Meet ASO Agent, automate App Store Optimization across every market.Contact sales
ASO Agent

Privacy Policy

Last updated: July 2, 2026

This Privacy Policy describes Our policies and procedures regarding the collection, use, disclosure, storage, and protection of Your Personal Data when You use Our Service and explains Your privacy rights under applicable laws, including the European Union General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the California Online Privacy Protection Act ("CalOPPA"), and other applicable privacy laws.

By accessing or using the Service, creating an account, purchasing Our products or services, or otherwise interacting with Us, You acknowledge that You have read and understood this Privacy Policy.

If You do not agree with this Privacy Policy, please do not use the Service.


Interpretation and Definitions

Interpretation

Words whose initial letter is capitalized have meanings defined under the following conditions. The following definitions have the same meaning whether they appear in singular or plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access the Service.
  • Affiliate means an entity that controls, is controlled by, or is under common control with the Company.
  • Business, for purposes of the CCPA/CPRA, refers to the Company.
  • Company ("Company", "We", "Us", or "Our") refers to Deep Labs, LDA, Rua Dr. Francisco Duarte, N.º 287, 4715-017 Braga, Portugal.
  • Consumer has the meaning given under the CCPA/CPRA.
  • Cookies are small files stored on Your Device that allow websites to remember information about Your visit.
  • Country refers to Portugal.
  • Device means any computer, smartphone, tablet, or other device capable of accessing the Service.
  • Personal Data (also referred to as Personal Information) means any information relating to an identified or identifiable individual.
  • Sensitive Personal Information has the meaning provided under the California Privacy Rights Act (CPRA).
  • Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, analysis, deletion, or destruction.
  • Service refers to the ASOAgent website, applications, APIs, and related services.
  • Service Provider means any third party processing Personal Data on behalf of the Company.
  • Usage Data means information collected automatically when using the Service.
  • Website refers to ASOAgent, accessible at https://www.asoagent.com.
  • You means the individual accessing or using the Service, or the company or legal entity on whose behalf such individual accesses the Service.

Collecting and Using Your Personal Data

Categories of Information We Collect

Depending on how You interact with the Service, We may collect the following categories of information.

1. Information You Provide Directly

When You create an account, contact Us, purchase products, or otherwise interact with the Service, We may collect:

  • First and last name
  • Email address
  • Company name
  • Billing information
  • Country
  • User account credentials
  • Customer support communications
  • Feedback and survey responses
  • Any information You voluntarily provide

2. Social Login Information

If You choose to register or sign in using a third-party authentication service, such as:

  • Facebook Login
  • Sign in with X (formerly Twitter)
  • Google Sign-In
  • Apple Sign-In
  • GitHub Login
  • or other supported identity providers

We may receive information associated with Your social media account, subject to the permissions You grant that provider.

This information may include:

  • Name
  • Email address
  • Public profile identifier
  • Profile photograph
  • Language preference
  • Country or region
  • User ID associated with the provider
  • Any other information You choose to share through that provider.

We use this information solely to authenticate You, create or manage Your account, prevent fraud, and improve the Service.

Your relationship with these providers is governed by their own privacy policies, and We encourage You to review them.


3. Payment Information

Payments made through the Service are processed by third-party payment processors, including Stripe.

We do not store or have access to complete payment card numbers. Payment information is transmitted directly to Stripe using encrypted connections. Stripe processes payment information in accordance with its own Privacy Policy and security standards, including PCI-DSS.

We may receive limited payment-related information such as:

  • Payment status
  • Transaction identifiers
  • Last four digits of payment cards
  • Card brand
  • Billing country
  • Subscription status
  • Invoice history

This information is used for billing, fraud prevention, customer support, tax compliance, and accounting purposes.


4. Usage Data

Usage Data is collected automatically whenever You access or use the Service.

Usage Data may include:

  • IP address
  • Browser type
  • Browser version
  • Device identifiers
  • Operating system
  • Language settings
  • Referring URLs
  • Pages visited
  • Session duration
  • Features used
  • Crash reports
  • Error logs
  • Performance metrics
  • Time and date of requests
  • Network information

When You use the Service from a mobile device, We may additionally collect information such as the mobile operating system, device model, mobile browser type, and mobile device identifiers.


