Legal

Privacy Policy

Last updated: 21 July 2026 · Effective: 21 July 2026

This policy explains what personal data Aproli collects, why we collect it, who we share it with, and what rights you have. We keep it in plain English on purpose. If anything is unclear, email privacy@aproli.co and we'll explain it.

1. Who is responsible for your data

The data controller is [LEGAL NAME OF OPERATOR], established in Portugal, registered address [FULL ADDRESS], tax number [NIF / VAT NUMBER], operating the service at aproli.co.

Data protection contact: privacy@aproli.co.

Where a brand uses Aproli to manage its own campaigns, the brand is the controller of the creator data it collects for its own purposes, and Aproli acts as its processor for that activity. For running the platform itself, Aproli is the controller.

2. What we collect

CategoryWhat it includesWhere it comes from
Account data Name, email address, password (stored hashed), account type (brand or creator), profile photo, language, time zone. You, at sign-up
Profile data Creators: bio, niche/categories, country, content examples, rates. Brands: company name, website, logo, industry, team members. You, during onboarding
Social account data Connected platform handles, follower counts, audience demographics where available, post metrics (views, likes, comments, shares), and the campaign content you submit. Social platforms, via Phyllo, with your authorisation
Campaign data Briefs, applications, approvals and rejections, submitted content, deadlines, messages between brands and creators, tracked link clicks. You and the other party
Payment data Payout account status, amounts paid and received, invoices, subscription plan and status. Card numbers and bank details are held by Stripe, not by us. You and Stripe
Technical data IP address, browser and device type, pages viewed, timestamps, error logs, security events such as sign-in attempts. Automatically, when you use the site
Support data Emails you send us and the content of support conversations. You

We do not deliberately collect special category data (health, religion, political opinions, sexual orientation). Please don't put such information into free-text fields.

3. Why we use your data, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Create and run your account; let you use the platformPerformance of a contract
Match creators to campaigns, show applications to brands, run approvalsPerformance of a contract
Measure campaign performance and calculate what is owedPerformance of a contract
Process payments, payouts and subscriptionsPerformance of a contract; legal obligation (accounting)
Send service emails (verification, invites, campaign updates, receipts)Performance of a contract
Keep the platform secure; prevent fraud, spam and metric manipulationLegitimate interests
Improve the product, fix bugs, understand which features are usedLegitimate interests
Marketing emails about AproliConsent (you can withdraw at any time)
Meet tax, accounting and anti-money-laundering obligationsLegal obligation
Establish, exercise or defend legal claimsLegitimate interests

Where we rely on legitimate interests, we've weighed them against your rights and think our use is what you'd reasonably expect. You can object — see Your rights.

4. Social account data

Aproli connects to social platforms through Phyllo Inc., a data aggregation provider. When you connect an account:

  • You authorise the connection yourself, through the platform's own login screen. Aproli never sees your social platform password.
  • We read profile details, follower and audience statistics, and metrics for the content relevant to campaigns. We never post, delete, or message on your behalf.
  • We use this data to verify that you own the account, to show brands accurate reach, and to calculate performance-based payments.
  • You can disconnect any account at any time in your settings. We stop pulling new data immediately; previously collected metrics tied to a completed campaign may be kept as a record of what was paid.

Each social platform's own privacy policy also applies to your relationship with them.

5. Payment data

All payments run through Stripe. Card numbers, bank account details, and identity documents you submit for payout verification go directly to Stripe and are stored by Stripe, not by Aproli. We receive only what we need to run the service: whether your payout account is verified, transaction amounts, dates, and status.

Stripe acts as an independent controller for its own compliance and fraud-prevention purposes. See stripe.com/privacy.

6. Who we share data with

We do not sell your personal data. We share it only with the providers we need to run Aproli:

ProviderWhat it doesData involved
SupabaseDatabase, authentication, file storage, backend functionsAll account, profile and campaign data
StripePayments, subscriptions, creator payouts, identity verificationPayment and identity data
PhylloSocial account connection and metricsSocial profile and content metrics
ResendTransactional email deliveryEmail address, name, message content
VercelWebsite hosting and content deliveryTechnical data such as IP address
Google FontsServes the typefaces used on the siteIP address, browser type

We may also disclose data to our accountants and legal advisers, to authorities where the law requires it, and to a buyer if the business is sold or reorganised (you'd be told beforehand).

7. What brands and creators see about each other

  • Brands see a creator's public profile, connected handles, follower and audience statistics, campaign applications, submitted content, and the performance of that content. Brands do not see a creator's bank details, home address, or identity documents.
  • Creators see a brand's company profile, campaign briefs, budgets and rate models, and messages from that brand.
  • Messages between a brand and a creator are visible to both sides and stored on our systems. Aproli staff access them only where necessary — for support, a reported dispute, or a legal obligation.

8. International transfers

Some of our providers are based outside the European Economic Area, mainly in the United States. Where data leaves the EEA, we rely on the safeguards required by the GDPR — usually the European Commission's Standard Contractual Clauses, and the EU–US Data Privacy Framework where the provider is certified.

You can ask us for a copy of the safeguards in place by emailing privacy@aproli.co.

9. How long we keep data

DataKept for
Account and profile dataWhile your account is active, then deleted or anonymised within 90 days of closure
Campaign records and messages3 years after the campaign closes, for dispute and audit purposes
Invoices, payouts and accounting records10 years — required by Portuguese tax law
Technical and security logsUp to 12 months
Marketing consent recordsUntil you withdraw consent, plus 2 years as proof
Support emails2 years after the conversation ends

When you delete your account from the app, we remove your profile and personal identifiers. Records we're legally required to keep (mainly financial ones) are retained but locked down.

10. Your rights

Under the GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected. Most of it you can edit yourself in settings.
  • Erasure — ask us to delete your data, where we don't have a legal reason to keep it.
  • Restriction — ask us to pause processing while a dispute is sorted out.
  • Portability — receive the data you gave us in a machine-readable format.
  • Object — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, withdraw it at any time (this doesn't undo what was done before).

Email privacy@aproli.co and we'll respond within one month. We may need to verify your identity first. Exercising your rights is free.

11. Security

  • All traffic is encrypted in transit with HTTPS/TLS; data is encrypted at rest by our infrastructure providers.
  • Passwords are hashed — we never see or store them in readable form.
  • Database access is restricted per-user with row-level security, so accounts can only reach their own data.
  • Brand team members only get access to the areas the account owner grants them.
  • Payment credentials never touch our servers.

No system is perfectly secure. If a breach affects your rights, we will notify the Portuguese supervisory authority within 72 hours and tell you directly where the law requires.

12. Automated decision-making

We don't make decisions with legal or similarly significant effects about you purely by machine. Campaign matching and search ranking use automated sorting, but a human at the brand decides who is accepted. Fraud and metric-manipulation checks may flag activity automatically; a person reviews before any account is restricted.

13. Children

Aproli is for people aged 18 and over. We don't knowingly collect data from children. If you believe a minor has an account, tell us and we'll remove it.

15. Changes to this policy

We'll update this page when our practices change and update the date at the top. If a change materially affects you, we'll tell you by email or in-app before it takes effect.

16. Contact & complaints

[LEGAL NAME OF OPERATOR]
[FULL ADDRESS], Portugal
Email: privacy@aproli.co

If you're not happy with how we've handled your data, you can complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD)cnpd.pt — or to the authority in the EU country where you live.