Privacy Policy

Last updated: July 28, 2026

At Super44, we believe your data is your business — literally. This policy explains what we collect, why, and what you can do about it. We've kept it in plain language because legal jargon helps nobody.

Who We Are

Super44 GmbH is the data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR).

  • Company: Super44 GmbH
  • Address: Rheinwerkallee 6, 53227 Bonn, Germany
  • Commercial register: Amtsgericht Bonn, HRB 30568
  • Managing Director: Alexander Riesenkampff
  • Email: hello@super44.ai

What Data We Collect

We only collect what we need to make Super44 useful for you. Here's the full list:

  • Email address — collected when you sign up via Clerk authentication
  • Name (if provided) — collected during sign-up
  • Business name — you enter this during onboarding
  • Business address / location — entered once during setup so we can tailor insights to your area
  • Chat messages and conversation history — everything you ask Super44 and the responses you get
  • POS / sales transaction data — pulled from your point-of-sale system when you connect it
  • Google Business Profile data — when you connect or authorize a profile, we access relevant account, location, profile, review and performance data to provide profile management and, where authorized, connect your business locations to your advertising account
  • Receipt images and expense data — photos of receipts you upload and the details extracted from them (amount, supplier, VAT, category) when you use receipt capture
  • Gmail access (read-only) — if you connect your Gmail inbox for receipt capture, we read emails solely to detect receipts and invoices. Access is read-only and revocable at any time
  • Billing and subscription data — when you choose a paid plan, Stripe collects your payment method, billing address and any tax details and processes the transaction. We receive and store subscription, invoice and payment-status data, and Stripe customer identifiers, but not your full card number or security code.
  • Device information (OS, app version) — collected automatically when you use the app
  • Crash logs and performance data — collected automatically to help us fix bugs and keep the app stable
  • Advertising measurement data — only with your marketing consent, selected page, lead, chat-start and registration events may include first-party advertising identifiers, IP address and browser information, and a hashed email address for Meta and OpenAI conversion measurement

Why We're Allowed to Process Your Data

Under GDPR, we need a legal basis for every type of processing. Here's ours:

  • Account creation, AI chat, business analytics, POS analysis, receipt capture, and Business Profile monitoring and management — Contract performance (Art. 6(1)(b)). You signed up for these features, and we need your data to deliver them.
  • Crash reporting and app stability — Legitimate interest (Art. 6(1)(f)). We have a legitimate interest in keeping the app running smoothly.
  • Service-related email communication — Legitimate interest (Art. 6(1)(f)). This includes security alerts, billing notifications, essential product updates, and AI-generated notifications you've requested (such as reminders or scheduled task results). We don't send marketing emails under this basis.
  • Subscription management and payment processing — Contract performance (Art. 6(1)(b)). Statutory invoice, tax and accounting records are retained where required by law (Art. 6(1)(c)); payment security and fraud prevention may also rely on our legitimate interests (Art. 6(1)(f)). Stripe determines its own legal bases where it acts as an independent controller.
  • Optional product analytics and advertising measurement — Consent (Art. 6(1)(a)). These technologies remain off until you choose to enable them, and you can withdraw consent at any time.

Who Else Handles Your Data

We work with a small number of trusted service providers and other recipients to run Super44. Where a provider processes data on our behalf, an appropriate Data Processing Agreement (DPA) is in place; some regulated providers also act as independent controllers for specific purposes.

  • Clerk (clerk.com) — handles authentication and user management. Based in the USA, protected by EU Standard Contractual Clauses (SCCs).
  • AWS (eu-central-1, Frankfurt) — hosts our servers, databases, file storage, and AI model processing (Anthropic Claude via AWS Bedrock). Your data stays in the EU.
  • Stripe (Stripe Payments Europe, Limited and relevant Stripe affiliates) — provides hosted Checkout, subscription billing, payment processing, invoicing, tax calculation, refunds, payment authentication, fraud prevention and security. Stripe receives billing, transaction, payment-method, device and technical data. Stripe acts partly as our processor and partly as an independent controller for regulated payment services, fraud prevention, legal compliance and its own service operations. Stripe may process data in the USA under the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses. See https://stripe.com/privacy.
  • Google (OAuth, Business Profile APIs, Gmail API) — handles Google account authorization, provides connected Business Profile data, and — only if you connect it — reads your Gmail inbox for receipt detection (read-only access). Based in the USA, protected by EU Standard Contractual Clauses (SCCs).
  • BetterStack — error and crash reporting to keep the service reliable. EU hosting.
  • PostHog — product analytics on the website and web app (not the mobile app), and routing of consented conversion events to Meta and OpenAI. EU hosting (EU Cloud). Not used for cross-site tracking.
  • Meta Platforms Ireland Ltd. — advertising measurement and relevant audiences (Meta Pixel and Conversions API), only with your marketing consent. We may share campaign page views, the start of an anonymous chat and account registration, together with technical identifiers (cookie IDs, IP address and browser information) and a hashed email address. We never send chat content or business names to Meta. Transfers to Meta in the USA are protected by the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses (SCCs).
  • OpenAI Ireland Ltd. — advertising conversion measurement and relevant audiences (OpenAI Ads Pixel and Conversions API), only with your marketing consent. We may share page views, accepted lead requests, the start of an anonymous chat and account registration, together with first-party advertising identifiers, IP address and browser information, and a hashed email address. We never send chat content or business names to OpenAI. OpenAI generally processes conversion data as an independent controller under its Conversion Terms and Ad Tools Data Processing Addendum. Transfers to countries without an adequate level of protection rely on EU Standard Contractual Clauses (SCCs) unless another valid transfer mechanism applies.

