Legal

Privacy policy

This policy explains what personal data RemarketOS handles, why, for how long, and the rights you have over it — whether you're an operator with an account, a client of an operator, or someone who received an email sent through the platform.

Last updated: July 31, 2026

1. Who we are and our role

RemarketOS is operated by APETEC LTD, a company registered in England and Wales (company number 17065917) with its registered office at 128 City Road, London, EC1V 2NX (“RemarketOS”, “we”, “us”). For data protection law in the UK and EU, we are based in the United Kingdom.

You can reach us about anything in this policy through the contact form or by writing to hello@apetec.co.uk.

Our role differs depending on whose data it is:

  • Operators — people who create a RemarketOS account. For your account, billing, and usage data, we are the data controller.
  • Clients of operators — the local businesses an operator works with. We are the controller of the connection records, and a processor acting on the operator’s and client’s instructions when sending email and working with calendar events.
  • Contacts on uploaded customer lists — the past customers a client asks their operator to win back, and the recipients of Business Finder pitches. The operator (and their client) is the controller; we are a processor, handling those lists only as instructed by the operator through the product.

2. Data we collect

Account data (operators)

  • Email address, name, and a password (stored as a hash by our auth provider, Supabase — we never see plaintext passwords).
  • Plan and billing status. Payment is handled by Stripe; we store your Stripe customer reference and subscription state, never your card number.

Google connections

  • When an operator or a client connects a Google account, we store the Google email address and OAuth tokens, encrypted at rest. We request exactly two permissions — send email, and view and edit calendar events. See Google account data below.

Client business details

  • Business name, contact name and email, industry, website, timezone, and postal address (required in campaign emails by US anti-spam law).

Uploaded customer lists

  • Names, email addresses, and phone numbers of a client’s past customers, uploaded by the operator as a CSV or pasted list.

Booking data

  • When someone makes a booking: their name, email, optional phone number, timezone, the chosen time slot, and any note they add about what they are booking for.

Business Finder results

  • Publicly listed business information (name, address, category, rating and review count, website, phone, published contact email) retrieved via our data provider, Apify.

Usage and technical data

  • First-party product analytics (for example: signed up, ran the Finder, launched a campaign), delivery events for emails we send (sent, bounced, unsubscribed), IP-based rate-limiting records, and error reports via Sentry. We do not use third-party advertising trackers.

3. How we use it — purposes and legal bases

  • Providing the service (accounts, sending campaigns and pitches as instructed, bookings, portals, support) — performance of a contract.
  • Billing — performance of a contract and legal obligation (tax and accounting records).
  • Compliance with email law — maintaining suppression lists of people who unsubscribed, bounced, or booked, so they are not emailed again — legal obligation and legitimate interest.
  • Security and abuse prevention (rate limiting, bot checks via Cloudflare Turnstile, error monitoring) — legitimate interest in keeping the service safe.
  • Product improvement — first-party, minimal analytics about feature usage — legitimate interest.
  • Service emails (booking confirmations and reminders, booking notifications, account notices) — performance of a contract.

We do not sell personal data, and we do not “share” it for cross-context behavioral advertising as defined by the CCPA. Uploaded customer lists are used only for the uploading operator’s own campaigns.

4. Google account data

Connecting a Google account grants RemarketOS exactly two scopes: gmail.send (send email on the account’s behalf) and calendar.events (view and edit calendar events). We do not request scopes that read, search, or modify inbox contents, so the app cannot read anyone’s inbox.

The app uses calendar.events for two things: it creates an event for each confirmed booking (and deletes that event if the booking is cancelled), and before showing a customer the available times it reads existing events on the primary calendar so an already-busy slot is never offered. That availability check reads only what decides whether a slot is free: when an event runs, whether it was cancelled or marked as free, and whether the account holder themselves declined it — never its title, description, location, or who else was invited — and it does not edit or delete an event the app did not create.

  • OAuth refresh and access tokens are stored encrypted and used only to send the emails, run that availability check, and create the calendar events you or your client initiate through the product.
  • Disconnecting or revoking a connection erases the stored refresh token; deleting the related client or account removes it too. Any of these stops sending for that connection.
  • Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Sharing and subprocessors

We use a small set of service providers to run RemarketOS. Each processes data only on our instructions under a data processing agreement. We may also disclose data where the law requires it, or in connection with a merger or sale of the business.

