PartnerXperience – Privacy Policy

Effective Date: 1 January 2026

This Privacy Policy explains how PartnerXperience (“we”, “us”, “our”) collects, uses, discloses, and protects personal data when you use our platform for rating and reviewing vendor partner programs (the “Platform” or “Services”), or otherwise interact with us.

1. Who We Are

2. Scope of this Policy

This Policy covers personal data processed through:

3. Categories of Personal Data We Collect

CategoryTypical ExamplesSource
Account DataEmail, display name, avatarProvided at registration or via OAuth
Verification DataLinkedIn profile URL, company name, verification statusLinkedIn verification process
Rating DataScores, reviews, relationship type, company sizeSubmitted by users during rating
Activity DataSaved programs, voting history, login timesAutomatically tracked during platform use
Technical DataIP address, browser type, device informationAutomatic server logs

4. Purposes and Legal Bases

PurposeLegal Basis (GDPR)
Manage user accounts and accessArt. 6(1)(b) – Contract
Process and display ratings/reviewsArt. 6(1)(b) – Contract
Verify user identity via LinkedInArt. 6(1)(b) – Contract
Generate aggregate program scoresArt. 6(1)(f) – Legitimate interest
Platform security and fraud preventionArt. 6(1)(f) – Legitimate interest
Service announcements and updatesArt. 6(1)(b)/(f)

5. Anonymity and Data Visibility

Your Ratings:

Verification:

Limits of Anonymity:

6. Cookies and Analytics

We use:

7. Service Providers

ProviderPurposeLocation
Vercel Inc.Platform hostingEU & US
Supabase Inc.Database & authenticationEU
LinkedIn (Microsoft)Identity verificationUS

All providers are bound by data processing agreements and appropriate safeguards.

8. Data Retention

Active Accounts: Data retained while account is active.

Ratings: Retained to maintain platform integrity. If you delete your account, your ratings remain on the Platform in fully anonymized form (the user identifier is permanently removed), meaning they can no longer be linked back to you.

Inactive Accounts: Deleted after 3 years of inactivity.

8a. Disclosure in Response to Legal Process

We may disclose your personal data if required to do so by law or in response to valid legal process, including:

We will review all legal requests for validity and scope, and where permitted by law, we will notify affected users before disclosing their data. We will only disclose the minimum information necessary to comply with the legal obligation.

9. Your Rights (GDPR)

You have the right to:

10. Exercising Your Rights

To exercise your rights or ask questions:

You may also lodge a complaint with the Spanish Data Protection Authority (AEPD) at aepd.es.

11. Changes to This Policy

We may update this Policy periodically. Material changes will be announced on the platform. The Effective Date indicates the latest revision.

12. Contact Information

For privacy-related questions: