Skip to content
buyerfly

Privacy policy

Effective · Version 1.1

This policy explains which personal data Buyerfly processes when you visit our website, use the app, build and publish sites, and pay for a plan. It also explains your rights.

1. Controller and contact

The controller for account, billing, security, and website data is Nikolaus Redl, Kleistgasse 18/41, 1030 Vienna, Austria. Buyerfly is a product of this business. VAT ID: ATU82884407.

Send privacy requests to contact@supercenter.app. We have not appointed a data protection officer, because our current activities do not meet the criteria that require one.

2. Our role for customer content

For account, billing, security, and website data, we act as an independent controller.

Customers use Buyerfly to build websites for their own business. For the content of these sites, chat messages, attachments, and contact-form messages, the customer decides the purpose, and we act as the processor of the customer. Our Data processing agreement sets out the Article 28 GDPR terms for this processing.

If you visit or contact a site that a customer built with Buyerfly, the business that runs that site is responsible for your data, and its own privacy policy applies. Contact that business first.

3. Data, purposes, and legal bases

Account and workspace

Data
Name, email address, profile picture (with Google sign-in only), workspace name, membership, role, and invites. When an Agency workspace connects a SCIM directory, the directory also sends user names, email addresses, and group memberships.
Purpose
Create your account, give you access to your workspace, and send service emails.
Legal basis
Contract with you (Art. 6(1)(b) GDPR). For members that a workspace invites, our and the customer's legitimate interest in giving the team access (Art. 6(1)(f) GDPR).

Sign-in and security

Data
Sign-in codes (stored only as a hash), session records with IP address and browser, rate-limit records with IP addresses, and the audit log of the workspace.
Purpose
Sign you in, keep accounts safe, stop abuse, and show workspace owners and admins who changed what.
Legal basis
Contract, and our legitimate interest in a secure service (Art. 6(1)(f) GDPR).

Sites, chats, and files

Data
Chat messages and AI replies, attachments, site code and texts, versions, media files, form and domain settings, preview error logs, and a record of each AI call (model, tokens, and cost).
Purpose
Build, preview, save, and publish your sites, charge credits for AI work, and find errors.
Legal basis
Contract. For personal data in this content, we act as the processor of the customer (see section 2).

Billing and credits

Data
Plan, subscription status, Stripe customer and subscription references, invoices, credit grants and use, the settings of automatic top-ups with the time and the person who agreed to them, and payment records. Stripe collects the card details. We do not store full card numbers.
Purpose
Sell plans and credit packs, collect payments and tax, prevent double charges, and keep accounting records.
Legal basis
Contract, and our duties under tax and accounting law (Art. 6(1)(c) GDPR).

Support and emails

Data
Your emails to us, support requests, and the delivery records of the emails that we send from noreply@messages.supercenter.app.
Purpose
Answer you, and deliver sign-in codes, invites, and service messages.
Legal basis
Contract, and our legitimate interest in good support (Art. 6(1)(f) GDPR).

Visits to our website

Data
IP address, time, requested page, and browser data in the request logs of our host.
Purpose
Deliver the pages and keep the website secure.
Legal basis
Our legitimate interest in a working and secure website (Art. 6(1)(f) GDPR).

Analytics and marketing (only with your consent)

Data
A random browser ID, your user ID when you are signed in, the pages that you open and the actions that you take, the source of your visit (referrer, campaign parameters, and the click IDs of Google and Meta), browser and device data, IP address, and conversion events: sign-up, checkout, payment (plan and amount), and leads from our free tools. For Meta, a hashed form of your email address.
Purpose
With analytics consent: understand how people use our website and the app, and improve them (PostHog, Google Analytics). With marketing consent: measure our ads and show them to people who may need Buyerfly (Meta, Google Ads).
Legal basis
Your consent (Art. 6(1)(a) GDPR and § 165(3) TKG 2021). You can withdraw it at any time with Privacy choices at the bottom of each page.

You must give us your account data and, for paid plans, your billing data. Without them, we cannot provide the service.

