technologies
  11. United States processing
  12. Retention and deletion
  13. Security
  14. Customer privacy requests
  15. Customer End User requests
  16. Regional privacy rights
  17. Children
  18. Automated decision-making
  19. Changes to this policy
  20. Contact

1. Scope and who we are

This Privacy Policy explains how Scalith, LLC (“Scalith,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects information through the Referral API website, software development kit, application programming interfaces, dashboard, documentation, support, and related services.

This Policy applies to our Customers, people acting for Customers, visitors to our Website, and Customer End User information that our Customers submit to the Services. It does not govern a Customer’s independent privacy practices. Customers must provide their own notices and satisfy their own legal obligations.

Scalith, LLC30 N Gould St Ste N, Sheridan, WY 82801, United StatesEmail: support@referralapi.dev

2. Definitions

Customer
A business or other legal entity that creates, controls, pays for, evaluates, or uses a Referral API account, including its authorized personnel.
Customer End User
A person whose information a Customer or its integration submits to or processes through Referral API, such as a referrer, referred customer, subscriber, or payout recipient.
Customer Data
Information submitted to or generated through the Services on a Customer’s instructions, including referral, attribution, event, user, subscription, payment-status, commission, payout, and reconciliation information.
Service Data
Information we process for our own business operations, including account, authentication, billing, usage, security, diagnostic, support, and legal-compliance information.
Website
Our website and the Referral API customer dashboard.
SDK
Referral API software that a Customer may install on its website or application to capture referral attribution.
Services
The Website, SDK, APIs, dashboard, documentation, support, and related Referral API features provided by Scalith.

3. Our privacy roles

When Scalith decides why information is processed

Scalith acts as a controller or business for Service Data used to establish and administer Customer accounts, authenticate users, manage subscriptions and billing, secure and operate the Services, provide support, enforce agreements, and meet legal obligations.

When a Customer decides why information is processed

For Customer Data, the Customer determines the purposes and means of processing and Scalith acts as its processor or service provider. We process that information on the Customer’s documented instructions, including the instructions expressed through its configuration and use of the Services, subject to our Terms and applicable law.

4. Information we process

Account and business information

This includes account-owner email address, business and application details, website domains, plan, subscription state, invoices, billing identifiers, communications, support requests, and account settings.

Authentication, credential, and security information

This includes authentication state, session and verification records, password-recovery state, API-key metadata and cryptographic hashes, permitted origins, security events, rate-limit identifiers, request identifiers, and evidence used to prevent unauthorized access. We do not intentionally store plaintext account passwords or complete payment-card credentials.

Customer End User and referral information

This may include external user identifiers, names, email addresses, account state, signup time, referral codes, referral relationships, attribution tokens, anonymous session identifiers, and the state and history of referrers and referred users.

Attribution and browsing context

The Services may process complete landing-page URLs, complete referring-page URLs, referral parameters, domain information, capture time, attribution time, claim time, expiration time, and related request context. URLs can contain information placed in them by a Customer or another website. Customers should avoid placing secrets or unrelated sensitive information in URLs.

API events and event payloads

We process event identifiers, event types, occurrence times, external user and transaction identifiers, subscription state, payment state, currencies, amounts, refunds, chargebacks, corrections, cancellations, voids, idempotency information, and the complete payloads that Customers send to the Services.

Commission, payout, and reconciliation information

This includes program rules, commission entries, qualification state, exchange-rate records, approved and reversed amounts, payout records, recovery balances, reconciliation rows, uploaded and exported file metadata, and audit history. Referral API tracks and reconciles these records; Scalith does not hold or send money to a Customer’s referrers.

Device, network, usage, and diagnostic information

This may include browser and device characteristics, IP-derived security identifiers, timestamps, request method and path, response outcome, usage counters, log records, job and retry state, error information, and diagnostic metadata. We use this information to operate, secure, troubleshoot, and improve the Services.

5. Where information comes from

We receive information:

  • Directly from Customers and their authorized personnel.
  • From Customer integrations, server applications, SDK deployments, API calls, uploads, and configuration choices.
  • Automatically through account activity, requests, browser storage, security controls, and service operations.
  • From communications with us, including support, privacy, billing, and security messages.
  • From service providers that help us authenticate users, process subscriptions, deliver communications, host infrastructure, secure the Services, and operate our business.

6. Why we process information

We process information to:

  • Create, authenticate, administer, and secure Customer accounts.
  • Capture complete referral activity and maintain referral continuity.
  • Attribute referred activity accurately across supported sessions and events.
  • Receive, validate, deduplicate, replay, and reconcile API events.
  • Reconcile subscriptions, payment status, refunds, chargebacks, corrections, and cancellations.
  • Calculate, mature, reverse, audit, report, and reconcile commissions and payouts.
  • Generate Customer-requested reports, exports, and operational files.
  • Detect and investigate fraud, abuse, security threats, outages, discrepancies, and violations of our agreements.
  • Debug integrations, answer support requests, resolve disputes, and preserve reliable audit trails.
  • Enforce plan limits, collect fees, administer subscriptions, and maintain business and financial records.
  • Comply with law and protect Scalith, Customers, Customer End Users, and the public.
  • Improve the Services using aggregated, deidentified, or otherwise lawfully processed information.

Complete referral URLs, attribution identifiers, events, event payloads, and reconciliation history are core service information. They support accurate attribution, diagnostics, fraud review, idempotency, dispute resolution, and financial integrity.

7. Legal bases

Where a law requires a legal basis, we rely as appropriate on performance of a contract, steps requested before entering a contract, our legitimate interests in operating and securing a B2B service, compliance with legal obligations, and protection or defense of legal rights. We balance legitimate interests against the rights and interests of affected people.

