Privacy Policy
Last updated: 27 September 2026
BusinessMCP is built privacy-first: our analytics are cookieless, pseudonymize visitors by design, and are never sold or shared with advertisers — with a Global Privacy Control opt-out for the optional ad-platform integrations a customer can enable. Two things to be plain about. We advertise, so our own marketing site runs a Google Ads tag and DataFast analytics, both of which set cookies and both of which wait for consent in the EU/EEA and UK (never the product, never a customer’s website) — see Cookie Policy. And company identification uses visitors’ IP addresses, including to maintain our own IP-to-company graph — see the section on it. This policy explains what we process, why, and the rights you have under the GDPR and similar laws. See also our Cookie Policy, Data Processing Agreement, and Security overview.
Who we are (data controller)
BusinessMCP, Inc.(“BusinessMCP”, “we”) is the data controller for the account and marketing data described below, and for our IP-to-company graph. For privacy questions or to exercise your rights, contact our privacy team at privacy@businessmcp.com or use the request form.
Two roles: controller and processor
For your BusinessMCP account (your email, billing, workspace content) we act as the controller. For the end-visitor analytics your workspace collects through our tracking script and support widget, you are the controller and we act as your processor, handling that data only on your instructions under our Data Processing Agreement. You are responsible for having a lawful basis and appropriate notice/consent for the visitors you track. There is one exception, explained in its own section: we use network-level data from every site that runs our script to maintain our own IP-to-company graph, and for that purpose we are an independent controller.
What we collect
- Account & billing: your email, workspace name, team membership, and subscription status. Payment card details are handled by Stripe and never stored on our servers.
- Workspace content: notes, playbooks, connections metadata, CRM contacts, and the messages you exchange with the AI assistant.
- Usage: agent runs, token counts, and cost — used for metering and abuse prevention.
- First-party analytics (pseudonymous):a random visitor id stored in the browser’s localStorage, a daily-rotating session hash that is one-way and re-identifiable only within a single UTC day (it cannot be reversed into a person or linked across days), page paths, coarse geo (country/region/city derived from IP then discarded), and device/browser type.
- IP addresses are never stored with analytics events.Each tracking request’s IP is used in memory for coarse geo, bot detection and the daily session hash. Separately, for company identification: on paid plans(on by default) the full address is stored until our enrichment job resolves the company, normally within a few hours, and is then deleted unless the workspace has turned on “Store visitor IP”; on every plan, Free included, the /24 (IPv4) or /48 (IPv6) network prefix is kept for 30 days as a network observation. A workspace can turn company identification off, which stops both. On sites that use our consent mode, none of this happens until the visitor consents. Detail and retention are below and in the retention table.
- Visitor identification (business context): for paid workspaces (on by default, and can be turned off), we identify the companybehind an anonymous business visitor from the network the visit originates on (in-house, no third party), and can surface a “likely person” from the workspace’s own contact records using page context — this uses company data only and no device access. Person-level identification(resolving an individual’s name and work email) is stricter: device/hashed-email matching runs only for US visitors under notice-and-opt-out, or elsewhere only where the visitor has given consent, is never performed for visitors in the EU/EEA/UK/Switzerland without consent, is disabled whenever a Global Privacy Control (GPC) signal is present, and every attempt is logged. A separate first-party mechanism recognizes a returning contact the workspace already knows (matching against its own records) — no third-party data is involved.
Legal bases (GDPR Art. 6)
- Contract: to provide the service you signed up for — your hosted MCP server, analytics dashboard and AI business analyst, storing your workspace, and billing you.
- Legitimate interests: operating cookieless, pseudonymous product analytics, securing the platform, and preventing abuse — balanced against your rights. This analytics is first-party and is not sold or shared for advertising (see Do Not Sell or Share below).
- Legitimate interests (company identification, for our customers): identifying the companybehind an anonymous business visit is a B2B, company-level operation. As processor we carry it out on the customer’s instructions; the customer, as controller, relies on Art. 6(1)(f). It reads nothing from the visitor’s device and sets no cookie: it uses the IP address the request arrives from (held in full only until the company is resolved on paid plans, unless the customer opts to keep it) and never stores an email local-part. It is not person-level identification and a workspace can turn it off.
