Skip to document
AppCradleHome
Legal · AppCradle

Privacy Policy

How AppCradle handles account information, connected store data and website analytics.

Last updated

At a glance

AppCradle processes account details and authorized store data to provide company analytics and app reviews. This policy explains the information involved, who can access it, the website analytics we use, and your choices.

Who we are and what this covers

AppCradle brings App Store Connect and Google Play reporting into a shared workspace. This policy describes information handled through our website, accounts, company workspaces, store connections, analytics and application-review features.

Operator
Volodymyr Perepelytsia
Business address
Tarasa Karpy 77C, Kropivnitskiy, Ukraine

We determine how account, security and website information is used to run AppCradle. When a company connects its stores, that company controls the data it provides and the people it authorizes to access it. Our handling of that workspace data also depends on the company’s instructions and any applicable data-processing agreement. This policy does not replace an app publisher’s own privacy notice to its customers.

Information we handle

  • Accounts and sign-in: email address, account identifiers, authentication records, role, and information associated with email/password, Google sign-in or passkeys. Password authentication is handled through Supabase. Passkey verification does not give AppCradle your fingerprint or facial image.
  • Company workspaces: company name, membership and invitation details, access roles, reporting currency, and creation or update dates.
  • Store connections: app identifiers, package names, subscription or product identifiers, reporting-bucket identifiers, and the API keys, private keys or service-account configuration supplied to connect a store.
  • Imported reports: sales and proceeds, currencies and exchange rates, subscription counts and states, acquisition metrics, dates, territories and other available report dimensions. Some reports include transaction references or other identifiers; not every imported field is anonymous or aggregated.
  • App reviews: review identifiers, public reviewer names or nicknames, ratings, review text, dates, language, territory, app version where available, and existing developer responses obtained from the connected stores.
  • Technical and support information: browser and device information, page addresses, referral information, approximate location, performance measurements, request or error logs, import status, and information you send when requesting help.

Account and connection details are needed to provide the related features. You can browse public pages without connecting a store; reporting features require authorized store access. Do not submit unrelated sensitive information in company names, review searches or support messages.

Where information comes from

Information comes from you, the company administrators who invite or manage you, your chosen sign-in provider, and Apple or Google when an authorized store connection is used. Public app reviews and developer responses come from the stores, rather than directly from reviewers. Technical information is generated when the website is used or an import runs. Currency conversion also uses external exchange-rate information.

Why we use information

  • Create accounts, authenticate users, manage invitations and enforce workspace access.
  • Connect authorized stores and run manual, historical and scheduled report imports.
  • Calculate analytics, convert currencies, display maps and provide report downloads.
  • Organize app reviews and existing developer responses for the authorized workspace.
  • Diagnose failed imports, protect accounts, respond to support requests and improve reliability.
  • Understand website usage and performance through the analytics described below.
  • Meet applicable legal obligations and handle disputes or misuse.

Where a legal basis is required, providing a service requested by an individual may rely on performing a contract. Business account administration, security and service reliability may rely on legitimate interests, balanced against individuals’ rights. Legal obligations and, where required and obtained, consent may apply to other processing. Processing company data on its behalf follows the company’s instructions and the applicable agreement.

Analytics summarize store performance. They are not used by this service to make automated decisions about individuals with legal or similarly significant effects.

Access and service providers

Authorized members can view their company’s workspace data. Company owners and administrators manage access; platform administrators have administrative capabilities. Consider who has access before connecting a store, inviting a member or downloading a report.

  • Supabase supports database storage and authentication, including authentication-related email delivery through the configured email service.
  • Vercel supports hosting, application execution, operational logs, Web Analytics and Speed Insights.
  • Apple and Google receive authentication and API requests needed for the store integrations you authorize. Google also supports optional Google sign-in and website analytics.

Information may also be disclosed when required by law or reasonably necessary to protect the service and its users, or in a business transfer subject to applicable protections. Providers’ own notices explain their separate services; they do not replace this policy.

Cookies and website analytics

Essential cookies support sign-in, session refresh and account-confirmation flows. A temporary pending-signup email cookie can last up to 24 hours. Blocking essential cookies can prevent authentication and confirmation links from working correctly.

Vercel Web Analytics measures visits and traffic information. Speed Insights measures page performance. These services can receive page URLs, browser/device details, approximate location and technical measurements. Their privacy designs do not mean that sensitive information in a page URL should be treated as anonymous.

Google Analytics may be enabled on the production website. It can use first-party cookies and collect browser/device information, page interactions and identifiers to measure usage. Its availability depends on the site’s configuration. AppCradle does not currently provide an on-site cookie-preference panel.

You can manage cookies in your browser and use Google’s supported Analytics opt-out browser add-on. These controls do not stop essential server processing. Where prior consent is legally required for optional analytics, the site must obtain it; this policy itself is not consent.

How long information is kept

Account and workspace records support ongoing access and historical reporting. Imported information does not automatically expire when the store stops making a report available. Removing a tracked app stops future refreshes but can leave previously imported reviews and report history in the workspace. Revoking store credentials is not the same as requesting deletion of saved information.

Retention decisions take account of the active service relationship, the company’s instructions, historical reporting needs, security and troubleshooting, legal obligations and disputes. Deletion from active systems and expiry from provider backups or logs can follow different schedules. Contact us for information about retention relevant to your account or workspace.

Security and international processing

AppCradle uses authenticated access, company-level authorization and encrypted storage of store private keys and service-account credentials. You should protect your sign-in methods, restrict store permissions, review workspace membership and rotate credentials if they may have been exposed. No service can guarantee absolute security.

Our infrastructure and integration providers can process information in countries other than your own, including outside Ukraine. International processing is subject to the protections required by applicable law. Contact the operator for information about provider locations and transfer arrangements relevant to your workspace, or before providing information subject to specific residency requirements.

Your choices and rights

Depending on the law that applies, you may have rights to access, correct, delete or receive a copy of personal information, restrict processing, or withdraw consent for processing based on consent. You may also have a right to object to processing based on legitimate interests, including a separate right to object to direct marketing.

Send requests to the contact listed above, identifying the account or app review involved. Do not include passwords, store private keys or service-account files. We may need to verify your identity or authority. Requests about a company-controlled workspace may need to be handled with that company. The app publisher or store may also need to address the original review or other source record.

Account removal and workspace-data deletion are not currently offered as a self-service account button; contact the operator to request them. Removing your membership does not necessarily remove a company’s business records. Where applicable, you can complain to the data-protection authority in the place you live, work or believe a violation occurred.

Children and third-party services

AppCradle is intended for people managing apps and business workspaces, not for children. If you believe a child has provided personal information through an AppCradle account, contact the operator. Linked websites, app publishers and stores have their own terms and privacy practices.

Changes and contact

Changes to this policy will be reflected in the date at the top. Material changes may also require notice or consent under applicable law. Contact the operator listed above about privacy, access or deletion requests.

Use of the service is also addressed in our Terms and Conditions.

Back to top