Legal
Privacy Policy
Last updated: 2 October 2026
Changes coming into effect on 11 October 2026. On 27 September 2026 we updated this policy to describe more fully what the service already does:
- Section 2.3: the storefront pixel also records ad click identifiers and, for logged-in shoppers, their Shopify customer ID, and is used for ad attribution.
- Section 2.4: Meta ad data is shared only with the sub-processors in section 5 that run the service.
- Section 2.11: outside the EU and UK, the Meta pixel on aplon.io starts when you arrive unless you switch it off.
- Section 5: a fuller list of the features that send data to Anthropic. Because our Data Processing Agreement gives 30 days' notice of changes to this table, this line takes effect on 27 October 2026.
- Section 2.12 (added 2 October 2026): what happens when you connect your own AI assistant, such as Claude or ChatGPT, to Aplon — a feature you switch on yourself.
1. Who we are
Aplon ("we", "us", "our") is the data controller responsible for your personal data. We are operated by Hallway Ltd, incorporated in Cyprus. Our registered address is: Tefkrou Anthia 90, Ayia Napa, 5330, Ammochostos, Cyprus.
This Privacy Policy applies to all personal data collected through our platform at app.aplon.io, our marketing website at aplon.io, and any related services. For all privacy enquiries, contact us at contact@aplon.io.
We act in two different roles, and it matters which. For data about you — your account, your billing, how you use Aplon — we are the controller and this policy explains what we do with it. For data about your customers, which reaches us from your Shopify store and your connected tools, you are the controller and we are your processor: we handle it only to produce your analytics, on your instructions. Sections 2.2 and 4 set out what that means in practice, and our Data Processing Agreement is the GDPR Article 28 contract that governs it. It is already in force — it forms part of our Terms of Service, so there is nothing for you to sign.
2. Data we collect and how we collect it
2.1 Account data
Your email address and, if you provide it, your name — collected when you create an account or sign in. We store your account creation date, last login, plan status, and notification preferences.
You can sign in with a one-time passcode sent to your email, or set a password. If you set one, we store it only as a salted PBKDF2 hash — we never store or have access to the password itself, and we cannot recover it for you. If you turn on two-factor authentication, we store the secret your authenticator app uses, and your recovery codes as hashes. We also record the devices with active sessions on your account so you can sign them out individually.
2.2 Shopify store data
When you connect a Shopify store, we request OAuth access and receive a Shopify access token. We use this token to read your store's order history, product catalogue, customer information, and revenue data via the Shopify Admin API. We store your store domain, shop name, and the encrypted access token. We do not store payment card numbers or Shopify customer passwords.
To keep your analytics fast, we maintain a copy of your store's order and product data in our database, refreshed automatically. This includes personal data about your customers — name, email address, location (country, region, city), order history, and visit or attribution data (such as referring source and landing page) — which we process solely on your behalf to generate your analytics (for example, customer lifetime value, repeat-purchase, and sales-by-region insights). For this customer personal data, you are the data controller and Aplon is your data processor. We do not sell it or use it for our own marketing. It is encrypted, access is restricted and logged, and it is deleted when you delete your account, when you uninstall the app, or on a valid deletion request — including a deletion request Shopify forwards to us on a shopper's behalf.
2.3 Storefront analytics pixel
When you connect a store, Aplon installs a first-party analytics pixel on your Shopify storefront so we can give you traffic, funnel, and marketing-attribution analytics. This pixel collects, from visitors to your storefront: page views and page URLs, referrer, UTM parameters (source, medium, campaign, content, term), device type, approximate country (derived from IP address, which is not itself stored against the visitor), and completed-purchase events (the Shopify order ID). It also records the advertising click identifiers an ad platform adds to a link (for example fbclid or gclid), so you can see which ad an order came from, and, when a shopper is logged in to your store, their Shopify customer ID, so their visits on different devices can be joined up. To connect a visitor's sessions across pages it stores a randomly generated visitor and session identifier in the visitor's own browser (local and session storage). The pixel does not collect names, email addresses or payment details. It is used for traffic, funnel and ad-attribution analytics for you; it is not used for retargeting or audience building, and the data is never sold or shared with advertising platforms.
