HelpBob is a product of Luna And The Stars LLC, a Delaware limited liability company. On this page, “HelpBob,” “we,” “us,” and “our” refer to Luna And The Stars LLC.
01Who we are
This Privacy Policy explains how Luna And The Stars LLC (a Delaware limited liability company) collects, uses, shares, and protects personal data when you visit our website, create an account, receive business outreach from us, or use the HelpBob service (the “Service”). For the personal data we handle about our own customers, prospects, and website visitors, Luna And The Stars LLC is the data controller.
02The data we collect
We collect only what we need to run the Service:
- Account data — name, work email, company, role, password (hashed), and preferences you set.
- Billing data — plan, billing address, tax identifiers, and partial card details. Full card numbers are handled by our payment processor; we never see or store them.
- Connected-site data (as controller) — the list of domains you connect, your configuration, and the tamper-evident audit-trail metadata of remediations. The personal data contained in the content of your scanned pages, and the technical data of your visitors, are processed under our role as processor and are governed by the DPA, not this Policy.
- Usage & device data — log data such as IP address, browser type, pages viewed, and timestamps, collected to keep the Service secure and reliable.
- Prospect data — limited business contact details we use for B2B outreach (see Section 4).
- Support & communications — messages you send us by email or chat.
We do not intentionally collect special categories of data, and we ask that you not send them to us through support channels.
03How we use your data
We use personal data to:
- Provide, operate, and maintain the Service, including running scans and applying fixes.
- Create and secure your account and process payments.
- Provide support and respond to your requests.
- Send service messages and, where permitted, product updates you can opt out of at any time.
- Contact business prospects about HelpBob (Section 4).
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Improve our detection and remediation using aggregated, de-identified data, which we may use as a controller and which does not identify you or any individual.
- Comply with legal obligations and enforce our Terms.
We never sell your personal data, and we do not use the content of your pages to train models for unrelated purposes.
04Marketing & business outreach
To our customers. We send you service messages necessary to run the Service (on the basis of our contract), and we may send product updates and marketing where permitted. You can opt out of marketing at any time via the unsubscribe link or by emailing [email protected]; service messages will continue while you have an account.
To business prospects. If you receive a message from us as a prospect, we process limited business contact data — your name, business email, company, and role — that we obtain from publicly available sources and commercial providers, to tell you about HelpBob where we have a legitimate interest in business-to-business outreach. You can object and opt out at any time using the unsubscribe link or by emailing us, after which we will stop contacting you and, if you ask, delete your details. We respect applicable electronic-marketing rules, which are stricter in some countries (for example, Germany).
05Legal bases for processing (EU/UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure, improve, and promote the Service, and to carry out B2B outreach, where those interests are not overridden by your rights.
- Consent — for non-essential cookies and, where required, optional marketing, which you can withdraw at any time.
- Legal obligation — to meet accounting, tax, and other legal requirements.
06Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Our accessibility scanning and any scoring we apply relate to websites and business prospects — not to automated decisions about your access to, or treatment within, the Service.
07Cookies & similar technologies
We use cookies and similar technologies on our website to keep you signed in, remember your preferences, keep the site secure, and understand how the Service is used:
- Strictly necessary — required for the site to function (e.g. authentication and security). These cannot be switched off.
- Preferences — remember choices such as language or currency.
- Analytics — we use PostHog (EU region, hosted in Frankfurt) to measure and improve the Service. Where the law requires it, analytics are set only after you consent through our cookie banner.
We show a consent banner to visitors in the EEA, the UK, and other regions where consent is required, and you can change your choices at any time through that banner or your browser settings. The HelpBob remediation script that runs on your own site does not set any cookies on your visitors.
08How we share data
We share personal data only as needed, and never in exchange for money. We share with:
- Service providers we use as controller — vetted vendors that help us run our business: Stripe (payments, US), Postmark (transactional email to US recipients, US), Brevo (transactional and marketing email to EU recipients, EU), and PostHog (product analytics, EU). Our sub-processors that handle your connected-site data on your behalf (cloud hosting and CDN) are listed, with a change-notification subscription, at helpbob.ai/subprocessors and are governed by the DPA.
- Professional advisors — lawyers, accountants, and auditors, where needed.
- Legal & safety — authorities or third parties where required by law, to enforce our terms, or to protect rights, safety, and the integrity of the Service. We review the legality of government requests and disclose only what is necessary.