5. Analytics Information

We use analytics providers to better understand how users interact with the Service. These providers may use cookies, SDKs, pixels, and similar technologies.

Analytics providers may include:

  • Google Analytics
  • Google Analytics 4 (GA4)
  • Google Tag Manager
  • Google Search Console
  • Microsoft Clarity
  • Cloudflare Analytics
  • PostHog
  • Mixpanel
  • Amplitude
  • or similar analytics providers.

These providers may collect:

  • IP address (which may be shortened or anonymized where supported)
  • Browser information
  • Operating system
  • Session identifiers
  • Device identifiers
  • Traffic source
  • Clickstream data
  • Page interactions
  • Session recordings where enabled
  • Aggregate usage statistics

Where required by law, analytics cookies are only activated after obtaining Your consent.


6. Cookies and Similar Technologies

We use cookies, web beacons, pixels, local storage, SDKs, and similar technologies to operate the Service, remember Your preferences, analyze performance, provide security, measure advertising effectiveness, and improve the user experience.

Further details about the categories of cookies We use, their purposes, retention periods, and how to manage cookie preferences are provided later in this Privacy Policy and in Our Cookie Policy.


Cookies and Tracking Technologies

We use Cookies and similar tracking technologies to operate the Service, improve functionality, remember Your preferences, analyze usage, measure the effectiveness of Our marketing campaigns, protect the security of the Service, and comply with legal obligations.

Depending on Your jurisdiction, non-essential cookies will only be placed on Your Device after obtaining Your consent through Our cookie banner or consent management platform.

Types of Cookies We Use

Strictly Necessary Cookies

These cookies are essential for the operation of the Service and cannot be disabled in Our systems.

Examples include:

  • User authentication
  • Session management
  • Load balancing
  • Security monitoring
  • Fraud prevention
  • Remembering cookie consent choices

Legal Basis (GDPR): Legitimate Interest.


Functional Cookies

These cookies remember Your preferences to improve Your experience, including:

  • Language selection
  • Region preferences
  • User interface settings
  • Recently viewed content
  • Account preferences

Legal Basis (GDPR): Consent where required; otherwise Legitimate Interest.


Analytics Cookies

Analytics cookies help Us understand how visitors interact with the Service. This allows Us to improve usability, performance, and features.

Analytics providers may include:

  • Google Analytics 4
  • Google Tag Manager
  • Microsoft Clarity
  • Cloudflare Analytics
  • Mixpanel
  • PostHog
  • Amplitude
  • Similar analytics platforms

Analytics providers may collect:

  • IP address
  • Device identifiers
  • Browser type
  • Operating system
  • Session duration
  • Referring websites
  • Clicks
  • Scroll activity
  • Feature usage
  • Crash reports
  • General geographic region

Where available, We configure analytics services to reduce the amount of personally identifiable information processed, including IP anonymization or equivalent privacy features.

Legal Basis (GDPR): Consent.


Advertising and Marketing Cookies

We may use advertising or remarketing technologies to understand the effectiveness of Our marketing campaigns and to show relevant advertisements.

These technologies may include advertising pixels, conversion tracking tags, and audience measurement tools.

Advertising cookies are only used where permitted by applicable law and, where required, only after obtaining Your consent.


Managing Cookies

You may withdraw or modify Your cookie consent at any time through Our cookie preferences tool, if available.

You may also disable cookies through Your browser settings. However, disabling certain cookies may affect the functionality of the Service.


Email Communications

Service Emails

We may send You emails that are necessary for providing the Service, including:

  • Account verification
  • Password reset emails
  • Purchase confirmations
  • Subscription updates
  • Billing notifications
  • Security alerts
  • Changes to the Service
  • Important legal notices

These communications are considered part of the Service and cannot generally be opted out of while maintaining an active account.


Marketing Emails

If You choose to subscribe, or where otherwise permitted by applicable law, We may send You promotional emails, newsletters, product announcements, educational materials, special offers, surveys, and updates regarding Our products and services.

Marketing emails are sent only:

  • with Your consent;
  • or where permitted under applicable law based on an existing customer relationship.

You may unsubscribe from marketing emails at any time by:

  • clicking the "Unsubscribe" link contained in the email;
  • changing Your account notification preferences;
  • contacting Us directly.

