1. What this policy covers
This policy explains how AppExpertly (“we”, “us”) handles personal data across the marketplace at appexpertly.com, the applications we distribute through it, and our support desk. It sits alongside our Terms of Service, which govern use of the applications themselves.
It covers two quite different situations, and the difference matters for your rights, so §2 sets it out before anything else.
2. Our role: controller or processor
When you visit this website, email us or open a support ticket, we decide why and how your data is handled. For that data we are the controller, and this policy is the notice describing it.
When you install an application into your GoHighLevel account, the contacts and content it reads there are yours. You decide why they are processed and we act on your instructions, so for that data you are the controller and we are your processor. Our obligations are set by our agreement with you rather than by this policy, and we do not decide what happens to that data on our own.
3. What we collect
As controller, the categories are small and each one has a reason:
- Account details — the name, business name and email address you give us when you install an application or create an account.
- Support correspondence — what you write in a ticket or an email, including any screenshots or logs you attach, and our replies.
- Billing records — plan, invoices and payment status. Card details go directly to the payment provider; we never see or store a full card number.
- Technical logs — IP address, browser type, timestamps and error traces produced when an application runs, kept so we can debug failures and detect abuse.
- Your theme preference — whether you chose light or dark, stored in your own browser and never sent to us. See §6.
We do not ask for special category data — health, biometrics, political opinions and the like — and applications are not designed to process it. Please do not put it into a support ticket.
4. Data inside your GoHighLevel account
Applications reach your GoHighLevel data only through the permissions you approve at install. Those permissions are shown to you before you grant them, and they are the exact limit of what we can see.
We use that access to operate the application you installed and nothing else. Specifically, we do not use your data or your contacts' data to train machine learning models, we do not sell it, we do not rent it, and we do not share it with anyone for their own marketing.
You can withdraw that access whenever you like by uninstalling the application or revoking it from your dashboard. Revocation takes effect immediately and processing stops.
5. Analytics and tracking
This website runs no analytics. There is no Google Analytics, no tag manager, no advertising pixel, no session recorder and no cross-site tracking of any kind. We do not build profiles of visitors, and we do not sell or share personal data for behavioural advertising.
That is a description of how the site is actually built, not an aspiration. If it ever changes, this section changes with it and the date at the top of this page moves.
6. Cookies and browser storage
We set no cookies of our own. The only thing we store in your browser is a single entry called ax-theme, held in local storage, which records whether you chose the light or dark appearance. It contains that one word, identifies nobody, and never leaves your device. Clearing your browser storage removes it.
Three third-party embeds do load on our pages, and each necessarily receives your IP address and basic browser information in order to respond at all. They may set storage of their own under their own policies:
- The chat widget, provided by GoHighLevel, on every page — so you can start a conversation with us.
- The ticket form, also provided by GoHighLevel, on the support page — this is what actually files your ticket.
- Two font services, Google Fonts and Fontshare, which deliver the typefaces the site is set in.
If you would rather not load the chat widget or the fonts, a content blocker will stop them and the site still works.
7. Why we process it
- To provide what you asked for — running the applications you installed, and performing our contract with you.
- To support you — answering tickets and fixing what broke.
- To keep the service working and safe — debugging, monitoring, preventing abuse and protecting other customers. This rests on our legitimate interest in a service that functions.
- To bill you — and to keep the financial records we are required to keep.
- To tell you things you need to know — service notices, security issues and changes to these documents. Marketing email, if we ever send it, goes only to people who asked for it, and every message carries an unsubscribe link.
Where the law that applies to you frames these as legal bases, they correspond to performance of a contract, legitimate interests, legal obligation and — for optional messages — consent.
8. Who we share it with
We do not sell personal data. We share it only with service providers who help us run the service, and only to the extent they need it to do their job:
- GoHighLevel — the platform the applications extend, and the provider of our chat widget and ticket form.
- Cloud hosting and storage providers — where the applications run and where their data sits.
- Payment providers — who process payments and hold the card details we deliberately never see.
- Communication tools — the systems that carry our email and support correspondence.
Each is bound to use the data only on our instructions and to keep it confidential. We will also disclose data where the law genuinely requires it, and we will tell you when we are permitted to. If the business is ever sold or merged, data may transfer with it, and this policy continues to apply until you are told otherwise.
9. How long we keep it
Uninstalling an application revokes its access immediately and stops all processing. Data already stored is kept for 30 days, so that reinstalling within that window restores your configuration, and is then deleted automatically. Ask us to purge it sooner and we will.
Support correspondence is kept while it is useful for context on later tickets. Billing records are kept for as long as financial and tax law requires. Technical logs are short-lived and rotate out on their own. Backups persist for a short period after deletion before they age out on their normal cycle.
10. Where it is processed
We and our service providers operate internationally, so your data may be processed outside the country you are in. Where a transfer is subject to rules requiring safeguards, we rely on the mechanisms recognised for that purpose — standard contractual clauses or an adequacy decision covering the destination.
If you need the specifics — the jurisdictions involved, the safeguards in place, or our list of sub-processors — for a data processing agreement or a vendor review, write to dev@appexpertly.com and we will provide them.
11. How we protect it
Access is encrypted in transit, granted on a least-privilege basis, and limited to the people who need it to build and support the applications. Application permissions are scoped to what each one actually requires rather than to everything your account can reach.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data and creates a real risk to you, we will notify you and any regulator we are required to notify, within the time the applicable law allows.
12. Your rights
Depending on where you live, you may have the right to ask us to do some or all of the following with the data we hold as controller:
- Access — get a copy of it.
- Correct — fix it if it is wrong.
- Delete — remove it, where we have no obligation to keep it.
- Port — receive it in a portable format, or have it sent onward.
- Object or restrict — challenge processing based on legitimate interests, or ask us to pause it.
- Withdraw consent — at any time, where consent is what we relied on.
Email dev@appexpertly.com and we will action it. We do not charge for this, we will not treat you differently for asking, and we aim to respond within 30 days. We may need to confirm who you are first, which protects you rather than us.
You are also entitled to complain to your local data protection authority. We would appreciate the chance to fix the problem first.
13. If you are an end client
If your details reached an application because an agency using AppExpertly added you to their GoHighLevel account, that agency is the controller of your data — not us. We process it on their instructions.
Requests to access or delete it should go to them, because they hold the relationship and the record. If you contact us instead, we will pass your request on and help them answer it.
14. Children's data
Our applications are business tools, not intended for children, and we do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, tell us and we will delete it.
15. Changes to this policy
We update this policy when what we do changes. The date at the top shows when it last did. Where a change materially affects your rights, we will give reasonable notice by email or in-app before it takes effect, rather than quietly editing the page.
16. How to reach us
Questions about this policy, or a request under §12, go to the same place as everything else:
AppExpertly
dev@appexpertly.com
For a data processing agreement, our sub-processor list, or our registered details for a vendor onboarding pack, write to the same address and we will provide them. Anything broken rather than private is better raised as a support ticket.