- Legitimate interests (our IP-to-company graph): as an independent controller we keep /24 · /48 network prefixes and email-domain confirmations from every site that runs our script, for 30 days, to learn which networks belong to which organisations. Our interest is accurate B2B company identification for all of our customers; the processing is limited to network prefixes and company domains, is never used to identify or profile a person, and expires. You can object at any time — see below.
- Consent: for marketing email you can withdraw at any time. Where your end-visitors require consent for tracking, obtaining it is your responsibility as their controller.
AI processing
Workspace content is used solely to run the service for you: the AI business analyst reads your business context, playbooks, thread history and the tool results it pulls (analytics, CRM contacts, connected data) to do the work you ask for. We do not train models on your data and we do not sell data to third parties.
The included AI tier is served by OpenRouter(openrouter.ai, United States). Every workspace that has not connected its own model key runs on it. What is sent per run: the prompt, the compacted thread, your business description and goals, workspace memory, and the results of the tools the assistant calls — which can include contact names and emails from your CRM. Processing happens in the US under OpenRouter’s own policy (which names the model provider it routes each request to); we do not make promises on a provider’s behalf beyond what its policy states.
Bring your own key:if you connect Anthropic, OpenAI, Google, Groq, DeepSeek, xAI, Mistral, OpenRouter, MiniMax or a custom endpoint, runs go to that provider on your key and under your contract with them instead — nothing reaches the included tier. The full list, with each provider’s location, is in the sub-processor table.
Connected mailboxes, files, repositories and databases
When you connect Gmail, Google Drive, Slack or GitHub, we read only what the connection authorises. Content from those sources is stored in your workspace knowledge base tagged as untrusted, meaning the assistant treats it as data, never as instructions.
Connected databases.If you connect your own PostgreSQL, MySQL, BigQuery or Snowflake, the credential is held in our encrypted vault and the connection is read-only. Two different things happen to what we read. The database’s shape— table and column names and types — is refreshed into your knowledge base every six hours; no sample rows are ever stored there. Query results are not stored by us at all: they are passed to whichever AI model your workspace is configured to use, in order to answer the question that was asked, and they appear in that conversation. Queries are logged (truncated) against the run that made them. You decide what the connection can reach by scoping the database role you create for it, and you can disconnect it at any time from Connections, which deletes the stored credential.
Gmail inbox sweep.With a connected mailbox, we check for new inbound mail every 15 minutes. Automated and bulk mail is filtered out. A reply from a known contact is logged on that contact’s timeline; a first email from a genuinely new human sender creates a CRM contact for that person (name, email, the message) and an assisted reply draft that you review before anything is sent.
Those senders are third parties whose data you, the workspace owner, are the controller of. Where GDPR applies you carry the Art. 14 duty to inform them (typically satisfied by your own privacy notice and the reply you send). Disconnect the mailbox at any time from Connections; stored contacts stay until you delete them.
Company identification and our IP-to-company graph
For our customers (we are processor).On paid plans, company identification is on by default. When a visitor loads a page on a customer’s site, we store the IP address the request came from on that visitor’s pseudonymous enrichment record, look it up in our own in-house graph to find the organisation that uses that network, and link the company to the visit. A job that runs every three hours finishes any lookup the page view did not, and then deletes the address. A workspace can instead choose to keep addresses (“Store visitor IP”), or turn company identification off entirely, in Settings. On a site using our consent mode this only happens after the visitor consents.
For our own graph (we are an independent controller).Separately from the service we provide to any one customer, we use data from every site that runs our script — on every plan, Free included — to maintain the graph itself, which maps network ranges to the organisations that use them. Because we decide this purpose ourselves, we are the controller for it, not our customers’ processor. What we use:
- Network observations— the /24 (IPv4) or /48 (IPv6) network prefix a visitor was seen on, never the full address for this purpose, with the site’s pseudonymous visitor id, country, time zone and connection type. Kept for 30 days after the visitor was last seen on that network, at most 8 networks per visitor.
