Privacy Policy
1. Who we are
This Privacy Policy ("Policy") describes how Aploai Ltd (אפלו איי.אי בע"מ), registered in Israel under company number ח.פ. 517348058, with its registered office at HaHashmonaim St 103, Tel Aviv-Yafo 6713319, Israel ("aploai", "we", "us", or "our") collects, uses, discloses, and protects personal data.
Our primary website is https://app.aploai.com. Our product ("Service") is an AI-powered customer support platform that enables businesses ("Customers") to communicate with their own end-users ("End-Users") across messaging channels including WhatsApp, Telegram, and web chat.
Contact for privacy matters: privacy@aploai.com.
2. Scope of this Policy
This Policy applies to:
- Visitors to aploai.com and our marketing pages ("Visitors").
- Users of our dashboard and administrative interfaces ("Users") - typically employees or agents of our Customers.
- End-Users whose messages are processed by our Service on behalf of our Customers.
Our Customers act as data controllers for End-User data that flows through their instance of the Service; aploai acts as a data processor on our Customers' behalf under a Data Processing Agreement.
3. Personal data we collect
3.1 Visitor data
- Server logs: IP address, browser user-agent, pages requested, and referrer URL, collected as part of standard infrastructure and security logging.
- Contact form submissions: name, email, company, message content.
- Cookies: see Section 10.
3.2 User (dashboard) data
- Account data: name, email, and your authentication identity managed by Google Firebase Authentication (we do not store passwords ourselves).
- Organization / billing data: company name, billing address, VAT ID.
- Usage logs: dashboard actions, feature usage, API calls.
3.3 End-User data processed on behalf of Customers
When a Customer connects their WhatsApp Business Account to aploai through Meta's Embedded Signup flow, and conducts conversations with End-Users, we process:
- Phone numbers of End-Users contacting the Customer.
- Message content: text, images, audio, video, documents, location, interactive elements, and reactions sent to or from the Customer's WhatsApp number.
- WhatsApp profile data exposed by Meta: display name, profile picture (when shared by the End-User), user identifier.
- Metadata: timestamps, message status (sent, delivered, read, failed), message template category (utility, marketing, authentication), conversation identifiers.
- Opt-in records: source of opt-in (website form, purchase receipt, in-store sign-up, etc.), timestamp, opt-out timestamp if applicable.
- AI processing outputs: classifications, extracted entities, suggested replies generated by our large-language-model subprocessors.
We do not request, store, or process End-User credit-card data; payment information for the Customer's messaging costs is handled by Meta directly.
Shopify data. When a Customer connects a Shopify store, we process order identifiers and numbers, totals, currency, fulfillment status, and order attributes used to link orders to support conversations and report commerce performance.
Customer imports and abandoned-checkout workflows can also process customer display names, email addresses, phone numbers, marketing-consent status, and abandoned-checkout links. These features are disabled by default for the aploai public Shopify app until the required protected-field access has been approved and enabled. They can be used with separately authorized custom integrations. We use this data on the Customer's behalf for customer support and the workflows they configure.
Shopify data-access and deletion requests are handled through customers/data_request, customers/redact, and shop/redact webhooks.
4. Sources of personal data
- Directly from Visitors and Users when they sign up, contact us, or use the Service.
- From the Meta / WhatsApp Business Platform when a Customer connects their WhatsApp Business Account via Embedded Signup and when End-Users message the Customer.
- From Meta Login for Business when a User authenticates to consent to Embedded Signup (we receive a Facebook user identifier and a business-scoped access token).
5. Legal bases for processing
Where applicable data-protection law (including the Israeli Protection of Privacy Law) requires a legal basis for processing, we rely on:
- Contract performance - processing necessary to provide the Service to the Customer and, by extension, their End-Users.
- Legitimate interest - security, fraud prevention, product improvement, and service analytics, balanced against data-subject rights.
- Consent - marketing to Visitors; Customer consent to subprocessors; and, as required, End-User consent for marketing messages (obtained and logged by the Customer).
- Legal obligation - tax records, legal hold, regulatory compliance.
6. How we use personal data
- Operate, maintain, and secure the Service.
- Route inbound WhatsApp messages to the correct Customer's instance and deliver outbound messages via the Meta Cloud API.
- Generate AI-driven responses and suggestions for the Customer's review.
- Enforce the 24-hour WhatsApp customer-service window, template opt-in rules, and opt-out handling required by the WhatsApp Business Policy.
- Detect abuse, spam, and violations of our Terms of Service.
- Communicate with Users about their account, billing, security, and product updates.
- Comply with legal obligations and respond to lawful requests.
We do not sell personal data. We do not use WhatsApp message content to train general-purpose AI models; AI processing is scoped to producing the Customer's own responses within the Customer's workspace.
7. Subprocessors
We share personal data with a limited set of subprocessors who process data on our behalf under written contracts:
| Category | Subprocessor | Purpose | Region |
|---|---|---|---|
| Cloud hosting | Google Cloud Platform (GCP) | Compute, storage, networking | EU / US |
| Messaging infrastructure | Meta Platforms, Inc. (WhatsApp) | Delivery of WhatsApp messages via Cloud API | Global (per Meta) |
| Authentication | Google Firebase Authentication (Google LLC) | User authentication | US / EU |
| AI processing | OpenAI OpCo, LLC / Google LLC (Gemini) | Large-language-model inference for response generation | US |
| Observability | Self-hosted Prometheus / Grafana / Tempo (on GCP) | Metrics, traces, alerting | US (us-central1) |
| Email transactional | Resend, Inc. | Account and operational email | US |
A current list of subprocessors is available on request from privacy@aploai.com; this table is updated before new subprocessors are engaged.
