This policy explains what AptoAir (“we”, “us”), a service operated by Credible Arena Pvt. Ltd., collects, why we collect it, how long we keep it and what rights you have. It covers the website at https://aptoair.com and the AptoAir application.
There are two different groups of people in this policy, and it matters which one you are: customers — businesses that hold an account with us — and end users — the people who message those businesses. For end-user data, the business you messaged is the data controller and we act as their processor.
1. Information we collect
Information you give us
- Account details: your name, business name, email address and phone number.
- Billing information. Card and UPI details are handled by our payment gateway; we never see or store them.
- Content you create: message templates, automation flows, AI instructions and documents you upload.
- Credentials you connect: WhatsApp Business Account tokens and e-commerce store API keys, which are encrypted at rest.
Information we process on your behalf
- Messages sent to and from your business, including text, media and delivery status.
- Contact records: names, phone numbers, email addresses, tags and any custom fields you define.
- Order and customer data imported from an e-commerce store you connect.
Information collected automatically
- Log data: IP address, browser and device type, pages visited and timestamps.
- Usage data: which features you use, message volumes and AI usage, for billing and support.
- Cookies strictly necessary for signing in and keeping you signed in.
2. How we use information
- To provide the service: delivering messages, running automations, generating AI replies and syncing store data.
- To bill you accurately, including metering AI usage against your prepaid wallet.
- To support you when you contact us, which may require looking at the specific records involved in a fault.
- To keep the service secure, detect abuse and protect the messaging quality rating of every account.
- To send service communications — trial expiry, low balance, failed payments, security notices.
- To comply with legal obligations.
3. What we do not do
- We do not sell, rent or trade your data or your contacts to anyone.
- We do not pool your contacts with other businesses' contacts.
- We do not message your customers on our own behalf.
- We do not use your conversations or uploaded documents to train AI models.
- We do not use end-user data for advertising.
4. AI processing
When your AI agent generates a reply, the relevant conversation history, your instructions and any documents it needs are sent to a third-party AI model provider to produce that reply. This is inherent to the feature — a model cannot answer a question it has not been shown.
This data is sent only to generate that specific response. We do not use it to train models, and our providers are engaged on terms that do not permit training on it. If you never enable an AI step in an automation, no conversation data is sent to any model provider.
5. Sharing information
We share data only with service providers necessary to run the product:
- Meta Platforms — to send and receive WhatsApp, Instagram and Messenger messages.
- AI model providers — to generate AI replies, as described above.
- Payment gateway — to process subscription payments and wallet top-ups.
- Email provider — to send transactional and service emails.
- Hosting and infrastructure providers — to run the service.
- E-commerce platforms you connect — to read your orders and products, using credentials you supply.
We may also disclose information where legally required, or to protect the rights, safety and property of ourselves, our customers or the public.
6. Retention
- Account and conversation data is kept for as long as your account exists.
- You can delete individual contacts and conversations yourself at any time; deleting a contact deletes their conversation history.
- After account closure we delete or anonymise your data within a reasonable period, except where we must retain records for legal, tax or accounting purposes.
- Backups are retained on a rolling basis and are overwritten in the ordinary course.
7. Security
- All traffic is encrypted in transit using TLS.
- Store credentials and access tokens are encrypted before being written to storage.
- Every record is scoped to a single organisation and filtered by it on every query.
- Role-based permissions limit what each of your team members can see and do.
- Inbound webhooks are signature-verified; unsigned or tampered requests are rejected.
- Internal access to production data is limited to what is needed to operate and support the service.
No system is perfectly secure. We do not currently hold SOC 2 or ISO 27001 certification, and we say so plainly on our security page rather than implying otherwise.
8. Your rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and data, subject to legal retention requirements — see the account & data deletion page for the exact steps.
- Export your data in a portable format — contacts can be exported from the app at any time.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
To exercise any of these, email support@aptoair.com. If you are an end user who messaged a business using AptoAir, contact that business first — they control their data, and they can delete your record themselves.
9. End users' data
If you message a business that uses AptoAir, that business decides what to do with your data. We process it on their instructions. Requests to access or delete it should go to the business you contacted; we will assist them in fulfilling it.
10. International transfers
Some of our service providers operate outside India. Where data is transferred internationally we rely on the safeguards offered by those providers, including standard contractual terms.
11. The mobile app
Our Android and iOS apps are clients for the same account and process the same data described above — the app does not collect anything extra beyond what is needed to run it:
- A push-notification token for your device, used only to deliver notifications you have enabled — new messages, assignments and account alerts. Disable them any time in your device settings.
- Device permissions such as camera, photos or files are requested only at the moment you use the corresponding feature (for example, attaching an image to a reply), and are never accessed in the background. Denying a permission only disables that feature.
- Basic diagnostic information — app version, device model and crash logs — used solely to fix problems.
The apps contain no advertising, no advertising SDKs and no cross-app tracking, and we do not sell app data to anyone. You can delete your account and its data from within the app or by email — the exact steps are on our account & data deletion page.
12. Children
The service is intended for businesses and is not directed at children under 18. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.
13. Changes
We may update this policy. Material changes will be notified by email or in the app before they take effect. The date at the top always reflects the current version.
14. Contact
Credible Arena Pvt. Ltd., Patna, Bihar, India
Email: support@aptoair.com