Privacy Policy
This policy explains what information Super-Agent collects, why we collect it, how we use and share it, and the choices you have.
1. Who we are
Super-Agent ("Super-Agent", "we", "us", or "our") operates a unified AI agent platform that helps ecommerce businesses respond to customers across voice calls, WhatsApp, SMS, and other messaging channels. This Privacy Policy applies to our website at super-agent.dev and to the Super-Agent services, integrations, and applications (collectively, the "Services") used by our business customers and the end-users who interact with our customers through those channels.
2. Information we collect
2.1 Information you provide directly
- Account information: name, business name, email address, phone number, role, and password when you create an account or book a demo.
- Billing information: billing contact and payment details, processed by our payment processor (we do not store full card numbers on our own servers).
- Configuration data: store information, product catalogs, policies, workflows, prompts, and other content you upload or configure inside Super-Agent.
- Support communications: messages, screenshots, and attachments you send when contacting us.
2.2 Information collected automatically
- Usage data: pages viewed, features used, time spent, click events, and similar product analytics.
- Device and log data: IP address, browser type and version, operating system, device identifiers, referrer URLs, and timestamps.
- Cookies and similar technologies: used for authentication, preferences, analytics, and basic site performance. See Cookies below.
2.3 Information collected from end-user conversations
When end-users interact with our customers' Super-Agent deployments via phone, WhatsApp, SMS, web chat, or other supported channels, we process information such as:
- Phone numbers, WhatsApp user IDs, Messenger IDs, or other channel identifiers.
- Profile data made available by the channel (e.g., display name, profile photo where applicable).
- Message content, including text, voice recordings, transcriptions, images, and files shared during the conversation.
- Order, shipping, return, and account information shared during the conversation or pulled from connected systems to answer the request.
- Metadata such as timestamps, channel, language, and conversation status.
Super-Agent acts as a data processor for this content on behalf of the business customer that operates the deployment. That business customer is the data controller and is responsible for the lawful basis under which end-user data is collected and for posting its own privacy notice to end-users.
2.4 Information from third-party platforms
If you connect Super-Agent to third-party platforms (for example, Meta Business Suite, WhatsApp Business Platform, Messenger, Instagram, Shopify, your telephony provider, your CRM, or your help desk), we receive information from those platforms that is necessary to operate the integration — such as page IDs, business account IDs, access tokens, message history within scope, and customer records. We only request the permissions and scopes needed to deliver the features you enable.
Connected stores. When you connect a store — Shopify or WooCommerce — we read what the scopes you approved allow, and we keep a synchronized copy of your customers, orders, and abandoned checkouts so the agent can answer a shopper without a live round-trip to your store on every message. Product and catalog details are read on demand to answer a question and are not kept in that copy. We use it only to run the features you enabled for your own store: answering order, shipping, and product questions, building your customer segments and campaign audiences, and attributing sales back to the conversation or campaign that produced them. It is kept separate from every other merchant's data, never used for advertising, and never sold. See what happens when you disconnect or uninstall.
3. How we use information
We use the information described above to:
- Provide, operate, secure, and improve the Services.
- Authenticate users, prevent abuse, and detect fraud.
- Generate AI responses to end-user messages on behalf of our business customers, using language models and related tools.
- Route, escalate, or hand off conversations to human agents as configured.
- Send transactional communications (billing, security, service updates).
- Provide customer support and respond to your requests.
- Produce aggregated, de-identified analytics on platform performance.
- Comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not use the content of end-user conversations to train third-party foundation models. Where AI model providers are used, they are bound by data processing terms that prohibit training on customer content.
4. How we share information
We share information only as described below:
- With the business customer operating the deployment. If you are an end-user messaging a business, your conversation and related metadata are made available to that business inside their Super-Agent workspace.
- With service providers (subprocessors) that help us run the Services — for example, cloud hosting, telephony providers, messaging gateways, AI model providers, analytics, error monitoring, and payment processing. These providers are contractually limited to processing data on our behalf.
- With third-party platforms you connect (e.g., Meta, WhatsApp, Shopify) to the extent needed to deliver the integration.
- For legal reasons when we believe in good faith that disclosure is necessary to comply with the law, legal process, or a government request, or to protect rights, safety, or property.
- In connection with a business transaction such as a merger, acquisition, or sale of assets, subject to customary confidentiality protections.
