Privacy Policy

Privacy Policy

Last updated: 11/22/2025

This Privacy Policy explains how SUMPLER (“we”, “us”, “our”) processes personal data when you access or use AnsrFast, our SaaS web application available at https://www.ansrfast.com (“Service”).

We aim to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and globally recognized privacy best practices.

We also comply with the Google API Services User Data Policy, including the Limited Use requirements, for all Google OAuth data.

Using AnsrFast means you accept this Privacy Policy. If you disagree, please discontinue your use of the Service.

1. Who We Are

Data Controller:

SUMPLER

Country: France

Email: contact@ansrfast.com

SUMPLER develops and operates AnsrFast, a platform that enables customer-facing teams to create and manage AI chatbots for help centers and websites.

2. Scope

This Privacy Policy covers all personal data processed through:

  • The AnsrFast website
  • The web application
  • Authentication flows (including Google Sign-In)
  • Support and communication channels
  • Embedded widgets

It applies to all users, including business users from the EU, EEA, UK, US, and other regions.

3. Personal Data We Collect

3.1. Account Data

Collected when you create or manage your account:

  • Name
  • Email address
  • Password hash (never the plain password)
  • Company name (optional)
  • Profile picture (if provided)

If you sign up via Google, certain items come from Google OAuth (see section 3.2).

3.2. Google OAuth Data

If you choose Google Sign-In, we receive:

  • Google account email
  • Basic profile information (name, profile photo)
  • Google user ID
  • OpenID Connect tokens strictly necessary for login

We do not access or read:

  • Gmail content, Drive files, Calendar events, Contacts, Photos, YouTube data, or any sensitive Google scope.

Scopes requested:

openid, email, profile (minimum needed for authentication only).

Purpose:

Authentication, account creation, session management, and security.

We do NOT:

  • Sell Google user data
  • Use Google OAuth data for advertising
  • Combine Google data with third-party data for profiling
  • Share Google data with unauthorized third parties

We fully comply with the Google API Services User Data Policy and Limited Use restrictions.

3.3. Usage Data

Collected automatically when you access the Service:

  • IP address
  • Device information (browser, OS)
  • Pages viewed and actions performed
  • Timestamps, logs, and error reports
  • Referrer information
  • Approximate location (country-level) derived from IP

This helps ensure security, improve performance, and understand how the product is used.

3.4. Content & Knowledge Base Data

To configure your chatbot, you may upload or enter:

  • Help center articles
  • Documentation or FAQs
  • Text snippets
  • Structured or unstructured content

This data belongs to you. We process it only to operate, improve, and deliver your chatbot features.

3.5. Payment & Billing Data

Payments are processed by Stripe. We may receive:

  • Billing name
  • Billing email
  • Billing address (if required for invoicing)
  • Subscription status and payment history
  • Last 4 digits of your card (from Stripe)

All sensitive payment information is stored by Stripe, not by us.

3.6. Cookies & Analytics

We may use:

  • Plausible Analytics (privacy-friendly)
  • or Google Analytics depending on configuration

These tools collect anonymous or pseudonymous metrics to help us improve the product.

We do not use analytics for targeted advertising.

4. How We Use Personal Data

4.1. To Provide and Operate the Service

  • User account creation and authentication (incl. Google Sign-In)
  • Delivering the chatbot features
  • Processing payments and subscriptions
  • Ensuring platform reliability and security

4.2. To Provide Support

  • Respond to support tickets
  • Assist with onboarding and troubleshooting
  • Communicate important service messages

4.3. To Improve the Product

  • Analyze feature usage
  • Identify usability or performance issues
  • Enhance user experience and reliability

4.4. Communications

We may send:

  • Transactional communications (e.g. receipts, password resets)
  • Product updates
  • Security alerts
  • Onboarding tips or educational content

You can unsubscribe from non-essential emails at any time.

5. Legal Bases for Processing (GDPR)

We rely on the following legal bases:

Performance of a contract:

To provide, maintain, and support the Service.

Legitimate interests:

To improve the product, ensure security, prevent fraud, and ensure stable operation.

Consent:

For optional analytics, cookies, and marketing communications where required.

6. Data Sharing & Sub-Processors

We share data only with service providers who act on our behalf and only for necessary operational purposes.

Sub-processors include:

6.1. Hosting & Infrastructure

  • Vercel – application hosting
  • Cloudflare – CDN, security, performance
  • Neon (on AWS Frankfurt) – database hosting

6.2. Payment Processor

  • Stripe – billing and invoicing

6.3. Analytics & Monitoring

  • Plausible Analytics / Google Analytics
  • Logging and error tracking via infrastructure providers

6.4. Other Providers

We may use email, support, or operational tools as needed.

Each provider processes data under strict confidentiality and data protection agreements.

We do not sell or rent personal data.

7. International Data Transfers

Your data may be processed in countries outside the EU/EEA, including the United States.

When this occurs, we rely on safeguards such as:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions where available
  • Additional technical and organizational measures

We aim to ensure your data benefits from a level of protection consistent with EU standards.

8. Data Retention

We retain personal data only for as long as necessary to:

  • Provide the Service
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements

Typical retention examples:

  • Account data: kept until your account is deleted
  • Google OAuth data: kept only as long as needed for authentication
  • Logs: retained for security and diagnostics for a limited period
  • Billing data: retained as required by accounting law

You may request deletion at any time.

9. Security Measures

We take appropriate technical and organizational measures, including:

  • HTTPS encryption
  • Secure password hashing
  • Access control and permissions
  • Continuous security monitoring
  • Data minimization and strict access logs
  • Use of reputable infrastructure providers

While no security system is infallible, we continuously work to protect your data.

10. Your Rights

10.1. GDPR Rights (EU/EEA/UK Users)

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Request a portable copy of your data
  • Withdraw consent at any time
  • File a complaint with a data protection authority

10.2. CCPA/CPRA Rights (California Users)

You have the right to:

  • Request to know what personal information we collect
  • Request deletion of your personal data
  • Request correction of inaccurate data
  • Access your personal information
  • Opt out of “sale” or “sharing” (we do not sell personal data)
  • Non-discrimination for exercising your rights

To exercise your rights, contact: contact@ansrfast.com

11. Children’s Privacy

AnsrFast is not intended for children under 13 (or 16 where applicable under GDPR).

We do not knowingly collect data from children.

If you believe data was collected from a child, contact us immediately.

12. Third-Party Links

Our Service may link to third-party websites or services. Their privacy practices are governed by their own privacy policies, not ours.

13. Changes to This Policy

We may update this Privacy Policy from time to time.

We will publish updates on this page, and for significant changes, we may notify users by email.

14. Contact Us

For questions or privacy requests, contact:

Email: contact@ansrfast.com

Website: https://www.ansrfast.com