Privacy Policy

Last updated: June 2026

1. Who we are

This Privacy Policy describes how BusinessCore("BusinessCore", "we", "us") collects and uses personal data when you use our service. BusinessCore acts as the data controller of the personal data described below.

2. What we collect

  • Account data: email, name, login credentials.
  • Business profile data: business name, industry, goals, and other data you provide.
  • Product data: leads, finance entries, campaigns, automations, and other content you create.
  • Support messages: information you send when contacting us.
  • Usage & technical data: logs, device identifiers, IP address, and basic telemetry needed to operate the Service.

Payment data (card details, billing address) is collected directly by our Merchant of Record, Paddle — we do not store full payment details.

3. Purposes & legal basis

  • Providing the Service (account creation, running features) — legal basis: performance of a contract.
  • Security & fraud prevention, product improvement, and analytics — legal basis: our legitimate interests in operating a secure, reliable product.
  • Customer support — legal basis: performance of a contract.
  • Transactional communications (billing, security, service updates) — legal basis: performance of a contract / legal obligation.
  • Marketing communications, where applicable — legal basis: consent (which you can withdraw at any time).
  • Tax and accounting records — legal basis: legal obligation.

4. AI processing

Your prompts and the relevant business context (e.g. your KPIs) are sent to AI providers to generate responses. Providers act as our processors under data-processing agreements and do not train on your data.

5. Storage & security

Data is encrypted in transit and at rest, scoped per workspace with row-level security. Only authorized team members can access production systems. We apply appropriate technical and organisational measures to protect personal data.

6. Sharing & recipients

We share personal data only with:

  • Hosting and infrastructure providers that operate our platform.
  • AI providers that process prompts to generate responses.
  • Paddle.com, our reseller and Merchant of Record, for the sale of subscriptions, payment processing, subscription management, fraud prevention, invoicing, and tax compliance. See Paddle's Privacy Notice.
  • Professional advisers (legal, accounting) where required.
  • Authorities where legally required to disclose data.

We do not sell your personal data.

7. Retention

We retain personal data while your account is active and for a short period after deletion for backup, security, and legal purposes (e.g. tax records). When data is no longer needed, it is deleted or anonymised.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent at any time. You can also lodge a complaint with your local data protection authority. To exercise any right, email privacy@founderos.app — we will respond within the period required by applicable law.

9. Cookies

We use cookies and similar technologies that are strictly necessary to keep you signed in and operate the Service. Where we use analytics cookies, we ask for consent where required.

10. Contact

Privacy questions? Email BusinessCore at privacy@founderos.app.