ApolloUi
TourPricingFAQAbout UsContact
Sign inJoin early access

Apollo Privacy Policy

Last updated: 3 July 2026


This Privacy Policy explains how APOLLOUI LTD (Apollo, we, us, our) collects, uses and protects personal data in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

It applies to our public website, marketing communications, account registration, the Apollo workspace, the client portal, billing, and related platform operations.

This document does not mean Apollo is “GDPR compliant” as a marketing claim. It describes our current practices and commitments in plain language.

Related documents:

  • Terms and Conditions — contract for use of Apollo
  • Cookie Policy — cookies and similar technologies on our website
  • Data Processing Agreement (DPA) — tenant processor processing
  • Disclaimer — platform scope and limits

If you use Apollo on behalf of a photography business (a tenant), your organisation may also have its own privacy notices for its clients and staff. Where we process personal data on that business’s instructions, they are usually the data controller and we act as a data processor.


1. About this Privacy Policy

1.1 This Privacy Policy describes:

  • what personal data Apollo collects and uses;
  • our role as data controller or data processor in different situations;
  • who we share data with;
  • how long we keep data;
  • your rights and how to contact us.

1.2 Registering interest in Apollo (for example via our website or Mailchimp form) does not create a contract with us and does not guarantee access to the platform. A contract generally arises when you accept our Terms as part of account creation, invitation acceptance, or subscription checkout, as applicable.

1.3 We may update this Privacy Policy from time to time. The “Last updated” date at the top shows when it was last revised. Material changes will be communicated as appropriate (for example by email to account holders or a notice on our website).

1.4 This Privacy Policy is intended for business users and individuals who interact with Apollo in a business context (for example property photography businesses, their staff, and their clients using the client portal). Apollo is not directed at children.


2. Who we are

Apollo is operated by:

APOLLOUI LTD
A private limited company registered in England and Wales
Company number: 17093007
Registered office: 38 Mercer Avenue, Ebbsfleet Valley, Swanscombe, England, DA10 1BR

General contact: hello@apolloui.co.uk
Privacy contact: hello@apolloui.co.uk

We have not appointed a Data Protection Officer (DPO). For privacy matters, contact us at hello@apolloui.co.uk.


3. Scope of this policy

3.1 This Privacy Policy applies to personal data processed when you:

  • visit our public website and marketing pages (for example apolloui.co.uk);
  • register interest in early access;
  • create or use an Apollo account;
  • are invited to a tenant workspace or the client portal;
  • use the tenant workspace (/{tenantId}/… routes);
  • use the client portal (/client/… routes);
  • contact us for support or enquiries;
  • subscribe to Apollo or interact with our billing systems.

3.2 Out of scope for this document alone:

  • Tenant-controlled data. Personal data that a tenant uploads or generates about its clients, staff, orders, properties, and media is primarily controlled by that tenant business. Section 6 and section 21 explain how we process that data as a processor and how rights requests should be routed.
  • Third-party websites. If you follow a link to Mailchimp, Stripe, or another third party, their privacy policies apply on their sites.

3.3 Apollo is a software platform only. We do not provide photography services and we are not a marketplace.


4. Our role: controller and processor

4.1 Under UK GDPR, organisations may act as:

  • a controller — deciding why and how personal data is processed; or
  • a processor — processing personal data on the controller’s documented instructions.

4.2 In general:

SituationApollo’s usual roleWho the data subject relates to
Website visits, early-access marketing, our own billing with tenant owners, platform accounts, support requests to Apollo, security and operational logsControllerVisitors, prospective customers, account holders
Tenant workspace data (clients, orders, property details, messages, invoices, uploaded media, staff operational data)ProcessorTenant’s clients, contacts, staff — as determined by the tenant
Secure invitation emails and account onboarding sent by our systemsController for the email channel; processor for tenant-initiated invitationsInvitees
Client portal access to tenant-selected dataProcessor (data controlled by tenant); Controller for the portal user’s Apollo accountClient portal users

4.3 Where we act as a processor, processing is governed by our Terms, and where required by law, our DPA (see section 16).