4. AI processing

When you ask for a change, Buyerfly sends data to an AI model through Vercel AI Gateway. The model receives your chat message, earlier requests for the same site, the site files that the agent reads, your attachments, screenshots of preview pages, and the text of web pages that the agent loads. The default model today is Claude from Anthropic. We can change the model.

Pictures that the model receives are copies without metadata, such as camera and location data. When the agent puts an attachment on your site, Buyerfly stores a copy without this metadata.

When you name a public web page in the chat, Buyerfly loads it, directly or through Firecrawl, so that the agent can read it.

Do not put personal data into a chat message or an attachment unless your site needs it. The AI does not make decisions about people. It changes the code and the text of websites.

5. Contact forms on customer sites

Published sites can have contact forms. A form sends its message to Buyerfly, and Buyerfly emails it through Resend to the workspace member that the site owner chose. Buyerfly does not keep a copy of the message and does not show messages in an inbox. For this processing, we act as the processor of the business that runs the site.

To stop spam, we keep one record for each form and IP address: a counter and the start time of a 10-minute window. We delete these records within about 24 hours.

6. Recipients and service providers

We share personal data only when we need it to run, secure, or charge for the service, when you instruct us, or when the law requires it. We do not sell personal data. These providers receive personal data:

Vercel

Purpose
Hosting of the Buyerfly app and of each published site, serverless functions, the Sandboxes that run previews and AI edits, file storage (Vercel Blob), and AI Gateway, which sends requests to AI models.
Data
Request data such as IP address and browser, account and workspace data, site code and content, media files, chat attachments, and the requests to AI models.
Role and location
Processor. The app, the Sandboxes, and the media store run in Frankfurt, Germany. Vercel delivers published sites through its global network. Vercel Inc. is based in the United States.
Safeguards
Vercel DPA and EU Standard Contractual Clauses.

Neon

Purpose
PostgreSQL database.
Data
Account, workspace, sign-in, chat, version, billing, credit, and audit records.
Role and location
Processor. Frankfurt, Germany (AWS eu-central-1). Support can involve other locations.
Safeguards
Neon DPA and EU Standard Contractual Clauses where they apply.

GitHub

Purpose
Version history. The code of each site lives in a private repository of our GitHub organization.
Data
Site code, texts, links to media files, and commit messages that start with the text of each chat request.
Role and location
Processor. United States and other GitHub locations.
Safeguards
GitHub Data Protection Agreement, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.

AI model providers, through Vercel AI Gateway

Purpose
The AI model that reads each change request and changes the site. The default model today is Claude from Anthropic.
Data
Chat messages, the site files that the agent reads, attachments, screenshots of preview pages, and the text of web pages that the agent loads.
Role and location
Sub-processor through Vercel. United States and other locations of the model provider.
Safeguards
Vercel's contracts with the model providers and EU Standard Contractual Clauses.

Firecrawl

Purpose
Loads a public web page that a user names in the chat, so that the agent can read it.
Data
The address of the page. Firecrawl returns the content of the page.
Role and location
Processor. United States.
Safeguards
Data processing terms and EU Standard Contractual Clauses where they are required.

Resend

Purpose
Email delivery: sign-in codes, workspace invites, and the messages of contact forms on published sites.
Data
Recipient address, email content, and delivery records.
Role and location
Processor. United States and Resend sub-processor locations.
Safeguards
Resend DPA and EU Standard Contractual Clauses.

Stripe

Purpose
Checkout, subscriptions, invoices, tax calculation, card payments for automatic top-ups, and fraud prevention.
Data
Name, email address, billing address, VAT ID, payment details, and transaction records.
Role and location
Processor, and independent controller for some regulated payment activities. European Economic Area, United States, and other Stripe locations.
Safeguards
Stripe data processing terms and the transfer safeguards that apply.

PostHog (only with analytics consent)

Purpose
Product analytics for our website and the app: which pages and features people use, and where they leave.
Data
A random browser ID, your user ID when you are signed in, pages and actions, the source of the visit, browser and device data, and events such as sign-up and payment (plan and amount).
Role and location
Processor. European Union (PostHog EU cloud, Frankfurt).
Safeguards
PostHog DPA.