8. International transfers
aploai is based in Israel. Israel currently benefits from a European Commission adequacy decision for transfers of personal data from the EEA (adopted in 2011), which is under ongoing review by the Commission. Where transfers rely on that decision, we monitor its status and will implement Standard Contractual Clauses or equivalent safeguards if adequacy is modified or withdrawn. Transfers to subprocessors outside Israel and the EEA rely on:
- European Commission Standard Contractual Clauses (SCCs) where the subprocessor is in a non-adequate jurisdiction.
- Commission adequacy decisions where available.
- Additional technical and organizational measures (encryption in transit and at rest, access controls, audit logging).
9. Data retention
- Message content and metadata: retained for 24 months from the date of the message, then deleted or anonymized. AI-generated conversation summaries are cleared once the underlying messages are deleted. Customers may configure shorter retention in their workspace settings.
- Opt-in records: retained for the duration of the Customer's subscription plus 24 months, to demonstrate lawful basis for messaging.
- Billing and tax records (invoices, payments, VAT-relevant data): retained for up to 7 years, as required by Israeli bookkeeping and VAT law.
- Other account data: deleted on account termination, as described in our Terms of Service.
- Embedded Signup session logs: 24 months (required by Meta).
- Security and audit logs: 12 months.
Data is permanently deleted on Customer account termination, subject to the retention periods required by law.
11. Your rights
Subject to applicable law (including the Israeli Protection of Privacy Law), you have the right to:
- Access your personal data.
- Correct inaccurate data.
- Delete your data ("right to be forgotten"), subject to legal retention.
- Restrict or object to certain processing.
- Portability - receive a machine-readable copy of your data.
- Withdraw consent at any time for consent-based processing.
- Complain to a supervisory authority (such as the Israeli Privacy Protection Authority).
To exercise any of these rights, email privacy@aploai.com from the address associated with your account (or provide equivalent verification). We acknowledge requests within 5 business days and respond within 30 days.
11.1 End-User requests
End-Users who wish to exercise rights over data processed by aploai on behalf of a Customer should contact the Customer first. If the End-User cannot reach the Customer or their request relates to our processing activity directly, they may contact privacy@aploai.com or use our self-serve deletion form at https://app.aploai.com/data-deletion.
11.2 Meta-initiated deletion (business admins)
aploai implements the Meta Data Deletion Callback at
https://api.aploai.com/webhooks/meta/data-deletion. This callback is
invoked by Meta when a business admin who authenticated to aploai via
Meta Login for Business (as part of WhatsApp Embedded Signup) subsequently:
- removes the aploai app from their Facebook Business Manager,
- revokes the business-integration token issued to aploai, or
- deletes their Facebook account.
On receipt of a signed request from Meta, we locate the WhatsApp Business Accounts and associated records tied to that business admin, anonymize or delete the associated WhatsApp conversation data retained on the business customer's behalf, notify the business customer of the revocation, and return a confirmation URL where the deletion status can be tracked.
This callback does not fire when an End-User messages a business via WhatsApp - End-Users have no Facebook-to-aploai connection. End-Users wishing to exercise deletion rights should use the direct channels described in §11.1.
11.3 California residents
If aploai accepts California customers, this section will be expanded to provide a Notice to California Residents as required by the California Consumer Privacy Act and California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.), including categories of personal information collected, sources, purposes, sharing disclosures, and the right to opt out of sale/sharing.
12. Security
We implement industry-standard technical and organizational measures:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 envelope encryption for secrets, database-level encryption).
- Role-based access control with row-level security for tenant isolation.
- Principle of least privilege for employee access.
- Audit logging of administrative actions.
- Regular security reviews and penetration testing.
- Incident response procedures, including breach notification within the timeframes required by law.
13. Children
The Service is not directed at children under the age of 16. We do not knowingly collect data from children. If you believe a child has provided personal data to us, contact privacy@aploai.com and we will delete it.
14. WhatsApp-specific disclosures
In connection with the WhatsApp Business Platform:
- We process End-User data only to operate messaging services requested by our Customers, not for our own marketing or advertising purposes.
- We do not sell or license WhatsApp-sourced data, and we do not use it to build user profiles across unrelated businesses.
- We do not share End-User data with Meta beyond what is necessary for message delivery via the Cloud API.
- We require Customers to obtain lawful opt-in from End-Users before sending marketing-category template messages, and we log opt-in and opt-out events as required by the WhatsApp Business Policy.
- Customers are contractually obligated to comply with the WhatsApp Business Policy and the WhatsApp Commerce Policy.
15. Changes to this Policy
We may update this Policy. Material changes will be announced in the dashboard and via email to Users at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
16. Contact
- Email: privacy@aploai.com
- Postal: Aploai Ltd, HaHashmonaim St 103, Tel Aviv-Yafo 6713319, Israel
- Response time: we acknowledge privacy inquiries within 5 business days and resolve them within 30 days.