- Confirmations— when a visitor identifies with a business email (a form, a verified sign-up, a click on or reply to an outreach email), the network prefix, the email’s domain (never the part before the @), the site and that site’s pseudonymous visitor or contact id (never an email address). Unconfirmed entries expire after 30 days; a corroborated one becomes a company-level fact (“this network is used by this organisation”) that holds nothing about the visitor.
- A coverage benchmark — each day a sample of resolved addresses and network prefixes is checked against ipapi.is to measure how accurate the graph is. Only the address or prefix is sent, with no visitor or workspace attached, and results are deleted after 30 days.
Lawful basis:legitimate interests (GDPR Art. 6(1)(f)) — our interest, and our customers’, in accurate company-level identification of business visitors. We weighed it against visitors’ interests: the graph uses network prefixes and company domains only, reads nothing from the visitor’s device, is never used to identify, profile or contact an individual, does not link a person across sites, and expires within 30 days. It is disclosed to our customers in the DPA.
Your choices: as a visitor you can object to this processing at any time by writing to privacy@businessmcp.com with the network or address concerned; we will stop using it and delete the related observations. As a customer, turning company identification off in Settings stops your site contributing, on any plan where that switch is available to you; on any plan you can also ask us to stop it by email.
Business contact data we compile
Separately from our customers’ data, we compile business-contact records about people in their professional capacity: name, job title, employer, work email, work phone where published, LinkedIn profile URL and the employer’s firmographics. They come from public company websites, public company registries and search-engine results, and businesses using our sales and CRM features can look up the people at a company they are researching. We are the controller of these records. For people in the EU/EEA and UK we rely on legitimate interests (Art. 6(1)(f)) in business-to-business contact, and you can object at any time.
We also offer these records through our Data API, to business customers under our Hub Terms, except records about people in the EU/EEA, the UK or Switzerland, or people we cannot place, which we never sell. The full disclosure, including sources and recipients, is on our data-broker page. To take your record out, use the opt-out form: no account or ID is needed, matching records are removed within about 24 hours, and we keep only a one-way hash so we do not collect you again.
Lead quality checks
To keep form spam out of your CRM and out of automated outreach, we score the domainof a newly captured lead email. We look up the domain’s registration age through RDAP (IANA bootstrap, rdap.org and the TLD registry) and its MX and A records through Google Public DNS (dns.google). Only the bare domain is sent — never the address, the person’s name, or their IP.
Verdicts are cached per domain for 180 days and shared across workspaces, so a domain is looked up once. A poor verdict flags the contact and keeps it out of automated outreach; it never deletes data, and a workspace owner can override it. We deliberately do not consult IP or country reputation lists for this purpose.
Our own analytics and advertising on businessmcp.com
We are the controller for everything in this section. Our marketing site runs three kinds of measurement: our own cookieless tracker (in the consent mode described on the Cookie Policy), Vercel Web Analytics (a cookieless page-view count), and the two cookie-setting tags below — DataFast and Google Ads.
DataFast(datafa.st, operated by JustShipIt Pte. Ltd., Singapore) is a second analytics tool we use to see which pages and channels bring sign-ups. It sets two first-party cookies — a visitor id kept for a year and a 30-minute session id — and receives your IP address and browser details with each request. It loads only after you accept, or automatically outside the EU/EEA and UK, and never inside the app or on a customer’s website.
We buy ads on Google, so businessmcp.com loads Google’s advertising tag (gtag.js) to measure which ads produce sign-ups and subscriptions, and to build remarketing audiences. Google acts as our advertising processor for that measurement and is listed in the sub-processor register under its Ads Data Processing Terms.
Three boundaries, and they are enforced in code rather than promised: it never runs on a customer’s website (the script our customers install is a different, cookieless one), it never runs inside the logged-in app at /dashboard, and in the EU/EEA, the UK, or wherever we cannot determine your location it is not requested at all until you accept the notice. Outside those jurisdictions it runs under legitimate interest with Google Consent Mode set from your Global Privacy Control signal. DataFast follows the same three boundaries. Cookie names and lifetimes are in the Cookie Policy.
We also record a sign-up or subscription to Google from our own servers, so the measurement works when the tag is blocked. That upload carries the ad click identifier and a hashed email — never a plain address, and never anything about a customer’s own workspace data.
