Privacy policy
Effective · Version 1.1
This policy explains which personal data Buyerfly processes when you visit our website, use the app, build and publish sites, and pay for a plan. It also explains your rights.
1. Controller and contact
The controller for account, billing, security, and website data is Nikolaus Redl, Kleistgasse 18/41, 1030 Vienna, Austria. Buyerfly is a product of this business. VAT ID: ATU82884407.
Send privacy requests to contact@supercenter.app. We have not appointed a data protection officer, because our current activities do not meet the criteria that require one.
2. Our role for customer content
For account, billing, security, and website data, we act as an independent controller.
Customers use Buyerfly to build websites for their own business. For the content of these sites, chat messages, attachments, and contact-form messages, the customer decides the purpose, and we act as the processor of the customer. Our Data processing agreement sets out the Article 28 GDPR terms for this processing.
If you visit or contact a site that a customer built with Buyerfly, the business that runs that site is responsible for your data, and its own privacy policy applies. Contact that business first.
3. Data, purposes, and legal bases
Account and workspace
- Data
- Name, email address, profile picture (with Google sign-in only), workspace name, membership, role, and invites. When an Agency workspace connects a SCIM directory, the directory also sends user names, email addresses, and group memberships.
- Purpose
- Create your account, give you access to your workspace, and send service emails.
- Legal basis
- Contract with you (Art. 6(1)(b) GDPR). For members that a workspace invites, our and the customer's legitimate interest in giving the team access (Art. 6(1)(f) GDPR).
Sign-in and security
- Data
- Sign-in codes (stored only as a hash), session records with IP address and browser, rate-limit records with IP addresses, and the audit log of the workspace.
- Purpose
- Sign you in, keep accounts safe, stop abuse, and show workspace owners and admins who changed what.
- Legal basis
- Contract, and our legitimate interest in a secure service (Art. 6(1)(f) GDPR).
Sites, chats, and files
- Data
- Chat messages and AI replies, attachments, site code and texts, versions, media files, form and domain settings, preview error logs, and a record of each AI call (model, tokens, and cost).
- Purpose
- Build, preview, save, and publish your sites, charge credits for AI work, and find errors.
- Legal basis
- Contract. For personal data in this content, we act as the processor of the customer (see section 2).
Billing and credits
- Data
- Plan, subscription status, Stripe customer and subscription references, invoices, credit grants and use, the settings of automatic top-ups with the time and the person who agreed to them, and payment records. Stripe collects the card details. We do not store full card numbers.
- Purpose
- Sell plans and credit packs, collect payments and tax, prevent double charges, and keep accounting records.
- Legal basis
- Contract, and our duties under tax and accounting law (Art. 6(1)(c) GDPR).
Support and emails
- Data
- Your emails to us, support requests, and the delivery records of the emails that we send from noreply@messages.supercenter.app.
- Purpose
- Answer you, and deliver sign-in codes, invites, and service messages.
- Legal basis
- Contract, and our legitimate interest in good support (Art. 6(1)(f) GDPR).
Visits to our website
- Data
- IP address, time, requested page, and browser data in the request logs of our host.
- Purpose
- Deliver the pages and keep the website secure.
- Legal basis
- Our legitimate interest in a working and secure website (Art. 6(1)(f) GDPR).
Analytics and marketing (only with your consent)
- Data
- A random browser ID, your user ID when you are signed in, the pages that you open and the actions that you take, the source of your visit (referrer, campaign parameters, and the click IDs of Google and Meta), browser and device data, IP address, and conversion events: sign-up, checkout, payment (plan and amount), and leads from our free tools. For Meta, a hashed form of your email address.
- Purpose
- With analytics consent: understand how people use our website and the app, and improve them (PostHog, Google Analytics). With marketing consent: measure our ads and show them to people who may need Buyerfly (Meta, Google Ads).
- Legal basis
- Your consent (Art. 6(1)(a) GDPR and § 165(3) TKG 2021). You can withdraw it at any time with Privacy choices at the bottom of each page.
You must give us your account data and, for paid plans, your billing data. Without them, we cannot provide the service.
4. AI processing
When you ask for a change, Buyerfly sends data to an AI model through Vercel AI Gateway. The model receives your chat message, earlier requests for the same site, the site files that the agent reads, your attachments, screenshots of preview pages, and the text of web pages that the agent loads. The default model today is Claude from Anthropic. We can change the model.
