Privacy Policy
Last updated: 10 August 2026
1. Who we are
Aptire is an email platform operated from 281 E Hamilton Ave #10, Campbell, CA 95008, USA. This policy explains what personal data we handle, why, and what you can do about it. Questions go to info@aptire.com.
2. Two different roles — please read this first
Aptire handles personal data in two distinct capacities, and your rights differ depending on which one applies to you.
- As a controller, for people who hold an Aptire account. We decide why and how your account data is processed, and this policy governs it directly.
- As a processor, for the contact data our customers upload and send to. If you received an email sent through Aptire, we did not choose to contact you — our customer did, using their own list and their own sending domain. We process that data only on their instructions. Requests about it are handled by them as the controller; if you contact us we will route your request to them and tell you who they are where we are permitted to.
3. What we collect
Account data. Your name, email address, password (stored only as a hash), and the workspaces you belong to.
Workspace content. Contacts and lists you import, segments, templates, campaigns, sending-domain records, and API keys you create. This is your data; we hold it for you.
Sending and engagement records. For every message sent through the platform we record the recipient address, the time, and the delivery outcome — delivered, bounced, complained — plus opens and clicks where tracking applies. This exists so campaigns can be measured, and so addresses that bounce or opt out are suppressed and never mailed again.
Billing data. Subscription and module-activation records. Card details are entered directly with our payment processor and never reach or pass through Aptire's servers.
Technical logs. IP address, browser user agent, and request metadata, kept for security, abuse investigation and debugging.
4. What we do not do
- We do not sell personal data, and never have.
- We do not share or rent contact lists between customers, or use one customer's contacts to benefit another.
- We do not use the content of your campaigns or contacts to train machine-learning models.
- We do not send marketing email to contacts you upload. Only you send to your list.
5. Isolation between customers
Every workspace is provisioned with its own separate database rather than a shared table partitioned by a customer identifier. Contacts, campaigns, templates and messages belonging to one workspace are not stored alongside another's. This is an architectural property of the platform, not a policy setting that can be misconfigured.
6. Tracking in email we deliver
Where a customer has tracking enabled, messages may contain a 1×1 image used to record an open, and links rewritten to record a click before forwarding to the destination. These run on the customer's own verified tracking hostname, not on a shared Aptire domain. Unsubscribe links are never rewritten or tracked — an opt-out must always work, and must never be recorded as engagement.
7. Who we share data with
We use a small number of sub-processors, each for a specific and necessary function:
- Amazon Web Services — email delivery and infrastructure hosting.
- Stripe — payment processing. Stripe receives your billing details directly; we receive only a confirmation and a subscription record.
We also disclose data where we are legally required to, or where it is strictly necessary to investigate abuse of the platform. We will tell you when that happens unless we are legally prohibited from doing so.
8. Where data is processed
Data is processed in the United States. If you are in the European Economic Area, the United Kingdom, or another region with data-transfer restrictions, you are instructing us to transfer it there when you use the service.
9. How long we keep it
- Workspace content — for as long as your account is open. Delete a workspace and its database is dropped.
- Suppression records — addresses that hard-bounced, complained or unsubscribed are retained after deletion of the surrounding data. Forgetting an opt-out would mean mailing that person again, so this record is kept deliberately.
- Billing records — as long as tax and accounting law requires.
- Technical logs — a rolling window, then discarded.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, delete or restrict the processing of your personal data, to object to it, and to withdraw consent. Account holders can exercise most of these directly in the app; for anything else, write to info@aptire.com and we will respond within the period the applicable law requires. We will not charge you for exercising a right, and we will not treat you differently for having done so.
If you are a contact on a customer's list rather than an account holder, see section 2 — the customer is the controller of that data and your request goes to them.
11. Security
Access to production systems is restricted and authenticated. Passwords are stored hashed, never in a recoverable form. API keys are scoped to a single workspace and can be revoked at any time without affecting anything else. No system is immune to compromise; if a breach affects your data we will notify you and any required regulator within the applicable deadline.
12. Children
Aptire is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
13. Changes to this policy
We may update this policy. When a change materially affects how we handle your data we will notify account holders by email before it takes effect, rather than relying on the date at the top of this page changing.
14. Contact
info@aptire.com
Aptire, 281 E Hamilton Ave #10, Campbell, CA 95008, USA