Last updated: June 9, 2026
This Privacy Policy explains how Apparently, Inc. collects, uses, and protects information about you when you use our website and services.
Account and profile information: When you register, we collect your name, email address, company name, and role. If you are a key person on a license application, we may collect additional identifying information required by state gaming regulators (e.g., date of birth, address, prior regulatory history).
Business information: To provide filing and compliance services, we collect information about your business activities, licenses held, ownership and control structure, jurisdictions of operation, and other regulatory details required to prepare and submit filings on your behalf.
Documents you upload: We store documents you upload (business plans, financial statements, existing licenses, organizational charts, identification documents, etc.) to assist with activity classification and filing preparation.
Payment information: Payment card data is collected and processed by our third-party payment processor (Stripe). We do not store full card numbers on our servers. We retain records of transaction amounts, dates, and service identifiers for billing and compliance purposes.
Portal and key-person session data: Individuals invited to complete a key-person compliance portal may provide identification documents, background information, and other regulatory disclosures through a dedicated session. That data is associated with the relevant organization's compliance record.
Compliance API usage data: For customers using our Compliance API, we log API request metadata (endpoint, timestamp, response code, token consumption) for billing, rate limiting, and service quality purposes. We do not log the contents of API queries in a manner that identifies end-users of your application without your consent.
On-chain identifiers: For customers using loyalty and rewards program services, we may process blockchain wallet addresses and on-chain transaction references provided by you or your users in connection with those programs. We do not collect private keys.
Usage data: We automatically collect log data including IP address, browser type, pages visited, timestamps, and referring URLs. We use this for security monitoring, abuse prevention, and service improvement.
Communications: If you contact us by email or through our forms, we retain those communications to respond to your inquiry and improve our services. We may retain correspondence with regulatory authorities conducted on your behalf as part of your compliance record.
We do not sell your personal information. We share information only as follows:
We retain your account and service data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements. Regulatory filing records may be retained for extended periods given applicable recordkeeping requirements under gaming regulations and federal law.
Documents you upload are retained for the duration of your engagement and for a reasonable period after. You may request deletion of specific documents at any time, subject to our obligations to retain records for pending or completed regulatory submissions and any applicable legal hold.
API usage logs are retained for billing and audit purposes for a minimum of 12 months. Anonymized aggregate usage statistics may be retained indefinitely.
We use cookies and similar technologies to authenticate sessions, remember preferences, and collect analytics data. We do not use advertising trackers or sell data to ad networks.
We use session cookies (deleted when you close your browser) and persistent cookies (stored for a defined period) for authentication and preferences. Most browsers allow you to refuse cookies; note that some features may not function without them.
We implement industry-standard security measures including TLS encryption in transit, access controls, and regular security reviews. Our API endpoints are protected by rate limiting and authentication controls. Sensitive operations require multi-factor authentication where supported.
No system is perfectly secure. If we become aware of a security breach affecting your data, we will notify you as required by applicable law.
Depending on your jurisdiction, you may have rights including:
To exercise any of these rights, contact us at privacy@apparently.com. We will respond within 30 days. We may require verification of your identity before processing certain requests. Note that deletion requests cannot be honored for information that has already been submitted to a regulatory authority or that we are required by law to retain.
Apparently is based in the United States. If you access our services from outside the U.S., your information will be transferred to and processed in the United States. For users in the European Economic Area, United Kingdom, or other jurisdictions with data transfer restrictions, we rely on standard contractual clauses or other appropriate transfer mechanisms.
If you are located in the EEA or UK, you have additional rights under the GDPR / UK GDPR, including the right to lodge a complaint with your local supervisory authority.
Our services are intended for business users and are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date. For material changes, we will provide additional notice (e.g., by email).
Questions or concerns about this Privacy Policy? Contact our privacy team at privacy@apparently.com.