4.4 Dual-role situations. A client portal user has an Apollo account (we are controller for account data) but much of what they see in the portal is tenant-controlled (tenant is controller). Section 12 and section 21 explain how to exercise rights in those cases.


5. Personal data we collect as controller

When Apollo is the controller, we may collect and use the categories below.

5.1 Website visitors

DataExamplesSource
Technical and usage dataIP address, browser type, device information, pages viewed, referral URL, date/time of accessAutomatically when you visit our site
Cookie/consent preferencesMarketing and preferences choices stored in your browserCookie banner on marketing pages

We do not currently use third-party analytics tools (such as Google Analytics) on our marketing website unless we update this policy or our Cookie Policy to say otherwise.

5.2 Early-access / register-interest contacts

DataExamplesSource
Contact detailsEmail address; name if you provide it on the Mailchimp formYou submit via Join early access / register-interest (external Mailchimp form or deliberate click-through)
List preferencesSubscription status, unsubscribe recordsMailchimp

You can join our early-access list without accepting marketing cookies on our website. The external register-interest link is a deliberate click that takes you to Mailchimp’s site, which has its own cookies and privacy notice.

5.3 Account users (workspace and portal)

DataExamplesSource
Identity and contactEmail address, display name, profile photo (if using Google sign-in), phone number (if added in settings)You; Firebase Authentication; Google OAuth if you choose it
Account metadataUser ID, account creation dateOur systems
Membership and accessTenant IDs, roles (for example OWNER, ADMIN, STAFF, EDITOR, CLIENT), permission overrides, membership statusInvitations, signup, tenant administration

5.4 Tenant owners and billing contacts

DataExamplesSource
Subscription and billing metadataStripe customer ID, subscription ID, price/plan identifiers, billing status, grace period dates, checkout session recordsStripe and our billing integration
Workspace settingsWorkspace name, tenant contact email, invoice remittance detailsTenant settings entered by OWNER/ADMIN

We do not store full payment card numbers. Payment instruments are handled by Stripe.

5.5 Invitations and platform email delivery

DataExamplesSource
Invitation recordsInvitee email, optional invited name, role, invitation status, hashed invitation token (not the raw link token)Tenant administrators; our invitation system
Email delivery logsRecipient, template type, delivery status, related invitation IDOur transactional email system

5.6 Support and enquiries

DataExamplesSource
Support requestsYour user ID, email, name, role, tenant ID (if applicable), message content, categoryWorkspace help form (stored in our systems; not all support channels send email today)
Email enquiriesWhatever you choose to sendEmail to hello@apolloui.co.uk

5.7 Security, authentication and platform operations

DataExamplesSource
Session dataAuthentication session via secure httpOnly cookie (__session)When you sign in
Preference cookiesPortal context preference, connection filter preference (where used)Your use of Apollo
Webhook and audit metadataStripe webhook event IDs and types, billing audit recordsStripe webhooks; platform operations
Hosting and security logsRequest logs, error logs, abuse-prevention signalsOur hosting and infrastructure providers

6. Personal data we process for tenants as processor

When a tenant uses Apollo, they upload or generate personal data about their business, clients, staff, and jobs. The tenant is usually the controller for that data. Apollo processes it as a processor to provide the platform on the tenant’s instructions (as described in our Terms and, where applicable, our DPA).

Categories include:

CategoryExamples of personal data
CRM — clients, branches, contactsClient and branch names, billing email and address, agent names and emails, linkage to portal users
Orders and diaryProperty addresses, postcodes, access notes, on-site contact name/phone/email, scheduling, assigned staff
Messages and notesIn-app order messages, threads, operational notes
Invoices and payments (tenant side)Client billing context, amounts, due dates, settlement status; payment record metadata (not card numbers)
Staff and freelancersStaff directory entries, availability, service capabilities, and operational compensation/payment-status metadata where used
Uploaded media and filesPhotographs, video, floorplans, documents — may show people, property interiors, and identifying details
Client portal exposureData the tenant chooses to make visible to a client user for a selected client/branch context
Order and workflow auditEvent types, user IDs, timestamps, workflow metadata

We process this data to host, display, transmit, back up, secure, and operate the features the tenant uses — and as otherwise described in our Terms, our DPA where applicable, and documented product behaviour.