Subprocessors and what they do
ProviderPurposeData involved
VercelApplication hostingAll traffic to the app
SupabaseDatabase and authenticationAll stored data; operator credentials
StripeSubscription billingOperator name, email, payment details (held by Stripe)
GoogleEmail sending and calendar (via connected accounts)Outgoing emails, calendar events, OAuth tokens
ApifyBusiness Finder data retrievalSearch terms; publicly listed business data
PostmarkTransactional email (confirmations, reminders, notices)Recipient email and message content
AnthropicAI editing and result descriptorsDraft email text and factual business fields sent for processing; not used to train models
CloudflareBot protection (Turnstile)IP address and browser signals on public forms
SentryError monitoringTechnical error context

6. International transfers

We are UK-based; most of our subprocessors store data in the United States. Where personal data moves from the UK or EU to the US, we rely on the UK International Data Transfer Addendum and EU Standard Contractual Clauses with each provider, and on the EU–US Data Privacy Framework where the provider is certified.

7. How long we keep data

  • Customer lists: deleted when the client they belong to is deleted, and when the operator’s account is deleted. Operators can delete a client at any time.
  • Suppression records: an opt-out from an operator’s own cold outreach is kept even after that operator’s account is deleted, so the address is not pitched again. A client’s campaign suppressions (unsubscribed, bounced, or booked) belong to that client’s list and are deleted with it when the client or the account is deleted — every campaign for that client stops at the same moment. Each record holds only the email address and the reason for suppression.
  • Google OAuth tokens: the stored refresh token is erased when a connection is disconnected or revoked, and when the related client or account is deleted.
  • Account data: deleted when you delete your account — your profile, clients, uploaded lists, campaigns, bookings, Google connections, and the log of emails we sent for you. We hold no card data; payment records live with Stripe under their own retention.
  • Email delivery logs: these hold third-party recipient addresses, so they are deleted after 90 days, and immediately when the operator’s account is deleted.
  • Product analytics: usage events are kept to improve the product; when an account is deleted, its events are disassociated from the operator rather than kept against a named person.

8. Your rights (GDPR & CCPA)

Under UK/EU GDPR, you have the right to access, correct, delete, and receive a copy of your personal data, to restrict or object to our processing, and to withdraw consent where processing is based on consent. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.

Under the CCPA/CPRA (California), you have the right to know what personal information we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information, so there is nothing to opt out of.

To exercise any right, use the contact form or email hello@apetec.co.uk. We verify requests and respond within the period the law allows. If your data is on a customer list controlled by an operator or their client, we will forward your request to them and suppress your address on our side in the meantime.

9. If you received an email sent through RemarketOS

Emails sent through RemarketOS come from a real business — either a local business you’ve bought from before (Email Remarketing campaigns go only to a business’s own past customers) or an individual introducing their service to your business. In line with the US CAN-SPAM Act, every campaign email includes a working one-click unsubscribe link, the sending business’s physical postal address, and truthful sender information — mail is sent from the business’s own address, not a lookalike.

Once you unsubscribe, book, or your address bounces, you are added to a suppression list that is checked before every send. If you want your data removed entirely, use the contact form and include the address the email was sent to — we will suppress it and pass deletion requests to the responsible business where they, not we, control the data.

10. Cookies and local storage

We use only what the service needs to function:

  • Authentication cookies — keeping operators signed in (set by Supabase Auth).
  • Security — Cloudflare Turnstile may set a cookie while verifying you are human on public forms.
  • Local storage — your light/dark theme choice is stored in your browser’s local storage, not in a cookie, and is never sent to us.

There are no advertising or cross-site tracking cookies, which is why you don’t see a cookie banner.

11. Security

We use technical and organisational measures appropriate to the risk, including encryption of traffic in transit, encryption at rest by our database provider, application-level encryption of Google OAuth tokens, row-level access controls between accounts, and hashed passwords and links.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.

12. Children

RemarketOS is a business tool for adults. You must be at least 18 to create an account, and we do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes and contact

We may update this policy from time to time. The date at the top shows when it last changed, and we will let operators know where a change materially affects them.

Questions, requests, or complaints: contact form, or write to APETEC LTD, 128 City Road, London, EC1V 2NX.