π‘ Feature Request: Option to Show Referred User Emails
Summary
It would be very helpful to add a feature that allows affiliates to see the email addresses of their referred users/customers. Ideally, this should be an admin-controlled option (checkbox or toggle) to decide whether emails are visible or not.
Use Case
In many affiliate campaignsβespecially influencer marketingβaffiliates grant bonuses or extra services to customers who purchased using their link.
- To deliver those bonuses, affiliates need to know who the customers are (at least their email).
- Without this, the process becomes complicated, as customers must send receipts or screenshots, which is harder to regulate and less practical.
Why Itβs Important
-
Influencer Partnerships
- Many influencers wonβt join a program if they canβt see the emails of their referrals.
- We have faced cases where potential affiliates refused to use Fluent Affiliate and insisted on other platforms that offer this functionality.
- For them, this is both a way to validate purchases and a method of lead generation.
-
Privacy & Control
- If managed with a simple admin option (to share or not share emails), it would be easier and more transparent than current workarounds.
- This approach balances privacy with business needs.
Conclusion
- Being able to show customer emails is already standard in many affiliate platforms.
- It is particularly critical in bigger campaigns with creators and influencers, where bonuses are part of the deal.
- Without this feature, some clients may prefer other tools, even though Fluent Affiliate is stronger in many aspects.
Extra Note
A related idea is the ability to manage Joint Venture Partnerships (co-productions/revenue sharing between partners). This may be more relevant to FluentCart but worth mentioning here.
I agree this is very helpful. I'm an affiliate for several programs and sometimes I like to offer bonuses if someone uses my affiliate link. I'm making that offer for FluentAffiliate, too.
It can get tedious to keep asking a vendor to validate that an affiliate purchased from my link before I grant access to the bonus. Matching the email address and the order number would resolve that issue.
William BeemΒ absolutely!
We have been working with content creators since 2017, and this is a common clause: and a really handy one in terms of reporting and lead generation.
I really hope Shahjahan JewelΒ and the team can check if this could be possible.
Mat βΒ already mentioned that Jewel talked about this briefly in the live, but definitely I wanted to post this here again as a feature request in case itβs not planned. As well as the aforementioned Joint Venture / coproduction feature. Again, a very common feature while making online launches or agency partnerships πͺ (probably. This last one is more on the Cart side though).
Before your post, I didn't notice that my report of referred customers to WPMN products, doesn't show emails.
It is not necessary on every case, but in your use-case is mandatory.
I agree 100% with you.
Jose Luis DuronΒ Thanks for bringing this up Jose!
Being able to see the referred customer info is indeed a key requirement in many affiliate campaigns, especially in Europe. Without it, we often end up forced to use βbig platformsβ that already offer this feature. (and that are actually very chaotic regarding privacy).
Many users also requested the Joint Venture Partnership option (co-production, shared income, etc.), and Iβd say both features are truly important for real-world use cases!
I asked again in todayβs live, and Shahjahan JewelΒ mentioned a possible workaround using hooks...
But I am not sure how that could be achieved in practice nor if it will be ideal in this case. But what I am certain of is this: without referred customer info, Fluent Affiliate cannot be used in influencer or bonus-based campaigns, which are very common in Spain and across the EU π
Now, regarding privacy and GDPR I can give my legal opinion (as a lawyer) in case Shahjahan Jewel and the team have this concern for making this feature possible:
-
Yes, showing customer data has privacy implications.
-
But GDPR does not forbid this functionality if implemented correctly.
-
The solution is about how you manage your Privacy Policy, obtain user consent (or establish a valid legal basis), and keep proof of acceptance.
This is, nothing changes regarding that you must comply with legal requirements anyway π
If the platform provides an admin-controlled option (to decide whether to show or hide referred emails -as many platforms do) and clear guidance on how to reflect this in the Privacy Policy, then this feature is absolutely possible in compliance with GDPR. Transparency and minimization are the keys.
