Data Processing Addendum
Last updated: August 19, 2026.
1. Roles
You (the Caply customer) are the controller of event and end-user data you submit. the operator of the Caply service available at trycaply.com is the processor. This DPA applies whenever we process personal data on your behalf through the Caply platform.
2. Subject matter
Processing conversion and diagnostic events so they can be delivered to Meta Conversions API, deduplicated, retried, and shown in your dashboard. Categories: identifiers (email, phone, name, location — hashed before Meta), technical data (IP, user agent, fbp/fbc), and commercial event parameters (value, currency, content ids).
3. Instructions
We process data only to provide the service: ingest, normalize, hash, queue, deliver to Meta using tokens you supply, log delivery, and meter usage. We will not sell this data or use it for our own advertising.
4. Security
Access tokens are encrypted at rest (AES-256-GCM). Source API keys are stored hashed. Transport is TLS. Access to production systems is limited to operators who need it.
5. Subprocessors
Hosting and data stores: Vercel, Supabase, Upstash. Payments: Stripe. Optional sign-in: Google. Optional browser scans: Browserless. Destination: Meta Platforms, Inc. We will not add a subprocessor that processes customer event payloads without updating this page.
6. Assistance and deletion
We will assist with data-subject requests that relate to data we store. After account deletion or a written request to privacy@trycaply.com, we will delete or anonymize event payloads within 30 days, except data we must keep for legal claims or tax.
7. International transfers
Where subprocessors process data outside the EEA/UK, transfers use SCCs or an equivalent mechanism published by that subprocessor.