Privacy Policy
This Privacy Policy explains how Aparim LLC (“Aparim,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal and business information when you use the Aparim mobile application, our web and admin applications, and related services (together, the “Services”).
1. Who we are and how the Services work
Aparim provides a multi-tenant ordering platform used by wholesale suppliers (for example grocery and food distributors, each a “Supplier”) and their business customers (for example hotels, restaurants, caterers and retailers, each a “Buyer”).
- Buyers use the Aparim app to browse their Supplier’s catalog and place wholesale orders.
- Suppliers use the Aparim admin panel to manage products, customers, credit terms and orders.
Accounts are created by, or at the invitation of, a Supplier. The Services are intended for business use only and are not directed to consumers or personal shopping.
Controller and processor roles
For information you provide directly to us (account credentials, business verification details, platform usage), Aparim acts as a controller. For catalog, customer and order information that a Supplier stores and manages on the platform, Aparim generally acts as a processor / service provider on that Supplier’s behalf. If you are a Buyer with questions about how a specific Supplier uses your information, please contact that Supplier directly; we will assist where we can.
2. Information we collect
a. Information you or your Supplier provide
| Category | Examples | Purpose |
|---|---|---|
| Account information | Email address, password (stored only as a salted hash), full name, role (buyer / store admin) | Create and secure your account; sign-in |
| Business information | Legal or trading business name, contact name, business phone number, business and delivery addresses, account status, credit limit and payment terms set by your Supplier | Associate you with the correct Supplier; fulfil and deliver orders; apply credit terms |
| Business verification information (where applicable) | Employer Identification Number (EIN) or other business tax identifier, resale or seller’s permit number, business registration details, and, for Suppliers, information required by our payment partner to verify the business and its authorised representative | Verify that an account belongs to a genuine business; support tax-exempt wholesale transactions; meet payment-partner and legal requirements |
| Order information | Products and quantities ordered, order totals, requested delivery date, selected payment method, order notes, status history, outstanding balances | Create, transmit, track and reconcile orders |
| Payment-related information (when online payments are enabled) | Payment status, amount, currency, last four digits and card brand, payment reference identifiers returned by our payment processor. For Suppliers receiving payouts: payout account identifiers held by the processor | Show payment status, reconcile orders, and route funds — see Section 3 |
| Communications | Support requests, feedback, messages you send us | Respond to you; improve the Services |
b. Information collected automatically
- Device and app information — device model, operating system version, app version, language; used for compatibility and troubleshooting.
- Log and diagnostic data — timestamps, error and crash information, and technical logs generated when the app communicates with our servers.
- Session data — an authentication token stored securely on your device so that you remain signed in.
If you install the app through Apple TestFlight, Apple may share crash logs and basic beta usage data with us under Apple’s own terms.
c. Information we do not collect
- We do not collect your precise location.
- We do not access your contacts, photos, microphone or camera.
- We do not collect or store full payment card numbers, card security codes, or online banking credentials (see Section 3).
- We do not request Social Security Numbers from Buyers. Where a payment partner must verify a Supplier’s authorised representative, any government identifier is collected by that partner directly, not stored by Aparim (see Section 4).
- We do not use advertising identifiers, ad networks or cross-app / cross-site tracking, and we do not engage in “tracking” as defined by Apple’s App Tracking Transparency framework.
3. Payments and financial information
Today, orders placed through the Services are typically settled directly between Buyer and Supplier off-platform (for example by cheque, cash on delivery, or agreed credit terms). The app records only the payment method selected and the payment status recorded by the Supplier.
We are introducing optional online card payments. When that feature is enabled for your Supplier:
- Payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. Card details are entered into Stripe’s secure fields and transmitted directly to Stripe. Aparim never receives, processes or stores your full card number, expiry or security code.
- Funds for an order are paid directly to the Supplier’s own connected Stripe account. Aparim may receive a platform fee deducted within the same transaction. Aparim does not hold, custody or transmit your funds.
- Aparim stores only non-sensitive payment metadata — amount, currency, status, timestamp, card brand and last four digits, and Stripe’s transaction reference — so that you and your Supplier can reconcile orders.
- Suppliers who accept card payments must complete Stripe’s onboarding and identity/business verification (“Know Your Customer”). That information is collected and held by Stripe under Stripe’s Privacy Policy; Aparim receives only the verification status and a payout account identifier.
- Refunds, chargebacks, and any dispute over an order’s goods or price are handled by the Supplier, with Stripe processing the transaction.
No purchases of digital content are made through the app; the Services are used to order physical wholesale goods, which are paid for outside of Apple’s in-app purchase system as permitted by Apple’s guidelines for goods and services consumed outside the app.
4. Business verification and tax identifiers (EIN)
Because Aparim serves wholesale trade, we or your Supplier may ask for business verification details such as an EIN or other business tax identification number, a resale or seller’s permit, or business registration information. We use these only to:
- confirm that an account belongs to a genuine, authorised business;
- support tax-exempt or resale wholesale transactions and correct invoicing;
- satisfy requirements of our payment partner and applicable law; and
- prevent fraud and unauthorised account creation.
An EIN is a business identifier rather than a personal one; however, we treat tax identifiers as confidential information and apply heightened protection: access is restricted to personnel who need it, values are encrypted at rest, they are never displayed in full to other users, and they are never used for marketing or shared with any party other than the Supplier that requires them, our payment processor, or where required by law. If your business is a sole proprietorship and you provide an identifier that is also a personal identifier, we treat it as sensitive personal information and process it strictly for the verification purposes above.
5. Messaging, WhatsApp and Twilio
Order notifications are core to the Services and are transactional, not marketing.
