7. Cookies and external content
Affiliate partners and referral attribution
For partner reports, we count referral-page loads in daily totals by partner, campaign and placement. This counter uses no cookies or browser identifier and stores no visitor IP addresses or user agents. Repeat page loads count again. Visit totals earn no commission. Campaign and placement labels must not contain personal data or individual visitor identifiers.
Partner links open the homepage with its Spotlight or advertiser signup directly. The URL carries a partner code and optional stable campaign and placement labels. Opening the link alone sets no affiliate cookies and establishes no commission attribution. On the homepage, you can allow attribution through “Support the referring partner”; the Spotlight works without making that choice. Only after consent do we set nyl_affiliate (signed partner and campaign identifier, 30 minutes) and nyl_affiliate_visitor (random browser identifier, 30 days), both first-party cookies with HttpOnly and SameSite=Lax. We do not fingerprint devices. Optional terminal access and attribution rely on §25(1) TDDDG and Art. 6(1)(a) GDPR. Withdraw referral attribution removes the cookies for future visits.
For signed-in accounts, we count clicks using a per-placement pseudonymous account identifier for commission accounting and fraud prevention (Art. 6(1)(b) and (f) GDPR). Without sign-in or consent, we do not collect an individual click identifier for this purpose. Partners see their own aggregate clicks, commissions, campaign/sub-IDs and referral events, without visitor email addresses or referred advertisers’ confidential bids. Partners should not put personal data in campaign/sub-ID fields.
An explicitly supplied partner code and campaign during advertiser registration is retained for referral accounting. No referral commission arises without a paid auction win. Stripe Connect handles payouts. Identity and bank documents are collected in Stripe-hosted onboarding; we store the Stripe account identifier, verification status and accounting records, without identity-document copies. Partner callbacks go only to operator-approved public HTTPS addresses and are signed.
We set technically necessary first-party cookies: theme preference (nyl-theme), language (nyl_locale), login session (nyl_sess), a navigation login-state hint (nyl_auth), a short-lived passkey challenge (nyl_passkey_flow, up to 5 minutes), and like management (nyl_visitor, nyl_liked_days). These are exempt from consent under §25(2) TDDDG. Cloudflare Web Analytics and our visitor counter are cookieless.
When enabled and only with your consent, we use Google Analytics 4 (Google Ireland Limited) to measure page views and steps leading to bid submission. Google may also process data in the United States. The legal bases are Art. 6(1)(a) GDPR and §25(1) TDDDG. Google Analytics is not loaded before you accept. Analytics cookies (_ga, _ga_*) have a maximum lifetime of 180 days; your choice is stored for 180 days. You can withdraw consent at any time through “Analytics settings”. Withdrawal stops future collection and removes analytics cookies; it does not affect the lawfulness of earlier processing.
Collected data includes sanitized page categories, events such as page views, navigation, requested login links and accepted bids, cookie identifiers, and basic device and browser information. Google also receives your IP address when the connection is made. We do not send email addresses, account IDs, bid amounts, payment details, form entries or URL parameters to Google Analytics. Google Signals, advertising personalization and automatic Enhanced Measurement are disabled.
GA4 retention for event- and user-level data is set to two months; new activity does not extend this period. This setting does not apply to standard aggregated reports.
Google Ireland Limited processes analytics data as a processor. For EEA transfers to Google LLC in the United States, Google identifies the EU-US Data Privacy Framework (Art. 45 GDPR); its processing terms provide Standard Contractual Clauses as a fallback where no applicable transfer framework is used.
With your renewed analytics consent, we also use PostHog Inc. with EU hosting for page and funnel analytics. The legal bases are Art. 6(1)(a) GDPR and §25(1) TDDDG. Earlier Google-only consent does not authorize PostHog. We send only the sanitized page categories and explicitly selected events described above, plus a random identifier stored in this browser tab's session storage. It is not linked to your account and is removed on withdrawal. PostHog technically receives your IP address when connecting; location enrichment is disabled. We do not collect session recordings, automatically captured form entries, email addresses, account IDs, bid amounts or URL parameters. Do Not Track and Global Privacy Control prevent collection. Withdrawal and expiry of the 180-day consent stop further events. The identifier lasts at most for the browser-tab session; events already sent are retained for one year under the current PostHog free plan.
Renewed consent includes optional surveys about advertising clarity, bidding and report usefulness. Responses are transmitted only when voluntarily submitted. PostHog stores survey and display status in browser local storage to show each survey once and separate surveys by at least seven days; this applies per browser and can reset when storage is cleared. Please do not include personal or confidential information in survey responses.
On /support you can explicitly open PostHog support chat without analytics consent. PostHog processes messages and contact details you voluntarily send, technical connection data and the support page address. A local browser identifier lets you resume the conversation. We do not link this to your nowyourlink account or record your session. Processing your request is based on Art. 6(1)(b) GDPR for contract-related requests, otherwise Art. 6(1)(f) GDPR (responding to enquiries). You can alternatively email support@nowyourlink.com.
PostHog privacy policy · PostHog processing terms
Google processing terms · Transfer mechanisms and safeguards · Google privacy policy
MakerMap badge
You can choose to load the MakerMap badge in the footer. Only after that click does your browser load an SVG image from MakerMap (Pyrean B.V., Netherlands). This gives MakerMap technical connection data such as your IP address and browser information; your browser may also send this site's domain as a referrer. MakerMap says it records the embedding domain and fetches the page daily to verify the badge. The legal basis for this optional load is your separate consent (Art. 6(1)(a) GDPR; §25(1) TDDDG where terminal access occurs). Analytics consent does not activate the badge. We do not store this choice: the badge starts off on every new page. “Hide badge” removes it from the current page but cannot undo requests already sent.
MakerMap privacy policy