Legal

Privacy Policy

How we collect, use, and share personal data — and your rights.

Last updated: 2026-08-15

1. What this policy covers

This Privacy Policy describes how SupportHub, Inc. ("we", "us", or "our") collects, uses, and shares personal data when you use our customer-support platform (the "Service") and when your visitors interact with the widget you embed on your website.

It applies to data we collect as a data controller (account-level data, billing data) and as a data processor on your behalf (your visitors' conversations, transcripts, contact details that flow through the Service).

2. Data we collect

  • Account data — name, email, organization, profile photo, authentication credentials (we never store your password in plaintext).
  • Billing data — billing address, tax ID, last four digits of your card, billing history. Card numbers are stored by our payment processor (Stripe); we never see full numbers.
  • Usage data — IP address, browser type, pages viewed, timestamps, error reports.
  • Content data — articles, training data, canned responses, macros, automations you upload.
  • Visitor data — name, email, phone, conversation transcripts, IP, and any custom fields you collect. We process this data on your behalf; you are the controller of that data.

3. How we use data

  • To operate and improve the Service (the lawful basis under GDPR is "contract" for account data and "legitimate interest" for usage data).
  • To train and operate the AI models that power the chatbot, voice agent, and content studio. We never train our base models on your data, but we do use your data as input to a hosted inference API.
  • To respond to support requests, billing inquiries, and security incidents.
  • To comply with legal obligations and respond to lawful requests from authorities.

4. Subprocessors

We share your data with a small set of subprocessors to operate the Service. Before launch, replace this list with the actual list of subprocessors you use and notify your customers of changes.

  • Stripe — payment processing.
  • OpenAI / Anthropic / OpenRouter — large-language-model inference for the chatbot and content studio.
  • Your hosting provider (currently a Dokploy-managed VPS or equivalent) — database, application server, file storage.
  • Resend, Postmark, or your SMTP provider — outbound transactional email.
  • Sentry or equivalent — error reporting and performance monitoring.

5. Cookies and similar technologies

We use cookies and local storage for authentication (so you stay signed in) and for product analytics (so we can see which features are used). We do not use third-party advertising cookies.

A full cookie-by-cookie breakdown lives on our Cookie Policy page.

6. Data retention

We retain your account data for as long as your account is active. If you cancel, we delete your account data within 30 days unless we are required to retain it (for example, to satisfy a tax audit or to comply with a legal hold).

Visitor conversation data is retained according to your plan's retention window. You can configure shorter retention from the workspace settings.

7. Your rights (GDPR, CCPA, and similar)

You can request access, correction, deletion, or export of your personal data from the account settings page or by emailing [email protected]. We respond within 30 days.

If you are a California resident, you have the right to opt out of the sale or sharing of your personal data. We do not sell or share your personal data with third parties for advertising purposes.

If you are an EU / UK / Swiss resident, you have the right to lodge a complaint with your local data-protection authority.

8. International transfers

We process data in the United States and the European Union. When we transfer personal data from the EU/UK to the US, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Contact us for a copy.

9. Security

We encrypt data in transit (TLS 1.2+) and at rest (AES-256). Access to production data is limited to authorized engineers and is logged. We run annual third-party security reviews and maintain a published status page.

If you discover a vulnerability, please email [email protected] (replace with your real security contact).

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to this policy

If we make material changes, we will notify you by email and by posting a banner in the product at least 30 days before the change takes effect.

12. Contact

Privacy inquiries: [email protected]. We respond within 30 days.


Questions about this document? Email [email protected] (replace with your real legal contact email before launch).