Secrets and credentials
API keys and tokens you store in the vault are encrypted at rest, are never returned to the browser after saving, and are only decrypted server-side at the moment an integration call is made on your behalf.
Retention
How long each kind of data is kept. Shorter on request where the law allows.
| Data | Kept for | Notes |
|---|---|---|
| Raw analytics events | Up to 13 months | Pseudonymous visitor id, page path, coarse geo, device type. No IP address. Expire automatically in the event store (400-day time-to-live). |
| Sessions, daily rollups and visitor profiles | Life of the account | Aggregate and pseudonymous, no IP. Kept so lifetime journeys and year-over-year reports survive the raw window. |
| Session replays and heatmap backdrops | 7 days (Growth), 30 days (Scale), kept while the account is open (Business and Enterprise) | Off entirely on Free and Starter. Only recorded where a site enables it, and after consent on consent-gated sites. A workspace can choose a shorter window; it cannot choose a longer one. |
| Raw heatmap events (clicks and scroll reach) | 30 days, every plan | A fixed expiry on the event store itself, not a plan setting: no plan keeps click or scroll history longer, and the window above applies only to the replays and page snapshots stored alongside it. |
| Visitor IP address — request handling | Not stored by us | Read in memory on each tracking request for coarse geo, bot detection and the daily-rotating session hash, and never written to analytics events. Our hosting and error-monitoring providers may log it transiently under their own retention (see sub-processors). |
| Visitor IP address — company identification (paid plans) | Until the enrichment job processes it — normally a few hours | On paid plans company identification is ON by default, so the full address is stored on the visitor’s enrichment record. A job that runs every three hours resolves the company and then deletes the address. If the workspace turns on “Store visitor IP”, the address is kept instead until the workspace deletes it or the workspace is deleted. Turning company identification off stops the capture. |
| Network observations (/24 IPv4 or /48 IPv6 prefix) | 30 days after the visitor was last seen on that network | Every plan, Free included, unless the workspace turns company identification off. The network prefix (never the full address), the site’s pseudonymous visitor id, country, time zone and connection type, capped at 8 networks per visitor. Where a paid workspace has turned on “Store visitor IP”, the full address is recorded here instead, for the same 30 days. See “Company identification and our IP-to-company graph”. |
| IP-graph confirmations | 30 days unless corroborated | The network prefix, the email DOMAIN (never the local part), the site and that site’s pseudonymous visitor or contact id (never an email), recorded when a visitor identifies with a business email. A confirmation that is corroborated becomes a company-level entry (“this network is used by this organisation”) that holds no visitor data and is kept while it stays accurate. |
| IP coverage benchmark | 30 days | A daily sample of resolved addresses and network prefixes with our verdict and ipapi.is’s verdict, and the matched company domain where known. No visitor id or workspace is stored with it. |
| Visitor enrichment records (without the IP) | Life of the account | The company a visitor was matched to, country, Do-Not-Sell (GPC) and consent flags, time zone, languages and connection type — the pseudonymous profile the dashboard shows. |
| Workspace audit log | Life of the workspace | Which team member changed a setting or key, when, and the IP address the change came from. |
| Abuse-prevention counters | Until the rate-limit window closes (at most a day) | Contact and enterprise forms count submissions per IP address to stop spam; the counter, which contains the address, is removed once its window has closed. |
| Domain reputation (lead quality) | 180 days | Keyed by email DOMAIN only (registration age, MX and A-record presence). Shared across workspaces; contains no address, name or IP. |
| Email send and event logs | 400 days | Delivery, open, click and bounce events plus a per-recipient send ledger. Lifecycle one-time markers are kept so a nudge is never sent twice. |
| Hiring assessment telemetry | 30 days | Timing, focus and paste signals from the careers assessment, pseudonymised by HMAC. Scores stay with the application. |
| Job applications | 6 months | Name, email, links and written answers. Deleted earlier on request. |
| Account, workspace content and vault secrets | Until you delete the workspace or account | Threads, notes, CRM contacts, connections and encrypted credentials are removed on deletion, subject to legal retention. |
Sub-processors
The vendors below process data to run the service. Core rows apply to every workspace; optional rows only see data when a workspace connects or enables that vendor. Each is bound by a data-protection agreement no less protective than our DPA.
