Contents
- 1Introduction and Scope
- 2Controller and Privacy Contact
- 3Our Role in the Processing
- 4Who this Policy Applies to
- 5Personal Data We Process and Purposes
- 6What We Do Not Do in the App
- 7Use of Data for AI Model Training
- 8Recipients and Subprocessors
- 9International Data Transfers
- 10Data Retention
- 11Security of Processing
- 12Your Rights
- 13Right to Lodge a Complaint
- 14Changes to this Privacy Policy
- 15Contact
1Introduction and Scope
This Privacy Policy describes how StackBooster Corporation ("StackBooster", "we", "us") processes Personal Data in connection with the StackBooster Platform, including the StackBooster web application available at https://app.stackbooster.pro and related APIs and tools (the "App").
StackBooster Corporation is the controller of the Personal Data described in this Privacy Policy in connection with the operation, maintenance, security and use of the App. StackBooster Corporation is also the owner and provider of the Platform technology, the operator of the App, and the contracting and invoicing entity and controller of billing, invoicing, tax and administrative data of clients that have entered into an Order Form or another commercial agreement with StackBooster.
StackBooster Corporation is a corporation organized and existing under the laws of the State of Delaware, United States of America, with its registered address at 8 The Green #12146, Dover, DE 19901, United States of America.
This Privacy Policy applies to the App. The public StackBooster website at stackbooster.io is subject to the separate Website Privacy and Cookies Policy.
This Privacy Policy does not govern the processing of Client Personal Data that our business clients submit to the Platform or make accessible to it to run their AI Agents, Hosted Applications and Campaigns - including Client Content, conversations with AI Agents in the client's workspace, data in connected accounts and cloud environments, Lead Data, Outbound Communication data, and data of visitors and users of websites and applications built or hosted for our clients. Such processing is carried out by StackBooster in the role of processor (or, where the client itself acts as a processor, sub-processor) and is governed by the applicable Master SaaS Agreement and Data Processing Agreement.
Access to the App is limited to:
- authorized personnel of StackBooster's business clients that have accepted the Master SaaS Agreement and have been added to the App as members of the client's workspace;
- authorized StackBooster personnel operating, supporting and maintaining the App; and
- registered prospective users who have created an App account to evaluate the Platform or whose organization has not yet subscribed.
The App is a business-to-business product intended exclusively for adult professional users. StackBooster does not knowingly collect Personal Data from persons under 18 years of age through the App.
2Controller and Privacy Contact
2.1Controller
StackBooster Corporation, a corporation under the laws of the State of Delaware, United States of America, with its registered address at 8 The Green #12146, Dover, DE 19901, United States of America. General contact: contact@stackbooster.io. Privacy contact: privacy@stackbooster.io.
2.2Privacy contact
StackBooster has designated a privacy point of contact for all matters relating to this Privacy Policy, reachable at privacy@stackbooster.io. StackBooster has not appointed a Data Protection Officer, as it is not required to do so; should one be appointed, the contact details will be published here.
3Our Role in the Processing
Depending on the type of data and the purpose of the Processing, StackBooster acts in different roles:
- Controller - with respect to the Personal Data described in this Privacy Policy, including App account data, authentication, account configuration, billing data, security telemetry, error monitoring, support communications, service communications and data of prospective users. StackBooster processes such data as a controller established in the United States; the EU GDPR applies to this processing on the basis of Article 3(2) EU GDPR where applicable.
- Processor - with respect to data submitted by our clients to the Platform or made accessible to it to operate their AI Agents, Hosted Applications and Campaigns. Such Processing is governed by the Data Processing Agreement (the "DPA") entered into between StackBooster and the relevant client and falls outside the scope of this Privacy Policy. The DPA is available at https://stackbooster.io/legal/dpa.
If you are a visitor or user of a website or application built or hosted by StackBooster for one of our clients, an End User of an AI Agent operated by one of our clients, or a recipient of communications or content published by one of our clients through the Services, the relevant controller of your Personal Data is that client. For the legal basis, purpose and scope of such processing, please consult that client's privacy notice.
4Who this Policy Applies to
This Privacy Policy applies to the following categories of Data Subjects:
- Client Team Members - employees, contractors and other authorized personnel of our business clients who have been granted App access by their organization.
