Acme — Legal

Privacy Policy

Effective date: July 24, 2026

Acme Labs, Inc. ("Acme", "we", "us", or "our") built the Acme Android application (the "App"). This policy explains what information we collect, why we collect it, and how it is used, shared, and protected when you install or use the App, visit https://www.acme.example, or otherwise interact with us.

1. Overview

We collect information to operate the App, provide customer support, communicate with you about your account and our services, and understand how the App is used so we can improve it. We use a small set of trusted third-party providers to do this — Vero Analytics, Customer.io, Google Analytics, and Smartlead.ai — each described in Section 4 below. We do not sell your personal information.

2. Information We Collect

Account and profile information. Name, email address, phone number (if provided), company name, and any other details you submit when you register or update your profile.

Usage and device information. App interactions (screens viewed, features used, buttons tapped), session length, timestamps, device model, operating system version, language, IP address, and unique device or advertising identifiers.

Communications data. Records of emails, in-app messages, or push notifications we send you, along with engagement signals such as opens, clicks, and unsubscribes.

Customer and lead data (B2B context). If our customers use the App to manage their own contacts or leads, we may process names, business email addresses, job titles, and outreach activity on their behalf.

Support data. Information you share with us when you contact support, including message content and attachments.

3. How We Use Your Information

  • Provide, maintain, and secure the App
  • Personalize your experience and remember preferences
  • Send transactional messages (account, billing, security notices)
  • Send marketing communications, product updates, and onboarding sequences, where you have consented or as otherwise permitted by law
  • Measure feature adoption, retention, and performance to guide product decisions
  • Detect, investigate, and prevent fraud or misuse
  • Comply with legal obligations

4. Third-Party Services We Use

We rely on the following processors to deliver core functionality. Each provider only receives the data needed to perform its function, under a data-processing agreement.

Vero Analytics

Used for in-app event tracking and behavioral analytics (e.g., feature usage, funnel completion). Data shared typically includes a device/user identifier, event names and properties, and timestamps. This helps us understand how the App is used and where the experience can be improved.

Customer.io

Used for lifecycle marketing and transactional messaging — email, push notifications, and/or SMS. Data shared typically includes contact details (email, phone), behavioral event data, and message engagement history, used to trigger and personalize messages such as onboarding flows, product updates, and re-engagement campaigns.

Google Analytics (Firebase)

Used for App usage analytics via the Firebase SDK for Android. Data shared typically includes device information, advertising identifiers, app interactions, and approximate/coarse location derived from IP address. You can review Google's own privacy practices at policies.google.com/privacy.

Smartlead.ai

Used for outbound email sequencing to prospective and existing customers as part of our sales and marketing outreach. Data shared typically includes business contact details (name, email, company) and email engagement data (opens, replies, bounces) needed to run and measure outreach campaigns.

We periodically review this list as our stack evolves. The current version of this policy always reflects the providers in active use.

5. Android Permissions

The App may request the following Android permissions. We request only what is needed for the related feature to work, and each is optional unless noted.

  • Internet / Network state — required to sync data and load content.
  • Notifications (POST_NOTIFICATIONS) — to deliver push messages via Customer.io; you can disable this in system settings at any time.
  • Camera / Photos — only if you use features such as profile photo upload or document scanning.
  • Location (coarse) — only if used for region-based content; the App does not request precise background location.
  • Advertising ID — used by Google Analytics for aggregated, non-precise usage measurement.

A complete, current list of requested permissions is always visible on our Google Play Store listing and in the App's system settings page on your device.

6. Sharing and Disclosure

We share information only in the following circumstances:

  • With the service providers named in Section 4, to operate and improve the App
  • With professional advisors (legal, accounting) where necessary
  • In connection with a merger, acquisition, or asset sale, with continuity of protection under this policy
  • When required by law, regulation, legal process, or enforceable governmental request
  • With your direction or consent

We do not sell personal information to third parties.

7. Data Retention

We retain personal information for as long as your account is active or as needed to provide the App, comply with legal obligations, resolve disputes, and enforce agreements. Analytics and marketing engagement data is generally retained for up to 24 months from the last activity, after which it is deleted or aggregated so it no longer identifies you. You can request earlier deletion — see Section 8.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing, including marketing. This applies, for example, to residents of the EU/EEA and UK under the GDPR, and to California residents under the CCPA/CPRA.

  • Marketing opt-out: use the unsubscribe link in any marketing email, or adjust notification settings in-app; transactional messages will continue as needed to operate your account.
  • Access / deletion requests: email privacy@acme.example; we will verify your identity and respond within the timeframe required by applicable law.
  • Do Not Track / Global Privacy Control: where legally required, we honor recognized opt-out signals.

9. Security

We use industry-standard safeguards — encryption in transit, access controls, and regular review of our vendor relationships — to protect your information. No system is perfectly secure; if we become aware of an incident affecting your data, we will notify affected users and relevant authorities as required by law, and share the steps we're taking to resolve it.

10. Children's Privacy

The App is not directed to children under 13 (or the minimum age required by your local law), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at privacy@acme.example and we will delete it promptly.

11. International Data Transfers

Our service providers may process data in countries other than your own, including the United States. Where required, we rely on recognized transfer mechanisms such as Standard Contractual Clauses to protect data moved across borders.

12. Changes to This Policy

We may update this policy as our App, stack, or legal obligations evolve. Material changes will be highlighted in-app or via email ahead of taking effect. The "Effective date" above always reflects the latest version.

13. Contact Us

Questions about this policy or your data can be sent to:

Acme Labs, Inc.
123 Market Street, Suite 400, San Francisco, CA 94103, USA
Email: privacy@acme.example
Data Protection contact: dpo@acme.example

This template is provided as a starting point and does not constitute legal advice. Confirm final language with counsel before publishing, and align the Google Play Data Safety form with the data practices described here.