Unsubscribing from marketing emails does not affect service-related communications that are necessary to provide the Service.


Legal Bases for Processing Personal Data (GDPR)

If You are located within the European Economic Area ("EEA"), United Kingdom, or another jurisdiction applying similar privacy laws, We process Personal Data only where We have a lawful basis.

Depending on the circumstances, Our legal bases include:

Consent

We process Personal Data where You have freely given Your consent, including:

  • marketing emails;
  • analytics cookies;
  • optional cookies;
  • certain integrations;
  • other situations where consent is legally required.

You may withdraw consent at any time. Withdrawal does not affect processing already carried out before consent was withdrawn.


Performance of a Contract

We process Personal Data where necessary to:

  • create Your account;
  • provide the Service;
  • process payments;
  • deliver purchased products;
  • provide customer support;
  • maintain subscriptions.

Legal Obligations

We may process Personal Data where necessary to comply with legal obligations, including:

  • tax laws;
  • accounting regulations;
  • court orders;
  • anti-fraud obligations;
  • law enforcement requests;
  • consumer protection laws.

Legitimate Interests

We may process Personal Data where We have legitimate business interests that are not overridden by Your rights and freedoms.

These interests include:

  • maintaining Service security;
  • fraud detection;
  • bug fixing;
  • customer support;
  • product improvement;
  • analytics;
  • network administration;
  • business planning;
  • internal reporting;
  • preventing abuse of the Service.

How We Use Personal Data

We may use Personal Data for one or more of the following purposes:

  • To provide and maintain the Service.
  • To authenticate users.
  • To create and manage user accounts.
  • To process purchases and subscriptions.
  • To process payments through Stripe and other payment providers.
  • To prevent fraud and unauthorized access.
  • To analyze usage of the Service.
  • To improve features and performance.
  • To personalize user experience.
  • To respond to customer support requests.
  • To send transactional emails.
  • To send newsletters and marketing communications where permitted.
  • To monitor infrastructure health and application performance.
  • To enforce Our Terms of Service.
  • To investigate security incidents.
  • To comply with applicable laws.
  • To establish, exercise, or defend legal claims.
  • To conduct internal business operations.
  • To perform statistical analysis.
  • To create aggregated and anonymized reports.

Automated Decision-Making and Profiling

We do not make decisions producing legal or similarly significant effects based solely on automated processing of Personal Data.

We may use automated systems to detect spam, prevent fraud, improve security, recommend features, and analyze usage patterns. These processes are intended to improve the Service and are not designed to make legal or similarly significant decisions about individuals.


Sharing and Disclosure of Personal Data

We do not sell Your Personal Data for monetary consideration. We may disclose Personal Data only as described in this Privacy Policy or where required by applicable law.

Depending on how You use the Service, We may share Personal Data with the following categories of recipients.


Service Providers

We engage trusted third-party service providers to perform services on Our behalf. These providers may process Personal Data only as necessary to provide their services to Us and are contractually required to protect such information.

Examples include providers of:

  • Cloud hosting and infrastructure
  • Content delivery networks (CDNs)
  • Data storage
  • Authentication services
  • Payment processing
  • Email delivery
  • Customer support
  • Analytics
  • Error monitoring
  • Security monitoring
  • Fraud prevention
  • Application performance monitoring

Payment Processors

Payments made through the Service are processed by third-party payment providers, including Stripe.

Payment information is transmitted directly to the payment processor over secure, encrypted connections. We do not store complete payment card numbers or security codes.

Stripe acts as an independent controller of certain payment information and processes such information in accordance with its own Privacy Policy and legal obligations, including PCI-DSS requirements.


Analytics Providers

We may share limited information with analytics providers for purposes including:

  • understanding how users interact with the Service;
  • measuring Service performance;
  • identifying bugs;
  • improving user experience;
  • measuring marketing effectiveness.

These providers may include Google Analytics, Google Analytics 4, Google Tag Manager, Microsoft Clarity, Cloudflare Analytics, Mixpanel, PostHog, Amplitude, or similar providers.


Authentication Providers

If You sign in using a third-party identity provider such as Facebook, Google, Apple, X (formerly Twitter), GitHub, or another supported authentication provider, information required to authenticate Your account will be exchanged between Us and that provider.

