Privacy Policy
Last updated: August 27, 2026
At Super44, we believe your data is your business β literally. This policy explains what we collect, why, and what you can do about it. We've kept it in plain language because legal jargon helps nobody.
Who We Are
Super44 GmbH is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR and Data Protection Act 2018.
- Company: Super44 GmbH
- Address: Rheinwerkallee 6, 53227 Bonn, Germany
- Commercial register: Amtsgericht Bonn, HRB 30568
- Managing Director: Alexander Riesenkampff
- Email: hello@super44.ai
What Data We Collect
We only collect what we need to make Super44 useful for you. Here's the full list:
- Email address β collected when you sign up via Clerk authentication
- Name (if provided) β collected during sign-up
- Business name β you enter this during onboarding
- Business address / location β entered once during setup so we can tailor insights to your area
- Chat messages and conversation history β everything you ask Super44 and the responses you get
- POS / sales transaction data β pulled from your point-of-sale system when you connect it
- Google Business Profile data β when you connect or authorize a profile, we access relevant account, location, profile, review and performance data to provide profile management and, where authorized, connect your business locations to your advertising account
- Receipt images and expense data β photos of receipts you upload and the details extracted from them (amount, supplier, VAT, category) when you use receipt capture
- Gmail access (read-only) β if you connect your Gmail inbox for receipt capture, we read emails solely to detect receipts and invoices. Access is read-only and revocable at any time
- Staffing data β when your business enables Superstaff, we process staff names, roles, contact details where supplied, date of birth, employment classification and legal status, employment start date, agreed rates and weekly hours, holiday-pay method, leave-year start and vacation entitlements, right-to-work and onboarding-compliance evidence, availability, schedules, time-off and swap requests, clock and timesheet records, kiosk/device information, and payroll-export data on the business's instructions
- Billing and subscription data β when you choose a paid plan, Stripe collects your payment method, billing address and any tax details and processes the transaction. We receive and store subscription, invoice and payment-status data, and Stripe customer identifiers, but not your full card number or security code.
- Device information (OS, app version) β collected automatically when you use the app
- Crash logs and performance data β collected automatically to help us fix bugs and keep the app stable
- Mobile product analytics β account and user identifiers (including email), app and device details, and interactions with product features in the Super44 and Superstaff mobile apps, used to understand adoption, troubleshoot and improve the services
- Advertising measurement data β only with your marketing consent, selected page, lead, chat-start and registration events may include first-party advertising identifiers, IP address and browser information, and a hashed email address for Meta, OpenAI and TikTok conversion measurement
Why We're Allowed to Process Your Data
Under GDPR, we need a legal basis for every type of processing. Here's ours:
- Account creation, AI chat, business analytics, POS analysis, receipt capture, and Business Profile monitoring and management β Contract performance (Art. 6(1)(b)). You signed up for these features, and we need your data to deliver them.
- Superstaff β for business owners, providing the staffing service is contract performance (Art. 6(1)(b)). For staff information supplied by a business, that business is the controller and Super44 acts as processor under our Data Processing Agreement; the business determines its lawful basis and provides required notices to staff.
- Crash reporting and app stability β Legitimate interest (Art. 6(1)(f)). We have a legitimate interest in keeping the app running smoothly.
- Service-related email communication β Legitimate interest (Art. 6(1)(f)). This includes security alerts, billing notifications, essential product updates, and AI-generated notifications you've requested (such as reminders or scheduled task results). We don't send marketing emails under this basis.
- Subscription management and payment processing β Contract performance (Art. 6(1)(b)). Statutory invoice, tax and accounting records are retained where required by law (Art. 6(1)(c)); payment security and fraud prevention may also rely on our legitimate interests (Art. 6(1)(f)). Stripe determines its own legal bases where it acts as an independent controller.
- Mobile product analytics and operational product events β Legitimate interest (Art. 6(1)(f)). We use these events in the Super44 and Superstaff mobile apps to understand feature adoption, troubleshoot and improve the services. They are not used for cross-site advertising, and you may object to this processing.
- Optional website analytics and advertising measurement β Consent (Art. 6(1)(a)). These website technologies remain off until you choose to enable them, and you can withdraw consent at any time.
Who Else Handles Your Data
We work with a small number of trusted service providers and other recipients to run Super44. Where a provider processes data on our behalf, an appropriate Data Processing Agreement (DPA) is in place; some regulated providers also act as independent controllers for specific purposes.
- Clerk (clerk.com) β handles authentication and user management. Based in the USA, protected by EU Standard Contractual Clauses (SCCs).