Google Analytics and Google Ads (only with consent)

Purpose
Website statistics with analytics consent. With marketing consent, also the measurement of our Google ads (which ad led to a sign-up or a payment).
Data
A random browser ID, pages and events, the source of the visit and the Google click ID, browser and device data, approximate location, and conversion events from our server with the same IDs.
Role and location
Processor for Google Analytics; for advertising features, Google can act as an independent controller. European Economic Area, United States, and other Google locations.
Safeguards
Google Ads Data Processing Terms, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.

Meta Platforms Ireland (only with marketing consent)

Purpose
The Meta Pixel and the Conversions API: measure our ads on Facebook and Instagram, and show our ads to people who may need Buyerfly.
Data
The browser IDs of Meta (_fbp, _fbc), pages and events, browser data, IP address, and for conversions from our server (sign-up, checkout, payment, lead) a hashed email address, the amount, and an event ID.
Role and location
Joint controller with us for the collection and transfer to Meta; Meta is the controller for its own use of the data. Ireland, United States, and other Meta locations.
Safeguards
Meta Business Tools Terms, the Controller Addendum, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.

Google (only with Google sign-in)

Purpose
Sign-in with a Google account, when we turn it on and you choose it.
Data
The name, email address, and profile picture of your Google account.
Role and location
Independent controller. European Economic Area, United States, and other Google locations.
Safeguards
Google terms, EU-US Data Privacy Framework, and the transfer safeguards that apply.

7. International transfers

Our app, our database, and the Sandboxes that run previews and edits are in Frankfurt, Germany. Some providers process data outside the European Economic Area, mainly in the United States. Where a country has no EU adequacy decision, we rely on the Standard Contractual Clauses of the European Commission and additional safeguards. Some providers are certified under the EU-US Data Privacy Framework. You can ask our privacy contact for information about the safeguards for a provider.

8. Retention

  • Accounts and workspaces. We keep account, workspace, and membership records while the account or workspace exists. After it closes, we normally delete them within 30 days, unless the law requires us to keep them.
  • Sites. We keep the chat, attachments, versions, and files of a site while the site exists, so that you can see its history and restore any version.
  • Media files. A media file can belong to several versions and sites, so a removal on the Media screen does not delete the stored file. When you ask us to delete a file, we delete it unless another site still uses the same file.
  • Sessions and sign-in codes. A session ends when you sign out, or 30 days after you last used Buyerfly. A sign-in code is valid for 10 minutes.
  • Rate-limit records. We delete them automatically: sign-in records after a few minutes, and contact-form records within about 24 hours.
  • Audit log. The audit log of a workspace stays after a member leaves or the workspace closes. We keep it while we need it to show what happened in the workspace, for example to defend legal claims.
  • Billing records. We keep invoices, payment records, and tax records for the statutory period, which can be up to ten years in Austria.
  • Analytics and marketing. We keep your consent choice for 3 years, to show that you agreed. We delete the analytics context of a browser 13 months after its last change, and the record of each event that our server sent 90 days after the delivery. Google Analytics keeps data for 14 months. PostHog and Meta keep data under their own rules.
  • Logs and emails. Our host keeps request logs, and our email provider keeps sent emails and delivery records, for a limited time under their own retention rules.
  • Backups. Deleted data stays in the backups of our database provider until these backups expire.

9. Security and support access

We use encrypted connections (TLS), encryption at rest at our providers, sign-in codes and directory tokens that we store only as hashes, role-based permissions, separate records for each workspace, private repositories, and isolated Sandboxes for site code. No service can guarantee complete security. If you think that your account or data is at risk, contact us at once.

Buyerfly staff can sign in to a customer account only for support, troubleshooting, or abuse checks. The audit log of the workspace records each such session, and the app shows a banner while it lasts.

10. Your rights

Under the GDPR, you can ask for access to your data, correction, deletion, restriction of processing, data portability, and information about recipients. You can object to processing that is based on legitimate interests. You can withdraw a consent at any time. The withdrawal does not affect processing that took place before it.

Send your request to contact@supercenter.app. We may need to confirm your identity. We normally answer within one month. When we process the data for a customer, we forward your request to that customer.

You can complain to the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, Austria, www.dsb.gv.at, or to the supervisory authority in the country where you live or work or where the infringement took place.