Use of Google API Data

Super44's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google Business Profile data is used only to provide features authorized by you. This may include retrieving profile and performance information and publishing profile updates or review replies when specifically authorized.

Gmail data is accessed read-only and used solely to identify and import supplier invoices and receipts into your own expense records. It is never used for advertising, sold, or used to train generalized AI models. Humans only see this data with your explicit consent, for security reasons, or where required by law.

You can revoke Google access at any time in the app or at myaccount.google.com/permissions.

How Long We Keep Your Data

We don't keep data longer than we need to.

  • Active account — your data is retained for as long as your subscription is active.
  • After account deletion — personal and business data that we do not need to retain is deleted within 30 days. Invoice, payment, tax and accounting records may be retained for the statutory period, then deleted or anonymized. Stripe may retain data independently where required for payment regulation, fraud prevention, legal claims or other legal obligations. Anonymized, aggregated analytics may be retained.
  • Chat history — kept for the life of your account. You can delete individual conversations at any time.
  • POS data — cached while your integration is connected. Deleted when you disconnect the integration or delete your account.
  • Backups — any backups containing your personal data are purged within 90 days of a deletion request.

Your Rights Under GDPR

You have strong rights over your data under the GDPR (Articles 15–22). Here's what you can do:

  • Access (Art. 15) — request a copy of all personal data we hold about you.
  • Rectification (Art. 16) — ask us to correct any inaccurate data.
  • Erasure (Art. 17) — ask us to delete all your data (the "right to be forgotten").
  • Restriction (Art. 18) — ask us to limit processing while a complaint is being resolved.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on our legitimate interest.
  • Automated decision-making (Art. 22) — Super44's AI provides suggestions and insights only. We don't make automated decisions that have legal or similarly significant effects on you.

To exercise any of these rights, email us at hello@super44.ai. We'll respond within 30 days. You also have the right to lodge a complaint with your local data protection authority. For Super44, this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). For data Stripe processes as an independent controller, you may also contact Stripe through its privacy channels.

Data Transfers Outside the EU

Your data is primarily processed in the EU — our servers run on AWS in Frankfurt (eu-central-1). Some providers and partners (Clerk, Google, Stripe, Meta and OpenAI) also process data in the USA or other countries. These transfers are protected by an applicable adequacy framework, including the EU-U.S. Data Privacy Framework where available, and/or EU Standard Contractual Clauses (SCCs). Stripe may transfer data to Stripe, LLC and its affiliates or subprocessors as needed to provide payment services. AI processing (Anthropic Claude) runs on AWS Bedrock in Frankfurt and does not leave the EU. We do not transfer data without appropriate safeguards.

Cookies and Tracking

The Super44 mobile app does not use cookies or third-party advertising SDKs. We use BetterStack for error and crash reporting to keep the service stable. On our website and web app, optional analytics uses PostHog to understand product usage. Optional marketing uses the Meta and OpenAI Ads Pixels and Conversions APIs to measure campaigns and create relevant audiences; selected conversion events are routed through PostHog. These technologies may set or read first-party advertising cookies and identifiers. The choices are separate, remain off until you consent, and do not affect Super44's functionality. When you choose a paid plan, you are redirected to Stripe's hosted Checkout, where Stripe may use necessary cookies and device signals for payment authentication, security and fraud prevention. These are not advertising cookies set by Super44. You can change your optional analytics and marketing choices at any time through Cookie Settings in the footer or Privacy settings in the web app.

Children's Data

Super44 is a business tool and is not directed at children under 16. We don't knowingly collect data from anyone under 16. If we learn that we've collected data from a child under 16, we'll delete it promptly.

Changes to This Policy

If we make material changes to this policy, we'll notify you via in-app notification and/or email. This page always shows the current version with the "Last updated" date at the top. Continued use of Super44 after we notify you of changes means you accept the updated policy. Where required, we'll ask for your consent again.

Data Protection Contact

We're a small team and haven't appointed a formal Data Protection Officer (this isn't required for most SMEs under Art. 37 GDPR). For any data protection questions, requests, or concerns, reach out to us directly at hello@super44.ai.