Privacy Policy

Last updated: 5/31/2026

This Privacy Policy explains how APP TEAM ("APP TEAM", "we", "us"), a sole-proprietorship based in Surat, Gujarat, India, trading as "AppTeam", handles personal data when you visit appteam.in or purchase one of our iOS apps. APP TEAM is the data controller for the personal data described below.

1. Categories of personal data we collect

  • Identity & contact data: name, email address, WhatsApp number.
  • Order data: order number, items purchased, purchase type, order status, delivery timestamps.
  • Communications: messages you send us by email or WhatsApp.
  • Technical data: minimal cookies required for the cart, checkout, and admin login (no advertising or tracking cookies).
  • Payment confirmation: the fact that a payment succeeded. Card numbers, billing address and tax details are collected and held by our payment processor (see §3) — we do not see or store them.

2. Purposes and legal basis

  • Provide the service & deliver your order (account, code-folder delivery, App Store transfer coordination) — legal basis: performance of a contract.
  • Customer support (responding to your emails and WhatsApp messages) — legal basis: performance of a contract / legitimate interests.
  • Fraud prevention and security (download-link abuse, payment fraud) — legal basis: legitimate interests.
  • Tax, accounting and legal compliance (keeping minimum order records) — legal basis: legal obligation.

3. Who we share data with

  • Paddle.com Market Limited ("Paddle") — our Merchant of Record and payment processor. Paddle collects and processes your name, email, billing address, payment method and tax data to handle the sale, billing, tax compliance, invoicing and refunds. Paddle acts as an independent controller for that data. See Paddle's privacy notice at paddle.com/legal/privacy.
  • Hosting and infrastructure providers (database, file storage, email delivery) acting as our processors under written agreements.
  • Professional advisers (accounting, legal) and government authorities where required by law.

We do not sell or rent your data and we do not share it with any third party for advertising or marketing.

4. International transfers

APP TEAM is based in India. Some of our processors (and Paddle) operate from the UK, EEA and US. Where personal data of UK/EEA users is transferred outside the UK/EEA, we rely on appropriate safeguards such as the UK IDTA or EU Standard Contractual Clauses, or on the recipient's adequacy status.

5. Data retention

  • Identity & contact data and communications: kept for up to 24 months after our last interaction, then deleted or anonymised.
  • Order records (order number, items, amount, date): kept for 8 years after the order date to meet Indian tax and accounting record-keeping obligations.
  • Download tokens: deleted after the link expires.
  • Payment records held by Paddle: retained per Paddle's own retention schedule.

6. Your rights

Subject to applicable law (including the GDPR / UK GDPR and India's DPDP Act), you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict or object to certain processing;
  • Data portability — receive your data in a portable format;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with your local supervisory authority (e.g. the ICO in the UK or your EEA Data Protection Authority).

To exercise any of these rights, email dhaval@appteam.in. We respond within 30 days. We may need to retain a minimal record of an order for tax compliance even after an erasure request.

7. Security

We apply appropriate technical and organisational measures to protect your personal data, including HTTPS/TLS in transit, encryption of credentials at rest, role-based access control to our admin and database, row-level security on user-specific data, and limited, time-bound and download-capped delivery links. We review these measures regularly.

8. Cookies & advertising measurement

We use only essential cookies required for the cart, checkout, and admin login. We also use the Meta Pixel and Meta's Conversions API for advertising measurement and retargeting (showing relevant ads to people who have visited the site). No advertising cookies are set without the pixel being enabled, and we never share form contents, payment data, or other sensitive information with Meta.

9. Children

APP TEAM is a B2B product aimed at iOS developers. It is not directed at children under 16.

10. Contact

APP TEAM, Surat, Gujarat, India. Questions about this policy: dhaval@appteam.in.