Looks like you're browsing from the United States — you're seeing the EU version.Switch to the US version
Legal

Privacy Policy

Last updated June 25, 2026Effective June 25, 2026Version 2.0

The short version: We collect the minimum we need to run HelpBob, we use it to provide and secure the Service, and we never sell your data. For the sites you connect we act as a processor on your behalf. Your account data and your visitors’ scan data live in the EU; only our payment and US email vendors are in the US. You can access, correct, or delete your data at any time — just email [email protected].

HelpBob is a product of Luna And The Stars LLC, a Delaware limited liability company. On this page, “HelpBob,” “we,” “us,” and “our” refer to Luna And The Stars LLC.

01Who we are

This Privacy Policy explains how Luna And The Stars LLC (a Delaware limited liability company) collects, uses, shares, and protects personal data when you visit our website, create an account, receive business outreach from us, or use the HelpBob service (the “Service”). For the personal data we handle about our own customers, prospects, and website visitors, Luna And The Stars LLC is the data controller.

Processor, not controller, for your visitors’ dataWhen HelpBob scans and remediates the sites you connect, we act as a processoron your behalf — you remain the controller of the personal data on your pages and of your visitors’ data. Those terms are set out in our Data Processing Agreement. This Privacy Policy covers the data for which we are the controller.

02The data we collect

We collect only what we need to run the Service:

  • Account data — name, work email, company, role, password (hashed), and preferences you set.
  • Billing data — plan, billing address, tax identifiers, and partial card details. Full card numbers are handled by our payment processor; we never see or store them.
  • Connected-site data (as controller) — the list of domains you connect, your configuration, and the tamper-evident audit-trail metadata of remediations. The personal data contained in the content of your scanned pages, and the technical data of your visitors, are processed under our role as processor and are governed by the DPA, not this Policy.
  • Usage & device data — log data such as IP address, browser type, pages viewed, and timestamps, collected to keep the Service secure and reliable.
  • Prospect data — limited business contact details we use for B2B outreach (see Section 4).
  • Support & communications — messages you send us by email or chat.

We do not intentionally collect special categories of data, and we ask that you not send them to us through support channels.

03How we use your data

We use personal data to:

  • Provide, operate, and maintain the Service, including running scans and applying fixes.
  • Create and secure your account and process payments.
  • Provide support and respond to your requests.
  • Send service messages and, where permitted, product updates you can opt out of at any time.
  • Contact business prospects about HelpBob (Section 4).
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Improve our detection and remediation using aggregated, de-identified data, which we may use as a controller and which does not identify you or any individual.
  • Comply with legal obligations and enforce our Terms.

We never sell your personal data, and we do not use the content of your pages to train models for unrelated purposes.

04Marketing & business outreach

To our customers. We send you service messages necessary to run the Service (on the basis of our contract), and we may send product updates and marketing where permitted. You can opt out of marketing at any time via the unsubscribe link or by emailing [email protected]; service messages will continue while you have an account.

To business prospects. If you receive a message from us as a prospect, we process limited business contact data — your name, business email, company, and role — that we obtain from publicly available sources and commercial providers, to tell you about HelpBob where we have a legitimate interest in business-to-business outreach. You can object and opt out at any time using the unsubscribe link or by emailing us, after which we will stop contacting you and, if you ask, delete your details. We respect applicable electronic-marketing rules, which are stricter in some countries (for example, Germany).

If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure, improve, and promote the Service, and to carry out B2B outreach, where those interests are not overridden by your rights.
  • Consent — for non-essential cookies and, where required, optional marketing, which you can withdraw at any time.
  • Legal obligation — to meet accounting, tax, and other legal requirements.

06Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Our accessibility scanning and any scoring we apply relate to websites and business prospects — not to automated decisions about your access to, or treatment within, the Service.

07Cookies & similar technologies

We use cookies and similar technologies on our website to keep you signed in, remember your preferences, keep the site secure, and understand how the Service is used:

  • Strictly necessary — required for the site to function (e.g. authentication and security). These cannot be switched off.
  • Preferences — remember choices such as language or currency.
  • Analytics — we use PostHog (EU region, hosted in Frankfurt) to measure and improve the Service. Where the law requires it, analytics are set only after you consent through our cookie banner.

We show a consent banner to visitors in the EEA, the UK, and other regions where consent is required, and you can change your choices at any time through that banner or your browser settings. The HelpBob remediation script that runs on your own site does not set any cookies on your visitors.

08How we share data

We share personal data only as needed, and never in exchange for money. We share with:

  • Service providers we use as controller — vetted vendors that help us run our business: Stripe (payments, US), Postmark (transactional email to US recipients, US), Brevo (transactional and marketing email to EU recipients, EU), and PostHog (product analytics, EU). Our sub-processors that handle your connected-site data on your behalf (cloud hosting and CDN) are listed, with a change-notification subscription, at helpbob.ai/subprocessors and are governed by the DPA.
  • Professional advisors — lawyers, accountants, and auditors, where needed.
  • Legal & safety — authorities or third parties where required by law, to enforce our terms, or to protect rights, safety, and the integrity of the Service. We review the legality of government requests and disclose only what is necessary.
  • Business transfers — a successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.

