Privacy Policy

Effective date: 5 October 2026

This Privacy Policy explains how BetterSuite handles personal data. It covers the personal data we control: information about the businesses that sign up to use BetterSuite ("operators") and about visitors to our websites.

Two different roles. BetterSuite is white-label software. When an operator runs a branded application on our platform, the operator decides how their end users' data is used — the operator is the data controller for that data, and BetterSuite acts as a processor on the operator's behalf under our Data Processing Agreement. If you are an end user (for example, a rider, driver, shopper, or buyer of a business that uses BetterSuite), please refer to that business's own privacy notice; this policy describes only the data for which BetterSuite is itself responsible.

1. Who is responsible

The controller of the personal data described here is Lume Agency Inc., trading as BetterSuite, registered at 7 Tigranyan Street, Yerevan, Armenia. For any privacy question or request, contact us at [email protected].

2. What we collect

When you sign up and use BetterSuite as an operator:

  • Account and contact data — name, business name, email address, phone number, and login credentials (including passkeys and, if you use social sign-in, your Google or Apple account identifier).
  • Billing data — subscription plan, billing contact, and payment details. Card details are collected and stored by our payment provider, Stripe; we receive limited information such as the card type and last four digits.
  • Configuration and content — the settings, branding, catalogues, and other content you add to run your applications.
  • Usage and device data — how you interact with our dashboard and websites, IP address, browser and device information, and diagnostic logs.

When you visit our websites:

  • Cookies and similar technologies (see our Cookie Policy), and information from marketing links such as a Google Ads click identifier.
  • Information you submit through forms, such as a contact or demo request.
  • Chat messages — if you write to us through the chat on our websites, the messages you send, any name or email address you choose to give us, and when you last had the conversation open, which is how we show you the replies you have not read yet and how our team knows a reply has been read. If you sign in to your dashboard in a browser where you have chatted with us, we attach those conversations to your account, so you can carry them on from the dashboard or another device and our team can see which workspace they are about. Conversations you start from the dashboard are attached to your account from the first message. When we reply to an attached conversation and you do not have the chat open, we tell you with a notification in your dashboard and an email to your account's address.
  • Details of the visit a chat started from — your IP address and the approximate location (country and city) we derive from it, your browser and device information, your language, the page you were on, and the site that referred you. Where you have consented to analytics and marketing cookies, or where consent is not required in your region, we also attach the campaign information described in our Cookie Policy.
  • Messages on WhatsApp or Telegram — if you choose to write to us there instead of in the chat on our websites, we receive your messages together with the phone number or username and the profile name your account shows. Those services handle the conversation under their own terms and privacy policies.

3. How we use personal data

We use personal data to:

  • provide, operate, secure, and support the Service;
  • set up and manage your account and process billing through Stripe;
  • respond to enquiries and provide customer support;
  • monitor, debug, and improve the platform, including error monitoring;
  • measure and improve our marketing, and understand how our websites are used;
  • send service messages and, where permitted, relevant product updates; and
  • comply with legal obligations and enforce our Terms of Service.

Legal bases (where the GDPR or similar law applies). We rely on: performance of our contract with you; our legitimate interests in running and improving the Service and marketing it responsibly; your consent where required (for example, certain cookies); and compliance with legal obligations.

4. Cookies and analytics

Our websites use cookies and similar technologies for essential functions (such as keeping you signed in) and for analytics and marketing measurement, including Google Analytics, Google Tag Manager, Google Ads conversion measurement, and error monitoring and session diagnostics through Sentry. You can control cookies through your browser and the options described in our Cookie Policy.

5. Who we share data with

We share personal data with service providers ("subprocessors") that help us run the Service, and only as needed for the purposes above. Our subprocessors include:

ProviderPurpose
StripeSubscription billing and payment processing
HetznerCloud hosting and infrastructure (EU)
CloudflareCDN, edge security, and object storage
Google (incl. Firebase)Maps, push notifications, analytics, and advertising measurement
MapboxMaps and geolocation
TwilioSMS and voice messaging
SendGrid, Resend, PostmarkTransactional and marketing email delivery
SentryError monitoring and diagnostics
OpenAI, AnthropicAI-powered features, including helping our team draft replies to support and chat messages

A subprocessor list specific to the data we process on operators' behalf is maintained in our Data Processing Agreement.

We may also disclose personal data where required by law, to protect our rights or the safety of others, or as part of a merger, acquisition, or sale of assets. We do not sell your personal data.

6. International transfers

We host the Service in the European Union (Hetzner, Finland). Some of our subprocessors are located outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.

7. How long we keep data

We keep personal data for as long as your account is active and as needed to provide the Service, then for as long as required to meet legal, accounting, tax, or dispute-resolution obligations, after which we delete or anonymise it. Retention periods vary by data type and legal requirement.

Website chat. We delete the details of the visit attached to a chat — IP address, city, browser and device information, language, page, referrer, and campaign information — 90 days after the chat starts, keeping only the country. We delete the conversation itself, including any name or email address you gave us, 24 months after its last message. You can ask us to delete it sooner. Attaching a conversation to your account does not change these periods. If your account is deleted first, the conversation is detached from it and deleted on the same schedule.

8. How we protect data

We use technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption of sensitive credentials at rest, access controls, and hosting with a reputable EU provider. No system can be guaranteed completely secure; we work to identify and address risks on an ongoing basis. If a personal-data breach affects you, we will notify you and any regulator as required by law.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal data, to object to certain processing, to data portability, and to withdraw consent. To exercise a right, email [email protected]. You also have the right to complain to your local data-protection authority.

If your request concerns data processed by an operator's application (where you are that business's end user), we will refer you to, or act on the instructions of, that operator as the controller.

10. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children through our own websites.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and, if the change is material, provide additional notice. The "Effective date" above shows when it last changed.

12. Contact

For any privacy question or request, contact [email protected].