A Customer is responsible for the legal basis that applies to its own collection and use of Customer Data. If the Customer relies on consent, the Customer is responsible for obtaining and managing that consent and for controlling when its integration or SDK operates.

8. How information is disclosed

We may disclose information:

  • To infrastructure, storage, authentication, communications, billing, security, support, and professional-service providers that process it for us under appropriate obligations.
  • To the relevant Customer and its authorized personnel, including through dashboards, APIs, reports, and exports.
  • To comply with law, valid legal process, or binding governmental requests, or to protect rights, safety, property, and service integrity.
  • In connection with a financing, reorganization, merger, sale, acquisition, insolvency, or transfer of all or part of our business, subject to appropriate confidentiality and legal requirements.
  • At the direction of the Customer or with valid authorization.

We do not publish the identities of service providers or disclose provider-specific operational information in this Policy.

9. No sale or behavioral advertising

Scalith does not sell personal information for money or other valuable consideration. Scalith does not share personal information for cross-context behavioral advertising and does not use Customer Data to advertise unrelated products to Customer End Users.

10. Cookies and similar technologies

We use necessary cookies and similar technologies for authentication, security, fraud prevention, and service operation. The SDK may use browser storage on a Customer-controlled website to preserve referral attribution. The Customer controls its deployment of the SDK and is responsible for any notice or consent required on its property.

See our Cookies Policy for more detail.

11. United States processing

All information handled through the Services is stored and processed in the United States. We do not offer Customer-specific or user-specific data-residency choices.

If information originates outside the United States, it is transferred to and processed in the United States. United States privacy laws may differ from the laws where the Customer or Customer End User is located. Where required, the Customer and Scalith may use an appropriate data-processing agreement or transfer mechanism.

12. Retention and deletion

We retain information for as long as reasonably necessary to provide and secure the Services, preserve accurate referral and financial records, perform API and payout reconciliation, resolve disputes, prevent fraud and abuse, enforce agreements, comply with Customer instructions, and meet legal, accounting, and operational obligations. Retention varies by information type, account state, service purpose, legal requirement, and Customer instruction.

Temporary exports and operational files may expire sooner than core referral, financial, security, and audit records. Backup copies are removed through normal backup-expiration cycles and may not be immediately accessible for individual deletion.

When information is deleted, we may retain deidentified or aggregated information and records needed for financial reconciliation, fraud and security investigations, disputes, legal compliance, and the establishment, exercise, or defense of legal claims. We may also preserve non-identifying referral and financial facts after associated identity information is deleted or deidentified.

13. Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These safeguards include access controls, tenant and environment isolation, protected credentials, private file storage, encrypted transport, request validation, logging, monitoring, and controlled data-management procedures.

No method of transmission, storage, or operation is completely secure. Customers must protect their accounts, API credentials, integrations, devices, and authorized users and must promptly report suspected unauthorized access by email.

14. Customer privacy requests

A verified Customer may request access to, correction of, export of, or deletion of its account information by emailing support@referralapi.dev from the account email address. The request must identify the Customer account and the requested action. We may require additional evidence of identity, authority, or account control before acting.

An authorized agent must provide proof of authority and may also be required to have the Customer verify the request directly. We may deny or limit a request when permitted by law, including when we cannot verify it, it would expose another person’s or Customer’s information, it conflicts with legal or security obligations, or the information must be retained for an applicable exception.

If applicable law gives the Customer a right to appeal our decision, the Customer may appeal by replying to our decision email and stating why it believes the decision should be reconsidered.

15. Customer End User requests

If a Customer submitted or collected your information through Referral API, direct any access, correction, deletion, objection, portability, consent, or similar request to that Customer. The Customer controls that information and is responsible for verifying and responding to you. We assist the Customer after receiving its authenticated instruction.

We do not independently authenticate or fulfill Customer End User requests sent directly to Scalith, and we will not confirm whether a particular Customer has submitted or processed your information. If you contact us directly, we will direct you to the relevant Customer when that can be done without exposing protected information.

16. Regional privacy rights

Depending on applicable law and subject to exemptions, verified Customers may have rights to know or access information, correct inaccurate information, receive a portable copy, delete information, restrict or object to processing, withdraw consent, or appeal a request decision. We do not discriminate against a person for exercising a right protected by applicable law.

These rights are not absolute. Scalith does not voluntarily extend a jurisdiction-specific right where the law does not apply. Mandatory rights remain available where applicable. Customer End Users must exercise rights through the Customer as explained above.

17. Children

The Services are business tools and are not intended for anyone under 18. We do not knowingly invite a person under 18 to create an account. Customers must not use the Services to submit children’s personal information where doing so is prohibited or requires authorization the Customer does not have.

18. Automated decision-making

Scalith does not use personal information to make solely automated decisions that produce legal or similarly significant effects about people. The Services apply Customer-configured referral, commission, eligibility, and reconciliation rules, but the Customer remains responsible for its program and decisions based on service output.

19. Changes to this policy

We may update this Policy to reflect changes in the Services, our practices, or legal requirements. The “Last updated” date identifies the current version. We will send material changes to the account email when required or reasonably appropriate. Continued use after an updated Policy takes effect is subject to applicable law and our agreements.

If any part of this Policy is unenforceable, the remaining provisions continue to apply. A delay in enforcing a provision is not a waiver. Nothing in this Policy limits a non-waivable right or obligation.

20. Contact

Privacy, security, support, and contractual communications must be sent by email to support@referralapi.dev. Our street address identifies the legal entity and is not a customer support or correspondence channel, except where applicable law makes another method mandatory.

Scalith, LLC30 N Gould St Ste N, Sheridan, WY 82801, United StatesEmail: support@referralapi.dev
Referral infrastructure for small SaaS.
Privacy PolicyTerms and ConditionsCookies PolicyDisclaimerRefund Policy