Last updated: 2026-09-26 · 18 core, 49 only when a workspace connects or enables them.
| Name | Purpose | Data | Location | Optional | DPA |
|---|---|---|---|---|---|
| Supabase | Primary database, authentication, file storage (session replays, snapshots) and the encrypted credential vault. |
| US (AWS us-east-1) | Core service | Privacy / DPA |
| Vercel | Application hosting, serverless functions and the global edge network that receives tracking beacons. Vercel Web Analytics also runs on our own marketing pages in production (app/layout.tsx), which is a page-view count about visitors to businessmcp.com — it is not part of the product and never runs on a customer’s site. |
| US (global edge) | Core service | Privacy / DPA |
| Sentry (Functional Software, Inc.) | Application error monitoring. Receives a stack trace and request context when a server or browser error occurs. |
| US | Core service | Privacy / DPA |
| ipapi.is | IP-classification benchmark. A nightly job scores a sample of the addresses our own IP graph resolved (paid workspaces) and of the network prefixes visitors came from (every plan) against this vendor to measure coverage. Only the address or prefix is sent, with no visitor or workspace attached; its verdict never drives a customer-visible reveal. |
| EU | Core service | Privacy / DPA |
| Tinybird | Raw analytics event store (the firehose our rollups are computed from). |
| UK (London) | Core service | Privacy / DPA |
| Stripe | Subscription and usage billing and payments, and payouts to marketplace sellers through Stripe Connect (identity verification, bank details and tax forms are collected and held by Stripe). Card and bank details never touch our servers. |
| US | Core service | Privacy / DPA |
| Resend | Transactional and notification email; sending and inbound-reply capture for customer email domains. |
| US | Core service | Privacy / DPA |
| Cloudflare | DNS and proxy for businessmcp.com, and the Turnstile bot check on our public forms. |
| US (global edge) | Core service | Privacy / DPA |
| Tavily | Live web research for the assistant and sales research (queries only, never workspace records). |
| US | Core service | Privacy / DPA |
| Google Public DNS | Lead-quality screening: MX and A-record lookups on the DOMAIN of a submitted lead email, and DNS checks for domain setup cards. |
| US | Core service | Privacy / DPA |
| RDAP registries (IANA bootstrap, rdap.org, TLD registries) | Lead-quality screening: domain registration age for the DOMAIN of a submitted lead email. |
| Varies by registry | Core service | Privacy / DPA |
| Serper | Google search results used to find a prospect or contact LinkedIn profile URL. |
| US | Core service | Privacy / DPA |
| Apify | Managed scraping of public social profiles and posts for handle-tracked accounts, and Google Maps business listings for prospect discovery. |
| EU (Czech Republic) | Core service | Privacy / DPA |
| DataForSEO | AI-visibility probes (asking answer engines about your category) and keyword or SERP data. |
| US | Core service | Privacy / DPA |
| Microlink | Website screenshot and metadata fetch used to generate a brand kit during onboarding. |
| EU (Spain) | Core service | Privacy / DPA |
| Google Ads (advertising measurement) | Measuring which of our own ads produce sign-ups and subscriptions, and building remarketing audiences, on businessmcp.com only. Never loaded on customer websites, and never inside the logged-in app. |
| US | Core service | Privacy / DPA |
| DataFast | Second-opinion analytics on businessmcp.com itself, loaded only after consent (or outside a consent jurisdiction). Never loaded on customer websites or inside the logged-in app. |
| Singapore (company); infrastructure mainly US | Core service | Privacy / DPA |
| OpenRouter | The included AI tier: every workspace that has not connected its own model key runs its assistant, insights and AI drafts on models routed through OpenRouter. Also the target when you connect your own OpenRouter key. |
| US | Core service | Privacy / DPA |
| Typeform | Form submissions delivered to BusinessMCP by webhook when a workspace connects its Typeform account. |
| US / EU (per the account) | Only if you connect it | Privacy / DPA |
| Tally | Form submissions delivered to BusinessMCP by webhook when a workspace connects its Tally account. |
| EU | Only if you connect it | Privacy / DPA |
| Calendly | Meeting bookings and cancellations delivered by webhook, plus upcoming-meeting reads through the customer-supplied API token. |
| US | Only if you connect it | Privacy / DPA |
