How Amplaro collects, uses, stores and protects personal information.
Last updated: 20 July 2026
Amplaro ("Amplaro", "we", "us", "our") provides a software platform that helps franchise brands (head office) prepare local advertising campaigns and lets their franchise partners launch those campaigns for their own stores. This policy explains what personal information we collect through our website and platform, how we use it, who we share it with, and the choices and rights you have. Amplaro is operated from Australia and handles personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and, where it applies, the EU and UK General Data Protection Regulation (GDPR).
Amplaro is a multi-tenant platform. For the personal information a franchise brand and its partners put into the platform (for example store details and campaign data), that brand is the data controller and Amplaro acts as a processor on its behalf, under our agreement with them. For the information we collect directly through our public website and for running Amplaro as a business, we are the controller. If you are a franchise partner or store user, questions about your data are usually best directed to your head office first, and you can also contact us.
When an account is created for you, we store your name, email address, role (head office or franchise partner), the stores you are linked to, and a securely hashed password. We never store passwords in readable form.
Head office users add store details such as store name, address, city, geographic coordinates, the linked social pages, and the franchisee's registered company name and business number (Eg: ABN). This is used to target and label local campaigns and to produce billing statements.
To create campaigns on your behalf, we store the identifiers of the ad accounts and pages you connect (for example Meta ad account and Page IDs, Google Ads customer IDs) and the access tokens or credentials you provide. These credentials are encrypted at rest and are used only to operate campaigns you set up. You keep ownership of your own ad accounts and billing.
We store the campaigns you build and launch and the performance figures (such as spend, impressions, clicks, orders, revenue and return) that we retrieve from the connected advertising platforms to show your reporting.
Like most online services, our servers automatically record technical information such as IP address, browser type, pages requested and timestamps, for security, troubleshooting and to keep the service reliable.
If you contact us through the website or by email, we keep your message and contact details so we can respond and keep a record of the enquiry.
The Amplaro platform uses a single essential cookie to keep you signed in during your session. It is required for the service to work and is not used for advertising or cross-site tracking. Our public marketing website does not set advertising or third-party tracking cookies. You can clear cookies in your browser at any time, though doing so will sign you out of the platform.
Where the GDPR applies, we rely on: performance of a contract (to provide the service to you or your organisation); our legitimate interests (to run, secure and improve the platform, balanced against your rights); your consent where we ask for it; and compliance with legal obligations.
We do not sell personal information. We share it only as needed to run the service:
We protect information with measures including encryption in transit (HTTPS), encryption at rest for sensitive credentials such as ad-platform tokens, access controls that separate one organisation's data from another's, security headers, and regular encrypted backups. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any issue.
We keep personal information for as long as your organisation's account is active and as needed to provide the service, and then for a reasonable period to meet legal, tax and audit obligations, after which it is deleted or anonymised. If an account is closed, we will delete or return the associated data in line with our agreement with the organisation, subject to any retention the law requires.
Amplaro is operated from Australia and some of our service providers (for example hosting, email and the advertising platforms) may process data in other countries. Where personal information is transferred across borders, we take reasonable steps to ensure it is handled consistently with this policy and applicable law.
Depending on where you live, you may have rights to access the personal information we hold about you, ask us to correct it, request deletion, object to or restrict certain processing, and request a copy in a portable format. Australian users have rights of access and correction under the Australian Privacy Principles. To exercise a right, contact us using the details below. If your data was entered by a franchise brand using Amplaro, we may direct your request to that organisation, as they control that information. You can also complain to your local privacy regulator (in Australia, the Office of the Australian Information Commissioner).
Amplaro is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.
We may update this policy from time to time. When we make material changes we will update the date above and, where appropriate, notify account administrators. Continued use of the service after an update means you accept the revised policy.
For any privacy question or request, contact us at hello@amplaro.com or through our contact page.
Amplaro is operated from Australia. This page describes our current practices for the Amplaro platform and website.