AK_top.one AK_top.one
Terms of Service Home

AK_top.one · Legal

Privacy Policy

Effective date: 22 September 2026 · Last updated: 06 October 2026

This Privacy Policy describes how AK_top.one (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit https://www.aktop.one/, create an account, request a quote, join a waitlist, purchase or receive any service, or otherwise use our platform.

1. Controller and contact

The controller within the meaning of Art. 4(7) GDPR is Ismail Aldahik, sole trader trading as “AK_top.one”, Moerser Straße 214, 47198 Duisburg, Germany, email info@aktop.one (see also our Legal notice). We are not required to appoint a data protection officer.

AK_top.one operates the website and customer platform. For privacy requests, write to info@aktop.one, use the contact form at https://www.aktop.one/#contact with the subject “Privacy”, or reply to an official AK_top.one account / invoice email.

2. Scope of services covered

This Policy applies to the whole AK_top.one platform, including without limitation:

  • Google Maps review management and reply agents
  • Website design and related digital delivery
  • Website / listing management and maintenance
  • Appointment and booking systems
  • Shop pages and orders
  • Advertising / local campaign services
  • Support, waitlists for services in preparation, and customer accounts
  • Any future service launched under the same brand and domain, unless a separate notice is published

3. Data we collect

3.1 Identity and account

  • Name, company, email, phone, country, postal address
  • Password (stored as a one-way hash only)
  • Language preference, signup path/referrer, account role and staff permissions (if applicable)
  • Google Sign-In data when you choose it (email, name, Google subject id)

3.2 Commercial and billing

  • Cart/order contents, selected plans, options, service configuration you submit
  • Subscription status, invoices, promo/gift codes, payment method choice
  • Payment references from PayPal or other enabled processors (we do not store full card numbers)
  • Time-limited access links sent by email for order or account follow-up
  • Contract evidence for each order: the version of the Terms of Service you accepted, your declarations at checkout (including any request that we start the service before the withdrawal period ends), the language of the checkout, date and time, and the IP address and browser user agent used for the order, together with the order, contract and withdrawal confirmations we send to you

3.3 Service delivery data

  • Business assets you provide (for example Maps URLs, websites, branding notes, booking details, campaign goals)
  • Operational logs needed to deliver, support, and improve the ordered service
  • Where a service connects to Google Business Profile or similar APIs after your explicit authorisation: OAuth tokens, listing identifiers, and content required to perform the authorised actions (such as reading reviews and posting replies)
  • Where AI drafting is enabled for a service: content snippets needed to generate drafts for that service only

3.4 Website, security, and support

  • Visit metadata (path, language, referrer, user agent, hashed IP for abuse limits)
  • Contact-form messages and waitlist emails
  • Cookies / local storage for session, language, and checkout helpers

3.5 Shop orders

Shop orders and the messages on an order are stored so the shop can receive the order, then removed after the retention window. AK_top.one does not open these orders, sell them, or use them. We receive only our service fees and have no part in the goods money.

4. Why we use data

  • Provide accounts, authentication, and customer areas
  • Fulfil every ordered or gifted service across the catalogue
  • Process payments, invoices, trials, renewals, and cancellations
  • Communicate service, security, and contractual notices
  • Prevent fraud, spam, and unauthorised access
  • Improve reliability, quality, and security of the platform
  • Comply with legal and accounting obligations

We do not sell personal data.

5. Google API data and Limited Use

When a service uses Google APIs (Sign-In and/or Business Profile features you authorise), AK_top.one’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Google user data is used only to provide or improve user-facing features that are clear in that service.
  • It is not used for advertising, credit decisions, or unrelated profiling.
  • It is not transferred for third parties’ independent use, except as needed to operate hosting/security or as required by law.
  • Human access is limited to security, compliance, support you request, or data you already made public.
  • You may revoke Google access in your Google Account; when a connected service ends we stop automation and clear stored connection credentials for that connection.

6. Legal bases

  • Contract — delivering accounts and purchased services
  • Legitimate interests — security, abuse prevention, service improvement
  • Consent — optional offers email where collected; third-party authorisations you approve
  • Legal obligation — tax, accounting, and regulatory duties

In terms of the GDPR: contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (for example invoices under § 147 AO and § 14b UStG, confirmations under § 312f BGB); legitimate interests — Art. 6(1)(f), including keeping contract evidence to establish, exercise or defend legal claims, such as customer complaints, PayPal disputes and chargebacks; consent — Art. 6(1)(a), which you may withdraw at any time with effect for the future.

7. Processors and sharing

We share data only as needed to run the platform, for example:

  • Payment processors (e.g. PayPal), including the order and delivery evidence we submit when a payment is disputed or reversed
  • Google (Sign-In / APIs you authorise)
  • Email delivery / SMTP providers
  • Contact-form provider (Formspree)
  • Hosting and infrastructure providers
  • AI or tooling providers configured for a specific service draft/automation task

We may disclose data if required by law or to protect rights, safety, and security.

8. Retention

  • Account and commercial records: while active and as required for invoices, disputes, and law
  • Invoices and accounting records: 8 or 10 years, as required by German tax and commercial law (§ 147 AO, § 257 HGB)
  • Contract evidence (accepted Terms version, checkout declarations, timestamps, IP address and user agent at checkout): for the term of the contract and 3 years after the end of the year in which it ended (§§ 195, 199 BGB); longer only while a dispute or claim is still open
  • Service delivery records: for the life of the engagement and a reasonable support/audit period
  • Connected API tokens: only while the connection is authorised and the related service is live
  • Security rate-limit data: short windows

9. Security

We apply measures appropriate to the platform: HTTPS, hashed passwords, staff permission controls, ownership checks on sensitive actions, and secrets kept off the public web root. No system is perfectly secure.

10. Your rights and data deletion

Depending on your location, you may request access, correction, deletion, restriction, portability, or objection. You may also update your profile in your account and revoke third-party authorisations at the provider.

Where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence or place of work; the authority competent for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de.

For a clear deletion path (including Google Sign-In / Google API data), use our Data deletion request page, or the contact form with the subject “Data deletion”.

11. Children

The platform is intended for businesses and adults. We do not knowingly collect data from children under 16.

12. International transfers

Data may be processed in countries where our providers operate (hosting, Google, PayPal, email). We select reputable processors and apply appropriate contractual/security steps.

13. Changes

We may update this Policy. The “Last updated” date will change; material changes may be notified by email or site notice.

Related: Terms of Service · Right of withdrawal · Legal notice · Data deletion · aktop.one

© AK_top.one · Privacy Terms Withdrawal Legal notice Cancel contracts here Data deletion