Tenants are responsible for:

  • having a lawful basis to collect and upload personal data;
  • providing privacy information to their clients and staff;
  • responding to data subject requests for tenant-controlled data;
  • configuring access controls, portal scope, and delivery rules appropriately.

7. How we collect personal data

We collect personal data through:

7.1 Direct interactions — when you register interest, create an account, accept an invitation, update profile or tenant settings, submit a support request, or email us.

7.2 Automated technologies — when you visit our website (server and hosting logs), sign in (session cookies), or use optional marketing cookies if you consent (see section 10).

7.3 Third-party sign-in — if you use Google to authenticate, we receive information from Google consistent with your Google account settings (for example email and basic profile information).

7.4 Tenant and authorised users — when a tenant administrator invites you, creates client records, creates orders, uploads files, or assigns work.

7.5 Payment providers — Stripe provides us with billing identifiers and subscription status when a tenant subscribes or manages billing. We do not receive full card details from Stripe in our database.

7.6 Service providers — subprocessors listed in section 16 may process personal data on our behalf as part of delivering the platform.


8. Why we use personal data and lawful bases

UK GDPR requires a lawful basis for processing. The main bases we rely on are:

PurposeTypical dataLawful basis (controller processing)Notes
Provide and operate Apollo accounts and the platformAccount, membership, session, workspace accessContractNecessary to perform our contract with the tenant or user
Subscription billing and fraud preventionBilling metadata, Stripe IDs, webhook logsContract; Legal obligation (tax/accounting where applicable); Legitimate interests (billing integrity)Stripe handles payment instruments
Secure invitations and authentication emailsInvitee email, delivery logsContract; Legitimate interests (security, onboarding)Fail-closed invite delivery
Website hosting, security, abuse preventionIP, logs, technical dataLegitimate interests (secure, reliable service)Balanced against user rights
Early-access / marketing communicationsEmail, name, list statusConsent (where required for marketing); Legitimate interests (B2B pre-contract enquiries where applicable)Register-interest is a deliberate sign-up action
Marketing cookies (Mailchimp popup on our site)Cookie identifiers, browsing signals on our siteConsentLoaded only if you accept marketing cookies
Support requests and enquiriesContact details, message contentLegitimate interests; Contract (supporting customers)
Comply with law and defend legal claimsRelevant recordsLegal obligation; Legitimate interests
Processor processing for tenantsTenant workspace data (section 6)Tenant’s lawful basis — Apollo processes on documented instructions as processorSee DPA where applicable

Where we rely on legitimate interests, we do so where our interests are not overridden by your rights. You may object in certain cases (see section 20).

Where we rely on consent, you may withdraw it at any time (for example marketing cookies via Cookie settings, or marketing emails via Mailchimp unsubscribe). Withdrawal does not affect processing already carried out.


9. Marketing and early-access communications

9.1 Early access / register interest. We offer a Join early access path on our website. This typically links to a Mailchimp hosted form (mailchi.mp/apolloui.co.uk/website or equivalent). When you submit that form, Mailchimp and Apollo receive the details you provide. This is separate from browsing our website with marketing cookies rejected.

9.2 Mailchimp connected-site popup. If you accept marketing cookies on our website, Mailchimp may show an optional early-access prompt while you browse. If you reject marketing cookies, that script does not load on our site. You can change your choice via Cookie settings in our website footer.

9.3 Lawful basis. For our early-access and marketing list, we rely on consent where required for marketing communications, and may rely on legitimate interests for B2B pre-contract enquiries where applicable. You may unsubscribe at any time.

9.4 Unsubscribe. Marketing emails from our list should include an unsubscribe mechanism operated by Mailchimp. You may also contact hello@apolloui.co.uk.

9.5 No tenant marketing automation in MVP. Apollo’s product documentation describes future tenant operational emails (orders, invoices, reminders). Automated tenant-to-client email campaigns are not described as live in the current product. This Privacy Policy focuses on Apollo-controlled marketing unless we publish an update.