- StackBooster Personnel - our employees and contractors operating, supporting and maintaining the App, to the extent their use of the App is concerned.
- Prospective Users - persons who have registered an App account to evaluate the Platform or whose organization has not yet subscribed.
- Billing and Business Contacts - persons designated by our clients as billing, legal, administrative or privacy contacts.
5Personal Data We Process and Purposes
5.1Account and Profile Data
We process the following information about App users:
- first and last name;
- business email address;
- the organization (client) and workspace to which the user belongs;
- the user's role and permissions in the App;
- authentication credentials (passwords are stored exclusively as salted one-way hashes, or authentication is delegated to a third-party identity provider such as Google where the user chooses that sign-in method);
- account preferences and settings.
Purposes: providing App access, account administration, role-based access control, user authentication and applying user preferences. Legal bases: Article 6(1)(b) EU GDPR (performance of the contract with the user or with the client through which the user obtains access, and steps prior to entering into a contract) and Article 6(1)(f) EU GDPR (the legitimate interests of StackBooster and the client in operating a secure user account system).
5.2Authentication and Session Data
We process authentication events, session identifiers, login timestamps, IP addresses associated with sessions and the information necessary to maintain a secure logged-in state for the duration of the user's session.
Purposes: user authentication, session security, detection and prevention of unauthorized access, protection against brute-force attacks, rate limiting and account lockouts. Legal bases: Article 6(1)(b) EU GDPR and Article 6(1)(f) EU GDPR (legitimate interest in securing our service).
5.3Cookies and Local Storage
The App uses a limited set of cookies and browser local storage entries that are necessary for the operation of the App. The App does not use advertising or profiling cookies and does not embed Meta Pixel, LinkedIn Insight Tag, TikTok Pixel or equivalent advertising tracking technology.
| Storage type | Identifier / category | Purpose | Retention period |
|---|---|---|---|
| Cookie | Authentication session cookie | Maintaining the user's authenticated session. | Session or until logout or session expiry. |
| Local storage | Account and interface preferences | Persisting preferences between sessions in the same browser. | Until cleared by the user or the browser. |
Because the cookies and local storage entries described above are strictly necessary to deliver the App at the user's request, consent is not required under Article 5(3) of Directive 2002/58/EC and its national implementations. Users may delete cookies and clear local storage at any time through their browser settings; doing so may, however, disrupt the operation of the App.
Should any non-essential cookies, advertising cookies, profiling cookies or third-party analytics technologies be introduced in the App in the future, we will update this Privacy Policy and implement the consent mechanism required by applicable law before activating such technologies.
5.4Product Usage Data
We process records of how users use the App - for example, features used, tasks started, errors encountered and resource consumption - in order to meter usage against the client's subscription, provide support and improve the App. Where we use such data for product improvement, we use it in aggregated or de-identified form where possible.
Purposes: usage metering and billing, service operation, troubleshooting and improvement of the App. Legal bases: Article 6(1)(b) EU GDPR (performance of the contract) and Article 6(1)(f) EU GDPR (legitimate interest in operating and improving our service).
5.5Error Monitoring
The App may use application error monitoring tools for error diagnostics and performance telemetry. We configure masking, scrubbing or equivalent controls for sensitive form fields and user-entered content to the extent technically supported. Error monitoring is used for diagnostics, security investigations and product stability - not for advertising, profiling or behavioral marketing.
Purposes: application error diagnostics, performance monitoring, security incident investigations and continuous improvement of the App. Legal basis: Article 6(1)(f) EU GDPR (legitimate interest in maintaining a secure, stable and high-quality service).
5.6Support Communications
If a user contacts StackBooster by email, chat or other support channels, we process the content of such communications, including any Personal Data contained in them, for the purposes of providing support, troubleshooting and keeping a record of communications.
Legal bases: Article 6(1)(b) EU GDPR (performance of a contract) and Article 6(1)(f) EU GDPR (legitimate interest in providing client support and keeping a record of communications).
5.7Sign-up, Evaluation and Meeting Booking
If a user creates an App account to evaluate the Platform, or books a walkthrough or onboarding call with StackBooster, we process the information provided (such as name, business email, company, website and the details the user chooses to share) and any booking details we receive from the scheduling tool used. Where a third-party scheduling tool is embedded, the information entered into it is collected by that provider in accordance with its own privacy notice, and we process the booking details we receive as a separate controller.