Pictures that the model receives are copies without metadata, such as camera and location data. When the agent puts an attachment on your site, Buyerfly stores a copy without this metadata.
When you name a public web page in the chat, Buyerfly loads it, directly or through Firecrawl, so that the agent can read it.
Do not put personal data into a chat message or an attachment unless your site needs it. The AI does not make decisions about people. It changes the code and the text of websites.
5. Contact forms on customer sites
Published sites can have contact forms. A form sends its message to Buyerfly, and Buyerfly emails it through Resend to the workspace member that the site owner chose. Buyerfly does not keep a copy of the message and does not show messages in an inbox. For this processing, we act as the processor of the business that runs the site.
To stop spam, we keep one record for each form and IP address: a counter and the start time of a 10-minute window. We delete these records within about 24 hours.
6. Recipients and service providers
We share personal data only when we need it to run, secure, or charge for the service, when you instruct us, or when the law requires it. We do not sell personal data. These providers receive personal data:
Vercel
- Purpose
- Hosting of the Buyerfly app and of each published site, serverless functions, the Sandboxes that run previews and AI edits, file storage (Vercel Blob), and AI Gateway, which sends requests to AI models.
- Data
- Request data such as IP address and browser, account and workspace data, site code and content, media files, chat attachments, and the requests to AI models.
- Role and location
- Processor. The app, the Sandboxes, and the media store run in Frankfurt, Germany. Vercel delivers published sites through its global network. Vercel Inc. is based in the United States.
- Safeguards
- Vercel DPA and EU Standard Contractual Clauses.
Neon
- Purpose
- PostgreSQL database.
- Data
- Account, workspace, sign-in, chat, version, billing, credit, and audit records.
- Role and location
- Processor. Frankfurt, Germany (AWS eu-central-1). Support can involve other locations.
- Safeguards
- Neon DPA and EU Standard Contractual Clauses where they apply.
GitHub
- Purpose
- Version history. The code of each site lives in a private repository of our GitHub organization.
- Data
- Site code, texts, links to media files, and commit messages that start with the text of each chat request.
- Role and location
- Processor. United States and other GitHub locations.
- Safeguards
- GitHub Data Protection Agreement, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.
AI model providers, through Vercel AI Gateway
- Purpose
- The AI model that reads each change request and changes the site. The default model today is Claude from Anthropic.
- Data
- Chat messages, the site files that the agent reads, attachments, screenshots of preview pages, and the text of web pages that the agent loads.
- Role and location
- Sub-processor through Vercel. United States and other locations of the model provider.
- Safeguards
- Vercel's contracts with the model providers and EU Standard Contractual Clauses.
Firecrawl
- Purpose
- Loads a public web page that a user names in the chat, so that the agent can read it.
- Data
- The address of the page. Firecrawl returns the content of the page.
- Role and location
- Processor. United States.
- Safeguards
- Data processing terms and EU Standard Contractual Clauses where they are required.
Resend
- Purpose
- Email delivery: sign-in codes, workspace invites, and the messages of contact forms on published sites.
- Data
- Recipient address, email content, and delivery records.
- Role and location
- Processor. United States and Resend sub-processor locations.
- Safeguards
- Resend DPA and EU Standard Contractual Clauses.
Stripe
- Purpose
- Checkout, subscriptions, invoices, tax calculation, card payments for automatic top-ups, and fraud prevention.
- Data
- Name, email address, billing address, VAT ID, payment details, and transaction records.
- Role and location
- Processor, and independent controller for some regulated payment activities. European Economic Area, United States, and other Stripe locations.
- Safeguards
- Stripe data processing terms and the transfer safeguards that apply.
PostHog (only with analytics consent)
- Purpose
- Product analytics for our website and the app: which pages and features people use, and where they leave.
- Data
- A random browser ID, your user ID when you are signed in, pages and actions, the source of the visit, browser and device data, and events such as sign-up and payment (plan and amount).
- Role and location
- Processor. European Union (PostHog EU cloud, Frankfurt).
- Safeguards
- PostHog DPA.