| Cal.com | Meeting bookings, reschedules and cancellations delivered by webhook when a workspace connects Cal.com. |
| US / EU (per the account; self-hostable) | Only if you connect it | Privacy / DPA |
| Shopify | Order and refund events delivered by webhook, plus order/product/customer reads through the customer-supplied Admin API token. |
| US / Canada | Only if you connect it | Privacy / DPA |
| WooCommerce (Automattic) | Order and refund events delivered by webhook from the customer-hosted WooCommerce store. |
| Customer-hosted (the store itself); Automattic US | Only if you connect it | Privacy / DPA |
| Paddle | Merchant-of-record billing events (payments, subscriptions, refunds) delivered by webhook when a workspace connects its Paddle account. |
| UK / EU | Only if you connect it | Privacy / DPA |
| Lemon Squeezy | Merchant-of-record billing events (orders, subscriptions, refunds) delivered by webhook when a workspace connects its Lemon Squeezy store. |
| US | Only if you connect it | Privacy / DPA |
| Chargebee | Subscription-billing events (payments, plan changes, cancellations, refunds) delivered by webhook when a workspace connects its Chargebee site. |
| US / EU (per the site) | Only if you connect it | Privacy / DPA |
| Hunter.io | Email deliverability verification before an outreach email is sent, and — when an agent is asked for them — email lookups against a domain. Only on a Hunter key you connect yourself. |
| EU (France) | Only if you connect it | Privacy / DPA |
| ElevenLabs | Narration audio for our public Academy course (script text only, no customer data). Also available as an optional workspace text-to-speech connector. |
| US | Only if you connect it | Privacy / DPA |
| Anthropic | AI inference when you connect your own Anthropic key (replaces the included tier). |
| US | Only if you connect it | Privacy / DPA |
| OpenAI | AI inference and embeddings when you connect your own OpenAI key; grounded AI-visibility probes on your key. |
| US | Only if you connect it | Privacy / DPA |
| Snowflake (your own account) | Running the read-only SQL you or the assistant ask for against a Snowflake account you connect. We hold a token you issue; the account, the data and the grants are yours. |
| Your Snowflake region | Only if you connect it | Privacy / DPA |
| YouTube (Google) — tutorial videos | Tutorial video playback in the dashboard, loaded only when you press play. |
| US | Only if you connect it | Privacy / DPA |
| Google (Gemini API and connected Google services) | Gemini inference on your own key; Calendar, Gmail, Drive, Search Console, Google Analytics 4, Google Ads, YouTube and BigQuery when you connect them. The Analytics connection is read-only and imports your own historical traffic reports; the BigQuery connection is read-only and runs the queries you ask for. |
| US | Only if you connect it | Privacy / DPA |
| Groq | AI inference when you connect your own Groq key. |
| US | Only if you connect it | Privacy / DPA |
| DeepSeek | AI inference when you connect your own DeepSeek key. |
| China | Only if you connect it | Privacy / DPA |
| xAI | AI inference when you connect your own xAI (Grok) key. |
| US | Only if you connect it | Privacy / DPA |
| Mistral AI | AI inference when you connect your own Mistral key. |
| EU (France) | Only if you connect it | Privacy / DPA |
| MiniMax | Cheap-tier completions (compaction, compression, drafts) when you connect your own MiniMax key. |
| Singapore | Only if you connect it | Privacy / DPA |
| BigDBM | Person-level visitor identification (hashed-email graph). Only when you enable person-level reveal, and only where the geo gate allows it. |
| US | Only if you connect it | Privacy / DPA |
| LeadPipe | Person-level visitor identification from IP. Only when you enable person-level reveal, and only where the geo gate allows it. |
| US | Only if you connect it | Privacy / DPA |
| RB2B | Person-level visitor identification from IP. Only when you enable person-level reveal, and only where the geo gate allows it. |
| US | Only if you connect it | Privacy / DPA |
| Versium | Person-level visitor identification (hashed-email graph). Only when you enable person-level reveal, and only where the geo gate allows it. |
| US | Only if you connect it | Privacy / DPA |
| Instantly.ai | Alternative cold-email sending when you connect your own Instantly account. |
| US | Only if you connect it | Privacy / DPA |
| Microsoft (Graph) | Microsoft 365 calendar free/busy and event creation for booking when you connect it. |
| US | Only if you connect it | Privacy / DPA |
| Apple iCloud (CalDAV) | iCloud calendar free/busy and event creation for booking when you connect it with an app-specific password. |