So, from a legal and practical perspective: this functionality is not only feasible, itβs also essential if Fluent Affiliate wants to compete with larger platforms in Europe.
Hopefully, we can see this integrated soon π
It is true this has privacy concerns (luckily I am a lawyer specialized in Data protection π ). So, I can firmly say the only concern here is how you manage your Privacy Policy and how you proof acceptance π
In many cases, it is actually the referred customer and not the affiliate the most interested part in proving they used the affiliate link so as to get the benefit of the bonus.
Just as an anecdote, this is also very common in european banking and financial electronic services companies. They do not use the term "Affiliate" but "referrer", and even this has some nuances, they actually have systems for letting you know who signed in your name:
Like "Hey, your Friend Jose opened a bank account: you both receive $25". Or, membership rewards and fidelity programs. Those in which you get points for referring new clients too, and they let you know so as to get the rewards that sometimes are shared with the new referred customer.
So, in conclusion: just a matter of how you (the producer) legally manage your privacy policy and your affiliate program terms and conditions.
In case it helps!
Just thinking out loud how this could be implemented...
Email notification sent to an Affiliate could include a hash of ref email+salt (salt=AffiliateEmail if applicable) so when an Affiliate knows that email he could create a hash of email+salt (on his end if needed) and verify if that is his user.
However giving access to someone email to an Affiliate can be taken as: Affiliate = Data Processor (GDPR) so the Admin of that page/shop would need to share a list of all sub processors in the Policy Privacy when someone is Accepting Terms of that page (shop) during purchase. Also accepting Terms/Policy should not force giving consent for such a data sharing as this is marketing related subject (Affiliate=Marketing >> maybe a separate consent is needed, who knows what else).
Note: if I would see that my data is shared with some 3rd parties/Affiliates than I would think twice before buying from that store... On the other site I could get a list of all Affiliates (sub processors) as this should be available (maybe on request but still).
But of course I understand a business case when someone need such a feature however banks dont share users emails or logins with their affiliate programs because its not only about Privacy Policy but also about some security related rules (what would happen if an affiliate account would be accessed by someone else etc).
Mat βΒ All good points. In my case, the buyer has to contact me to request the bonus. I'd get the buyer's email. However, that doesn't mean the buyer is the person who actually made the purchase. More than once I've had people contact me to pretend they bought through my link and didn't pass verification via the vendor.
If we do a hash of email+salt, I either need a way to replicate that on my end with the requester's email address or I have to bug the vendor in order to deliver the bonus.
If I can't deliver a bonus, then I've lost the incentive I provide for people to choose my affiliate link.
William BeemΒ maybe hash+salt is not needed but MD5 (ex: https://www.md5hashgenerator.com/) would be OK but just giving idea so this case can be resolved somehow. Generating MD5 is not perfect but still... better than a plain text. I am pretty sure someone can come up with a briliant idea or a best practise in this matter so we all can learn how to do it right.
Mat βΒ Mat, thanks a lot for your thoughtful input. Let me add some nuances from both a GDPR and practical perspective.
as you said, I am thinkingout loud too! haha
1. Affiliate role under GDPR
Affiliates are not automatically βprocessors.β In most cases they act as independent controllers, since they use customer data to fulfill their own obligations (e.g. delivering bonuses) and not on behalf of the shop. This is a key distinction under Art. 28 GDPR.
2. Pseudonymization vs. direct sharing
Youβre absolutely right that raw email disclosure must be handled carefully...
A technical option where the admin decides whether to disclose the email or provide only a pseudonymized identifier would cover both worlds. Many platforms already use hashed or masked emails - enough to confirm eligibility without enabling full re-identification (at least not easily). Both approaches can be GDPR-compliant, depending on the business model. And of course of the risk every merchant is willing to assume if they do not conduct the proper DPIA (Data protection Impact Assesment of the art. 35 GDPR).
