Privacy Policy
Last updated: 31 July 2026 · Effective: 31 July 2026
This policy explains what personal data Aproli collects, why we collect it, who we share it with, and what rights you have. We keep it in plain English on purpose. If anything is unclear, email privacy@aproli.co and we'll explain it.
1. Who is responsible for your data
The data controller is Aproar Tech, Unipessoal Lda, established in Portugal, registered address Rua Mouzinho da Silveira, Número 32, operating the service at aproli.co.
Data protection contact: privacy@aproli.co.
Where a brand uses Aproli to manage its own campaigns, the brand is the controller of the creator data it collects for its own purposes, and Aproli acts as its processor for that activity. For running the platform itself, Aproli is the controller.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, email address, password (stored hashed), account type (brand or creator), profile photo, language, time zone. | You, at sign-up |
| Profile data | Creators: bio, niche/categories, country, content examples, rates. Brands: company name, website, logo, industry, team members. | You, during onboarding |
| Social account data | Connected platform handles, follower counts, audience demographics where available, post metrics (views, likes, comments, shares), and the campaign content you submit. | Social platforms directly, with your authorisation |
| Campaign data | Briefs, applications, approvals and rejections, submitted content, deadlines, messages between brands and creators, tracked link clicks. | You and the other party |
| Payment data | Payout account status, amounts paid and received, invoices, subscription plan and status. Card numbers and bank details are held by Stripe, not by us. | You and Stripe |
| Technical data | IP address, browser and device type, pages viewed, timestamps, error logs, security events such as sign-in attempts. | Automatically, when you use the site |
| Support data | Emails you send us and the content of support conversations. | You |
We do not deliberately collect special category data (health, religion, political opinions, sexual orientation). Please don't put such information into free-text fields.
3. Why we use your data, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and run your account; let you use the platform | Performance of a contract |
| Match creators to campaigns, show applications to brands, run approvals | Performance of a contract |
| Measure campaign performance and calculate what is owed | Performance of a contract |
| Process payments, payouts and subscriptions | Performance of a contract; legal obligation (accounting) |
| Send service emails (verification, invites, campaign updates, receipts) | Performance of a contract |
| Keep the platform secure; prevent fraud, spam and metric manipulation | Legitimate interests |
| Improve the product, fix bugs, understand which features are used | Legitimate interests |
| Marketing emails about Aproli | Consent (you can withdraw at any time) |
| Meet tax, accounting and anti-money-laundering obligations | Legal obligation |
| Establish, exercise or defend legal claims | Legitimate interests |
Where we rely on legitimate interests, we've weighed them against your rights and think our use is what you'd reasonably expect. You can object — see Your rights.
5. Payment data
All payments run through Stripe. Card numbers, bank account details, and identity documents you submit for payout verification go directly to Stripe and are stored by Stripe, not by Aproli. We receive only what we need to run the service: whether your payout account is verified, transaction amounts, dates, and status.
Stripe acts as an independent controller for its own compliance and fraud-prevention purposes. See stripe.com/privacy.
7. What brands and creators see about each other
- Brands see a creator's public profile, connected handles, follower and audience statistics, campaign applications, submitted content, and the performance of that content. Brands do not see a creator's bank details, home address, or identity documents.
- Creators see a brand's company profile, campaign briefs, budgets and rate models, and messages from that brand.
- Messages between a brand and a creator are visible to both sides and stored on our systems. Aproli staff access them only where necessary — for support, a reported dispute, or a legal obligation.
8. International transfers
Some of our providers are based outside the European Economic Area, mainly in the United States. Where data leaves the EEA, we rely on the safeguards required by the GDPR — usually the European Commission's Standard Contractual Clauses, and the EU–US Data Privacy Framework where the provider is certified.
You can ask us for a copy of the safeguards in place by emailing privacy@aproli.co.
9. How long we keep data
| Data | Kept for |
|---|---|
| Account and profile data | While your account is active, then deleted or anonymised within 90 days of closure |
| Campaign records and messages | 3 years after the campaign closes, for dispute and audit purposes |
| Invoices, payouts and accounting records | 10 years — required by Portuguese tax law |
| Technical and security logs | Up to 12 months |
| Marketing consent records | Until you withdraw consent, plus 2 years as proof |
| Support emails | 2 years after the conversation ends |
When you delete your account from the app, we remove your profile and personal identifiers. Records we're legally required to keep (mainly financial ones) are retained but locked down.
10. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected. Most of it you can edit yourself in settings.
- Erasure — ask us to delete your data, where we don't have a legal reason to keep it.
- Restriction — ask us to pause processing while a dispute is sorted out.
- Portability — receive the data you gave us in a machine-readable format.
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time (this doesn't undo what was done before).
Email privacy@aproli.co and we'll respond within one month. We may need to verify your identity first. Exercising your rights is free.
11. Security
- All traffic is encrypted in transit with HTTPS/TLS; data is encrypted at rest by our infrastructure providers.
- Passwords are hashed — we never see or store them in readable form.
- Database access is restricted per-user with row-level security, so accounts can only reach their own data.
- Brand team members only get access to the areas the account owner grants them.
- Payment credentials never touch our servers.
No system is perfectly secure. If a breach affects your rights, we will notify the Portuguese supervisory authority within 72 hours and tell you directly where the law requires.
12. Automated decision-making
We don't make decisions with legal or similarly significant effects about you purely by machine. Campaign matching and search ranking use automated sorting, but a human at the brand decides who is accepted. Fraud and metric-manipulation checks may flag activity automatically; a person reviews before any account is restricted.
13. Children
Aproli is for people aged 18 and over. We don't knowingly collect data from children. If you believe a minor has an account, tell us and we'll remove it.
15. Changes to this policy
We'll update this page when our practices change and update the date at the top. If a change materially affects you, we'll tell you by email or in-app before it takes effect.
16. Contact & complaints
Aproar Tech, Unipessoal Lda
Rua Mouzinho da Silveira, Número 32, Portugal
Email: privacy@aproli.co
If you're not happy with how we've handled your data, you can complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD) — cnpd.pt — or to the authority in the EU country where you live.
4. Social account data
Aproli connects to every social platform directly, using our own developer credentials registered with that platform. No third-party data aggregator sits between you and us. In every case:
Each social platform's own privacy policy also applies to your relationship with them.
YouTube
Aproli's YouTube integration uses YouTube API Services. By connecting a YouTube channel you are also agreeing to the YouTube Terms of Service. Google's own handling of your information is described in the Google Privacy Policy.
We request two read-only permissions.
youtube.readonlylets us read your channel — its handle, profile picture and subscriber count — along with your list of videos and the view, like and comment counts on them; because creators are paid per view, those counts determine what you are paid.yt-analytics.readonlylets us read aggregate audience statistics for your channel — age ranges, gender split and top countries — which brands use to judge whether your audience fits a campaign.Aproli's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not transfer this data to anyone except as needed to provide or improve Aproli, to comply with the law, or as part of a merger or acquisition. We never use it for advertising, we never sell it, and no human reads it except with your explicit consent, for security purposes, where the law requires it, or where it has been aggregated and anonymised.
As well as disconnecting inside Aproli, you can review or revoke our access to your Google account at any time at myaccount.google.com/permissions.
Pinterest
We request two read-only permissions:
user_accounts:readfor your handle, profile picture and follower count, andpins:readfor your pins and each pin's performance. Pinterest does not publish a view count for pins, so we use its impression figure in place of views. Pinterest does not make audience demographics available for organic content, so we do not collect them.TikTok
Aproli's TikTok integration uses Login Kit and the Display API. We request four read-only permissions.
user.info.basicidentifies the account you connected — your display name and profile picture.user.info.profilereads your @handle, so your connected account is labelled correctly; TikTok grants this permission alongside your bio, profile link and verification status, and we do not read those.user.info.statsreads your follower count, total likes and video count, which brands use to judge whether your audience fits a campaign.video.listreads your own videos and their view, like, comment and share counts; because creators are paid per view, those counts determine what you are paid. None of these permissions allow us to post, upload, edit or delete anything on TikTok. TikTok does not make audience demographics available for organic content, so we do not collect them.