Purposes: preparing for and conducting the requested evaluation or meeting; lead qualification; pre-contract communication. Legal bases: Article 6(1)(b) EU GDPR (steps taken at the data subject's request prior to entering into a contract) and Article 6(1)(f) EU GDPR (legitimate interest in qualifying and responding to business enquiries).
5.8Billing and Payment Data
We process the billing contact details, company details, tax identification numbers, invoices, payment history and subscription status of our clients. Card and online payments are processed by our payment service provider; StackBooster does not store full card numbers.
Purposes: invoicing, payment collection, accounting, tax compliance and fraud prevention. Legal bases: Article 6(1)(b) EU GDPR (performance of the contract), Article 6(1)(c) EU GDPR (compliance with legal obligations, to the extent applicable) and Article 6(1)(f) EU GDPR (legitimate interest in complying with the tax and accounting obligations applicable to StackBooster in the United States).
5.9Security Telemetry, Audit Logs and Operational Logs
We process security-relevant telemetry, access logs, audit logs, logs of Agent Actions and similar operational data generated as a result of the use of the App, including IP addresses, user agent strings, device information, login and logout events, approvals, administrative actions and error events.
Purposes: protecting the security, integrity and availability of the App; preventing, detecting and investigating fraud, abuse and security incidents; demonstrating which Agent Actions were requested or approved and by whom; complying with our legal obligations. Legal bases: Article 6(1)(f) EU GDPR (legitimate interest in protecting our service and our clients) and Article 6(1)(c) EU GDPR (compliance with legal obligations, including those under Article 32 EU GDPR).
5.10Service and Product Communications
We send App users service communications that are necessary for the use of the App (for example, security alerts, approval requests, billing notices and changes to our terms). We may also send business contacts product updates and information about StackBooster services that are similar to those they use; every such message contains an easy way to unsubscribe.
Legal bases: Article 6(1)(b) EU GDPR (service communications) and Article 6(1)(f) EU GDPR (legitimate interest in informing business customers about similar services), or consent where required by applicable law.
6What We Do Not Do in the App
For the avoidance of doubt, in the App we do not:
- use third-party advertising tracking tools such as Meta Pixel, LinkedIn Insight Tag or TikTok Pixel;
- place advertising or profiling cookies;
- share Personal Data with advertising networks or data brokers;
- sell Personal Data, or share it for cross-context behavioral advertising;
- subject users to automated decision-making producing legal effects or similarly significantly affecting them within the meaning of Article 22 EU GDPR; or
- collect biometric identifiers or perform biometric categorization of users.
The statements above relate to the App operated by StackBooster. They do not relate to websites, applications, accounts or channels operated by our clients, including those built or hosted through the Platform, or to third-party platforms.
7Use of Data for AI Model Training
StackBooster does not use the Personal Data of App users, or the data our clients submit to the Platform, to train, fine-tune or otherwise improve AI models, unless a client has expressly opted in in writing. We access third-party AI models through commercial API or enterprise cloud services on terms under which the providers do not use the data we submit to train their models. The detailed terms governing client data are set out in Section 14 of the DPA, available at https://stackbooster.io/legal/dpa.
8Recipients and Subprocessors
The Personal Data described in this Privacy Policy is processed on the infrastructure of, or with the support of, the following categories of service providers, acting as our processors or, where so indicated, as separate independent controllers:
| Provider | Role | Function | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Processor | Cloud infrastructure hosting the App. | AWS regions selected by StackBooster (details on request) |
| Operational service providers (error monitoring, email delivery, support tooling) | Processor | Operating, monitoring and supporting the App and delivering service emails. | As indicated in the Subprocessor List or available on request |
| Payment service provider | Payment service provider; separate controller to the extent required by payment services regulations | Payment processing, where the client pays by card or online payment method. | United States and other locations, with Chapter V EU GDPR transfer mechanisms applied by the provider |
| Scheduling tool provider | Independent controller with respect to data entered directly into the embedded scheduling widget | Meeting booking for prospective users. | As stated in the provider's privacy notice |
| Other authorized service providers and Subprocessors | Processor | In accordance with the Subprocessor List, depending on the functionality and configuration selected by the client. | In accordance with the Subprocessor List |
The full and current list of subprocessors used by StackBooster in connection with the services provided to clients is available at https://stackbooster.io/legal/subprocessors.