The information shared depends on the permissions You authorize through the identity provider.


Email Service Providers

We may use third-party email delivery providers to send:

  • account notifications;
  • transactional emails;
  • password reset emails;
  • security notifications;
  • newsletters;
  • marketing communications.

These providers process Personal Data solely for delivering communications on Our behalf.


Business Transfers

If the Company is involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar corporate transaction, Personal Data may be transferred as part of that transaction.

Where required by law, We will notify affected users before Personal Data becomes subject to a different privacy policy.


Legal Compliance

We may disclose Personal Data where We reasonably believe disclosure is necessary to:

  • comply with applicable law;
  • respond to lawful governmental requests;
  • comply with court orders or subpoenas;
  • protect Our legal rights;
  • prevent fraud;
  • protect users and the public;
  • investigate security incidents;
  • enforce Our agreements.

With Your Consent

We may disclose Personal Data for purposes not described in this Privacy Policy where You have provided Your explicit consent.


Third-Party Services

The Service may integrate with or rely upon third-party services. Those third parties operate under their own privacy policies and terms.

Examples may include:

  • Stripe
  • Google Analytics
  • Google Cloud Platform
  • Cloudflare
  • Facebook Login
  • Google Sign-In
  • Apple Sign-In
  • X Login
  • GitHub Login
  • email delivery providers;
  • customer support providers;
  • monitoring services;
  • analytics providers;
  • cloud hosting providers.

We encourage You to review the privacy policies of these third-party services before providing Personal Data.


International Data Transfers

Your Personal Data may be transferred to and processed in countries other than Your own, including countries whose data protection laws may differ from those in Your jurisdiction.

Where Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland is transferred internationally, We implement appropriate safeguards as required by applicable law.

Such safeguards may include:

  • European Commission Standard Contractual Clauses (SCCs);
  • UK International Data Transfer Addendum;
  • adequacy decisions;
  • supplementary technical and organizational measures;
  • other legally approved transfer mechanisms.

We take reasonable steps to ensure transferred Personal Data receives an adequate level of protection regardless of where it is processed.


Retention of Personal Data

We retain Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention periods depend upon the type of information and the purpose for which it was collected.

Examples include:

  • Account information: for the lifetime of the account and up to 24 months after closure.
  • Billing records: as required by tax and accounting laws.
  • Customer support communications: up to 24 months after resolution.
  • Security logs: up to 24 months.
  • Analytics information: according to the configuration of the analytics provider and applicable legal requirements.
  • Marketing preferences: until withdrawn or no longer required.

Where possible, We anonymize or securely delete Personal Data once retention is no longer necessary.


Security of Personal Data

We implement appropriate technical and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Security measures may include:

  • Encryption in transit using TLS.
  • Encryption of sensitive data where appropriate.
  • Access controls.
  • Role-based permissions.
  • Authentication mechanisms.
  • Firewall protections.
  • Infrastructure monitoring.
  • Intrusion detection.
  • Routine backups.
  • Security logging.
  • Employee confidentiality obligations.
  • Vendor due diligence.

Although We strive to use commercially reasonable safeguards, no Internet transmission or electronic storage system can be guaranteed to be completely secure.


Your Privacy Rights

Depending on where You reside, You may have certain privacy rights under applicable law. We are committed to honoring those rights whenever legally required.


Rights Under the GDPR (European Economic Area, United Kingdom and Similar Jurisdictions)

If the GDPR or similar legislation applies to You, You may exercise the following rights:

Right of Access

You may request confirmation of whether We process Your Personal Data and obtain a copy of that information.

Right to Rectification

You may request correction of inaccurate or incomplete Personal Data.

Right to Erasure ("Right to be Forgotten")

You may request deletion of Your Personal Data where:

  • the information is no longer necessary;
  • You withdraw consent;
  • You successfully object to processing;
  • processing is unlawful;
  • deletion is required by law.

This right is subject to legal exceptions, including where We must retain data for legal, accounting, fraud prevention, or regulatory purposes.

Right to Restrict Processing

You may request that We temporarily restrict processing under certain circumstances provided by law.