10. Cookies and similar technologies

10.1 We use cookies and similar technologies on our public marketing website and in the authenticated application where needed for operation.

10.2 As implemented on our marketing website today:

  • Marketing cookies default to off. On public marketing pages and the signed-out home page, we show a cookie banner with Accept all, Reject non-essential, and Manage preferences.
  • Mailchimp connected-site popup. The Mailchimp popup script loads only if you accept marketing cookies. If you reject non-essential cookies, that script does not load on our site.
  • Join early access without marketing cookies. Our external Join early access / register-interest link remains available at all times. It is a deliberate click that takes you to Mailchimp’s hosted form and does not require you to accept marketing cookies on our website.
  • Cookie settings. You can reopen and change your choices at any time via Cookie settings in the website footer (on marketing pages).

10.3 Summary of main categories:

CategoryPurposeEssential?More detail
EssentialSecurity, session authentication, basic site deliveryYesIncludes httpOnly session cookie when you sign in
PreferencesRemember display settings (for example light/dark theme) on your deviceOptional preferenceFirst-party; see Cookie Policy
MarketingMailchimp connected-site popup on our marketing pagesNo — consent requiredConsent-gated; not loaded unless you accept marketing cookies

10.4 Application cookies. Signed-in users may receive additional httpOnly preference cookies (for example portal context selection). These support your use of the service and are described further in our Cookie Policy.

10.5 Full details, retention, and third-party cookie information are set out in our Cookie Policy.


11. Payments and billing

11.1 Apollo subscription (tenant pays Apollo). Paid workspace plans are billed via Stripe. Apollo is the merchant of record for Apollo subscriptions. We store billing metadata (for example Stripe customer and subscription IDs, plan/status, checkout audit records). Stripe stores payment methods and processes charges.

11.2 Tenant–client payments (optional / future-facing). Our product roadmap includes optional Stripe Connect features so tenants may collect payments from their clients. Where enabled, the tenant is typically merchant of record for those client payments. Apollo does not store client card numbers in tenant invoice records.

11.3 Billing communications. Subscription-related emails (for example payment failed, cancellation) may be sent by Apollo via our email providers when those features are enabled.

11.4 For payment provider privacy practices, see Stripe’s privacy notice. We use Stripe in accordance with their terms and applicable data protection requirements.


12. Client portal users

12.1 If you are a client portal user (for example an estate agent contact accessing orders, invoices, or deliverables for a photography company), you typically receive access because a tenant invited you or linked your account to their client record.

12.2 What you may see depends on the tenant’s configuration and your role. It may include orders, invoices, messages, branch contacts, and downloadable media for the selected client/branch context only.

12.3 Who controls your data.

  • For personal data about you as a contact of the photography business (for example your name, email, and role at the client organisation), the tenant photography business is usually the controller.
  • For your Apollo account (login email, profile fields you edit, session), Apollo is usually the controller.

12.4 Privacy information from your photography company. The tenant should provide you with their own privacy notice for their services. Apollo’s platform privacy notice does not replace that.

12.5 Rights requests. If your request relates to how the photography company uses your data (for example CRM records, order history, or invoices), contact the photography company first. If your request relates to your Apollo login account or Apollo’s platform processing, contact hello@apolloui.co.uk. See section 21.

12.6 Bulk downloads. The client portal may offer bounded export/download features (for example ZIP downloads of deliverables). Exports may be time-limited. This is not a full self-service data portability export of all tenant-held data.


13. Staff, editors, collaborators and invited users

13.1 Tenant administrators may invite staff, editors, collaborators, and client users by email. Invitations use a secure token system; we store a hash of the invitation token, not the raw link token.

13.2 We send invitation and account-setup emails through our transactional email provider (Amazon SES when configured). Email delivery outcomes may be logged.

13.3 If you are invited, we process your email address and optional invited name to enable access. The tenant decides who to invite. Apollo provides the secure delivery mechanism.

13.4 Collaborators (tenant-to-tenant connections) involve access rules defined by product configuration. Collaborators should not automatically receive broad access to another tenant’s business data beyond what the product explicitly allows.


