Legal

Privacy policy

Plain-language, but complete. What we collect, why, where it goes and how to exercise your rights.

In short: we keep the data needed to run your account and your funnels, we never sell it, your customers’ data is yours and processed only on your instructions, and you can export or delete what you have stored at any time.

1.Who we are and what this covers

AA Funnel (“AA Funnel”, “we”, “us”) provides a hosted platform for building sales funnels, checkout pages, online courses, email automations and related tools. This policy explains how we handle personal data when you visit aafunnel.com, create an account, or use the platform, and when you interact with a page or member area that one of our customers has built on it.

It applies together with our Terms of Service. If you use AA Funnel on behalf of a business, you confirm that you are authorised to accept this policy for it.

2.Two roles: controller and processor

For your own account data (name, email, billing details, usage of the dashboard) we are the data controller: we decide why and how it is processed.

For data that our customers collect through their funnels, checkouts, courses and contact lists (their leads, buyers and students), the customer is the controller and we are the processor. We process that data only on the customer’s instructions and under the data-processing terms in our Terms of Service. If you have arrived at this page from a page built with AA Funnel, the business that runs that page is responsible for how your data is used; please contact them first.

3.Data we collect

  • Account data: name, email address, password hash, workspace name, role and team invitations.
  • Billing data: plan, invoices, GSTIN if you provide one, and the last four digits and brand of a card. Full card numbers are handled by our payment processors and never reach our servers.
  • Content you create: funnels, pages, products, courses, email templates, automations, uploaded media and files.
  • Customer data you collect: contacts, orders, subscriptions, course progress, form submissions, comments and messages captured through your pages and member areas.
  • Integration credentials: API keys and tokens for gateways, email providers and connectors you connect. These are encrypted at rest (AES-GCM) and used only to call the service you connected.
  • Usage and device data: IP address, browser and device type, pages visited, actions taken in the app, timestamps, and error reports. On published funnel pages we record page views, opt-ins, checkout starts and purchases attributed to a random visitor id.
  • Support data: messages you send us by email or the contact form, and any attachments.

4.How we use it

  • To provide the service: render your pages, process orders through your connected gateway, deliver digital products, send the emails you configure, and grant course access.
  • To keep your account secure: session cookies, rate limits, audit logs of changes made by team members, API keys and AI assistants, and fraud and abuse detection.
  • To bill you and to issue tax-compliant invoices, including GST invoices for customers in India.
  • To support you and to answer your questions.
  • To improve the product: aggregate, de-identified usage statistics and error monitoring.
  • To send service messages (receipts, security notices, changes to terms). Marketing emails from us are optional and carry an unsubscribe link.
  • To comply with law, enforce our terms and protect our rights and those of our customers.

6.Cookies and tracking

On aafunnel.com and in the app we use strictly necessary cookies for sign-in sessions, security and remembering your preferences. We do not run third-party advertising trackers on our own site.

Pages built by our customers may set cookies for their own analytics and advertising pixels (for example Meta, Google Analytics, TikTok). Those pages can show a consent banner that lets you accept or decline non-essential categories; your choice is logged for the customer. A random visitor id cookie and an affiliate referral cookie (60 days) may be set to attribute visits and sales.

7.Who we share data with

  • Payment processors you connect or that we use for our own billing (Razorpay, Stripe, PayPal, Cashfree, Instamojo, Paddle, Paystack, Xendit).
  • Infrastructure providers that host the application, database, file storage and email delivery. Data is stored in Singapore (app and database) unless you self-host.
  • Email and marketing connectors you explicitly connect (for example Mailchimp, ActiveCampaign, Kit, Brevo, Klaviyo, HubSpot, Zoom, Slack, Google Sheets, Meta Conversions API). Data goes only where you send it.
  • AI providers, when you use AI features: the text you ask us to generate or rewrite, and the workspace data an assistant needs to answer, are sent to the model provider you or we have configured. We do not use your content to train models.
  • Professional advisers, regulators or courts when the law requires it.
  • A successor business if we are acquired or merge; this policy continues to apply to the transferred data.

We never sell personal data.

8.International transfers

Our servers are in Singapore and some providers operate in the United States and the EU. Where data leaves India or the EEA/UK we rely on the provider’s contractual safeguards (such as standard contractual clauses) and on the lawful-transfer provisions of the DPDP Act.

9.How long we keep data

  • Account and content data: for as long as your account is open, then deleted within 90 days of closure unless the law requires longer.
  • Orders, invoices and tax records: 8 years, as required by Indian tax and company law.
  • Email logs: 12 months. Audit logs: 24 months.
  • Backups: rolling backups are kept for up to 35 days and then overwritten.
  • Customer data you collect: deleted when you delete it, or when the account closes, subject to the same tax-record exceptions for orders.

10.Security

Passwords are hashed with bcrypt. Sessions use signed, HTTP-only cookies. Stored credentials for gateways and connectors are encrypted with AES-GCM. All traffic is served over TLS. Public endpoints are rate-limited, and gateway webhooks are signature-verified and re-checked with the provider before an order is settled. Access to production systems is limited to staff who need it and is logged.

No system is perfectly secure. If we learn of a breach affecting your data we will notify you and, where required, the Data Protection Board of India or another regulator without undue delay.

11.Your rights

  • Access a copy of your personal data and learn how it is used.
  • Correct inaccurate or incomplete data.
  • Erase your data (we may keep records the law obliges us to keep, such as invoices).
  • Withdraw consent at any time where processing is based on consent.
  • Nominate another person to exercise these rights for you, as the DPDP Act allows.
  • Object to or restrict certain processing and, under the GDPR, request portability and lodge a complaint with a supervisory authority.

Account holders can export contacts and funnels from the dashboard and close their account from Settings. For anything else email us at the address below; we respond within 30 days. If your data was collected by one of our customers, direct your request to them; we will help them fulfil it.

12.Children

AA Funnel accounts are for adults (18 and over). We do not knowingly collect personal data from children. Customers who sell to minors are responsible for obtaining verifiable parental consent as the DPDP Act requires.

13.Changes to this policy

We may update this policy as the product and the law change. Material changes are announced by email to account owners and on the changelog at least 14 days before they take effect. The date at the top of this page shows the latest revision.

14.Contact and grievance officer

Questions, requests and complaints about personal data go to support@aafunnel.com with “Privacy” in the subject line. Our grievance officer under the Information Technology Act and the DPDP Act can be reached at the same address and will acknowledge your complaint within 48 hours and resolve it within 30 days.