How the country is worked out. Our servers see the visitor's IP address, as any web server does, and use it only to derive an approximate country. We do not store the IP address against the visitor. Usually the country comes from a header our hosting or CDN provider already adds. Where it does not, we send the IP address to a geolocation provider (ipinfo.io, or ipapi.co as a fallback) to resolve the country, and cache the answer briefly. Those providers are listed in section 5 and receive nothing else.
The pixel respects shopper consent. Where you (the merchant) have enabled consent collection on your storefront, the pixel integrates with Shopify's Customer Privacy API and does not read or store any identifier, or send any event, until the shopper has given the consent Shopify asks for on our behalf, which covers analytics and marketing; if a shopper later grants consent, tracking begins from that point. The data collected belongs to you as the merchant and is used solely to produce analytics within your Aplon account.
2.4 Meta Ads integration data
If you choose to connect a Meta Ads account, you will be directed to authenticate via Meta's OAuth flow and will be asked to grant Aplon permission to read and, on plans that include ad management, change your ad account data. Upon connection, we receive and securely store an access token issued by Meta.
Using this token, we access the following data from Meta's Marketing API on your behalf:
- Ad account names and IDs
- Campaign, ad set, and ad names and IDs
- Ad performance metrics: spend, impressions, clicks, reach, frequency, CPM, CPC, CTR, ROAS, and conversions
- Attribution data associated with your ad campaigns
We do not access your personal Facebook profile, private messages, friends list, or any data outside of your connected ad accounts. You can disconnect your Meta Ads account at any time from the Settings page, which will revoke our access and delete your stored token. You can also revoke access directly from your Meta Business Settings.
Meta ad data accessed through our integration is used solely to provide you with advertising performance analytics within the Aplon platform. It is not sold, is shared only with the sub-processors in section 5 that run the service, and is not used for any purpose other than delivering the service to you.
Changes we make when you ask us to. On plans that include ad management, Aplon can act on your connected ad accounts at your instruction: pausing or resuming ads, changing budgets, and adding tracking parameters to ad destination URLs. These are writes to the live platform, not analytics. We record who made each change and when, in a log you can read in the Ads view. Aplon never changes an ad on its own initiative.
2.5 Google Ads integration data
If you choose to connect a Google Ads account, you will authenticate via Google's OAuth flow and grant Aplon access to your Google Ads account data. We access campaign performance metrics (spend, impressions, clicks, conversions, ROAS) to provide analytics within the Aplon platform, and — on plans that include ad management, and only at your instruction — make the same kinds of changes described above for Meta. The same access, storage, and deletion principles apply. You can disconnect at any time from Settings or directly from your Google account permissions.
2.6 Snapchat Ads integration data
If you connect a Snapchat Ads account, we store an access token issued by Snapchat and use it to read campaign, ad set, and ad performance metrics for advertising analytics. The same access, storage, and deletion principles apply. You can disconnect at any time from Settings.
2.7 Klaviyo integration data
If you connect Klaviyo, you give us a Klaviyo private API key, which we store encrypted at rest. We use it to read your account, campaign, flow and metric data — including aggregate engagement data about your subscribers, such as opens, clicks and revenue attributed to a campaign — in order to produce your email marketing analytics. Where you enable a feature that requires it, we may also write events back to your Klaviyo account. As with your Shopify customer data, you are the controller of this data and we are your processor. You can disconnect at any time from Settings, which deletes the stored key, and you can revoke the key from within Klaviyo.
2.8 Billing data
If you subscribed through our website, payments are processed by Stripe and we store your Stripe customer ID, subscription plan, billing status, and transaction history. If you installed Aplon from the Shopify App Store, your subscription is billed by Shopify and we store the Shopify charge identifier and your plan status instead. In neither case do we store payment card numbers, CVV codes, or bank account details — those are held by Stripe or by Shopify under their own PCI DSS compliance programmes.
2.9 Usage data
We collect data about how you interact with the Aplon platform, including pages visited, features used, Aplo AI chat messages and responses, Aplo request counts, error logs, and session metadata (browser type, device type, IP address, timestamps). This data is used to operate, maintain, and improve the service.
2.10 Push notifications and communications
If you enable push notifications, we store your browser push subscription endpoint and encryption keys to deliver notifications to your device. If you subscribe to email digests or AI insights, we store your email preferences. You can withdraw consent for both at any time from the Account page.