- AWS (primary application region eu-central-1, Frankfurt) β hosts our servers, databases, file storage, and AI model processing (Anthropic Claude via Amazon Bedrock). Application data is primarily hosted in the EEA. AI processing uses Bedrock EU and global cross-region inference profiles; configured global failover may process data outside the EEA or UK, protected by the applicable transfer safeguards described below.
- Upstash β provides the EU-hosted vector database used to store and retrieve conversation content.
- Langfuse β receives filtered AI observability traces, including the AI request and response data needed to diagnose and improve Super44's behaviour.
- Vercel β hosts and delivers the Super44 web applications and processes request, device and deployment-log data.
- Stripe (Stripe Payments Europe, Limited and relevant Stripe affiliates) β provides hosted Checkout, subscription billing, payment processing, invoicing, tax calculation, refunds, payment authentication, fraud prevention and security. Stripe receives billing, transaction, payment-method, device and technical data. Stripe acts partly as our processor and partly as an independent controller for regulated payment services, fraud prevention, legal compliance and its own service operations. Stripe may process data in the USA under the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses. See https://stripe.com/privacy.
- Google (OAuth, Business Profile APIs, Gmail API) β handles Google account authorization, provides connected Business Profile data, and β only if you connect it β reads your Gmail inbox for receipt detection (read-only access). Based in the USA, protected by EU Standard Contractual Clauses (SCCs).
- Twilio and Meta Platforms Ireland β process phone numbers, message content and delivery metadata when you choose to use Super44 through WhatsApp.
- Slack β receives limited account and operational-notification data so our team can support activations, source cutovers and service operations; staffing records are not sent to Slack.
- BetterStack β error and crash reporting to keep the service reliable. EU hosting.
- Sentry β application error and performance diagnostics for the web and mobile apps. Diagnostic events are minimised and must not contain staffing schedules, pay details or chat content.
- Expo β mobile app delivery services, including device push tokens and push-notification delivery for Super44 and Superstaff. Notification content is minimised.
- PostHog β signed-in product analytics and operational product events in the Super44 and Superstaff mobile apps; website and web-app analytics, and routing of conversion events to Meta, OpenAI and TikTok, only with the relevant consent. EU hosting (EU Cloud). Not used for cross-site tracking.
- Meta Platforms Ireland Ltd. β advertising measurement and relevant audiences (Meta Pixel and Conversions API), only with your marketing consent. We may share campaign page views, the start of an anonymous chat and account registration, together with technical identifiers (cookie IDs, IP address and browser information) and a hashed email address. We never send chat content or business names to Meta. Transfers to Meta in the USA are protected by the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses (SCCs).
- OpenAI Ireland Ltd. β advertising conversion measurement and relevant audiences (OpenAI Ads Pixel and Conversions API), only with your marketing consent. We may share page views, accepted lead requests, the start of an anonymous chat and account registration, together with first-party advertising identifiers, IP address and browser information, and a hashed email address. We never send chat content or business names to OpenAI. OpenAI generally processes conversion data as an independent controller under its Conversion Terms and Ad Tools Data Processing Addendum. Transfers to countries without an adequate level of protection rely on EU Standard Contractual Clauses (SCCs) unless another valid transfer mechanism applies.
- TikTok Technology Limited (Ireland) β advertising conversion measurement and relevant audiences (TikTok Pixel and Events API), only with your marketing consent. We may share page views, accepted lead requests, the start of an anonymous chat and account registration, together with first-party advertising identifiers, IP address and browser information, and a hashed email address. We never send chat content or business names to TikTok. TikTok acts as an independent controller for this data under its Business Products (Data) Terms. Transfers to countries without an adequate level of protection rely on EU Standard Contractual Clauses (SCCs) unless another valid transfer mechanism applies.
Use of Google API Data
Super44's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Business Profile data is used only to provide features authorized by you. This may include retrieving profile and performance information and publishing profile updates or review replies when specifically authorized.
Gmail data is accessed read-only and used solely to identify and import supplier invoices and receipts into your own expense records. It is never used for advertising, sold, or used to train generalized AI models. Humans only see this data with your explicit consent, for security reasons, or where required by law.
You can disconnect Super44's Google access at any time in the app, or revoke the Google grant at myaccount.google.com/permissions. Disconnecting in the app deletes the authorization token we hold, so we can no longer reach your inbox; revoking at myaccount.google.com additionally withdraws the grant on Google's side. Disconnecting Gmail does not delete invoices and receipts already imported into your expense records. Account closure and deletion requests are handled under the retention rules below.
How Long We Keep Your Data
We don't keep data longer than we need to.
- Active account β your data is retained for as long as your subscription is active.