Right to Data Portability

Where technically feasible and legally applicable, You may receive a copy of Your Personal Data in a structured, commonly used, machine-readable format and request that it be transferred to another controller.

Right to Object

You may object to processing based on Our legitimate interests or for direct marketing purposes.

Where Personal Data is processed for direct marketing, You have the right to object at any time.

Right to Withdraw Consent

Where processing is based upon consent, You may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint

You may lodge a complaint with the supervisory authority responsible for data protection in Your country of residence if You believe that Our processing of Your Personal Data violates applicable law.


California Privacy Rights (CCPA / CPRA)

If You are a California resident, You may have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

Right to Know

You may request information regarding:

  • the categories of Personal Information collected;
  • the categories of sources from which it was collected;
  • the business or commercial purposes for collection;
  • the categories of third parties receiving Personal Information;
  • the specific pieces of Personal Information collected about You.

Right to Delete

You may request deletion of Personal Information that We collected from You, subject to legal exceptions.

Right to Correct

You may request correction of inaccurate Personal Information.

Right to Data Portability

Where applicable, We will provide requested Personal Information in a portable, readily usable format.

Right to Limit Use of Sensitive Personal Information

If We collect Sensitive Personal Information as defined by the CPRA, We use such information only for the limited purposes permitted by law, including providing the Service, detecting fraud, ensuring security, processing payments, and meeting legal obligations.

We do not use Sensitive Personal Information to infer characteristics about individuals.

Right to Non-Discrimination

We will not discriminate against You for exercising Your privacy rights, including by denying services, charging different prices, or providing a different level of service except where permitted by law.


Sale or Sharing of Personal Information

We do not sell Your Personal Information for monetary consideration.

We also do not knowingly sell or share Personal Information of individuals under 16 years of age.

Certain analytics, advertising, or social media technologies may be considered "sharing" under California law. Where required by applicable law, We provide appropriate consent or opt-out mechanisms.


Exercising Your Privacy Rights

To exercise any applicable privacy rights, You may contact Us using the contact details provided at the end of this Privacy Policy.

We may request reasonable information to verify Your identity before processing Your request.

Authorized agents may submit requests on behalf of California residents where permitted by law, subject to appropriate verification.


California Online Privacy Protection Act (CalOPPA)

In accordance with CalOPPA:

  • Users may visit Our Website anonymously.
  • A link to this Privacy Policy appears on Our Website.
  • The Privacy Policy includes the effective date shown at the top of this page.
  • Material changes to this Privacy Policy will be posted on this page and, where required by law, communicated by additional means such as email or in-Service notice.

Do Not Track Signals

Some web browsers provide a "Do Not Track" ("DNT") feature.

Because there is currently no universally accepted standard governing how DNT signals should be interpreted, the Service does not currently respond to browser DNT signals.

You may nevertheless control tracking technologies through browser settings, cookie preferences, and other privacy controls where available.


Children's Privacy

The Service is not directed to children under the age of 16.

We do not knowingly collect Personal Data from children under 16 years of age. If We become aware that such information has been collected without appropriate consent where required by law, We will take reasonable steps to delete it.

Parents or legal guardians who believe a child has provided Personal Data may contact Us using the information below.


Links to Other Websites

The Service may contain links to third-party websites that are not operated by Us.

We are not responsible for the privacy practices or content of third-party websites and encourage You to review their privacy policies before providing any Personal Data.


Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

When We make material changes, We will revise the "Last updated" date shown at the top of this Privacy Policy and, where required by applicable law, provide additional notice through email, the Service, or other appropriate means.

Your continued use of the Service after such changes become effective constitutes acceptance of the updated Privacy Policy.


Contact Us

If You have any questions about this Privacy Policy or wish to exercise Your privacy rights, You may contact Us:

  • Email: support@asoagent.com
  • Postal Address:
    Deep Labs, LDA
    Rua Dr. Francisco Duarte, N.º 287
    4715-017 Braga
    Portugal

Data Protection Requests

Requests regarding access, deletion, correction, portability, restriction, objection, withdrawal of consent, or California privacy rights may be submitted using the contact information above.

We will respond within the timeframes required by applicable law. In certain circumstances, We may need additional information to verify Your identity before processing a request.

If We cannot fulfill a request, We will explain the legal basis for Our decision where required by applicable law.