2.11 Measuring our own marketing
We measure how our marketing website (aplon.io) performs in two ways. The first is our own first-party analytics, described in section 3.3: it records page visits, whether a visit was an engaged one (see below), and how far a visit got through signing up. That data goes to our own servers.
The second is the Meta pixel. We advertise Aplon on Facebook and Instagram, and the pixel is what tells us whether those ads work. If you allow it, a small script from Meta runs on aplon.io and reports four kinds of event to Meta: that you viewed a page, that you spent time on one and interacted with it, that you started a free trial, and that you asked to connect your Shopify store. The second of those is sent once you have been on a page for fifteen seconds and scrolled, clicked or typed — it tells us whether an ad brought someone who read the page rather than someone who bounced. Meta may connect those events to your Facebook or Instagram account, use them to measure and improve the ads we run, and use them to show you our ads again elsewhere on their platforms. Meta acts as an independent controller for that data under its own terms, which is why it appears in the table in section 5 as a recipient rather than as one of our sub-processors.
When it runs. In the EU and the UK — or if we cannot tell where you are — the Meta script is not loaded, and no Meta cookie is written, until you choose "Accept all" in our cookie banner. Elsewhere it starts when you arrive, the same rule section 3.3 sets out for analytics, and our banner lets you switch it off. Choosing "Essential only" at any time stops it, withdraws consent with Meta, and deletes its cookies from your browser. We also honour Global Privacy Control (section 10.4): with it on, the script does not load unless you choose "Accept all".
We do not use any other third-party advertising or analytics technology: no Google Ads conversion tag and no Google Analytics, on aplon.io or on app.aplon.io. There is no advertising technology of any kind on app.aplon.io — the pixel described here runs on the public marketing site only, never inside the product. The first-party storefront pixel described in section 2.3 is a separate tool installed on merchant storefronts. It measures which of the merchant's own ads and campaigns led to orders; it is not used to show ads to anyone, and its data is never sent to advertising platforms.
2.12 Connecting your own AI assistant (Second Brain)
If you choose to, you can connect Aplon to an AI assistant you use yourself, such as Claude or ChatGPT. You start this from the assistant, and you agree to it on an Aplon page that shows exactly what the assistant will be able to read. Once connected, it can read the analytics Aplon shows you for the stores you pick: sales, profit and loss, orders, products and costs, inventory, customers, reviews, email and ad performance. It cannot change anything in Aplon, in Shopify or in your ad accounts. Customer names and email addresses are withheld unless you tick the box to share them for that store.
What the assistant reads is sent to the company that provides it, because you have asked us to. That company is not one of our sub-processors: it handles the data under its own terms and your settings with it, including whether your chats may be used to train its models.
We never receive your conversation with the assistant, only its requests for data. We do not keep those requests, apart from a short-lived list of which screens it read and for which dates, held in memory to show you on the Second Brain screen. We do keep a record of each connection: who agreed, to which stores and to what wording, when and from where, and when it was last used. We keep that record after you disconnect, as proof of what was agreed. You can disconnect an assistant, or stop it reading one store, at any time from Second Brain in Aplon, and it stops on its next request.
3. Cookies and tracking technologies
3.1 What are cookies
Cookies are small text files stored on your device when you visit a website. We also use similar technologies including local storage and session storage to maintain your application state. Below we describe all cookies and tracking technologies we use.
3.2 Strictly necessary
These are essential for the platform to function and cannot be disabled. They include session authentication tokens (stored in local storage on app.aplon.io), CSRF protection tokens, Stripe's fraud prevention cookies used during payment flows, and a short aplon_geo cookie set by our hosting provider's edge network that records only a region and country code. That last one exists so we know whether to ask you for analytics consent before setting anything else, and your choice is remembered in a cookie_pref value in your browser's local storage. No consent is required for these, as they are necessary to deliver the service you have requested — or, in the case of the last two, to honour the choice you make about the rest.
3.3 Analytics storage (aplon.io only)
On our marketing website we use our own first-party analytics — no third-party analytics provider. It stores a randomly generated visitor identifier (_aplon_site_vid, in local storage), a session identifier (_aplon_site_sid, in session storage), and the campaign and landing-page values for your current session (_aplon_site_utm, _aplon_site_landing). These contain no directly identifying information and are sent only to our own servers.
