Legal
Privacy Policy
Last updated September 3, 2026
This policy covers getlive.ai. Get Live is the public agency brand. Affilio is the gated operator app at /app. We describe only data we actually handle today.
Who we are
The site is operated by Justin Pollack / Get Live. There is no separate legal entity listed for this site, and we do not publish a street address.
Contact: justin@getlive.ai.
What we collect
We collect the information below. We do not invent extra categories to look more complete.
- Waitlist / contact form (HubSpot). The public site links to an existing HubSpot form (share-na2.hsforms.com). If you submit it, HubSpot receives what you type — typically name, email, and anything you write about your shop. We use that to follow up. HubSpot’s own privacy policy applies to the form.
- Free shop analysis form. If you send a shop ID or handle plus your email (and optional name, brand, or note), we store that request so we can reply. Successful writes go to a server-side leads table (Supabase). If the write fails, the form says so — we do not pretend the request was saved.
- Creator network application. If you apply on /creators, we store your name, email, TikTok handle, niche, whether you already go live, and optional follower count or video/live link so we can review fit and follow up. Same leads table (form="creator-application"). If the write fails, the form says so and points you at rob@getlive.ai.
- Calendly booking. “Book a meeting” links go to Calendly. Anything you enter there is handled by Calendly under Calendly’s terms and privacy policy.
- Site analytics, if configured. The site can load Google Analytics 4, HubSpot page tracking, and an optional Meta pixel — but only when the matching ID is set in the hosting environment. If an ID is missing, that script does not load. Those vendors may set their own cookies and see page URLs.
- Operator login cookie. /app and /crm are password-gated. A successful sign-in sets an HTTP-only cookie named
affilio_crm(about 7 days). The cookie holds a signed session value, not your password. There is no public account registration. - TikTok Shop OAuth, if a shop is connected. When an operator authorizes a shop through TikTok, we receive and store access and refresh tokens, expiry times, and seller identifiers TikTok returns (for example open_id and seller name), plus authorized shop records (shop id, name, code, cipher, region, seller type). During that flow we also set a short-lived HTTP-only cookie named
affilio_tiktok_stateto prevent CSRF. - Operator-entered records. The operator may type shops, creator handles, names, emails, notes, campaigns, and outreach logs into Affilio. Public visitors do not submit this data.
- Hosting (Vercel). The site runs on Vercel. Hosting may process standard request data such as IP address, user agent, timestamps, and URLs for delivery, security, and debugging.
What we do not collect from TikTok Shop
Affilio can request Shop Authorized Information so we know which shop was connected. We do not pull GMV, orders, returns, products, ads, affiliate or open-collaboration data, samples, promotions, finance, or violation records. Those Partner APIs are not connected, and this policy does not claim that we process that data.
How we use information
- Follow up on waitlist, shop-analysis, creator-application, and contact submissions
- Authenticate the operator for /app and /crm
- Keep a TikTok Shop connection after the operator authorizes it
- Keep internal shop, creator, campaign, and outreach notes the operator entered
- Measure site traffic when analytics IDs are configured
- Host and secure the site
We do not sell personal information.
Who we share with
We share information only as needed to run the site:
- Google Preferred Sources — public pages load Google's official publisher script (
news.google.com/swg/js/v1/publisher.js) so a reader can add getlive.ai as a preferred source. That flow is Google's. We do not claim the site is already a preferred source. - HubSpot — waitlist form submissions, and page tracking if a HubSpot portal ID is configured
- Supabase — shop-analysis lead records
- Calendly — meeting bookings you start
- Google / Meta — analytics or pixel events only if those IDs are configured
- TikTok — OAuth if an operator connects a shop
- Vercel — hosting
- Someone we must tell because the law requires it, or because you asked us to
Cookies
Affilio sets these first-party cookies:
affilio_crm— operator session after password login, about 7 daysaffilio_tiktok_state— OAuth CSRF protection, about 10 minutes
If analytics IDs are configured, Google, HubSpot, or Meta may set their own cookies. The on-site FAQ chat widget is a fixed script. It does not send your typed questions to a model or a database.
Storage and retention
Operator records and TikTok tokens are stored in a server-side JSON file. On Vercel that file is ephemeral and may not survive every deploy or instance recycle. Waitlist submissions live in HubSpot. Shop-analysis requests live in Supabase. We keep them until we delete them or you ask us to.
Email justin@getlive.ai to request access, correction, or deletion of information we hold. We will do what we can with the systems we actually have.
Children
This site is not directed at children under 13. We do not knowingly collect their information.
Changes
If our practices change, we will update this page. The date at the top is the current version.
Questions: justin@getlive.ai