- Business transfers — a successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.
09International data transfers
Where your data lives.The personal data on your connected sites and your visitors’ technical data are stored within the European Economic Area (our hosting and CDN; see the DPA and sub-processor list). Your account, usage, and analytics data are also processed in the EU.
Transfers to the US. Because we are a US company, some data we hold as controller is transferred to the United States — specifically for payment processing (Stripe) and email delivery to US recipients (Postmark), and remote administrative access by our US team. Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we use appropriate safeguards — the European Commission’s Standard Contractual Clauses and, for UK data, the UK Addendum (and the EU-US Data Privacy Framework where a recipient is certified). A copy of the relevant safeguards is available on request.
10How long we keep data
We keep personal data only as long as we need it:
- Account & connected-site data — for as long as your account is active, and deleted within 90 days after your account closes.
- Audit trail — the scan-and-remediation audit trail is retained for up to 12 months after termination, so you can demonstrate past conformance, and then deleted (as set out in the DPA).
- Billing & tax records — retained for as long as required by applicable tax and accounting law.
- Prospect data — until you object, or until it is no longer useful for outreach.
- Other data — we may retain data longer where needed to meet legal obligations, resolve disputes, or enforce our agreements; otherwise we delete or de-identify it.
11How we protect data
We use technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, least-privilege practices, environment segregation, and monitoring. No system is perfectly secure, but we work hard to protect your data and keep our practices current. If a personal data breach is likely to result in a high risk to you, we will notify you in line with applicable law. If you discover a vulnerability, please report it to [email protected].
12Your rights (EU/UK GDPR)
If you are in the EEA, the UK, or Switzerland, you have the right to access, correct, delete, or restrict processing of your personal data; to object to processing (including direct marketing and B2B outreach); to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email [email protected]. We will respond within the timeframes required by law and may need to verify your identity first.
13EU & UK representatives
As a company outside the EU and UK, we have appointed representatives you and supervisory authorities can contact on data-protection matters:
- EU representative (Article 27 GDPR): JUNG & JUNGER, Kivimurru tn 34, 11411 Tallinn, Estonia
- UK representative (Article 27 UK GDPR): HelpBob UK, 124 City Road, London, EC1V 2NX, United Kingdom
You may contact either representative, or us at [email protected], regarding the processing of your personal data.
14Your rights (California & other US states)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use it, to request access to or deletion of it, to correct inaccurate information, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. Residents of certain other US states (including Virginia, Colorado, Connecticut, Utah, and Texas) have comparable rights.
We do not sell or “share” personal information for cross-context behavioral advertising, as those terms are defined under California law, and we do not use or disclose sensitive personal information (such as your account login credentials) beyond the purposes permitted by law or to infer characteristics about you. To exercise your rights, email [email protected]. You may use an authorized agent, and we will not discriminate against you for making a request.
Categories of personal information (CCPA/CPRA)
In the past 12 months we have collected the following categories. We disclose (but do not sell or share) these to the service providers in Section 8 to run the Service.
| CCPA category | Examples | Source | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Name, work email, account ID, IP address | You; your device | Provide and secure the Service; communicate with you | Account life + 90 days |
| Customer records / commercial information | Billing details, plan, transaction history | You | Process payments; accounting | As required by tax & accounting law |
| Internet / network activity | Usage, log, and device data | Your device | Security, reliability, and improvement | Limited operational period |
| Professional / employment information | Company, role | You; public & commercial sources (prospects) | Provide the Service; B2B outreach | Account life; prospects until objection |
| Sensitive PI — account credentials | Username and password (hashed) | You | Secure account access only | Account life |
| Geolocation (coarse) | Approximate location from IP | Your device | Security and localization (not precise geolocation) | Limited operational period |
We do not use sensitive personal information to infer characteristics, and we do not knowingly collect the personal information of minors.
15Children's privacy
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children under 16 (or under 13 in the United States). If you believe a child has provided us personal data, contact us and we will delete it.
16Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the current version, and for material changes we will provide additional notice by email or in-product. We encourage you to review this page periodically.
17How to reach us
For any privacy question or request, contact us:
- Email: [email protected]
- Post: Luna And The Stars LLC, 8 The Green, Suite B, Dover, DE 19901, United States
- EU/UK representatives: see Section 13