Affiliate PortalFYT
Effective 14 August 2026

Privacy policy

This policy covers the FYT Enterprises mobile app and the web portals it connects to: the staff portal at admin.fytenterprises.com and the affiliate portal at affiliates.fytenterprises.com. These are business tools for our staff and for affiliates who partner with our brands. In short: we collect what we need to run the affiliate program and our operations, we do not run ads, we do not sell data, and we do not track you across other apps or websites.

Who we are

FYT Enterprises, the operator of MyPeptidesLab and affiliated brands. For anything in this policy, contact us at support@mypeptideslab.com.

What we collect

Account details. Your name and email address, used to sign you in and identify your account. Staff sign-in additionally uses two-factor authentication handled by our authentication provider.

Affiliate program records. For affiliates: your coupon codes, the sales attributed to them, commission and payout records, your store-credit ledger, the bank or payout details you choose to save, and, when you request products, the shipping address and optional phone number you provide plus any note you attach to the request.

Notification tokens.If you turn notifications on, your device’s push token, used only to deliver those notifications. Turning notifications off stops them. We delete the token when your device unregisters, when Apple reports it inactive, or whenever you ask us to.

Sign-in cookies. Cookies keep you signed in. They exist only for authentication. The app and portals contain no advertising cookies and no third-party analytics.

Face ID.If you enable the app lock, Face ID runs entirely on your device through Apple’s own system. Biometric data never reaches us and we could not read it if we wanted to.

How we use it

To run the affiliate program: attributing sales to your coupons, calculating commissions and store credit, recording payouts, and fulfilling product requests. To run our own operations in the staff portal. To send you the notifications you opted into. That is the whole list.

The legal bases, in GDPR terms: performing our agreement with you (running the program and your account), legal obligations (keeping financial records), and your consent for notifications, which you can withdraw in the app at any time.

Who touches the data

We use a small set of service providers to run these systems: Supabase (authentication and database), Vercel (hosting), Apple (push notification delivery), and our commerce systems for order data. When we ship a product request, your name, shipping address, and phone number if you gave one go to our shipping platform and the carrier, because they are on the label. We do not sell personal data to anyone, and there are no advertising or data-broker relationships.

Some of these providers process data outside the EU. Where that happens, the transfer is covered by recognised safeguards such as the EU standard contractual clauses or an adequacy decision.

How long we keep it

Account and program records are kept while your account or partnership is active. Financial records (commissions, payouts) are kept as long as tax and accounting law requires. If you end the partnership, ask us at support@mypeptideslab.com and we will delete what the law does not oblige us to keep.

Your rights

Under the GDPR you can ask for a copy of your data, have it corrected or deleted, receive it in a portable format, or object to how it is handled. Email support@mypeptideslab.com and we will sort it out. You can also complain to your data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.

Children

These are business tools. They are not directed at, or intended for, anyone under 18.

Changes

If our data practices change, this page changes with them and the effective date above moves. Meaningful changes are announced to affected users.

Back to sign in