Legal
Privacy policy
1. Who we are
Shopmycode ("we", "us") is a referral and affiliate-marketing platform operated by TTL Media Private Limited, a company registered in India with its registered office at Office No. 205, Conclave, CTS No. 1703 B, Final Plot No. 100, Bhambhurda, Narveer Tanaji Wadi, Shivajinagar, Pune, Maharashtra 411005, India (CIN U73100PN2024PTC229413 · GSTIN 27AAKCT8705C1Z9). Our privacy contact is legal@ttlmedia.in. Our Grievance Officer under India's Digital Personal Data Protection Act, 2023 is Praddyumna Bapat, reachable at the same address.
This policy covers our websites (shopmycode.com and its sub-domains, including the short-link domain go.shopmycode.com and refrlink.com), the Shopmycode web app on any device, the one-line snippet brands place on their own pages, and our emails and messages.
2. Our role: who is responsible for what
| Situation | Who decides how data is used |
|---|---|
| You have an account (marketer, member, brand user, staff) | We are the controller ("data fiduciary" in India) of your account data. |
| You opened a Shopmycode link (a visitor) | We are the controller for the open itself (count, country, device family). If the link leads to a brand's own site, that site's own privacy policy applies from the moment you arrive there. |
| A brand runs campaigns on Shopmycode | The brand is the controller of its campaign data (results reported by its pages, sign-ups, orders). We act as its processor under our Data Processing Addendum. |
3. What we collect
3.1 If you open a link
- The open: time, which link, the country, region and city derived from your IP address (the address itself is not stored; a keyed one-way hash of it is kept for fraud checks — see §12), operating system, browser or in-app browser, phone brand and model where the browser reveals it, preferred languages, the page that referred you (for example Instagram or WhatsApp), and any tag the sharer put on the link (for example which post).
- Identifiers, unless you are in a "limited" region or have opted out: a visitor cookie and a device id cookie on go.shopmycode.com, and a device id in your browser's storage on the brand's page, so that a later sign-up or repeat open can be matched to the same link. On the short "bridge" page we may also read technical characteristics of your browser (screen size, graphics renderer, a rendering hash, CPU count, memory, time zone, connection type) to recognise the same device without cookies.
- On the brand's own site, if the brand installed our snippet: which page you are on, its title, how long you stay, when the tab is hidden or closed, and whether you tapped a link to an app store or an app. Only for visitors who came through a Shopmycode link. What you do inside an app is never visible to us.
- Results: if the brand's page reports a sign-up, order or other goal, we receive the goal name, the page address, and — only if the brand chooses to send it — its own user id for you.
Visitors in the EU/EEA, the United Kingdom and Switzerland are asked first: a short page explains the identifier and offers "Continue without" and "Allow and continue" side by side; the answer is kept for a year in one cookie (smc_consent) and can be changed on Your privacy choices. Those who decline, visitors whose browser sends the Global Privacy Control signal, and anyone who has opted out get the limited path: no cookies, no browser storage, no device characteristics — just a counted open and a plain redirect.
3.2 If you have an account
- Sign-in: email address or mobile number, and the one-time codes we send (stored hashed, expire in 10 minutes). We never hold a password.
- Profile: name, company, display name, photo, bio, city/region, categories, and the social channels you list. If you ask us to verify a channel we look up its public profile (follower count, engagement, display name) through Apify or the YouTube Data API and keep the result.
- Payout and tax details (marketers): UPI id or bank account (holder name, account number, IFSC), PAN, GSTIN, billing address and PIN code. Bank details may be verified through a bank-verification partner, which returns the registered account-holder name.
- Brand details (brand users): company name, website, logo, category, legal name, GSTIN, PAN, billing and invoice addresses.
- Activity: the campaigns, links, offers, settlements, wallet entries and payout requests you create; when you last used the app; notification preferences.
- Support and requests: what you write to us, including privacy requests.
3.3 What we do not collect
No passwords, no precise location, no contacts, no browsing outside our links and the pages carrying a brand's snippet, no data from children, no biometric data, no advertising profiles.
4. Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR / UK GDPR) | India (DPDP) |
|---|---|---|---|
| Counting opens and crediting the right link, sharer and campaign | Opens, results | Legitimate interest (running the service); consent where identifiers require it | Consent given when the link is opened via our page; legitimate use for the service |
| Live numbers, journeys and insights for the campaign owner | Opens, page presence, results | Legitimate interest; contract with the account holder | Contract / consent |
| Fraud, bot and abuse prevention; link caps | IP hash, device family, timing | Legitimate interest | Legitimate use (security) |
| Creating and securing your account, sending sign-in codes | Email/phone, codes | Contract | Contract / consent |
| Paying marketers, invoicing brands, tax and accounting | Payout, tax and billing details, wallet | Contract; legal obligation | Contract; legal obligation |
| Verifying social channels and bank accounts you ask us to verify | Channel handle, bank details | Consent (you press verify) | Consent |
| Emails about your account, your links, invitations and settlements | Email, name | Contract; legitimate interest | Contract |
| Answering privacy and support requests, keeping records the law requires | What you send us | Legal obligation; legitimate interest | Legal obligation |
We do not use personal data for advertising, we do not build profiles for other purposes, and no decision with legal effect on you is made automatically.
5. Who we share it with
- The campaign owner and the brand: see the numbers for their own campaigns and links — counts, country/city, device family, source, journeys of individual visitors identified only by a device label, and results their pages reported. They see a marketer's name and contact where they work together (for example a link handed to a person by name).
- The marketer or member holding a link: sees the numbers for their own links only.
- Service providers ("sub-processors") who act on our instructions:
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services (EC2, SES) | Hosting, database, sending our emails | India (Mumbai region) |
| PayU | Receiving brand payments (invoice checkout) | India |
| Easebuzz | Paying marketers | India |
| Meta Platforms (WhatsApp Business Cloud API) | Sending sign-in codes on WhatsApp (only if you sign in by phone) | United States / EU (Meta's own terms and transfer safeguards apply) |
| Apify, Google (YouTube Data API) | Looking up public social profiles you ask us to verify | EU / United States |
| MaxMind GeoLite | Country/city from IP — runs on our own servers, no data leaves | — |
- Affiliate networks and stores (for example Amazon Associates, Flipkart, Admitad, Cuelinks) when a product link goes to their store: they receive the click with a tracking id and report orders back to us. Their own policies apply on their sites.
- Authorities when the law requires it, and successors if the business is sold or merged (with this policy continuing to apply).
We do not sell personal data and we do not share it for cross-context behavioural advertising.
6. Where your data is kept and international transfers
Our servers and database are in India (AWS Mumbai). If you are in the EU/EEA, the UK or Switzerland, using Shopmycode means your data is transferred to India. We rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our providers, and on the limited-tracking path for visitors from those regions, which keeps what we hold about a visitor to a counted open. India is not the subject of an EU adequacy decision.
7. How long we keep it
| Data | Kept for |
|---|---|
| Individual opens, page presence, journeys, results | 13 months, then deleted automatically. Totals live on in the campaign's statistics without any identifier. |
| One-time sign-in codes | 10 minutes |
| Account and profile | While the account is open. On closure we delete your name, contact details, channels, bio and photo and keep only a keyed one-way hash so books can be tied to "an account that existed". |
| Wallet entries, payouts, invoices, settlements, tax details used on them | 8 years after the financial year, as Indian tax and company law require |
| Privacy requests and our replies | 3 years, as a record that we answered |
| Server logs | 30 days |
8. Your rights — everyone, everywhere
Whatever country you are in, you can ask us to: tell you what we hold about you, correct it, delete it, give it to you in a machine-readable file, stop a particular use, or withdraw consent you gave earlier. Account holders can do the first, third and fourth themselves: Profile → Account → Download my data / Close account. Anyone — including visitors who never had an account — can use the form on Your privacy choices or write to legal@ttlmedia.in. We reply within 30 days (45 days for California), and we may ask you to confirm you are the person concerned. We never charge for a first request and never treat you differently for making one.
Because a visitor's open is identified only by cookies on their own device and a keyed hash, we can usually act on a visitor's request by deleting what those identifiers point to; the opt-out on Your privacy choices stops anything new being stored on that browser.
9. India — Digital Personal Data Protection Act, 2023
We are a data fiduciary for account data and visitor opens. We process personal data for the purposes above with your consent or for the legitimate uses the Act allows (performing our service to you, security, legal duties). You may withdraw consent at any time; we then stop the processing that relied on it, keeping only what the law requires us to keep. You have the rights to access, correction, erasure, grievance redressal and to nominate a person to exercise your rights if you are unable to. Grievances go to our Grievance Officer at legal@ttlmedia.in; if you are not satisfied with our answer you may complain to the Data Protection Board of India. We notify the Board and affected people of any personal-data breach as the Act requires.
10. EU/EEA, United Kingdom and Switzerland
Our legal bases are in §4. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. Where we rely on legitimate interest you may object and we will stop unless we can show compelling grounds. Visitors from these regions are asked for consent before any identifier is set, with declining as easy as accepting; without consent no cookies, storage or device characteristics are used. You can complain to your national supervisory authority (in the UK, the ICO). We have not appointed a representative in the EU or UK under Article 27; contact us directly at legal@ttlmedia.in.
11. California and other US states
In the last 12 months we collected the categories in §3: identifiers, contact and commercial information, device and internet activity, geolocation at city level, and — for marketers being paid — financial and government-id information (PAN). Sources: you, your device, brands' pages, networks and stores. We use them for the purposes in §4 and disclose them to the providers in §5. We do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We honour the Global Privacy Control signal as an opt-out. You have the rights to know, delete, correct, and to limit use of sensitive personal information, and we will not discriminate against you for using them. Submit a request on Your privacy choices or by email; an authorised agent may act for you with your written permission. Similar rights under other US state laws are handled the same way.
12. Security
Traffic is encrypted (HTTPS). Sign-in uses one-time codes, not passwords; codes are stored hashed and expire. Network credentials brands give us are encrypted at rest. IP addresses are replaced by a keyed one-way hash before anything is stored. Access to production is limited to staff who need it. If a breach affects you we will tell you and the relevant authority without undue delay.
13. Children
Shopmycode is for people aged 18 and over. We do not knowingly collect data from children; if you believe a child has given us data, write to us and we will delete it.
14. Changes to this policy
When we change this policy we update the date at the top; for material changes we also email account holders. The current version is always at shopmycode.com/privacy.
15. Contact
TTL Media Private Limited · Office No. 205, Conclave, CTS No. 1703 B, Final Plot No. 100, Bhambhurda, Narveer Tanaji Wadi, Shivajinagar, Pune, Maharashtra 411005, India · CIN U73100PN2024PTC229413 · GSTIN 27AAKCT8705C1Z9 · legal@ttlmedia.in · Grievance Officer: Praddyumna Bapat. Courts in Pune, Maharashtra, India have jurisdiction, without prejudice to rights you have under the law of the place you live.