aploaiaploai
See the platform

One system to run, automate, and measure every customer conversation.

Integrations
WhatsAppGmail

Capabilities

AI SupportCart RecoveryNewAll ChannelsUpdatedAnalyticsAutomations

Explore

IntegrationsPricing
FeaturesPricing
Aploai Learning Hub

Guides, articles, and operator playbooks for support teams

Learn

Guides

Read

Articles

Explore

Help CenterChangelog

Privacy Policy

Effective: 2026-06-11 · Last updated: 2026-09-01

1. Who we are

This Privacy Policy ("Policy") describes how Aploai Ltd (אפלו איי.אי בע"מ), registered in Israel under company number ח.פ. 517348058, with its registered office at HaHashmonaim St 103, Tel Aviv-Yafo 6713319, Israel ("aploai", "we", "us", or "our") collects, uses, discloses, and protects personal data.

Our primary website is https://app.aploai.com. Our product ("Service") is an AI-powered customer support platform that enables businesses ("Customers") to communicate with their own end-users ("End-Users") across messaging channels including WhatsApp, Telegram, and web chat.

Contact for privacy matters: privacy@aploai.com.

2. Scope of this Policy

This Policy applies to:

  • Visitors to aploai.com and our marketing pages ("Visitors").
  • Users of our dashboard and administrative interfaces ("Users") - typically employees or agents of our Customers.
  • End-Users whose messages are processed by our Service on behalf of our Customers.

Our Customers act as data controllers for End-User data that flows through their instance of the Service; aploai acts as a data processor on our Customers' behalf under a Data Processing Agreement.

3. Personal data we collect

3.1 Visitor data

  • Server logs: IP address, browser user-agent, pages requested, and referrer URL, collected as part of standard infrastructure and security logging.
  • Contact form submissions: name, email, company, message content.
  • Cookies: see Section 10.

3.2 User (dashboard) data

  • Account data: name, email, and your authentication identity managed by Google Firebase Authentication (we do not store passwords ourselves).
  • Organization / billing data: company name, billing address, VAT ID.
  • Usage logs: dashboard actions, feature usage, API calls.

3.3 End-User data processed on behalf of Customers

When a Customer connects their WhatsApp Business Account to aploai through Meta's Embedded Signup flow, and conducts conversations with End-Users, we process:

  • Phone numbers of End-Users contacting the Customer.
  • Message content: text, images, audio, video, documents, location, interactive elements, and reactions sent to or from the Customer's WhatsApp number.
  • WhatsApp profile data exposed by Meta: display name, profile picture (when shared by the End-User), user identifier.
  • Metadata: timestamps, message status (sent, delivered, read, failed), message template category (utility, marketing, authentication), conversation identifiers.
  • Opt-in records: source of opt-in (website form, purchase receipt, in-store sign-up, etc.), timestamp, opt-out timestamp if applicable.
  • AI processing outputs: classifications, extracted entities, suggested replies generated by our large-language-model subprocessors.

We do not request, store, or process End-User credit-card data; payment information for the Customer's messaging costs is handled by Meta directly.

Shopify data. When a Customer connects a Shopify store, we process order identifiers and numbers, totals, currency, fulfillment status, and order attributes used to link orders to support conversations and report commerce performance.

Customer imports and abandoned-checkout workflows can also process customer display names, email addresses, phone numbers, marketing-consent status, and abandoned-checkout links. These features are disabled by default for the aploai public Shopify app until the required protected-field access has been approved and enabled. They can be used with separately authorized custom integrations. We use this data on the Customer's behalf for customer support and the workflows they configure.

Shopify data-access and deletion requests are handled through customers/data_request, customers/redact, and shop/redact webhooks.

4. Sources of personal data

  • Directly from Visitors and Users when they sign up, contact us, or use the Service.
  • From the Meta / WhatsApp Business Platform when a Customer connects their WhatsApp Business Account via Embedded Signup and when End-Users message the Customer.
  • From Meta Login for Business when a User authenticates to consent to Embedded Signup (we receive a Facebook user identifier and a business-scoped access token).

5. Legal bases for processing

Where applicable data-protection law (including the Israeli Protection of Privacy Law) requires a legal basis for processing, we rely on:

  • Contract performance - processing necessary to provide the Service to the Customer and, by extension, their End-Users.
  • Legitimate interest - security, fraud prevention, product improvement, and service analytics, balanced against data-subject rights.
  • Consent - marketing to Visitors; Customer consent to subprocessors; and, as required, End-User consent for marketing messages (obtained and logged by the Customer).
  • Legal obligation - tax records, legal hold, regulatory compliance.