14. Uploaded files, property media and order data

14.1 Tenants and authorised users upload and generate media and documents (photographs, video, floorplans, previews, deliverables) and enter property and job information (addresses, access instructions, on-site contacts).

14.2 Files and order data may include personal data, and in limited cases may reveal sensitive information, depending on what tenants upload or record. Tenants are responsible for ensuring they have a lawful basis and appropriate notices for the data they collect and upload.

14.3 Files are stored in cloud storage (Google Firebase / Cloud Storage) with access controls enforced by authentication, membership roles, and server-side authorization. Time-limited signed URLs may be used for downloads.

14.4 Apollo may retain file binaries and metadata as part of providing the service until deleted in accordance with tenant actions, retention settings, and section 18.


15. Who we share personal data with

We share personal data only where necessary, including with:

15.1 Subprocessors and infrastructure providers — see section 16.

15.2 Tenants and authorised users — workspace data is visible to users according to role and tenant configuration (for example OWNER, ADMIN, STAFF, client portal scope).

15.3 Payment providers — Stripe for subscriptions and, where enabled, Connect payments.

15.4 Professional advisers — lawyers, accountants, or insurers where required.

15.5 Regulators and law enforcement — when required by law or to protect rights, safety, and security.

15.6 Business transfers — if Apollo or its assets are acquired, personal data may transfer subject to appropriate safeguards and notice where required.

We do not sell personal data.


16. Subprocessors and service providers

We use trusted third parties to run Apollo. They process personal data on our instructions (as processors) or as independent controllers for their own services (for example when you visit Stripe or Mailchimp directly).

ProviderRoleTypical data processed
Google Firebase / Google CloudAuthentication, database (Firestore), file storage, cloud functionsAccount, workspace, and file data; auth tokens
VercelWebsite and application hosting, CDN, serverless executionIP addresses, request metadata, application traffic
StripeApollo subscriptions; optional Connect for tenant client paymentsBilling identity, payment method data (held by Stripe), transaction metadata
Mailchimp (Intuit)Early-access list; optional marketing popup (with consent)Email, name, marketing preferences, site interaction signals when consented
Amazon Web Services (Amazon SES)Transactional email (invitations and platform email when configured)Recipient email, message content for delivery
Google (OAuth)Optional sign-in with GoogleEmail, basic profile per Google settings

We may also use a business email provider for hello@apolloui.co.uk enquiry mailboxes.

Not currently active as subprocessors for live product features: accounting exports (for example Xero), tenant operational email fan-out for orders/invoices, third-party analytics on the marketing site. We will update this list before enabling such features.

A standalone subprocessor list is in section 16 above and in our DPA Annex 3.


17. International transfers

17.1 Personal data may be processed in the UK, EEA and other countries where our service providers operate.

17.2 We do not claim that all personal data is stored only in the UK.

17.3 Where UK GDPR requires safeguards for transfers outside the UK, we rely on appropriate safeguards under UK data protection law, which may include UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), Addendum to EU Standard Contractual Clauses, or another valid transfer mechanism.

17.4 You may contact hello@apolloui.co.uk for more information about transfers relevant to your relationship with Apollo.


18. How long we keep personal data

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required by law.

Tenant workspace data. We generally retain tenant workspace data for a limited period after closure or cancellation to allow recovery and export, after which it may be deleted or anonymised unless we need to retain it for legal, billing, security, or dispute reasons. Deletion and export may be handled manually and are not necessarily automated.

Other categories:

Data categoryTypical retention approach
Apollo subscription billing and accounting recordsUp to 7 years where required for tax, accounting, or legal purposes
Tenant invoice/payment records in ApolloGoverned by tenant business needs and our DPA as processor
Account dataWhile the account is active; deletion on request where applicable
Support requestsGenerally up to 24 months unless needed longer for disputes or security
Invitation records and email delivery logsGenerally up to 12 months unless needed longer for security or audit
Security and audit logsGenerally 12–24 months depending on log type
Marketing list data (Mailchimp)Until you unsubscribe/withdraw consent or the list is cleaned up
Cookie consent preferencesStored locally in your browser until you clear site data or change preferences

When data is deleted, it may persist in encrypted backups for a limited period before being overwritten.


