PRIVACY POLICY

Your business data should have a defined job.

This policy explains what Aperta collects, why it is needed, how connected-platform data is used, the controls available to customers, and how to request access or deletion.

NOTICE AT COLLECTION

Aperta collects account identity, workspace content, authorized connection data, service activity, and billing references to provide, secure, support, and improve the service. Aperta does not sell personal information or use customer data for cross-context behavioral advertising.

01

Who this policy covers

This Privacy Policy applies to Aperta's public website, application, support interactions, and connected marketing services. Aperta acts as a controller or business for its own account administration, security, billing, support, and website operations. Aperta generally acts as a processor or service provider when handling a customer's contacts, campaign records, analytics, messages, website events, and connected-platform data under that customer's instructions.

Customers remain responsible for their own privacy notices, lawful bases, audience permissions, consent records, and use of information they direct Aperta to process.

02

Information Aperta collects

Account and business identityName, business email, user identifier, role, workspace membership, organization profile, website, settings, and support communications.
Customer contentBrand materials, offers, audiences, contacts, consent and suppression records, drafts, media, messages, approvals, campaign plans, and results.
Connected-service dataOAuth identifiers, granted scopes, encrypted tokens, account mappings, analytics, search, social, advertising, commerce, CRM, CMS, email, and SMS records the customer authorizes.
AI and automation recordsPrompts, business context, inputs, outputs, quality evaluations, model and usage records, proposed actions, approvals, and verification results.
Service activityAuthentication and audit events, IP-derived security signals, browser and device information, diagnostics, errors, feature activity, and safety controls.
Billing referencesPayment-provider customer and subscription identifiers, plan, status, invoices, purchases, refunds, and tax records. Aperta does not store raw payment-card details.
03

Google user data

When a customer connects Google, Aperta may access the Google accounts, properties, or advertising accounts the customer selects. Depending on the enabled connection, this can include Search Console site and search-performance data; Google Analytics account, property, traffic, event, and conversion data; and Google Ads account, campaign, spend, audience, and conversion information.

Aperta uses Google user data only to provide customer-facing setup, analytics, SEO research, conversion measurement, reporting, recommendations, and approved advertising operations. Aperta does not use Google user data for advertising to the customer, sell it, combine it into a data-broker profile, or use it to train general-purpose AI models.

Google access and refresh tokens are encrypted and used only for authorized API requests. Access is limited to automated service processes and, when necessary, authorized personnel providing security or customer-requested support. Google user data is shared only with infrastructure providers that help operate Aperta, or with destinations the customer explicitly directs.

Aperta's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

04

Meta and X data

When a customer connects Meta, Aperta may receive the Facebook Pages and Instagram professional accounts the customer manages, account and Page identifiers, profile information, published content, engagement and insight metrics, and the permissions needed to create customer-approved posts. Aperta does not publish to a personal Facebook profile.

When a customer connects X, Aperta may receive the authorized account's identifier, profile information, posts, mentions, and available performance metrics. Aperta uses granted write access only for work the customer has approved under its saved publishing controls.

Connected-platform data is used to map the correct business account, prepare and publish approved content, import performance evidence, learn from results, and verify delivery. Customers can disconnect a provider at any time from Aperta and can also revoke access in the provider's own settings.

05

How information is used and disclosed

Aperta uses information to provide and personalize the service; authenticate users; enforce workspace roles, budgets, approvals, and quality controls; connect authorized services; generate and publish approved work; measure results; process billing; prevent abuse; troubleshoot; support customers; and comply with law.

Information may be disclosed to hosting, storage, authentication, AI, analytics, billing, email, support, security, and other service providers acting under contract; to connected platforms at the customer's direction; during a corporate transaction subject to safeguards; or when reasonably necessary to comply with law or protect rights and safety.

Aperta does not sell personal information. Customer-directed advertising, publishing, outreach, or audience transmission is performed only under the customer's instructions and permissions.

06

Retention, security, and deletion

Account and workspace recordsRetained for the service relationship and then until verified deletion is completed, subject to legal, security, billing, dispute, and backup requirements.
Connected credentialsRetained while the connection is active and revoked or deleted after disconnection, replacement, account closure, or verified deletion.
Behavior eventsConsented website behavior events are retained for 90 days unless a shorter customer setting applies.
Consent and suppression evidenceRetained as reasonably needed to honor opt-outs, demonstrate permission, prevent re-import, and comply with law.
Security and billing recordsRetained for periods proportionate to fraud prevention, incident response, accounting, tax, legal, and dispute obligations.

Aperta uses tenant isolation, encrypted transport and connected credentials, least-privilege access, role-based permissions, step-up authentication for protected actions, audit trails, provider response verification, and bounded automation. No system is perfectly secure.

Deletion instructions and provider-specific revocation steps are available on the Data Deletion page.

07

Choices and privacy rights

Depending on location, individuals may request access, correction, deletion, portability, restriction, objection, or information about processing; withdraw consent; opt out of a sale or qualifying sharing; and appeal a decision. Aperta will not discriminate against someone for exercising a privacy right.

Send a request to privacy@useaperta.com. Aperta may verify identity and authority before acting. Requests concerning records controlled by an Aperta customer may be directed to that customer.

Aperta is a business service for adults and is not directed to children under 18. Do not use Aperta to profile or target children or to process regulated sensitive data without a written agreement.

08

Changes and contact

Material changes will be posted on this page and, when appropriate, announced through the application or account email. Questions, rights requests, and privacy complaints may be sent to privacy@useaperta.com. Security or abuse reports may be sent to abuse@useaperta.com.