Privacy

How we handle your data.

What Aaptly collects, why we use it, who can receive it, how we protect it, and how to request access or deletion. We do not sell personal information or Google user data.

Effective date:August 25, 2026. Aaptly is operated by HigherGroundsTech LLC. This policy applies to Aaptly’s websites, applications, account integrations, and services unless a more specific notice is displayed.

The short version

  • We collect the data you give us and the data generated while you use Aaptly, including authorized Google account data.
  • We use it to run Aaptly for you and make it better — not to sell to advertisers.
  • We disclose data only to your authorized users, service providers needed to operate Aaptly, or when the law requires it.
  • You can export or delete your data at any time.
  • We use encryption, role-based access, secret management, audit records, and bounded retention to protect sensitive data.

What we collect

Account + billing information; content you create (services, clients, bookings, messages); technical data needed to operate the service (IP, device, usage logs); and analytics about how you use Aaptly to improve the product.

How we use it

To provide the service, bill you, contact you about the service, improve the product, comply with legal obligations, and (on your behalf, with consent) communicate with your clients.

Google user data

Aaptly requests Google permissions only after an authorized user chooses to connect a Google service. For Google Ads, the requested scope is https://www.googleapis.com/auth/adwords. Google Ads exposes this single scope for its API and does not provide a narrower read-only, account-discovery, or manager-link scope.

In the one-time manager-authorization flow for Google Cloud project 976596945344, Aaptly uses that scope only to list the Ads accounts directly available to the consenting Google user, read the minimum account and manager-link metadata needed for an informed selection, accept the exact pending Aaptly manager relationship selected by the user, and read the relationship back to verify that it is active. This grant does not read or change campaigns, budgets, ads, keywords, targeting, conversion actions, or performance data.

The one-time flow requests access_type=online and sets include_granted_scopes=false, so permissions the user may have granted elsewhere in the project are not added to this token. Its Google access token is used only in server memory and is discarded when the callback finishes; Aaptly does not ask for or store a Google refresh token. After the selected manager relationship is active, any ongoing Google Ads audit or management work uses a separately authorized Aaptly manager credential or a customer-elected integration provider, not this customer token. Those continuing workflows can access only the connected Ads accounts and may read campaigns, budgets, ad groups, ads, assets, keywords, search terms, targeting, landing pages, conversion settings, change history, and performance metrics as needed to provide the service the customer requested.

Aaptly uses Google Ads data only to provide the connected service the user requested. We do not use Google user data to build advertising profiles for unrelated parties, serve third-party advertising, determine creditworthiness, or train a generalized AI model.

Who receives Google user data

Google user data is visible only to the Aaptly customer that connected the account, that customer’s authorized Aaptly users, and Aaptly personnel who require access to deliver or support the requested service. We may disclose the minimum necessary data to the following processors strictly to operate the integration:

  • Google LLC, when Aaptly reads from or writes to Google APIs at the user’s direction.
  • Amazon Web Services, Inc., for encrypted application hosting, databases, object storage, secret storage, logging, and email infrastructure.
  • Zernio, Inc., only when a customer elects to use an Aaptly workflow powered by Zernio’s Google integration.
  • Professional advisers, regulators, or law-enforcement authorities, only when disclosure is legally required or necessary to protect users, Aaptly, or the public.

We do not sell, rent, license, or transfer Google user data to data brokers, advertisers, affiliates, or unrelated third parties. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. See the Google API Services User Data Policy.

How we protect sensitive data

  • Data is encrypted in transit using HTTPS/TLS and encrypted at rest in managed AWS storage and databases.
  • OAuth client secrets, provider credentials, and other production secrets are kept in encrypted secret-management systems with restricted service access.
  • Customer and operator access is protected by authenticated sessions, role-based authorization, least-privilege service identities, and private no-store responses for sensitive pages.
  • OAuth state is signed, time-limited, bound to the initiating workflow, and protected against replay. Sensitive tokens are excluded from browser payloads and logs.
  • Administrative actions and material Google Ads changes are recorded so they can be reviewed, verified, and, where supported, rolled back.
  • Production access is limited to personnel and systems that need it to operate or support the service. Access is removed when no longer required.

Retention and deletion

We retain Google account data and derived operational records only for as long as needed to provide the connected service, maintain security and change history, meet contractual or legal obligations, and resolve disputes. OAuth state and temporary authorization data expire after the applicable short session window. When a customer disconnects the integration or asks us to delete Google user data, we delete or de-identify data that is not required for security, fraud prevention, financial records, legal compliance, or an active dispute. Requests can be sent to privacy@aaptly.com. Users may also revoke Aaptly’s access from their Google Account or Google Ads account settings at any time.

SMS messaging & mobile information

When a client of an Aaptly-powered business gives their phone number on a booking form, opts in at an in-person check-in, or replies START / YES to a message, Aaptly stores that phone number and sends appointment confirmations, reminders, rescheduling updates, and AI-receptionist replies on behalf of that business. Standard message and data rates may apply. Message frequency varies with each client’s bookings.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Phone numbers, opt-in status, and the content of SMS messages are never sold, rented, shared with advertisers, or used for lookalike audiences, ad retargeting, or affiliate marketing. They are used solely to operate the messaging service the client opted into.

The only third parties that process SMS data are the sub-processors strictly required to deliver the service: Telnyx (our licensed SMS carrier), AWS (our hosting provider), and the end business (the studio or salon operating the booking page), each bound by data-processing contracts. Information shared with these sub-processors is limited to what is required to deliver the requested SMS, and is not used for their own marketing.

HELP replies return program information. STOP replies immediately unsubscribe the phone number from all messages from that business and log the opt-out on our servers. A subsequent STARTreply, or a re-submission of the same phone number on the same business’s booking form, re-subscribes. Opt-out records are retained to honor the request even if the number is later reused.

For questions about SMS data specifically, email sms-privacy@aaptly.com. For the full SMS program terms (program name, frequency, rates, HELP/STOP) see our SMS consent page and our Terms of Service → SMS Program.

Who we share with

In addition to the Google-specific disclosures above, Aaptly uses contracted service providers for hosting and email (AWS), payments, telecommunications (Telnyx), error monitoring, and product analytics. Aaptly customers receive the records created for their own business. Each recipient is limited to the data and purpose needed to provide its service. We do not sell personal information or share it with advertisers. Mobile information (phone numbers and SMS opt-in data) is never shared with third parties or affiliates for marketing or promotional purposes.

Your rights

Export, correct, or delete your data at any time via your dashboard or by emailing privacy@aaptly.com. EU and California residents have specific rights (right to be forgotten, do-not-sell) we honor on request. Clients of an Aaptly-powered business can also revoke SMS consent at any time by replying STOP to any message, or by emailing sms-privacy@aaptly.com.

Contact

privacy@aaptly.com
SMS & mobile-data queries: sms-privacy@aaptly.com
Data Protection Officer: available on request (EU customers).

Aaptly is operated by HigherGroundsTech LLC.

This policy applies to Aaptly’s websites, applications, account integrations, and services unless a more specific notice is displayed. Last updated August 25, 2026.