6. How we use personal data

  • Operate, maintain, and secure the Service.
  • Route inbound WhatsApp messages to the correct Customer's instance and deliver outbound messages via the Meta Cloud API.
  • Generate AI-driven responses and suggestions for the Customer's review.
  • Enforce the 24-hour WhatsApp customer-service window, template opt-in rules, and opt-out handling required by the WhatsApp Business Policy.
  • Detect abuse, spam, and violations of our Terms of Service.
  • Communicate with Users about their account, billing, security, and product updates.
  • Comply with legal obligations and respond to lawful requests.

We do not sell personal data. We do not use WhatsApp message content to train general-purpose AI models; AI processing is scoped to producing the Customer's own responses within the Customer's workspace.

7. Subprocessors

We share personal data with a limited set of subprocessors who process data on our behalf under written contracts:

CategorySubprocessorPurposeRegion
Cloud hostingGoogle Cloud Platform (GCP)Compute, storage, networkingEU / US
Messaging infrastructureMeta Platforms, Inc. (WhatsApp)Delivery of WhatsApp messages via Cloud APIGlobal (per Meta)
AuthenticationGoogle Firebase Authentication (Google LLC)User authenticationUS / EU
AI processingOpenAI OpCo, LLC / Google LLC (Gemini)Large-language-model inference for response generationUS
ObservabilitySelf-hosted Prometheus / Grafana / Tempo (on GCP)Metrics, traces, alertingUS (us-central1)
Email transactionalResend, Inc.Account and operational emailUS

A current list of subprocessors is available on request from privacy@aploai.com; this table is updated before new subprocessors are engaged.

8. International transfers

aploai is based in Israel. Israel currently benefits from a European Commission adequacy decision for transfers of personal data from the EEA (adopted in 2011), which is under ongoing review by the Commission. Where transfers rely on that decision, we monitor its status and will implement Standard Contractual Clauses or equivalent safeguards if adequacy is modified or withdrawn. Transfers to subprocessors outside Israel and the EEA rely on:

  • European Commission Standard Contractual Clauses (SCCs) where the subprocessor is in a non-adequate jurisdiction.
  • Commission adequacy decisions where available.
  • Additional technical and organizational measures (encryption in transit and at rest, access controls, audit logging).

9. Data retention

  • Message content and metadata: retained for 24 months from the date of the message, then deleted or anonymized. AI-generated conversation summaries are cleared once the underlying messages are deleted. Customers may configure shorter retention in their workspace settings.
  • Opt-in records: retained for the duration of the Customer's subscription plus 24 months, to demonstrate lawful basis for messaging.
  • Billing and tax records (invoices, payments, VAT-relevant data): retained for up to 7 years, as required by Israeli bookkeeping and VAT law.
  • Other account data: deleted on account termination, as described in our Terms of Service.
  • Embedded Signup session logs: 24 months (required by Meta).
  • Security and audit logs: 12 months.

Data is permanently deleted on Customer account termination, subject to the retention periods required by law.

10. Cookies

aploai uses a small set of first-party cookies and similar local-storage entries:

  • Strictly necessary - session management and authentication (Google Firebase Authentication). These are always active because they are required for you to sign in and use the service.
  • Preference - language and theme settings you choose. These are stored on your device only with your consent.
  • Marketing - the Meta Pixel (Meta Platforms), which we use to measure the effectiveness of our own advertising on our public marketing pages. It is loaded only with your consent and is never loaded inside the signed-in application. Data collected by the Meta Pixel is processed by Meta under its own privacy policy.

When you first visit, we show a cookie consent banner. Preference and marketing cookies are set only if you accept them; if you decline, your language and theme choices still work for the current session but are not saved between visits, and no marketing tracking occurs. You can change your choice at any time through the Cookie settings link in the site footer, or by viewing, managing, or deleting cookies through your browser settings; blocking strictly necessary cookies may prevent you from signing in.

Apart from the consent-based Meta Pixel described above, we do not use advertising cookies, third-party analytics cookies, or cross-site tracking of any kind.

11. Your rights

Subject to applicable law (including the Israeli Protection of Privacy Law), you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Delete your data ("right to be forgotten"), subject to legal retention.
  • Restrict or object to certain processing.
  • Portability - receive a machine-readable copy of your data.
  • Withdraw consent at any time for consent-based processing.
  • Complain to a supervisory authority (such as the Israeli Privacy Protection Authority).