| US | Only if you connect it | Privacy / DPA |
| HubSpot | Two-way CRM sync when you connect HubSpot (OAuth or a private-app token): contacts, deals, owners and pipelines are read into your BusinessMCP CRM every two hours, and — only if you switch on "Push to HubSpot" — our own enrichment is written back into a "businessmcp" property group on your contacts and companies. Your own HubSpot fields, including its lifecycle stage, are never overwritten and nothing is deleted. |
| US / EU (your HubSpot data residency) | Only if you connect it | Privacy / DPA |
| Pipedrive | CRM pull sync when you connect Pipedrive with your API token: persons, deals, stages and users are read into your BusinessMCP CRM every two hours. Nothing is written back. |
| EU | Only if you connect it | Privacy / DPA |
| Slack | Notifications to a channel you choose, and optional read access to channels you pick for assistant context. |
| US | Only if you connect it | Privacy / DPA |
| GitHub | Repository reads, pull requests the assistant opens, and optional ingestion of your repo docs into the workspace knowledge base. |
| US | Only if you connect it | Privacy / DPA |
| Meta (Facebook, Instagram, Meta Ads) | Page and Instagram stats, ad reporting, Custom Audiences and Conversions API when you connect them. |
| US | Only if you connect it | Privacy / DPA |
| Company-page stats, ad audiences and Conversions API when you connect them. |
| US | Only if you connect it | Privacy / DPA | |
| TikTok | Account stats, Customer File audiences and the Events API when you connect them. |
| US / Singapore | Only if you connect it | Privacy / DPA |
| X (Twitter) | Account stats and comment replies when you connect an X account. |
| US | Only if you connect it | Privacy / DPA |
| PostHog | Read-only queries against your own PostHog project when you connect it (US or EU Cloud, as you choose). |
| US or EU (your PostHog region) | Only if you connect it | Privacy / DPA |
| Account stats, recent pins and pin analytics when you connect a Pinterest account (read-only; we never create pins). |
| US | Only if you connect it | Privacy / DPA | |
| Intercom | Receives the conversations a customer chooses to forward from their Intercom inbox (inbound webhook only; we call no Intercom API). |
| US | Only if you connect it | Privacy / DPA |
| Crisp | Receives the chat conversations a customer chooses to forward from their Crisp inbox (inbound webhook only; we call no Crisp API). |
| EU (France) | Only if you connect it | Privacy / DPA |
| Mailchimp (Intuit) | Reads campaign and audience lists on the customer API key, and receives the engagement webhooks the customer points at us (opens, clicks, unsubscribes, cleaned addresses). |
| US | Only if you connect it | Privacy / DPA |
| Klaviyo | Reads campaign and list data on the customer API key, and receives the engagement webhooks the customer configures in their flows (opens, clicks, bounces, unsubscribes). |
| US | Only if you connect it | Privacy / DPA |
| Brevo | Receives nothing from us — Brevo POSTS its own email engagement events (delivered, opened, clicked, bounced, spam, unsubscribed) to a per-workspace webhook URL the customer registers. |
| EU (France) | Only if you connect it | Privacy / DPA |
| Notion | Searches the Notion workspace a customer connects, so the assistant can cite their own pages and databases. |
| US | Only if you connect it | Privacy / DPA |
| Linear | Reads recent issues from the Linear workspace a customer connects. |
| US | Only if you connect it | Privacy / DPA |
| Airtable | Reads records from the Airtable base a customer connects. A base can hold anything, including a contact list — which is why the connector is gated on the same data class as a document store. |
| US | Only if you connect it | Privacy / DPA |
| Zendesk | Reads recent tickets from the Zendesk instance a customer connects, so support volume and themes can be analysed alongside the rest of their data. |
| US / EU (your Zendesk data residency) | Only if you connect it | Privacy / DPA |
| PayPal | Reads recent transactions from the PayPal account a customer connects, so PayPal revenue can sit beside Stripe revenue. |
| US / EU | Only if you connect it | Privacy / DPA |
| Factors.ai | Reads the attribution report from the Factors.ai account a customer connects. |
| US | Only if you connect it | Privacy / DPA |
We email workspace owners at least 30 days before adding a new core sub-processor so you can object as described in the DPA. Any MCP server, ad platform or tool you connect yourself is your own choice and is not listed here.