When we ask, and when we assume. If you are in the EU or the UK — or if we cannot tell where you are — we set nothing beyond the essentials until you choose "Accept all" in our cookie banner. Elsewhere, analytics storage is on by default and our banner lets you turn it off. Either way you can change your mind at any time using the Cookies link in the footer of any page, and choosing "Essential only" deletes the visitor identifier.
Two things happen regardless of that choice, and are treated as strictly necessary. Your current session's campaign and landing-page values are kept in session storage, which lasts until you close the tab and never leaves your browser unless one of the events below is sent. And if you sign up for a trial we record that conversion, because it is a first-party record of an action you deliberately took. Neither is shared with anyone.
3.4 Advertising cookies (aplon.io only)
If you allow it, the Meta pixel described in section 2.11 writes two cookies on aplon.io: _fbp, a randomly generated browser identifier, and _fbc, which records that you arrived from a Meta ad. Meta uses them to match your visit to an ad and to show you our ads again. They are set only in line with the consent rule in section 2.11, and they last up to three months.
There are no other advertising cookies. There is no Google Ads conversion tag and no Google Analytics anywhere, and there is no advertising or retargeting cookie of any kind on app.aplon.io or on merchant storefronts. Choosing "Essential only" — from the banner or the Cookies link in any footer — deletes _fbp and _fbc from your browser and stops the pixel loading again.
3.5 Storefront analytics storage (merchant stores)
On the storefronts of merchants who use Aplon, our first-party analytics pixel (section 2.3) stores a randomly generated visitor identifier (_aplon_vid, in local storage) and a session identifier (_aplon_sid, in session storage), along with UTM and landing-page values for the current session. These contain no directly identifying information and are used only to produce the merchant's traffic and attribution analytics. Where the merchant has enabled consent collection, these are set only after the shopper consents via Shopify's Customer Privacy API. They are never used on app.aplon.io, and never used to show ads.
3.6 Managing cookies
You can change or withdraw your choice at any time using the Cookies link in the footer of any page on aplon.io, which reopens the banner and shows which option is currently in force. You can also control cookies through your browser settings — most browsers allow you to refuse cookies, delete existing cookies, or be notified when cookies are set. Note that disabling strictly necessary cookies may prevent the service from functioning correctly.
Declining non-essential storage in our banner stops the Meta pixel described in section 2.11 from loading, withdraws consent with Meta, and deletes its _fbp and _fbc cookies from your browser. It does not reach back to Meta: anything the pixel already sent while consent was in force is held by Meta as an independent controller under its own terms. To control what Meta does with it, use Facebook ad settings. Our own analytics are first-party, so there is no third-party opt-out for those. Clearing your browser's local and session storage for aplon.io removes the identifiers described in section 3.3.
4. How we use your data and our lawful bases
Under the EU General Data Protection Regulation (GDPR), we must have a lawful basis for each way we use your personal data. The table below sets out our processing activities and the lawful basis for each:
| Purpose | Lawful basis |
|---|---|
| Providing the analytics dashboard and Aplo AI assistant | Contract performance |
| Processing subscription payments via Stripe | Contract performance |
| Sending transactional emails (receipts, alerts, account notifications) | Contract performance |
| Fetching and displaying data from the ad and marketing accounts you have connected | Contract performance |
| Carrying out ad changes you instruct — pausing ads, changing budgets, tagging destination URLs | Contract performance |
| Diagnosing bugs, monitoring performance, improving the service | Legitimate interest |
| Authorised staff accessing your account to operate, support, and improve the service | Legitimate interest |
| Measuring how our own website performs, using first-party analytics | Consent |
| Measuring our Meta ads and showing them to you again, using the Meta pixel (section 2.11) | Consent |
| Sending weekly digests, Aplo AI insights, and push notifications | Consent |
| Complying with legal obligations (tax, accounting records) | Legal obligation |
Staff access to your account. To operate, support, troubleshoot, and improve the service, a limited number of authorised Aplon personnel may access your account and view the data in it — including your store analytics and the personal data described above — for example to reproduce a problem or check that a new feature displays your data correctly. Such access is read-only, restricted to authorised personnel, and recorded in an internal access log. We rely on our legitimate interest in providing and improving a reliable service, balanced against your rights. We do not use this access to alter your data.