To exercise any of these rights, email privacy@aploai.com from the address associated with your account (or provide equivalent verification). We acknowledge requests within 5 business days and respond within 30 days.

11.1 End-User requests

End-Users who wish to exercise rights over data processed by aploai on behalf of a Customer should contact the Customer first. If the End-User cannot reach the Customer or their request relates to our processing activity directly, they may contact privacy@aploai.com or use our self-serve deletion form at https://app.aploai.com/data-deletion.

11.2 Meta-initiated deletion (business admins)

aploai implements the Meta Data Deletion Callback at https://api.aploai.com/webhooks/meta/data-deletion. This callback is invoked by Meta when a business admin who authenticated to aploai via Meta Login for Business (as part of WhatsApp Embedded Signup) subsequently:

  • removes the aploai app from their Facebook Business Manager,
  • revokes the business-integration token issued to aploai, or
  • deletes their Facebook account.

On receipt of a signed request from Meta, we locate the WhatsApp Business Accounts and associated records tied to that business admin, anonymize or delete the associated WhatsApp conversation data retained on the business customer's behalf, notify the business customer of the revocation, and return a confirmation URL where the deletion status can be tracked.

This callback does not fire when an End-User messages a business via WhatsApp - End-Users have no Facebook-to-aploai connection. End-Users wishing to exercise deletion rights should use the direct channels described in §11.1.

11.3 California residents

If aploai accepts California customers, this section will be expanded to provide a Notice to California Residents as required by the California Consumer Privacy Act and California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.), including categories of personal information collected, sources, purposes, sharing disclosures, and the right to opt out of sale/sharing.

12. Security

We implement industry-standard technical and organizational measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 envelope encryption for secrets, database-level encryption).
  • Role-based access control with row-level security for tenant isolation.
  • Principle of least privilege for employee access.
  • Audit logging of administrative actions.
  • Regular security reviews and penetration testing.
  • Incident response procedures, including breach notification within the timeframes required by law.

13. Children

The Service is not directed at children under the age of 16. We do not knowingly collect data from children. If you believe a child has provided personal data to us, contact privacy@aploai.com and we will delete it.

14. WhatsApp-specific disclosures

In connection with the WhatsApp Business Platform:

  • We process End-User data only to operate messaging services requested by our Customers, not for our own marketing or advertising purposes.
  • We do not sell or license WhatsApp-sourced data, and we do not use it to build user profiles across unrelated businesses.
  • We do not share End-User data with Meta beyond what is necessary for message delivery via the Cloud API.
  • We require Customers to obtain lawful opt-in from End-Users before sending marketing-category template messages, and we log opt-in and opt-out events as required by the WhatsApp Business Policy.
  • Customers are contractually obligated to comply with the WhatsApp Business Policy and the WhatsApp Commerce Policy.

15. Changes to this Policy

We may update this Policy. Material changes will be announced in the dashboard and via email to Users at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

16. Contact

  • Email: privacy@aploai.com
  • Postal: Aploai Ltd, HaHashmonaim St 103, Tel Aviv-Yafo 6713319, Israel
  • Response time: we acknowledge privacy inquiries within 5 business days and resolve them within 30 days.
On this page
  1. 1. Who we are
  2. 2. Scope of this Policy
  3. 3. Personal data we collect
  4. 3.1 Visitor data
  5. 3.2 User (dashboard) data
  6. 3.3 End-User data processed on behalf of Customers
  7. 4. Sources of personal data
  8. 5. Legal bases for processing
  9. 6. How we use personal data
  10. 7. Subprocessors
  11. 8. International transfers
  12. 9. Data retention
  13. 10. Cookies
  14. 11. Your rights
  15. 11.1 End-User requests
  16. 11.2 Meta-initiated deletion (business admins)
  17. 11.3 California residents
  18. 12. Security
  19. 13. Children
  20. 14. WhatsApp-specific disclosures
  21. 15. Changes to this Policy
  22. 16. Contact
aploaiaploai

AI agents that handle your customer support, recover lost revenue, and scale with your business - across every channel.

Product

  • Features
  • Pricing

Company

  • About Us
  • Contact

Resources

  • Guides
  • Articles
  • Help Center
  • Changelog

Legal

  • Privacy Policy
  • Terms of Service
  • Data Deletion

© 2026 Aploai Ltd. All rights reserved.

Built with ❤️ for customer success teams everywhere