1. Who we are (Data Controller)
Cellusion Tech FZE, located at Dubai Silicon Oasis, Dubai, United Arab Emirates, is the controller responsible for personal data processed about account holders and website visitors. For analytics data that our customers collect about their own end users through the Service, our customers are the controllers and we act as their processor under the agreement described in Section 9.
2. Information we collect
We collect the following categories of data:
- Account data you provide, such as your name, email address, company name, and authentication details.
- Billing data processed by our payment provider, such as plan, billing contact, and the last four digits and brand of your card. We do not store full card numbers.
- Usage and device data, such as log entries, browser type, pages viewed, and approximate location derived from a truncated IP address, used to secure and improve the Service.
- Measurement data generated by banners and links you configure — including clicks, installs, device type, and aggregated, anonymized attribution events.
- Communications you send us, such as support requests and survey responses.
We do not fingerprint end users, and we do not build cross-site advertising profiles. IP addresses are truncated before storage, and identifiers are aggregated wherever possible.
3. How we use information
- to provide, operate, and maintain the Service, including deep linking, smart banners, attribution reports, and web push you configure;
- to process payments, manage subscriptions, and send service and transactional messages;
- to secure the platform, prevent abuse and fraud, and debug and improve features;
- to respond to your requests and provide customer support; and
- to comply with legal obligations and enforce our agreements.
4. Legal bases for processing (GDPR)
Where the GDPR or similar laws apply, we rely on the following legal bases:
- Contract — to provide the Service you have requested and administer your account.
- Legitimate interests — to secure, analyze, and improve the Service, balanced against your rights.
- Consent — for optional cookies and certain communications, which you can withdraw at any time.
- Legal obligation — to meet accounting, tax, and other regulatory requirements.
5. Cookies and consent
Our marketing site uses a single consent banner. Non-essential analytics scripts load only after you accept. Essential cookies needed for security and core functionality are always active. You can change or withdraw your choice at any time by clearing the consent stored in your browser, after which you will be asked again.
6. How we share information
We share personal data only in limited circumstances:
- with service providers (sub-processors) that host infrastructure, process payments, or provide support, under contracts that require appropriate safeguards;
- to comply with law, a valid legal request, or to protect rights, safety, and the integrity of the Service;
- in connection with a merger, acquisition, or asset sale, subject to this Policy; and
- with your consent or at your direction.
We do not sell personal data and do not share it for cross-context behavioral advertising.
7. Data retention
We keep personal data only as long as necessary for the purposes described in this Policy. Account data is retained while your account is active and deleted within 30 days of account closure, except where a longer period is required by law (for example, tax records). Aggregated analytics are retained according to your plan, and de-identified data may be kept for statistical purposes.
8. International data transfers
We may process data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms to ensure your data remains protected.
9. Data processing for customers
When you use the Service to collect data about your own end users, you are the controller and we are your processor. We process such data only on your documented instructions, maintain appropriate security measures, assist with data subject requests, and notify you without undue delay of any personal data breach affecting your data. A data processing addendum is available on request at the contact below.
10. Your rights
Depending on your location, you may have the right to access, correct, update, port, restrict, or delete your personal data, to object to certain processing, and to withdraw consent. Residents of the EEA/UK have rights under the GDPR; residents of California have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sales" or "sharing" (we do neither).
To exercise any right, contact us at hello@smartappbanner.com. We will respond within the timeframe required by applicable law and will not discriminate against you for exercising your rights. You also have the right to lodge a complaint with your local data protection authority.
11. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, least-privilege practices, and regular review of our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continuously to safeguard your information.
12. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, please contact us and we will take steps to delete it.
13. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email before they take effect, and we will update the "Last updated" date above.
14. Contact us
If you have questions about this Policy or how we handle your data, contact our team at hello@smartappbanner.com, or write to Cellusion Tech FZE, Dubai Silicon Oasis, Dubai, United Arab Emirates.