We may also disclose Personal Data: (a) to competent public authorities, courts or regulators where required by applicable law or in response to valid legal process; (b) to professional advisors, such as auditors, lawyers and accountants, bound by appropriate confidentiality obligations; and (c) to a legal successor or prospective acquirer in the context of a merger, acquisition, financing or similar corporate transaction, subject to appropriate safeguards.
9International Data Transfers
The controller is StackBooster Corporation, established in the United States. The App is hosted on Amazon Web Services; information on the hosting region is available upon request. StackBooster personnel and contractors may access Personal Data from the United States and from the other countries in which they are located to the extent necessary to operate, maintain, secure and support the App. Certain service providers process Personal Data in the United States and other countries.
Where Personal Data subject to the EU GDPR is transferred outside the European Economic Area, StackBooster relies on the appropriate Chapter V EU GDPR transfer mechanisms, including:
- the EU standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914;
- the EU-U.S. Data Privacy Framework, where the recipient is certified; and
- where applicable, European Commission adequacy decisions with respect to the recipient country.
With respect to Personal Data subject to the UK GDPR, the Chapter V UK GDPR transfer mechanisms apply accordingly, including the UK International Data Transfer Addendum to the EU SCCs or the relevant UK adequacy regulations. With respect to Personal Data subject to the Swiss Federal Act on Data Protection, the corresponding Swiss mechanisms apply.
With respect to Client Personal Data processed by StackBooster as a processor, international transfers are governed by the DPA.
10Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting or reporting requirements. The following retention periods apply:
| Category of Personal Data | Retention period |
|---|---|
| Account and profile data of App users | For the lifetime of the user's App account, plus up to 30 days after deactivation, then deleted, unless a longer retention period is required by applicable law. |
| Authentication and session data | Session data: until session expiry. Authentication logs: up to 12 months. |
| Cookies and local storage | In accordance with Section 5.3. |
| Product usage data | Up to 24 months in identifiable form; thereafter only in aggregated or de-identified form. |
| Error monitoring data | Up to 90 days from the date of recording. |
| Support communications | Up to 24 months from the date the relevant matter is resolved. |
| Prospective user and meeting booking data | Up to 24 months from the date of last contact, unless the prospective user's organization becomes a client, in which case the data is retained within the client relationship. |
| Security telemetry, audit logs, Agent Action logs and operational logs | At least 12 months and up to 24 months, in accordance with our internal security log retention policy, or longer where necessary to establish, exercise or defend legal claims. |
| Billing, invoicing and accounting records | 7 years from the end of the tax year to which they relate, in accordance with the tax and accounting laws of the United States, unless applicable law requires longer retention. |
| Marketing communication preferences and unsubscribe records | For as long as necessary to honor the preference. |
Where Personal Data is processed by StackBooster as a processor on behalf of a client, retention, return and deletion are governed by the DPA and the client's instructions.
Upon expiry of the applicable retention period, Personal Data is deleted or irreversibly anonymized in accordance with our internal procedures, except where applicable law requires further retention.
11Security of Processing
StackBooster implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the Processing, in accordance with Article 32 EU GDPR. These measures include, without limitation:
- encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent);
- storage of passwords exclusively as salted one-way hashes;
- multi-factor authentication for administrative access to production systems;
- role-based access control and the principle of least privilege;
- an encrypted secrets store for API keys, tokens and credentials of connected accounts;
- Approval Controls, spending and sending caps and a pause control for AI Agents, and logging of Agent Actions;
- isolation of client workloads and network segmentation;
- logging of security-relevant events and monitoring;
- vulnerability scanning, dependency management and security patching;
- documented incident response procedures;
- regular encrypted backups;
- personnel confidentiality obligations and security awareness training; and
- subprocessor due diligence and ongoing monitoring.
Further details of our technical and organizational measures are set out in Annex II to the DPA and in the StackBooster Security Annex, made available to clients upon request subject to appropriate confidentiality obligations.
12Your Rights
12.1Rights under the EU GDPR and UK GDPR
Subject to the conditions set out in applicable data protection laws, you have the following rights with respect to your Personal Data:
- Right of access - to obtain confirmation as to whether your Personal Data is being processed and, if so, to obtain access to such data and related information (Article 15 EU GDPR).