- With your consent or at your direction.
5. Third-party platforms (Meta, WhatsApp, Shopify, telephony, AI)
Meta Platforms (Facebook, Messenger, Instagram, WhatsApp)
When a business connects Super-Agent to Meta products through the Meta APIs or the WhatsApp Business Platform, our use and transfer of information received from Meta APIs adheres to Meta's Platform Terms and Developer Policies, including the Limited Use requirements. We use this data only to operate, improve, and provide the Services that the business has enabled, and we do not use it for advertising or sell it to data brokers.
Shopify
When a merchant installs Super-Agent on a Shopify store, we access
that store through the Shopify Admin API using only the scopes the
merchant approves, and we keep a synchronized copy of the customers,
orders, and abandoned checkouts needed to run the features they
enabled. Shopify store data is processed on behalf of that merchant,
is kept separate from every other merchant's data, and is never used
for advertising, never sold, and never shared with other merchants. We
honor Shopify's mandatory privacy requests
(customers/data_request, customers/redact,
and shop/redact).
If you remove the app, we do not keep your store's data. Disconnecting the store inside Super-Agent, or uninstalling the app from your Shopify admin, deletes the copy we hold — see Connected stores below.
Telephony and messaging providers
Voice calls and SMS may be handled by carriers and CPaaS providers (such as your selected telephony partner). Call audio, transcripts, and message content may be processed and temporarily stored by these providers to deliver the communication.
AI model providers
We use large language models from established providers to generate responses. Conversation content sent to these models is processed under zero-retention or limited-retention enterprise agreements where available, and is not used by the model provider to train their foundation models.
6. Data retention
We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods depend on the type of data and the configuration chosen by the business customer. End-users may request deletion of their personal information by contacting the business they were communicating with, or by contacting us using the details below — we will route the request to the appropriate controller.
Connected stores: disconnecting and uninstalling
The copy we hold of a connected store's customers, orders, and abandoned checkouts exists only for as long as that store is connected. Removing the connection removes the data — no archive is kept behind it, and reconnecting later starts from an empty copy that is re-imported from your store.
- You disconnect the store in Super-Agent. The stored credential is discarded and the synchronized copy of that store's data is deleted.
- You uninstall the Super-Agent app from your Shopify admin. Shopify notifies us, the credential stops working immediately, and the synchronized copy of that store's data is deleted.
- Shopify sends a
shop/redactrequest, which it does 48 hours after an uninstall. Anything still held for that store is deleted, and in every case within the 30 days Shopify requires. - Shopify sends a
customers/redactrequest for one shopper. That shopper's mirrored record and orders are deleted rather than the whole store. - You disconnect a WooCommerce store. The same deletion applies.
Three things a store disconnect does not delete, because they are not store data: your own Super-Agent account and billing records, which we keep while the account exists and afterwards only where law requires; the conversations your agent has already had with shoppers on WhatsApp, Messenger, Instagram, SMS, or web chat, which belong to the channel they happened on and are deleted with your account or on request; and aggregated, de-identified statistics that can no longer be linked to a store or a person. To delete those as well, close your account or write to us at hello@super-agent.dev.
7. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS), encryption at rest for stored conversation data, role-based access controls, audit logging, and regular security reviews of our infrastructure and vendors. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
8. Your rights and choices
Depending on where you live (for example, the EEA, UK, California, or Brazil), you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete personal information, subject to certain exceptions.
- Object to or restrict certain processing, including direct marketing.
- Receive a portable copy of certain information.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at hello@super-agent.dev. If your data is held by a business that uses Super-Agent to communicate with you, we will forward the request to that business (the controller) and assist them in responding.
Cookies
Our website uses a small number of cookies for essential site functionality, preferences, and basic analytics. You can control cookies through your browser settings. Disabling certain cookies may affect site functionality.
9. Children's privacy
The Services are not directed to children under 13 (or the equivalent minimum age in the relevant jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
10. International data transfers
We may transfer, store, and process personal information in countries other than your own. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or other lawful transfer mechanisms.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you by email or through the Services. Material changes will be communicated with reasonable notice before they take effect.
12. Contact us
If you have questions or requests regarding this Privacy Policy or our handling of personal information, contact us at:
Super-Agent
Email: hello@super-agent.dev