Google Analytics and Google Ads (only with consent)
- Purpose
- Website statistics with analytics consent. With marketing consent, also the measurement of our Google ads (which ad led to a sign-up or a payment).
- Data
- A random browser ID, pages and events, the source of the visit and the Google click ID, browser and device data, approximate location, and conversion events from our server with the same IDs.
- Role and location
- Processor for Google Analytics; for advertising features, Google can act as an independent controller. European Economic Area, United States, and other Google locations.
- Safeguards
- Google Ads Data Processing Terms, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.
Meta Platforms Ireland (only with marketing consent)
- Purpose
- The Meta Pixel and the Conversions API: measure our ads on Facebook and Instagram, and show our ads to people who may need Buyerfly.
- Data
- The browser IDs of Meta (_fbp, _fbc), pages and events, browser data, IP address, and for conversions from our server (sign-up, checkout, payment, lead) a hashed email address, the amount, and an event ID.
- Role and location
- Joint controller with us for the collection and transfer to Meta; Meta is the controller for its own use of the data. Ireland, United States, and other Meta locations.
- Safeguards
- Meta Business Tools Terms, the Controller Addendum, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.
Google (only with Google sign-in)
- Purpose
- Sign-in with a Google account, when we turn it on and you choose it.
- Data
- The name, email address, and profile picture of your Google account.
- Role and location
- Independent controller. European Economic Area, United States, and other Google locations.
- Safeguards
- Google terms, EU-US Data Privacy Framework, and the transfer safeguards that apply.
7. International transfers
Our app, our database, and the Sandboxes that run previews and edits are in Frankfurt, Germany. Some providers process data outside the European Economic Area, mainly in the United States. Where a country has no EU adequacy decision, we rely on the Standard Contractual Clauses of the European Commission and additional safeguards. Some providers are certified under the EU-US Data Privacy Framework. You can ask our privacy contact for information about the safeguards for a provider.
8. Retention
- Accounts and workspaces. We keep account, workspace, and membership records while the account or workspace exists. After it closes, we normally delete them within 30 days, unless the law requires us to keep them.
- Sites. We keep the chat, attachments, versions, and files of a site while the site exists, so that you can see its history and restore any version.
- Media files. A media file can belong to several versions and sites, so a removal on the Media screen does not delete the stored file. When you ask us to delete a file, we delete it unless another site still uses the same file.
- Sessions and sign-in codes. A session ends when you sign out, or 30 days after you last used Buyerfly. A sign-in code is valid for 10 minutes.
- Rate-limit records. We delete them automatically: sign-in records after a few minutes, and contact-form records within about 24 hours.
- Audit log. The audit log of a workspace stays after a member leaves or the workspace closes. We keep it while we need it to show what happened in the workspace, for example to defend legal claims.
- Billing records. We keep invoices, payment records, and tax records for the statutory period, which can be up to ten years in Austria.
- Analytics and marketing. We keep your consent choice for 3 years, to show that you agreed. We delete the analytics context of a browser 13 months after its last change, and the record of each event that our server sent 90 days after the delivery. Google Analytics keeps data for 14 months. PostHog and Meta keep data under their own rules.
- Logs and emails. Our host keeps request logs, and our email provider keeps sent emails and delivery records, for a limited time under their own retention rules.
- Backups. Deleted data stays in the backups of our database provider until these backups expire.
9. Security and support access
We use encrypted connections (TLS), encryption at rest at our providers, sign-in codes and directory tokens that we store only as hashes, role-based permissions, separate records for each workspace, private repositories, and isolated Sandboxes for site code. No service can guarantee complete security. If you think that your account or data is at risk, contact us at once.
Buyerfly staff can sign in to a customer account only for support, troubleshooting, or abuse checks. The audit log of the workspace records each such session, and the app shows a banner while it lasts.
10. Your rights
Under the GDPR, you can ask for access to your data, correction, deletion, restriction of processing, data portability, and information about recipients. You can object to processing that is based on legitimate interests. You can withdraw a consent at any time. The withdrawal does not affect processing that took place before it.
Send your request to contact@supercenter.app. We may need to confirm your identity. We normally answer within one month. When we process the data for a customer, we forward your request to that customer.
You can complain to the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, www.dsb.gv.at, or to the supervisory authority in the country where you live or work or where the infringement took place.
