- We collect what we need to run startbuddi: your account, billing, usage and support details.
- We never sell your data, and we do not use your workspace content to train AI models.
- Our main database is in the EU (Ireland), with safeguards for every transfer abroad.
- Website analytics only load if you say yes to cookies.
- You can ask to see, correct, export or delete your data at any time by emailing privacy@startbuddi.com.
- Covers the EU and UK GDPR, Nigeria's Data Protection Act 2023 and similar laws elsewhere.
This policy explains what personal data startbuddi collects, why, who we share it with, how long we keep it, and the rights you have. It covers our website (startbuddi.com), the startbuddi app (app.startbuddi.com) and the emails, chats and calls that come with them.
startbuddi is run by Tech Della Solutions Ltd, a private company limited by shares registered in Nigeria with the Corporate Affairs Commission (RC 7038770), based in Ibadan (“startbuddi”, “we”, “us”). For the personal data described in this policy we are the data controller. You can reach us about anything here at privacy@startbuddi.com.
Two kinds of data, two roles
- Data about you, as a visitor to our website, a person who signs up, or a member of a workspace team. We decide how this is used, so we are the controller and this policy applies.
- Data your business puts into startbuddi, such as your contacts, your customers’ messages, form answers, bookings and invoices. Your business decides how this is used, so your business is the controller and we are its processor. Our Data processing agreement covers that data. If you are one of our customers’ customers and want to ask about your data, please contact the business you dealt with first; we will help them answer you.
What we collect
When you visit our website
- Things you tell us: your name, email and any message when you fill in a form, such as the contact form, the newsletter or the form that unlocks our free tools, and optionally your business type or phone number.
- Technical data: your IP address, browser, device and the pages you ask for, which our hosting and security providers log to deliver the site and protect it from abuse. We use your country (from your IP address) to show prices in your currency. The lookup happens on our own server using the free IP to Country Lite database by DB-IP (CC BY 4.0), so your IP address is not sent anywhere for it.
- Analytics: only if you say yes in the cookie banner, we use Google Analytics and Mixpanel to see which pages are visited and how people find us. Our Cookie policy lists every cookie.
- Live chat and calls with Chip: if you chat with us or call Chip from our website, we keep the conversation, and anything you choose to share in it, so we can answer you and follow up.
When you sign up and use the app
- Account data: your name, email address, password (stored only as a secure hash by our authentication provider), phone number if you add one, profile photo, and your business name, location and type from onboarding. If you sign in with Google, we receive your name, email and profile picture from Google, and nothing else unless you connect a Google service later.
- Billing data: your plan, billing country, currency, invoices and payment history. Card and bank details go straight to Paystack, Stripe or PayPal and never reach our servers; we receive a payment reference, whether the payment succeeded, and sometimes the card type and last four digits so you can recognise it.
- Usage and device data: sign-in times, IP addresses, device and browser, the features you use, and errors you run into. We use it to keep your account secure (for example new-device alerts and account lockout after repeated failed sign-ins), to fix bugs, and to understand which features help people.
- Product analytics in the app: when you are signed in, we use Mixpanel to record which screens and features you use, including session recordings of how the app is used, and Sentry to capture errors, with a screen replay of a sample of sessions and of sessions where something breaks (Sentry replays mask all text and block images). We also note which campaign or website brought you to sign up, using first-party cookies. We use this to find and fix problems and improve startbuddi.
- Workspace activity: the audit log records who changed what and when, for example privacy, security, billing and ownership events, so workspace owners can see what happened.
- Support conversations: messages you send us by email, chat or WhatsApp, and anything you share in them.
- Chip conversations: what you ask Chip and what it answers, kept in your workspace so you can see your history.
We do not ask for special category data (such as health, religion or biometric data) about you, and we do not knowingly collect data from children.
Why we use it, and our lawful basis
Data protection laws, including the EU and UK GDPR and Nigeria’s Data Protection Act 2023 (NDPA), require a lawful basis for each use. Ours are:
- To provide startbuddi (creating your account, running your workspace, taking payments, sending service emails such as receipts, password resets and security alerts): because it is necessary for our contract with you.
- To keep startbuddi secure and prevent fraud, spam and abuse, to fix problems, and to improve the product using usage data: because we have a legitimate interest in running a safe, working service. We keep this proportionate and you can object.
- To send you product news, tips and offers: with your consent where the law requires it, or otherwise because of our legitimate interest in telling customers about similar services. Every marketing email has an unsubscribe link.
- Website analytics and marketing cookies: only with your consent, which you can withdraw at any time in Cookie settings.
- To answer your questions through the contact form, chat or email: because you asked us to, and our legitimate interest in replying.
- To keep records such as invoices and tax records, and to respond to lawful requests from authorities: because the law requires it.
Chip and AI
- When you use Chip, we send your request and the workspace information needed to answer it to our AI providers: Anthropic, and OpenAI (as a fallback, and for voice calls, transcription and images). When Chip researches the web for you, the search goes to Exa. Chip only sees what the person asking is allowed to see in the workspace.
- We use these providers under their business API terms, which do not allow them to train their models on the data we send. They may keep it for a short time to detect abuse, as their terms allow.
- We do not use your workspace content to train AI models.
- Our AI live chat and voice agent tell people they are talking to an AI. Where a workspace switches on recording or transcription for calls, the recording or transcript is kept in that workspace.
- Chip can make mistakes. It does not make decisions about you that have legal or similarly significant effects.
Who we share data with
We do not sell personal data, and we do not share it for other companies’ advertising.