19. Security

19.1 We implement appropriate technical and organisational measures for a B2B SaaS platform, including measures designed to:

  • encrypt data in transit (HTTPS/TLS);
  • restrict access by role and tenant membership;
  • validate authentication server-side and use secure session cookies;
  • hash invitation tokens at rest;
  • enforce tenant isolation in application logic and database rules;
  • log certain security and billing events.

19.2 No system is completely secure. You are responsible for maintaining the confidentiality of your credentials, using strong passwords, and notifying us promptly if you suspect unauthorised access.

19.3 If we become aware of a personal data breach affecting tenant data we process as a processor, we will notify affected tenants in accordance with applicable law and our DPA, where applicable.


20. Your data protection rights

Under UK GDPR, individuals may have the following rights, subject to conditions and exemptions:

RightSummary
AccessObtain a copy of personal data we hold about you
RectificationCorrect inaccurate personal data
ErasureRequest deletion in certain circumstances
RestrictionRequest limited processing in certain circumstances
ObjectionObject to processing based on legitimate interests or direct marketing
PortabilityReceive personal data you provided in a structured, commonly used format, where applicable
Withdraw consentWhere processing is based on consent (for example marketing cookies)

20.1 How to exercise your rights (Apollo as controller). Use our public data protection requests and complaints form, or email hello@apolloui.co.uk. You do not have to use the form or prescribed wording. We may need to verify your identity. We aim to respond within one month, as required by UK GDPR.

20.2 Manual processes. Self-service account deletion, full workspace export, and automated DSAR tooling may be limited or unavailable. We handle valid requests manually where our systems allow. We will not promise instant deletion where operational steps are required.

20.3 Marketing preferences. Use Cookie settings on our marketing site for marketing cookies. Use Mailchimp unsubscribe links or contact us for marketing emails.

20.4 Complaints. See section 24.


21. Requests involving tenant-controlled data

21.1 If your request relates to personal data processed by Apollo on a tenant’s instructions (for example your details as a client contact on an order, property access information, or invoice data held in a tenant workspace):

21.1.1 Contact the tenant photography business first — they are usually the controller.

21.1.2 The tenant may ask Apollo to assist with technical steps (access, export, restriction, deletion) as processor. We will support tenants as required by law and our DPA, where applicable.

21.2 If you are unsure whether Apollo or the tenant holds your data, contact hello@apolloui.co.uk and we will help route your request.

21.3 Apollo client portal users should read section 12 alongside this section.


22. Children

Apollo is a business platform and is not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact hello@apolloui.co.uk and we will take appropriate steps.


23. Changes to this policy

We may update this Privacy Policy to reflect changes in law, our services, or our data practices. The updated version will be posted with a revised Last updated date. Where changes are material, we will provide additional notice as appropriate.


24. Complaints and ICO

24.1 If you have concerns about how we handle personal data, please contact us first using our data protection requests and complaints form or hello@apolloui.co.uk so we can try to resolve the issue. You do not have to use the form.

24.2 You can also complain to the Information Commissioner’s Office (ICO), the UK data protection regulator: https://ico.org.uk

We would appreciate the opportunity to address your concerns before you contact the ICO, but you may contact the ICO at any time.


25. Contact us

For privacy questions, data protection rights requests, or notices to Apollo:

Web form: Data protection requests and complaints
Email: hello@apolloui.co.uk
Post: APOLLOUI LTD, 38 Mercer Avenue, Ebbsfleet Valley, Swanscombe, England, DA10 1BR

Related documents: Terms and Conditions · Cookie Policy · Data Processing Agreement · Disclaimer

ApolloUi

Built for property photographers by property photographers. Early access for UK property photography businesses. No payment today.

Apollo runs in the browser and is accessible from any modern device with an internet connection.

Product

  • Tour
  • Pricing
  • FAQ
  • Join early access

Company

  • About Us
  • Contact

Account

  • Sign in

© 2026 ApolloUI Ltd. All rights reserved.

TermsPrivacyData protectionCookies

Built in the UK for UK property photography businesses.