11. Cookies and similar technologies
Necessary storage keeps you signed in, keeps the editor working, and remembers your privacy choice. Under § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021), storage that is necessary for a service that you request needs no consent. Analytics and marketing storage is optional: it starts only after you agree in the banner or in Privacy choices, and a rejection does not limit Buyerfly in any way. If your browser sends Global Privacy Control, we treat it as a rejection. We host our fonts ourselves, so your browser does not contact Google Fonts.
Necessary storage:
Session
Cookie- Name
__Secure-better-auth.session_token- Purpose
- Keeps you signed in.
- Duration
- Until you sign out, or 30 days after you last used Buyerfly.
Session cache
Cookie- Name
__Secure-better-auth.session_data- Purpose
- A signed copy of your session, so that Buyerfly reads the database less often.
- Duration
- 60 seconds.
Google sign-in
Cookie- Name
__Secure-better-auth.state- Purpose
- Protects the sign-in with Google against forged requests. Only when you use Google sign-in.
- Duration
- 5 minutes.
Private preview
Cookie- Name
__Host-bf_preview- Purpose
- Opens the private preview of your site in the editor. The preview address of your site sets it.
- Duration
- 15 minutes. The editor renews it while you work.
Interface preferences
Local storage- Names
buyerfly:sidebar:widthbuyerfly:sidebar:collapsedbuyerfly:editor:chat-widthbuyerfly.edit-colors.<site ID>- Purpose
- Remembers the size of the sidebar and the chat panel, and your recent custom colors in edit mode.
- Duration
- Until you clear the storage of your browser.
Unsent chat message
Local storage- Name
buyerfly:draft:v1:<site ID>- Purpose
- Keeps a chat message that you have not sent yet, so that it survives a reload.
- Duration
- 7 days.
Preview connection
Session storage- Names
buyerfly-edit-noncebuyerfly-preview-nonce- Purpose
- Connects the preview to the editor tab.
- Duration
- Until you close the tab.
Privacy choices
Cookie and local storage- Names
bf_privacybuyerfly:privacy-consent:v1- Purpose
- Remembers your choice about analytics and marketing, so that the banner does not ask again.
- Duration
- 180 days. Then we ask again.
Optional storage, only after your consent:
Analytics ID
Analytics or marketing consent- Names
bf_contextbuyerfly:analytics-context:v1- Purpose
- A random ID that links the events of your browser with the events of our server, so that each one counts once.
- Duration
- The cookie: 180 days. The local storage entry: until you withdraw consent or clear the storage of your browser.
PostHog
Analytics consent- Names
ph_<project key>_posthog- Purpose
- Tells visits and sessions apart for product analytics.
- Duration
- 180 days.
Google Analytics
Analytics consent- Names
_ga_ga_<measurement ID>- Purpose
- Tells visitors and sessions apart for website statistics.
- Duration
- 180 days.
Meta Pixel
Marketing consent- Names
_fbp_fbc- Purpose
- Links visits and conversions to our ads on Facebook and Instagram. _fbc exists only after a click on an ad.
- Duration
- Up to 90 days.
Google Ads
Marketing consent- Names
_gcl_au_gcl_aw- Purpose
- Links conversions to clicks on our Google ads.
- Duration
- Up to 90 days.
With your consent, our server also sends conversion events (sign-up, checkout, payment, lead) to the tools that you agreed to, with the same event ID as your browser, so that each event counts once. Without your consent, our server sends nothing to these tools. You can change or withdraw your choice at any time with Privacy choices at the bottom of each page. A withdrawal stops the tools for the future and removes their storage in this browser where the browser allows it.
When you pay, the checkout and the customer portal are pages of Stripe. Stripe sets its own cookies there, as its privacy policy describes.
The sites that customers build are the responsibility of each customer. When a site owner adds trackers in Buyerfly, the site template shows a consent banner. The site loads the trackers only after consent, and it stores the choice of the visitor in the cookie and the local storage entry buyerfly-consent for 180 days.
12. Automated decisions and children
We do not make decisions about you that are based only on automated processing and that have legal or similarly significant effects. Buyerfly is for business users aged 18 or older. It is not directed at children.
13. Changes to this policy
We update this policy when our processing changes. We announce material changes in the app or by email to the account address. The effective date and the version at the top show the current text.