We do not sell your personal data to third parties. We do not use your store data, ad account data, or Aplo chat history to train AI models.
5. Sub-processors and data sharing
We share data with the following sub-processors solely to operate the service. Each operates under its own privacy policy and, where required, a Data Processing Agreement with us. This table is the single maintained list, and our Data Processing Agreement commits us to 30 days' notice before it changes.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication hosting | EU |
| Anthropic | AI model behind Aplo and the features built on it: chat, the weekly digest, the store scan, review themes and suggested replies to reviews, the Ad Builder's draft campaign and its ad-copy check, and a suggested first answer to support requests. Store data (including figures from ad accounts you connect), chat and support messages, and the text of reviews from review apps you connect, with the reviewer's name, are sent to Anthropic's API | USA |
| Stripe | Subscription billing and payment processing | USA / EU |
| Shopify | Store data, and subscription billing for App Store installs | Canada / USA |
| Render | Backend application hosting | USA |
| Vercel | Frontend hosting and edge delivery | Global CDN |
| Resend | Sending email — sign-in codes, digests, receipts, and support replies | USA |
| Sentry | Error monitoring. Payloads are scrubbed of personal data before they are sent | USA |
| ipinfo.io / ipapi.co | Resolving an IP address to a country when our CDN has not already done so (section 2.3). They receive the IP address and nothing else | USA |
| Meta (Facebook) | Ad data access for Meta Ads accounts you choose to connect | USA |
| Ad data access for Google Ads accounts you choose to connect | USA / EU | |
| Snapchat | Ad data access for Snapchat Ads accounts you choose to connect | USA |
| Klaviyo | Email marketing data for Klaviyo accounts you choose to connect | USA |
| Meta (Facebook) | Advertising pixel on our marketing site aplon.io only, under the consent rule in section 2.11. Receives the four kinds of event listed in section 2.11 — that list is the maintained one, so this row deliberately does not restate it. Acts as an independent controller, not our sub-processor. No merchant store data, ad account data or Aplo chat data is ever sent to it | USA / EU |
We do not share your personal data with any other third parties except where you ask us to, as when you connect your own AI assistant (section 2.12), where required by law, or to protect our legal rights.
6. International data transfers
Some sub-processors listed above are located outside the European Economic Area (EEA), including the United States. When your data is transferred outside the EEA, we ensure that appropriate safeguards are in place in accordance with GDPR Chapter V, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Reliance on an EU adequacy decision where applicable
- Sub-processor participation in recognised frameworks such as the EU-US Data Privacy Framework
You may request a copy of the relevant transfer mechanisms by contacting contact@aplon.io.
7. Data retention
We retain your personal data for as long as your account is active and as needed to provide the service. Specific retention periods:
- Account and store data: retained for the life of your account, and deleted immediately when you delete your account. Backups are overwritten on our provider's normal rolling cycle.
- Shopify order data: cached for a rolling 60 months (five years). Orders older than that are deleted automatically by a daily job, whether or not your account is still active.
- Storefront pixel data: retained for a rolling 24 months. Visitor events and visit-to-order links older than that are deleted automatically by the same daily job. We keep this for a shorter period than order data because it is behavioural and we do not need it for longer.
- Integration tokens and keys: deleted immediately upon disconnection or account deletion.
- Aplo chat history: retained for the life of your account unless you request earlier deletion.
- Push notification subscriptions: deleted when you unsubscribe or delete your account.
- Billing and commission records: retained for 7 years as required by applicable financial and tax law. This includes affiliate referral and commission records, which we keep after an account is deleted because they evidence money we have paid.
- Server logs: retained for up to 90 days for security and debugging purposes.
You can delete your account and all associated data at any time from the Settings page. Deletion is permanent and irreversible.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure:
- Integration access tokens and keys — Shopify, Meta, Google, Snapchat, Klaviyo — are encrypted at rest using AES-256-GCM
- All data in transit is encrypted via TLS 1.2 or higher
- Sessions expire after 30 days, and you can sign out any individual device from your account settings
- Passwords are stored only as salted PBKDF2 hashes, and two-factor authentication is available
- Access to production systems is restricted to authorised personnel only
- We do not log or store access tokens in plaintext anywhere in our systems
- Errors sent to our monitoring provider are scrubbed of personal data first
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Cyprus Commissioner for Personal Data Protection within 72 hours of becoming aware. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
9. Your rights under GDPR
If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
- Right of access (Article 15): to request a copy of the personal data we hold about you and information about how we process it
- Right to rectification (Article 16): to request correction of inaccurate or incomplete personal data
- Right to erasure (Article 17): to request deletion of your personal data where there is no longer a lawful basis for us to hold it. You can also delete your account directly from Settings.