09International data transfers

Where your data lives.The personal data on your connected sites and your visitors’ technical data are stored within the European Economic Area (our hosting and CDN; see the DPA and sub-processor list). Your account, usage, and analytics data are also processed in the EU.

Transfers to the US. Because we are a US company, some data we hold as controller is transferred to the United States — specifically for payment processing (Stripe) and email delivery to US recipients (Postmark), and remote administrative access by our US team. Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we use appropriate safeguards — the European Commission’s Standard Contractual Clauses and, for UK data, the UK Addendum (and the EU-US Data Privacy Framework where a recipient is certified). A copy of the relevant safeguards is available on request.

10How long we keep data

We keep personal data only as long as we need it:

  • Account & connected-site data — for as long as your account is active, and deleted within 90 days after your account closes.
  • Audit trail — the scan-and-remediation audit trail is retained for up to 12 months after termination, so you can demonstrate past conformance, and then deleted (as set out in the DPA).
  • Billing & tax records — retained for as long as required by applicable tax and accounting law.
  • Prospect data — until you object, or until it is no longer useful for outreach.
  • Other data — we may retain data longer where needed to meet legal obligations, resolve disputes, or enforce our agreements; otherwise we delete or de-identify it.

11How we protect data

We use technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, least-privilege practices, environment segregation, and monitoring. No system is perfectly secure, but we work hard to protect your data and keep our practices current. If a personal data breach is likely to result in a high risk to you, we will notify you in line with applicable law. If you discover a vulnerability, please report it to [email protected].

12Your rights (EU/UK GDPR)

If you are in the EEA, the UK, or Switzerland, you have the right to access, correct, delete, or restrict processing of your personal data; to object to processing (including direct marketing and B2B outreach); to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, email [email protected]. We will respond within the timeframes required by law and may need to verify your identity first.

13EU & UK representatives

As a company outside the EU and UK, we have appointed representatives you and supervisory authorities can contact on data-protection matters:

  • EU representative (Article 27 GDPR): JUNG & JUNGER, Kivimurru tn 34, 11411 Tallinn, Estonia
  • UK representative (Article 27 UK GDPR): HelpBob UK, 124 City Road, London, EC1V 2NX, United Kingdom

You may contact either representative, or us at [email protected], regarding the processing of your personal data.

14Your rights (California & other US states)

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use it, to request access to or deletion of it, to correct inaccurate information, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. Residents of certain other US states (including Virginia, Colorado, Connecticut, Utah, and Texas) have comparable rights.

We do not sell or “share” personal information for cross-context behavioral advertising, as those terms are defined under California law, and we do not use or disclose sensitive personal information (such as your account login credentials) beyond the purposes permitted by law or to infer characteristics about you. To exercise your rights, email [email protected]. You may use an authorized agent, and we will not discriminate against you for making a request.

Categories of personal information (CCPA/CPRA)

In the past 12 months we have collected the following categories. We disclose (but do not sell or share) these to the service providers in Section 8 to run the Service.

CCPA categoryExamplesSourcePurposeRetention
IdentifiersName, work email, account ID, IP addressYou; your deviceProvide and secure the Service; communicate with youAccount life + 90 days
Customer records / commercial informationBilling details, plan, transaction historyYouProcess payments; accountingAs required by tax & accounting law
Internet / network activityUsage, log, and device dataYour deviceSecurity, reliability, and improvementLimited operational period
Professional / employment informationCompany, roleYou; public & commercial sources (prospects)Provide the Service; B2B outreachAccount life; prospects until objection
Sensitive PI — account credentialsUsername and password (hashed)YouSecure account access onlyAccount life
Geolocation (coarse)Approximate location from IPYour deviceSecurity and localization (not precise geolocation)Limited operational period

We do not use sensitive personal information to infer characteristics, and we do not knowingly collect the personal information of minors.

15Children's privacy

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children under 16 (or under 13 in the United States). If you believe a child has provided us personal data, contact us and we will delete it.

16Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the current version, and for material changes we will provide additional notice by email or in-product. We encourage you to review this page periodically.

17How to reach us

For any privacy question or request, contact us:

  • Email: [email protected]
  • Post: Luna And The Stars LLC, 8 The Green, Suite B, Dover, DE 19901, United States
  • EU/UK representatives: see Section 13
Privacy questions or requests? Write to [email protected]. Luna And The Stars LLC · 8 The Green, Suite B, Dover, DE 19901, United States.

Compliance you can prove, not just promise.

Start a free scan and see every accessibility issue on your site in under two minutes — with the paper trail to back it up.

No credit card · 30-day money-back guarantee