11. Cookies and similar technologies

Necessary storage keeps you signed in, keeps the editor working, and remembers your privacy choice. Under § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021), storage that is necessary for a service that you request needs no consent. Analytics and marketing storage is optional: it starts only after you agree in the banner or in Privacy choices, and a rejection does not limit Buyerfly in any way. If your browser sends Global Privacy Control, we treat it as a rejection. We host our fonts ourselves, so your browser does not contact Google Fonts.

Necessary storage:

Session

Cookie
Name
__Secure-better-auth.session_token
Purpose
Keeps you signed in.
Duration
Until you sign out, or 30 days after you last used Buyerfly.

Session cache

Cookie
Name
__Secure-better-auth.session_data
Purpose
A signed copy of your session, so that Buyerfly reads the database less often.
Duration
60 seconds.

Google sign-in

Cookie
Name
__Secure-better-auth.state
Purpose
Protects the sign-in with Google against forged requests. Only when you use Google sign-in.
Duration
5 minutes.

Private preview

Cookie
Name
__Host-bf_preview
Purpose
Opens the private preview of your site in the editor. The preview address of your site sets it.
Duration
15 minutes. The editor renews it while you work.

Interface preferences

Local storage
Names
buyerfly:sidebar:widthbuyerfly:sidebar:collapsedbuyerfly:editor:chat-widthbuyerfly.edit-colors.<site ID>
Purpose
Remembers the size of the sidebar and the chat panel, and your recent custom colors in edit mode.
Duration
Until you clear the storage of your browser.

Unsent chat message

Local storage
Name
buyerfly:draft:v1:<site ID>
Purpose
Keeps a chat message that you have not sent yet, so that it survives a reload.
Duration
7 days.

Preview connection

Session storage
Names
buyerfly-edit-noncebuyerfly-preview-nonce
Purpose
Connects the preview to the editor tab.
Duration
Until you close the tab.

Privacy choices

Cookie and local storage
Names
bf_privacybuyerfly:privacy-consent:v1
Purpose
Remembers your choice about analytics and marketing, so that the banner does not ask again.
Duration
180 days. Then we ask again.

Optional storage, only after your consent:

Analytics ID

Analytics or marketing consent
Names
bf_contextbuyerfly:analytics-context:v1
Purpose
A random ID that links the events of your browser with the events of our server, so that each one counts once.
Duration
The cookie: 180 days. The local storage entry: until you withdraw consent or clear the storage of your browser.

PostHog

Analytics consent
Names
ph_<project key>_posthog
Purpose
Tells visits and sessions apart for product analytics.
Duration
180 days.

Google Analytics

Analytics consent
Names
_ga_ga_<measurement ID>
Purpose
Tells visitors and sessions apart for website statistics.
Duration
180 days.

Meta Pixel

Marketing consent
Names
_fbp_fbc
Purpose
Links visits and conversions to our ads on Facebook and Instagram. _fbc exists only after a click on an ad.
Duration
Up to 90 days.

Google Ads

Marketing consent
Names
_gcl_au_gcl_aw
Purpose
Links conversions to clicks on our Google ads.
Duration
Up to 90 days.

With your consent, our server also sends conversion events (sign-up, checkout, payment, lead) to the tools that you agreed to, with the same event ID as your browser, so that each event counts once. Without your consent, our server sends nothing to these tools. You can change or withdraw your choice at any time with Privacy choices at the bottom of each page. A withdrawal stops the tools for the future and removes their storage in this browser where the browser allows it.

When you pay, the checkout and the customer portal are pages of Stripe. Stripe sets its own cookies there, as its privacy policy describes.

The sites that customers build are the responsibility of each customer. When a site owner adds trackers in Buyerfly, the site template shows a consent banner. The site loads the trackers only after consent, and it stores the choice of the visitor in the cookie and the local storage entry buyerfly-consent for 180 days.

12. Automated decisions and children

We do not make decisions about you that are based only on automated processing and that have legal or similarly significant effects. Buyerfly is for business users aged 18 or older. It is not directed at children.

13. Changes to this policy

We update this policy when our processing changes. We announce material changes in the app or by email to the account address. The effective date and the version at the top show the current text.