- Right to restriction of processing (Article 18): to request that we limit how we use your data in certain circumstances
- Right to data portability (Article 20): to receive your personal data in a structured, commonly used, machine-readable format and to transfer it to another controller
- Right to object (Article 21): to object to processing of your personal data based on our legitimate interests
- Right to withdraw consent: where processing is based on consent (push notifications, email digests, and analytics storage on aplon.io), you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal
- Right not to be subject to automated decision-making: we do not make solely automated decisions that produce legal or similarly significant effects about you
To exercise any of these rights, email contact@aplon.io. We will respond within 30 days. We may ask you to verify your identity before processing your request.
You also have the right to lodge a complaint with the Cyprus Commissioner for Personal Data Protection (dataprotection.gov.cy) or the supervisory authority in your country of residence or place of work.
10. Your rights in the United States
If you live in a US state with a comprehensive privacy law — California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and a growing number of others — you have the rights set out below. We honour them for residents of every US state, whether or not we currently meet the thresholds that would make a particular law apply to us.
10.1 Which data this covers — please read this first
Aplon holds two different kinds of personal information, and your route to exercising a right depends on which one you are asking about.
- If you are an Aplon merchant or user — your account, usage and billing data (sections 2.1, 2.8, 2.9, 2.10). For this we are the business, and the rights below are ours to answer. Contact us directly.
- If you shopped at a store that uses Aplon — the Shopify customer records in section 2.2 and the storefront analytics data in section 2.3. For this the merchant is the business and Aplon is only their service provider: we hold the data on that merchant's instruction and process it solely on their behalf. Please send your request to the store you purchased from, and they will instruct us. If you contact us directly we will tell you so, and we will act on any request the merchant or Shopify forwards to us — including a deletion request Shopify passes on under its own shopper-privacy process.
10.2 Categories of personal information we collect
Using the categories named in the California Consumer Privacy Act. This describes information about you as an Aplon user; the full detail of what each item is, and where it comes from, is in section 2.
| Category | Collected | What it is in Aplon |
|---|---|---|
| Identifiers | Yes | Email address, name if you give it, account and store identifiers, IP address (section 2.1, 2.9) |
| Customer records information | Yes | Name and contact details held against your account (section 2.1) |
| Protected classification characteristics | No | We do not collect age, race, sex, disability, or any other protected characteristic |
| Commercial information | Yes | Your subscription plan, billing status and transaction history (section 2.8) |
| Biometric information | No | Never collected |
| Internet or network activity | Yes | Pages visited in the app, features used, Aplo chat messages, error logs, session metadata (section 2.9) |
| Geolocation data | Approximate only | Country derived from IP address. We do not collect precise geolocation (section 2.3) |
| Audio, video or similar sensory data | No | Never collected |
| Professional or employment information | No | Never collected |
| Education information | No | Never collected |
| Inferences used to build a profile | No | Aplon's analysis is about your store's performance. We do not build a profile of you as a person, and we do not profile you for decisions that produce legal or similarly significant effects |
| Sensitive personal information | Limited — see 10.3 | Your account log-in credentials, held only to sign you in (section 2.1) |
Where it comes from: from you directly, from the platforms you choose to connect (Shopify, Meta, Google, Snapchat, Klaviyo), from your use of the service, and from our payment provider. Why we collect it: the purposes are listed in section 4. Who we disclose it to: the sub-processors named in section 5, each for the stated operational purpose only. How long we keep it: section 7 sets the retention period for each kind of data — it is not repeated here so there is only ever one copy to maintain.
10.3 Sensitive personal information
The only sensitive personal information we hold is what lets you into your own account: your log-in credentials, stored as a salted PBKDF2 hash together with your two-factor secret and recovery-code hashes (section 2.1). We use it for one thing — authenticating you — and for the security and fraud-prevention purposes the law permits without further consent. We do not use or disclose it to infer characteristics about you. Because of that, the right to limit the use of sensitive personal information does not arise here; there is no additional use to limit.