- Device-initiated messages (current). When you place an order, the app can open WhatsApp on your device with a pre-filled message containing your order details, addressed to your Supplier. You choose whether to send it. Once sent, the message is handled by WhatsApp (Meta Platforms, Inc.) and by your Supplier under their own policies.
- Platform-sent notifications (being introduced). We are enabling automated order notifications — for example “order received”, “order confirmed” and “out for delivery” — sent through the WhatsApp Business Platform via Twilio Inc. as our messaging provider. To deliver these, we share with Twilio and Meta the recipient’s business phone number, the business or store name, and order reference details such as order number, total and status. Message content and delivery receipts are processed by those providers under Twilio’s Privacy Notice and Meta’s WhatsApp Business terms.
- Your choices. Order notifications are necessary to provide the Services; if you do not wish to receive them on WhatsApp, contact your Supplier or email us and we will disable WhatsApp notifications for your account where operationally possible. We will not send you promotional messages without your prior consent, and any such messages will include an opt-out.
6. How we use information
- Create, authenticate and secure accounts.
- Display the correct Supplier’s catalog, pricing and branding to the correct Buyer.
- Process, transmit and keep a record of orders, credit limits and payment status.
- Verify businesses and prevent fraud, abuse and unauthorised access.
- Send order-related notifications (Section 5).
- Provide customer support and respond to enquiries.
- Monitor, debug and improve reliability, performance and usability of the Services.
- Comply with legal, tax and accounting obligations, and enforce our terms.
We do not use your information to build advertising profiles, and we do not sell or rent it.
Legal bases (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract; legitimate interests (securing the platform, preventing fraud, improving the Services); legal obligation (tax, accounting, anti-fraud); and, where required, consent, which you may withdraw at any time.
7. How we share information
- With your Supplier. A Buyer’s account details, business details, credit status and orders are visible to the Supplier they order from. This is the core purpose of the Services.
- With service providers who operate the platform on our behalf under contracts limiting their use of data:
- Supabase — database, authentication and file storage (United States).
- Vercel — hosting for our web and admin applications.
- Expo (EAS) — mobile application builds and over-the-air updates.
- Apple — distribution via TestFlight and the App Store.
- Stripe — payment processing and payouts, where online payments are enabled.
- Twilio and the WhatsApp Business Platform (Meta) — delivery of order notifications.
- Professional advisers — accountants, auditors and lawyers, under duties of confidentiality.
- For legal reasons — where disclosure is required by law, regulation or legal process, or is necessary to protect the rights, property or safety of Aparim, our users or the public.
- Business transfers — in a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
8. Data separation between suppliers
The platform is multi-tenant. Every record is tagged to a specific Supplier and protected by database row-level security policies, so one Supplier and its Buyers cannot access another Supplier’s catalog, customers, pricing or orders.
9. Retention
We keep information for as long as your account is active and as long as needed to provide the Services. Order, invoice, payment and tax-identifier records are retained while your relationship with the Supplier continues and thereafter for the period required by legal, accounting, tax, dispute-resolution and audit obligations — typically up to seven years for transaction and tax records in the United States. Diagnostic logs are retained for a shorter period, generally up to 12 months. When information is no longer required we delete it or irreversibly anonymise it.
10. Security
- All data is encrypted in transit using TLS/HTTPS and encrypted at rest by our hosting providers.
- Passwords are stored only as salted hashes; we never see your password in plain text.
- Tax identifiers and other confidential business data are encrypted at rest and access-restricted.
- Row-level security enforces tenant isolation at the database layer.
- Administrative access is limited to authorised personnel on a need-to-know basis and protected by multi-factor authentication where available.
- Card data is handled exclusively by our PCI-DSS certified payment processor and never traverses Aparim’s servers.
No method of transmission or storage is completely secure. If we become aware of a breach affecting your information, we will notify you and any regulator as required by applicable law.
11. International transfers
Aparim is based in the United States, and our service providers store and process data primarily in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
12. Your rights, choices and account deletion
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal information, to withdraw consent, and not to be discriminated against for exercising these rights.
To exercise any right, email info@aparim.com from the address associated with your account. We will verify your request and respond within the timeframe required by law (generally 30 days; 45 days under the CCPA/CPRA, extendable where permitted). If your account was created by a Supplier who controls that data, we may refer your request to them and will tell you when we do.
Account deletion
You may request deletion of your Aparim account and associated personal information at any time by emailing info@aparim.com with the subject line “Delete my account”, or by asking your Supplier to remove your account from their admin panel. We will confirm and action verified requests within 30 days. We may retain limited order, invoice and tax records where retention is required by law, and information necessary to prevent fraud or resolve disputes; such retained records are isolated from active use.
California residents
In the past 12 months we collected the categories described in Section 2 for the purposes described in Section 6. We have not sold personal information and have not shared it for cross-context behavioural advertising, including with respect to consumers under 16. California residents may exercise CCPA/CPRA rights using the contact details above and may use an authorised agent.
13. Children’s privacy
The Services are intended solely for business use by individuals aged 18 or over acting on behalf of a business. They are not directed to children and we do not knowingly collect information from anyone under 18. If we learn we have collected such information, we will delete it promptly.
14. Changes and contact
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above, and for material changes — such as launching online payments or new notification channels — we will provide additional notice by in-app message or email before the change takes effect. Your continued use of the Services after an update means you accept the revised policy.
Questions, requests or complaints:
Aparim LLC
4905 Laurel Valley Ln
Enola, PA 17025
United States
Email: info@aparim.com
If you are in the EEA or UK and believe we have not resolved your concern, you may lodge a complaint with your local data protection authority.