AppVerticals
Legal

Privacy Policy

Last updated: July 2026

Introduction

This Privacy Policy explains how AppVerticals (“we”, “us”) handles information when you visit our website, configure an app in our builder, book a call, or use our app-as-a-service platform. It covers our own processing. Where we host an app for you, that app collects data from your customers and you are the controller of it — see “Data in the apps we build” below.

Information we collect

You give us: your name, email, phone number and company when you contact us, book a call, save a build or subscribe; the configuration you choose in the app builder; and your billing details, which go directly to Stripe — we never see or store your full card number. We collect automatically: device type, browser, pages visited, and the referring link, plus a session identifier so an enquiry can be joined to the build it came from.

How we use your information

To answer enquiries, schedule and run calls, build and operate your app, take payment, send service emails such as sign-in links, receipts and build summaries, and — only where you have opted in — send product news. We use aggregate usage data to improve the site. We do not sell your personal information, and we do not use your data to train machine-learning models.

Legal bases

Where the UK or EU GDPR applies, we rely on: performance of a contract, to build and run your app and take payment; legitimate interests, to secure the site, prevent fraud and understand which campaigns bring enquiries; consent, for analytics cookies and marketing email, which you may withdraw at any time; and legal obligation, for tax and accounting records.

Cookies and analytics

We use essential cookies to run the site and optional analytics cookies to understand how it is used. We use Google Analytics and Vercel Analytics to measure traffic, Microsoft Clarity to record anonymized session replays and heatmaps, and HubSpot to manage enquiries. Visitors in the EEA, UK and Switzerland are asked to consent before we set analytics or advertising cookies. Clarity masks the text you type into forms. We also store the advertising click identifier and campaign parameters from the link you arrived through, so we can tell which campaigns bring us enquiries. You can control cookies through your browser settings; disabling some may affect how the site functions.

Sign-in links

Your account has no password. When you ask to sign in we email a single-use link that expires in fifteen minutes. We store only a cryptographic hash of that link, never the link itself, and we only ever send one to an address that already belongs to a customer or enquiry — so the form cannot be used to send mail to strangers.

Data in the apps we build

The app we host for you collects data from your own customers. That data is yours: you decide what is collected and why, you are the controller of it, and we act as your processor. We use it only to run the app and support you. You can export it at any time, and we hand it over on request when you cancel.

How we share information

Only with providers who help us operate, under agreements that require them to protect it: Vercel (hosting), Neon (database), Stripe (payments), Resend (email), Google (analytics, calendar invites, and chat notifications to our team), Microsoft (Clarity) and HubSpot (CRM). We may also disclose information where the law requires it. We do not share your information with advertisers.

Data security

Encryption in transit, access controls, and credentials held in a managed secret store rather than in code. Payment card details never touch our servers — the card form is served by Stripe. No method of transmission or storage is perfectly secure, but we work to keep your data safe and will notify you and, where required, the regulator of a material incident without undue delay.

Data retention

Enquiry and lead records: three years from last contact. Customer account and billing records: seven years, as tax law requires. Sign-in tokens: fifteen minutes. Analytics: as configured in each tool, typically fourteen months. Saved builds you never completed: twelve months. After these periods we delete or anonymize the data.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or export your personal information, to object to processing based on legitimate interests, and to withdraw consent. Under US state privacy laws you may also opt out of targeted advertising. Email hello@appverticals.com and we will respond within thirty days. You may also complain to your local data protection authority — in the UK, the ICO.

International transfers

We are based in the United States and our providers operate globally, so your information may be processed outside your own country. Where we transfer personal data out of the UK or EEA we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.

Children

Our service is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under sixteen. If you believe a child has given us information, contact us and we will delete it.

Changes to this policy

We may update this policy. The date at the top of this page shows when it last changed, and we will tell customers directly about any change that materially affects their rights.

Contact us

Questions about this policy or your data? Email hello@appverticals.com, or write to AppVerticals, 1341 W Mockingbird Ln, Suite 600W, Dallas, TX 75247, USA.