10.4 Selling and sharing your personal information
We do not sell your personal information. We have never taken money, or anything else of value, in exchange for it, and we do not.
We do "share" it, in the narrow sense the CCPA uses. Since 24 August 2026 our marketing website aplon.io has run the Meta pixel described in section 2.11, and disclosing your visit and signup to Meta so that Meta can measure and re-show our ads counts as sharing for cross-context behavioural advertising. This applies only to visitors of aplon.io. The categories involved are identifiers and internet activity — no sensitive personal information, no store data, no ad account data and no Aplo chat data are ever disclosed for advertising. Nothing inside the product at app.aplon.io is shared with anyone for advertising. We have no knowledge of selling or sharing the personal information of anyone under 16.
How to stop it. Use the link in the footer of any page, or the Cookies link beside it — they open the same choice. Selecting "Essential only" stops the pixel loading, withdraws consent with Meta and deletes its cookies from your browser. No account is needed and we do not ask you to verify your identity for this.
Global Privacy Control. We honour it. If your browser or extension sends the GPC signal, we treat it as an opt-out request and the pixel does not load, without you having to do anything else. If you later choose "Accept all" on our own banner we treat that as the more recent and more specific choice, and it takes precedence — you can reverse it at any time.
10.5 Your rights
- Right to know and access: to be told what personal information we have collected about you, where it came from, why we collected it, who we disclosed it to, and to receive a copy of it
- Right to delete: to have your personal information deleted, subject to the exceptions the law allows — chiefly the billing and tax records in section 7 that we are legally required to keep
- Right to correct: to have inaccurate personal information corrected
- Right to data portability: to receive your data in a portable, readily usable format
- Right to opt out of sale, sharing, targeted advertising and profiling: we do not sell your information and we do not profile you to make decisions about you. We do share aplon.io visit and signup events with Meta for advertising, as set out in 10.4 — use the "Do Not Sell or Share My Personal Information" link in any footer to stop it, or send the GPC signal and it never starts
- Right to limit the use of sensitive personal information: see 10.3 — our only use is authenticating you, which the law permits without a limit right arising
- Right to non-discrimination: we will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights. We run no financial-incentive or loyalty programme tied to your data
- Right to appeal: if we refuse a request, you may appeal by replying to our decision or writing to the address below. We will respond to an appeal within 60 days, and if we uphold the refusal we will tell you how to complain to your state Attorney General
10.6 How to make a request
Email contact@aplon.io and say which right you are exercising. You can also delete your account and its data yourself, at any time, from Settings → Delete account — described in section 11.
We will confirm receipt within 10 business days and respond within 45 days. If we need longer we will tell you why, and take no more than a further 45 days. We will ask you to verify your identity first — normally by confirming control of the email address on the account — and for a request to know, we will match the request to the account before releasing anything. An authorised agent may act for you if they provide your written permission; we may still contact you to confirm it. Exercising these rights is free unless a request is manifestly unfounded or excessive, in which case we will say so rather than quietly ignore it.
10.7 California "Shine the Light"
Under Californian Civil Code section 1798.83, California residents may ask whether we disclosed personal information to third parties for those third parties' own direct marketing. We do not, and never have.
11. Data deletion requests
You can delete your Aplon account and all associated data at any time from Settings → Delete account. This immediately and permanently removes your login, every store connected to your account, your integration tokens and keys, your Aplo chat history, your team seats, and your notification subscriptions. Any active subscription is cancelled at the same time. Records we are required to keep for tax and accounting are listed in section 7. If you have connected a Meta Ads account, you can also revoke Aplon's access directly from Meta Business Integrations settings. For Google Ads, you can revoke access from your Google Account permissions.
12. Children's data
Aplon is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us at contact@aplon.io and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by updating the "Last updated" date at the top of this page at least 14 days before changes take effect. Continued use of the service after that date constitutes acceptance of the updated policy.
14. Contact
Hallway Ltd (operating as Aplon)
Tefkrou Anthia 90, Ayia Napa, 5330, Ammochostos, Cyprus
contact@aplon.io