AAppwarp

Legal

Privacy Policy

How Appwarp collects, uses, shares and protects your information. Last updated 5 June 2026.

1. Introduction

This Privacy Policy explains how Appwarp ("Appwarp", "we", "us" or "our") collects, uses, discloses and safeguards information when you visit appwarp.io, create an account, or install and use any of our applications, including StockTwin, FraudSentry, ChatIA and RefBoost (collectively, the "Services").

By using the Services you agree to the practices described in this policy. If you do not agree, please do not use the Services.

2. Who we are

Appwarp is the data controller for personal data we collect about merchants and visitors to our website. For data we process on behalf of a merchant about that merchant's own customers (for example, order and checkout data flowing through our apps), the merchant is the controller and Appwarp acts as a data processor under the merchant's instructions.

3. Information we collect

Information you provide

  • Account data — name, business name, email address and password when you register.
  • Billing data — plan selection and billing details. Card payments are handled by our payment and platform processors; we do not store full card numbers.
  • Support data — messages, attachments and other content you send when you contact us.

Information we collect automatically

  • Usage data — pages viewed, features used, clicks, and timestamps.
  • Device data — IP address, browser type, operating system and device identifiers.
  • Cookies — see the Cookies section below.

Store data processed through our apps

When you connect a store, our apps process the data needed to deliver each feature, which may include order and checkout metadata, product and inventory data, SKUs and barcodes, customer and order identifiers, risk and device signals (for fraud detection), and your app configuration. We only access the data scopes you authorise when installing an app.

4. How we use information

  • To provide, operate, maintain and improve the Services.
  • To detect fraud, synchronise inventory, power conversations and referrals, and deliver the features of each app you install.
  • To process payments and manage subscriptions.
  • To respond to support requests and communicate with you about your account.
  • To send service and, where permitted, marketing messages (you can opt out at any time).
  • To monitor security, prevent abuse and comply with legal obligations.

5. Legal bases for processing

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Services), legitimate interests (to secure and improve the Services), consent (for certain cookies and marketing), and legal obligation (to comply with applicable law).

6. How we share information

We do not sell your personal data. We share information only with:

  • Service providers (subprocessors) — hosting, database, email delivery and analytics providers who process data on our behalf under appropriate contracts.
  • E-commerce platforms — the platform your store runs on, to read and write the data each app requires.
  • Legal and safety — where required by law, regulation or legal process, or to protect the rights, property or safety of Appwarp, our users or others.
  • Business transfers — in connection with a merger, acquisition or sale of assets, subject to this policy.

7. Data retention

We retain personal data for as long as your account is active and as needed to provide the Services. After account closure we delete or anonymise data within a reasonable period, unless we must retain it to meet legal, accounting or dispute-resolution requirements. Fraud and risk signals are retained for up to 90 days unless a longer period is required to resolve a dispute.

8. Security

We use technical and organisational measures including encryption in transit, access controls and least-privilege practices. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. International transfers

We may process and store data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. Your rights

Depending on your location you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know and delete and the right not to be discriminated against for exercising those rights. To exercise any right, contact us at [email protected]. You may also lodge a complaint with your local data protection authority.

11. Cookies

We use cookies and similar technologies to keep you signed in, remember preferences, measure usage and improve the Services. You can control cookies through your browser settings; disabling some cookies may affect functionality.

12. Children

The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the "Last updated" date. Material changes may be notified by email or in-app.

14. Contact us

Questions about this policy or your data? Email us at [email protected].