3. Idiosyncrasy of affiliate collaborations
In practice, these collaborations often involve public campaigns with creators, where each one openly advertises a special bonus. In major launches, customers themselves choose through whom they purchase - but then comes the chaos of verifying who gets what bonus...
Having access to the customerβs email makes that process feasible. Of course, this does not authorize the affiliate to later run marketing campaigns with that email (even many do...); it is limited strictly to bonus delivery. Typically, if further marketing is intended, a separate opt-in is presented at that stage -and thatβs where valid consent comes in.
Also, many of this bonuses are usually Lead magnets (ππ€£).
4. Transparency & legal basis
GDPR does not require listing every single affiliate. What is required is transparency about categories of recipients. A Privacy Policy can lawfully state that customer contact may be shared with the relevant affiliate for bonus/service delivery. Thatβs enough for compliance.
As for the legal basis, if the bonuses (whatever it is) is part of the offer, disclosure can rely on contractual necessity.
Otherwise, legitimate interest may apply, provided data minimization and safeguards are respected.
BUT, it is usually, almost impossible to prove for us, mortals...
Consent is only needed if the affiliate later uses the data for independent marketing. But because a Lead-Magnet approach is usually followed... you can enter again into the "journey" of consent for treatment.
5. Business reality & safeguards
I think that having the opportunity to do it technically, a simple toggle, site owners could decide whether to enable email sharing or stick to pseudonymized IDs.
The important thing is that everything is properly documented. (Normally it isnβt - but thatβs another story π .)
Technically, just the email is sufficient; no further personal data needs to be shared.
6. Beyond emails: cookies & scripts
Al this debate remind me of another debate. One more note: when affiliates are allowed to insert their own tracking scripts, we enter the cookie/consent battlefield.
Thatβs far harder to justify, and regulators are unforgiving. Metaβs recent fine for βlocal host trackingβ is just one more example. Email-based confirmation is far safer ground compared to client-side tracking scripts. So again... hey, here it is your lead magnet bonus! π
In short: having a technical feature like this would be very useful for these kinds of influencer/affiliate campaigns.
I think itβs a real market demand in this niche of content creators.
Of course, not all of them will be involved in big launches, so, probably, as it is, this could be just something "that we would like" but "we may not need" in most cases. The pity is, that many creators are "used" to this, even for their small campaigns π . And think that this other platforms are "better" "because I can see the info of the customer".
Many clients wonβt work otherwise.
Some even go as far as linking multiple CRMs in automation (a real legal nightmare) just to solve this. The clean, handy solution could be allow the shop to share an email for bonus delivery, with the right transparency, safeguards, and the option to capture consent afterwards if marketing is intended.
That way, affiliates can deliver bonuses, customers get what they expected, and businesses can operate within GDPR without unnecessary friction.
As you said, I am just thinking out loud too. As every case, should be reviewed independently.
Technological tools are neither inherently good nor bad, yet they are not neutral either: as Kranzbergβs First Law reminds us, their impact depends on how they are designed and, above all, on how they are used. Therefore, the legality or illegality of their application does not lie in the tool itself but in the way professionals employ it within a specific regulatory framework π
I forgot to add another approach: using Joint Venture Partnership (JVP) Agreements. But here the use cases may differ.
For example, in JVP campaigns where several creators jointly create and sell a bundle, all of them are effectively co-owners of the product.
From a GDPR perspective, this usually means they are joint controllers, since they jointly determine the purposes and means of processing (e.g. who gets customer data, how bonuses are delivered, how revenue is split).
The exact allocation of responsibilities must be set out in the JVP agreement itself, especially regarding transparency and handling of data subject rights.
So, if this could be possible (technically), this time with FluentCart as myself an other users asked in the lives...
There could be workarounds too. π
I was asked to join the conversation,so here is my suggestion is if email privacy is that big of an issue why not share or send the influencer the username, or invoice number. Thereβs usually more than one way to get around obstacles. But we definitely need a way for verification for our influencers.