Legal
Privacy Policy
Last updated · Terms of Service
This Privacy Policy explains how AppActor ("AppActor", "we", "us") collects, uses, shares and protects personal data when you visit appactor.com, create an AppActor account, use the AppActor dashboard, SDKs, API and related services (together, the "Services"), or use a mobile app that has integrated AppActor.
AppActor is subscription infrastructure for mobile apps. That means we handle personal data in two very different roles, and this policy is organized around them: for our website visitors and account holders we are the data controller; for the end users of our customers' apps we act as a data processor on our customers' instructions.
1. Who we are
AppActor operates the AppActor Services. You can contact us at [email protected].
2. Who this policy applies to
We process personal data about three groups of people:
- Website visitors — anyone who browses our marketing website or documentation.
- Account holders — developers, founders and team members who create an AppActor account and use the dashboard, SDK keys, API and webhooks (our "Customers").
- End users — people who use a mobile app built by one of our Customers that has integrated the AppActor SDK. We process end-user data only as a processor, on the Customer's behalf and instructions. The Customer is the controller of that data, and their privacy notice governs how it is used inside their app.
3. Personal data we collect
From website visitors we collect:
- Technical data sent by your browser with every request, such as IP address, user agent and the pages you request. Our website sets no advertising or analytics cookies; the only cookie is the session cookie set when you log in.
- Anything you send us voluntarily, for example when you request access or contact us.
From account holders we collect: your name, email address and a password (stored only as a salted hash by our authentication service); your organization and project names; app identifiers such as bundle IDs and package names; the store credentials you connect (used only to validate purchases and receive store notifications); billing details if and when paid plans are introduced; support conversations; and usage and security logs (dashboard actions, API key usage, IP addresses, timestamps).
On behalf of our Customers, the AppActor SDK and API process end-user data needed to validate purchases and grant access. Depending on how the Customer configures AppActor, this includes: an app user ID chosen by the Customer and/or an anonymous device-scoped identifier generated by the SDK; purchase and subscription data reported by Apple's App Store and Google Play (transaction and original transaction IDs, product IDs, prices, currency, store country, purchase, renewal, cancellation, refund and grace-period status); device and app context (platform, OS version, app version, locale, timezone); attribution and integration identifiers the Customer chooses to set (for example an advertising ID or a third-party analytics ID); and remote-config and experiment assignments. AppActor never receives end users' payment card details — payments are processed entirely by Apple and Google.
4. How and why we use personal data
We use personal data to:
- Provide the Services: validate purchases with the app stores, keep entitlements current, deliver offerings, remote config and experiment assignments, send webhooks, and show analytics in the dashboard.
- Operate, secure and improve the Services: authenticate account holders, prevent abuse and fraud, monitor reliability, debug problems and understand how the product is used in aggregate.
- Communicate with account holders about their account, security, service changes and support requests.
- Comply with legal obligations and enforce our Terms of Service.
Where the GDPR or similar laws apply, our legal bases are: performance of our contract with the Customer (providing the Services), our legitimate interests (security, reliability, product improvement, business communications), your consent where we ask for it, and compliance with legal obligations. For end-user data we rely on the Customer's instructions under our data processing terms.
We do not sell personal data, and we do not use end-user data to build advertising profiles.
6. International transfers
Our infrastructure providers may store and process data in countries other than the one you live in. Where data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on adequacy decisions or standard contractual clauses and equivalent safeguards, and we require the same of our service providers.
7. How long we keep data
Account holder data is kept for as long as the account exists and for a limited period afterwards to resolve disputes, meet legal and accounting obligations and keep security logs. End-user data is kept for as long as the Customer uses the Services for that app, and is deleted or returned according to the Customer's instructions when the relationship ends, subject to legal retention requirements. Aggregated data that no longer identifies anyone may be kept for statistics and product improvement.
8. Security
All traffic to and from the Services is encrypted in transit with TLS. Purchases are validated server-side, entitlement data delivered to apps is signed so it can be verified, webhooks are signed, and API access is controlled through per-app public keys and per-project secret keys. Access to production systems is restricted to people who need it, and we review our security practices regularly. No method of transmission or storage is completely secure; if you believe your account or keys have been compromised, rotate the keys in the dashboard and contact us immediately.
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive it in a portable format, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. Account holders can view and update most of their data in the dashboard. If you are in the EEA, UK or Switzerland you also have the right to lodge a complaint with your local supervisory authority. California residents have the rights described in the CCPA, including the right to know, delete and opt out of sales (we make no sales of personal data).
If you are an end user of a Customer's app, please direct requests about your data to that app's developer first: they are the controller and can act on your request, and we assist them in doing so. You can contact us at [email protected].
11. Children
The Services are intended for businesses and developers. We do not knowingly collect personal data from children under 16 as a controller. Customers whose apps are directed at children are responsible for complying with the laws that apply to them, including obtaining any required parental consent, before sending data to AppActor.
12. Changes to this policy
We may update this policy from time to time. We will post the new version on this page with an updated date, and for significant changes we will notify account holders by email or through the dashboard before they take effect.
13. Contact
Questions about this policy or about how we handle personal data? You can contact us at [email protected].