We share it only with:
- Service providers (subprocessors) who run parts of startbuddi for us under contracts that require them to protect it and use it only for us. They include Vercel (hosting), Supabase (database and sign-in), Cloudflare (file storage and our website’s network), Resend (email sending), SMS providers such as Twilio, Termii, Africa’s Talking, Infobip and Sendchamp, Anthropic, OpenAI and Exa (Chip), Stripe, Paystack and PayPal (payments), Mixpanel, Google Analytics and Sentry (analytics and error monitoring), Pusher (real-time updates), Upstash (job queue), data providers such as Brandfetch, Hunter and People Data Labs (company details and contact research you ask Chip for) and Brevo (our own newsletter). The full list, with what each one sees and where it runs, is on our Security page and in the app at app.startbuddi.com/legal/subprocessors.
- Services you connect, such as WhatsApp, Messenger and Instagram (Meta), Google Calendar or Gmail, Microsoft Outlook, Telegram, Slack, Zapier, another CRM you import from, or your domain registrar. We exchange data with them only because you asked us to, and their own privacy policies apply to what they do with it.
- Your workspace: if you join a team, the workspace owner and admins can see your name, email, role and activity in that workspace.
- Authorities, when the law requires it, or to protect people’s safety or our rights. We push back on requests that are not lawful.
- A buyer, if startbuddi or Tech Della Solutions Ltd is ever sold or merged. We will tell you before your data becomes subject to a different privacy policy.
Where your data is kept, and international transfers
Our main database is hosted in the European Union (Ireland), our app servers run in the EU (Frankfurt) with a global network for fast delivery, and email is sent from the EU. Uploaded files are stored with Cloudflare. Some providers, including our AI, analytics, SMS and payment providers and the channels you connect, process data in the United States or elsewhere, and our team works from Nigeria. The workspace setting “Where your data is kept” records a preference; it does not move data today.
When personal data moves between countries, we protect it:
- From the EU, EEA or UK: using the European Commission’s Standard Contractual Clauses and the UK Addendum, or an adequacy decision where one exists.
- From Nigeria: under Part VIII of the NDPA, relying on the recipient country’s adequate protection or on the same contractual safeguards.
- From other countries: using the equivalent safeguards their law requires.
You can ask us for a copy of the safeguards that apply by emailing privacy@startbuddi.com.
How long we keep it
- Your account and workspace: for as long as they exist. If your paid plan ends, your workspace moves to the Free plan and nothing is deleted.
- When an owner deletes a workspace (Settings, then Danger zone): its data is removed from our live systems straight away and from backups within 90 days. This cannot be undone, so export first.
- When you ask us to delete your personal account: we delete it within 30 days of confirming your request.
- Items you bin, and files sent in chats: documents in the bin and chat attachments are deleted after 30 days.
- Invoices, payment and tax records: for as long as tax and accounting law requires, which can be up to 6 years or more depending on the country.
- Security logs and sign-in history: for a limited period, long enough to investigate problems and protect accounts.
- Website form submissions and chats: for as long as we need them to answer and follow up, and no longer than 24 months after our last contact with you unless you become a customer.
- Analytics data: for the retention period set in Google Analytics and Mixpanel, and only if you consented.
- Marketing preferences: if you unsubscribe, we keep your email address on a suppression list so we do not email you again.
How we protect it
We encrypt data in transit and at rest, encrypt connected-account tokens and secrets a second time with keys kept outside the database, keep each workspace’s data separate, and record important changes in an audit log. Sign-in is protected by rate limits and account lockout after repeated failed attempts. No system is perfectly secure; if a breach affects your personal data, we will tell you and the relevant regulator as the law requires. More on our Security page.
Your rights
Depending on where you live, you have the right to:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct data that is wrong or incomplete.
- Ask us to delete your data.
- Ask us to limit how we use your data, or object to our using it for legitimate interests or direct marketing.
- Get your data in a portable format. Workspace owners can export their workspace data at any time from Settings.
- Withdraw consent at any time, for example by unsubscribing or changing your cookie choices. This does not affect what we did before.
- Not be subject to decisions based only on automated processing that have legal or similarly significant effects on you.
- Complain to a data protection authority. In Nigeria that is the Nigeria Data Protection Commission (NDPC); in the UK, the Information Commissioner’s Office (ICO); in the EU, the authority in your country. We would like the chance to sort out your concern first.
Residents of some US states, and of other countries with privacy laws such as South Africa (POPIA), Kenya and Ghana, have similar rights. The same process applies.
How to use them: email privacy@startbuddi.com from the address on your account. Workspace owners and admins can also export workspace data themselves from Settings, then Danger zone. We may ask you to confirm your identity. We reply within one month, and tell you if we need longer for a complex request. We do not charge for requests unless they are clearly unfounded or excessive.
If you sign in with Facebook or connect Meta
If you connected a Facebook, Instagram or WhatsApp account and want the data we received from Meta deleted, remove startbuddi from your Facebook settings under Apps and websites, or email us. Meta will send us a deletion request, and we delete that data within 30 days unless the law requires us to keep it. You can check the status of a request at the link Meta gives you.
Children
startbuddi is for businesses and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you think a child has given us their data, email us and we will delete it.
Changes to this policy
We will update this policy when what we do with data changes. We will post the new version here with its effective date and, for significant changes, email account owners or show a notice in the app before they take effect.
Contact
Tech Della Solutions Ltd (RC 7038770), Ibadan, Nigeria. Privacy questions and requests: privacy@startbuddi.com. Anything else: hello@startbuddi.com.
Version history
Earlier versions
- Current version1 October 2026
- Earlier version (replaced in full by this version)
Questions about this document? Email privacy@startbuddi.com.