- Right to rectification - to obtain the rectification of inaccurate Personal Data and the completion of incomplete Personal Data (Article 16 EU GDPR).
- Right to erasure - to obtain the erasure of your Personal Data where the conditions of Article 17 EU GDPR are met.
- Right to restriction of Processing - to obtain the restriction of Processing where the conditions of Article 18 EU GDPR are met.
- Right to data portability - to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit such data to another controller where the conditions of Article 20 EU GDPR are met.
- Right to object - to object, on grounds relating to your particular situation, to the Processing of your Personal Data based on Article 6(1)(f) EU GDPR (legitimate interests), and to object at any time to direct marketing, in accordance with Article 21 EU GDPR.
- Right to withdraw consent - where Processing is based on your consent, you may withdraw such consent at any time, without affecting the lawfulness of Processing carried out before the withdrawal.
- Right not to be subject to automated decision-making - not to be subject to a decision based solely on automated Processing, including profiling, that produces legal effects concerning you or similarly significantly affects you (Article 22 EU GDPR). As stated in Section 6, the App does not subject users to such decision-making.
12.2Rights under US State Privacy Laws
If you are a resident of California or another US state with a comprehensive consumer privacy law, and that law applies to the processing described in this Policy, you may have the right to: (a) know and access the categories and specific pieces of Personal Data we have collected about you, the categories of sources, the business purposes and the categories of recipients; (b) correct inaccurate Personal Data; (c) delete Personal Data; (d) obtain a portable copy of your Personal Data; and (e) opt out of the sale or sharing of Personal Data and of targeted advertising and certain profiling. StackBooster does not sell Personal Data or share it for cross-context behavioral advertising, and does not use or disclose sensitive personal information for purposes that would give rise to a right to limit. We will not discriminate against you for exercising your rights. You may designate an authorized agent to make a request on your behalf, subject to verification. If we decline your request, you may appeal our decision by replying to our response or writing to privacy@stackbooster.io.
The categories of Personal Data we collected in the preceding 12 months are those described in Section 5 (identifiers, commercial information such as subscription and billing records, internet or other electronic network activity information, and professional or employment-related information), collected from you, from your organization and from your use of the App, for the business purposes described in Section 5, and disclosed to the categories of recipients described in Section 8.
12.3How to exercise your rights
To exercise any of these rights, contact us at privacy@stackbooster.io. We may need to verify your identity before responding. We will respond to your request without undue delay and in any event within one month of receiving it (or within the period required by applicable law). This period may be extended where permitted by applicable law, in which case we will inform you of the extension and its reasons.
If your Personal Data is processed by StackBooster as a processor on behalf of one of our clients, we may redirect your request to the relevant client, which is the controller responsible for responding to your request.
13Right to Lodge a Complaint
If you believe that our Processing of your Personal Data violates applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority, in particular the supervisory authority of the European Economic Area Member State of your habitual residence, place of work or the place of the alleged infringement, in accordance with Article 77 EU GDPR. Contact details of the EEA supervisory authorities are available through the European Data Protection Board (https://edpb.europa.eu). With respect to Personal Data subject to the UK GDPR, the competent authority is the UK Information Commissioner's Office (ICO), https://ico.org.uk. Where the data protection laws of your jurisdiction provide for a complaint to a local authority, you may also lodge a complaint with that authority in accordance with those laws.
We would appreciate the opportunity to address your concerns directly before you approach a supervisory authority. Please contact us at privacy@stackbooster.io.
14Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version is published at https://stackbooster.io/legal/privacy and is identified by the version number and effective date indicated at the top of this document. App users will be informed of material changes by email or by a prominent notice in the App at least thirty (30) days before such changes take effect. Previous versions are kept in our version control system and are available on request.
15Contact
If you have any questions or concerns regarding this Privacy Policy, please contact us:
- General contact: contact@stackbooster.io
- Legal matters: legal@stackbooster.io
- Privacy and data protection matters: privacy@stackbooster.io
- Controller and postal address: StackBooster Corporation, 8 The Green #12146, Dover, DE 19901, United States of America; state of incorporation: Delaware
© StackBooster Corporation. Legal document version 1.0.
Questions about this document: legal@stackbooster.io

