Privacy Policy
Last updated: August 2026
BusinessMCP is built privacy-first: our analytics are cookieless, pseudonymize visitors by design, and are never sold or shared with advertisers — with a Global Privacy Control opt-out for the optional ad-platform integrations a customer can enable. This policy explains what we process, why, and the rights you have under the GDPR and similar laws. See also our Cookie Policy, Data Processing Agreement, and Security overview.
Who we are (data controller)
BusinessMCP, Inc. (“BusinessMCP”, “we”) is the data controller for the account and marketing data described below. For privacy questions or to exercise your rights, contact our privacy team at privacy@businessmcp.com.
Two roles: controller and processor
For your BusinessMCP account (your email, billing, workspace content) we act as the controller. For the end-visitor analytics your workspace collects through our tracking script and support widget, you are the controller and we act as your processor, handling that data only on your instructions under our Data Processing Agreement. You are responsible for having a lawful basis and appropriate notice/consent for the visitors you track.
What we collect
- Account & billing: your email, workspace name, team membership, and subscription status. Payment card details are handled by Stripe and never stored on our servers.
- Workspace content: notes, playbooks, connections metadata, CRM contacts, and the messages you exchange with the AI assistant.
- Usage: agent runs, token counts, and cost — used for metering and abuse prevention.
- First-party analytics (pseudonymous):a random visitor id stored in the browser’s localStorage, a daily-rotating session hash that is one-way and re-identifiable only within a single UTC day (it cannot be reversed into a person or linked across days), page paths, coarse geo (country/region/city derived from IP then discarded), and device/browser type.
- IP addresses are not storedwith analytics events. IP is used transiently for geo and bot detection and then dropped. It is only retained when a workspace on a paid plan explicitly turns on company enrichment, and even then it is discarded after the company is resolved (“enrich then discard”).
Legal bases (GDPR Art. 6)
- Contract: to provide the service you signed up for — running your command center, storing your workspace, and billing you.
- Legitimate interests: operating cookieless, pseudonymous product analytics, securing the platform, and preventing abuse — balanced against your rights. This analytics is first-party and is not sold or shared for advertising (see Do Not Sell or Share below).
- Consent: for marketing email you can withdraw at any time. Where your end-visitors require consent for tracking, obtaining it is your responsibility as their controller.
How your data is used
Workspace content is used solely to operate your command center: agent runs read your business context, playbooks, and thread history to do the work you ask for. We do not train models on your data and we do not sell data to third parties.
Secrets and credentials
API keys and tokens you store in the vault are encrypted at rest, are never returned to the browser after saving, and are only decrypted server-side at the moment an integration call is made on your behalf.
Retention
- Raw analytics events: approximately 30 days, after which only aggregated, pseudonymous rollups remain.
- Pseudonymous visitor profiles & session summaries: kept for the life of your account so lifetime journeys survive the raw-data window.
- Session recordings & heatmaps: retained 7 or 30 days depending on plan, or off entirely on lower tiers.
- Account & vault data: kept until you delete your workspace or account, at which point workspaces, threads, notes, and vault secrets are removed.
Sub-processors
We rely on the following processors to run the service, each under a data-protection agreement:
- Supabase — database and authentication
- Vercel — application hosting
- Tinybird — analytics event storage
- Stripe — billing and payments
- Resend — transactional and notification email
- Anthropic and other LLM providers you connect — AI inference
- Tavily — live web research (when used)
- IPinfo / People Data Labs and similar — optional company enrichment
- Any MCP servers, ad platforms, and marketing tools you explicitly connect
Each connection is opt-in per workspace. We give notice of material sub-processor changes as described in the DPA.
International transfers
Where data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses and our providers’ data-protection frameworks to ensure an equivalent level of protection.
Do Not Sell or Share / Global Privacy Control
We do not sellyour personal information. Our first-party analytics is cookieless and pseudonymous and is not “shared” for cross-context behavioral advertising, so it is not gated by a privacy signal.
Where a customer enables our optional ad-platform integrations — server-side conversion measurement or audience matching that transfers data to networks like Meta or Google — that can constitute a “sale” or “share” under US state privacy laws (California, Colorado, Connecticut and others). For residents of states that recognize it, we honor a Global Privacy Control (GPC) browser signal as a valid opt-out: visitors who send GPC are excluded from those ad-platform transfers. First-party analytics is unaffected. Do-Not-Track is not an agreed legal standard and we do not rely on it.
Where a customer uses our optional Sales Automation feature to conduct business-to-business outbound outreach, that customer is the controller of the prospect data and is responsible for having a lawful basis (in the EU/UK, typically legitimate interest for B2B prospecting) and for honoring opt-outs. Every message includes an unsubscribe mechanism and sender identity; recipients who unsubscribe, existing customers, and GPC opt-outs are suppressed automatically. Prospect enrichment draws on lawfully-sourced public and licensed B2B data providers.
Your rights
Under the GDPR and similar laws you have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data, and to withdraw consent at any time.
To exercise any of these, email privacy@businessmcp.com. We respond within 30 days. If your request concerns end-visitor data held on behalf of one of our customers, we will refer you to that customer (the controller) or assist them in responding. You also have the right to lodge a complaint with your local supervisory authority.
Children
BusinessMCP is a business tool not directed to children, and we do not knowingly collect personal data from anyone under 16.
Changes & contact
We may update this policy; material changes will be announced by email. Questions? Email privacy@businessmcp.com.