- After account deletion β personal and business data that we do not need to retain is deleted within 30 days. Invoice, payment, tax and accounting records may be retained for the statutory period, then deleted or anonymized. Stripe may retain data independently where required for payment regulation, fraud prevention, legal claims or other legal obligations. Anonymized, aggregated analytics may be retained.
- Chat history β kept for the life of your account. You can delete individual conversations at any time.
- POS data β cached while your integration is connected. Deleted when you disconnect the integration or delete your account.
- Superstaff data β retained while the business account uses staff management and deleted or returned on the business's instruction or account deletion, subject to any legal retention the business requires and the backup period below.
- Beta enrollment evidence β the feature, business, requesting account, channel, time, conversation and message references, and accepted Terms/DPA versions are retained as needed to prove authorisation and the contract and to resolve disputes, subject to applicable limitation and record-keeping periods. We do not store another copy of the confirmation text in this record.
- Backups β any backups containing your personal data are purged within 90 days of a deletion request.
Your Rights Under GDPR and UK GDPR
You have strong rights over your data under the GDPR and UK GDPR (Articles 15β22). Here's what you can do:
- Access (Art. 15) β request a copy of all personal data we hold about you.
- Rectification (Art. 16) β ask us to correct any inaccurate data.
- Erasure (Art. 17) β ask us to delete all your data (the "right to be forgotten").
- Restriction (Art. 18) β ask us to limit processing while a complaint is being resolved.
- Data portability (Art. 20) β receive your data in a structured, machine-readable format.
- Objection (Art. 21) β object to processing based on our legitimate interest.
- Automated decision-making (Art. 22) β Super44's AI provides suggestions and insights only. We don't make automated decisions that have legal or similarly significant effects on you.
To exercise any of these rights, email us at hello@super44.ai. We'll respond within 30 days. You also have the right to lodge a complaint with your local data protection authority. For Super44, this is the Landesbeauftragte fΓΌr Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). For data Stripe processes as an independent controller, you may also contact Stripe through its privacy channels.
International Data Transfers
Your application data is primarily processed in the EEA β our primary AWS region is Frankfurt (eu-central-1). Some providers and partners, including AWS Bedrock, Clerk, Google, Stripe, Twilio, Meta, Langfuse, Vercel, Slack, Sentry, Expo, OpenAI and TikTok, may also process data in the USA or other countries. Bedrock AI processing prefers EU cross-region inference profiles where available, with configured global cross-region failover for resilience; global routing may process data outside the EEA or UK. Transfers are protected by an applicable adequacy framework where available and/or the relevant EU Standard Contractual Clauses, UK International Data Transfer Agreement or UK Addendum. UK-to-EEA processing relies on the UK's current EEA adequacy regulations while they apply. Stripe may transfer data to Stripe, LLC and its affiliates or subprocessors as needed to provide payment services. We do not transfer data without appropriate safeguards.
Cookies and Tracking
The Super44 and Superstaff mobile apps do not use cookies or third-party advertising SDKs. They use Sentry and BetterStack for reliability telemetry, Expo for push delivery, and PostHog EU Cloud for signed-in product analytics and operational product events. This in-app processing is described under our legitimate interests above and is separate from website cookie choices. On our website and web app, optional analytics uses PostHog to understand product usage. Optional marketing uses the Meta, OpenAI Ads and TikTok Pixels and Conversions APIs to measure campaigns and create relevant audiences; selected conversion events are routed through PostHog. These website technologies may set or read first-party advertising cookies and identifiers. The website analytics and marketing choices are separate, remain off until you consent, and do not affect Super44's functionality. When you choose a paid plan, you are redirected to Stripe's hosted Checkout, where Stripe may use necessary cookies and device signals for payment authentication, security and fraud prevention. These are not advertising cookies set by Super44. You can change your optional website analytics and marketing choices at any time through Cookie Settings in the footer or Privacy settings in the web app, and you may object to signed-in product analytics by contacting us.
Children's Data
Super44 is a business tool and is not directed at children under 16, who may not independently create a business account. A business using Superstaff may provide data about a young worker, including someone under 16 where their employment is lawful. In that case the business is the controller and Super44 processes the data only on its instructions under the Data Processing Agreement; the business is responsible for employment-law safeguards and notices. If we learn that a child's data was submitted outside that business-controlled staffing context, we will delete it promptly.
Changes to This Policy
If we make material changes to this policy, we'll notify you via in-app notification and/or email. This page always shows the current version with the "Last updated" date at the top. Continued use of Super44 after we notify you of changes means you accept the updated policy. Where required, we'll ask for your consent again.
Data Protection Contact
We're a small team and haven't appointed a formal Data Protection Officer (this isn't required for most SMEs under Art. 37 GDPR). For any data protection questions, requests, or concerns, reach out to us directly at hello@super44.ai.