International transfers
Our main database (Supabase) and our application hosting (Vercel) are in the United States, as are email, billing and the included AI tier. Our raw analytics event store (Tinybird) is in London, United Kingdom. Each vendor’s location is in the sub-processor table.
Personal data from the EU/EEA or UK is therefore transferred outside it. For transfers to the United States and other countries without an adequacy decision we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum for UK data) in our providers’ data-processing terms, or, where a provider is certified, on the EU-U.S. Data Privacy Framework and its UK Extension. EU data held in the UK is covered by the European Commission’s adequacy decision for the UK. You can ask us for a copy of the relevant safeguards at privacy@businessmcp.com.
Do Not Sell or Share / Global Privacy Control
Apart from the business-contact records described above, which we offer through our Data API, we do not sell personal information. Our first-party analytics is cookieless and pseudonymous and is not “shared” for cross-context behavioral advertising, so it is not gated by a privacy signal.
Our own Google Ads tag on businessmcp.com is advertising technology, so a GPC signal turns off its ad-personalisation and ad-user-data signals; in the EU/EEA and the UK it is not loaded at all until you accept the notice.
Where a customer enables our optional ad-platform integrations — server-side conversion measurement or audience matching that transfers data to networks like Meta or Google — that can constitute a “sale” or “share” under US state privacy laws (California, Colorado, Connecticut and others). For residents of states that recognize it, we honor a Global Privacy Control (GPC) browser signal as a valid opt-out: visitors who send GPC are excluded from those ad-platform transfers. First-party analytics is unaffected. Do-Not-Track is not an agreed legal standard and we do not rely on it.
Person-level visitor identification (US visitors, opt-in customers only) may use a third-party identity provider (BigDBM, LeadPipe, RB2B or Versium). That provider acts as a third party under US state law, not a service provider, under a contract limiting it to identity resolution with audit rights. GPC is honored as an opt-out for this processing, and it is never run for EU/EEA/UK/Swiss visitors absent consent. We do not resell visitor-identity data.
Where a customer uses our optional Sales Automationfeature to conduct business-to-business outbound outreach, that customer is the controller of the prospect data and is responsible for having a lawful basis (in the EU/UK, typically legitimate interest for B2B prospecting) and for honoring opt-outs. Every message carries the sender’s identity and postal address, a one-click unsubscribe link and List-Unsubscribe headers; recipients who unsubscribe, existing customers, and GPC opt-outs are suppressed automatically. Prospect enrichment draws on lawfully-sourced public and licensed B2B data.
Your rights
Under the GDPR and similar laws you have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data, and to withdraw consent at any time.
To exercise any of these, email privacy@businessmcp.com or use the request form. We respond within 30 days. We will first verify that you are the person the request concerns — usually by replying to the email address on record, or by asking for a detail only the account holder would know. Workspace owners can export or delete any contact directly from the CRM without contacting us.
If your request concerns end-visitor data held on behalf of one of our customers, we will refer you to that customer (the controller) or assist them in responding. You also have the right to lodge a complaint with your local supervisory authority.
Children
BusinessMCP is a business tool not directed to children, and we do not knowingly collect personal data from anyone under 16.
Changes & contact
We may update this policy; material changes will be announced by email. Questions? Email privacy@businessmcp.com.