AfterBooth

Privacy Policy

Last updated: April 4, 2026

1. Who We Are

AfterBooth is operated by AfterBooth, based in Toronto, ON, Canada. If you have any privacy-related questions or requests, contact us at privacy@afterbooth.com.

2. What Data We Collect

We collect two categories of data:

Account data (you provide directly):

  • Your name and business email address
  • Your company name and industry (set during onboarding)
  • Billing information (processed and stored by Stripe — we never see raw card numbers)

Lead data (you upload):

  • Names, business email addresses, job titles, company names, phone numbers
  • Booth notes and custom fields from your event CSV
  • AI-generated scores and email drafts derived from the above

Usage data (collected automatically):

  • Pages visited and features used within the app
  • Authentication session tokens (stored in browser cookies)
  • IP address and browser type for security logging

3. Why We Process Your Data (Legal Basis)

We process your account data to perform our contract with you — providing the AfterBooth service you signed up for.

We process lead data solely on your instruction, acting as a data processor on your behalf. You are the data controller of any lead data you upload. We do not independently determine the purpose or means of processing your leads — we only process it to provide the service features you use (scoring, draft generation, status tracking).

4. AI Processing

AfterBooth uses Anthropic's Claude API to score leads by purchase intent and generate personalized email drafts. Before any data is sent to Anthropic's API, we strip all directly identifying information — names, email addresses, and phone numbers are removed. Only job title, company, and booth notes are sent for scoring purposes.

Anthropic does not use API inputs to train their models. You can review Anthropic's privacy practices at anthropic.com/privacy.

5. Third-Party Sub-Processors

We share data with the following sub-processors to operate the service. All are contractually bound to protect your data:

ProcessorPurposeLocation
SupabaseDatabase & authenticationUnited States
VercelApplication hostingUnited States
AnthropicAI scoring & draft generation (anonymized data only)United States
StripePayment processingUnited States
ResendTransactional email (invites, receipts, reminders)United States

6. International Data Transfers

Our infrastructure is based in the United States. If you are accessing AfterBooth from Canada, the European Union, or any other jurisdiction, your data is transferred to and processed in the United States. By using AfterBooth, you acknowledge this transfer. We take steps to ensure your data is protected in accordance with applicable law.

7. Data Retention

Your account data and lead data are retained for as long as your account is active.

When you cancel your subscription, your data is retained for 30 days. If you reactivate within that period, everything is exactly where you left it. After 30 days following cancellation, all your data — leads, events, drafts, and reminders — is permanently deleted.

You can request earlier deletion at any time by emailing privacy@afterbooth.com. We will process deletion requests within 30 days.

8. Your Rights

Depending on where you are located, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your personal data (right to erasure / right to be forgotten).
  • Portability: Request your data in a portable, machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdrawal of consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.

California residents (CCPA): You have the right to know what personal information we collect, to request deletion, and to opt out of sale. We do not sell personal information.

Canadian residents (PIPEDA): You have the right to access your personal information and challenge its accuracy. You may withdraw consent to processing subject to legal or contractual restrictions.

To exercise any of these rights, email privacy@afterbooth.com. We will respond within 30 days.

9. Cookies

We use session cookies for authentication only. These are strictly necessary to keep you logged in and cannot be disabled without breaking the service. We do not use advertising cookies, tracking pixels, or analytics cookies. No third-party cookies are set by AfterBooth.

10. Security

We implement industry-standard security measures including encrypted data in transit (TLS), encrypted data at rest, row-level access controls so each organization can only access its own data, and rate limiting on all API endpoints. Despite these measures, no system is 100% secure. If you discover a security issue, please report it to privacy@afterbooth.com.

11. Your Obligations as Data Controller

When you upload lead data to AfterBooth, you are the data controller of that data. You are responsible for ensuring you have a lawful basis to process and store that data — for example, that your leads consented to follow-up contact at the event, or that you have a legitimate interest under applicable law. AfterBooth processes lead data solely on your instruction and is not responsible for the lawfulness of the underlying data collection.

12. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice in the app before the changes take effect. The date at the top of this page reflects the most recent update.

13. Contact

For any privacy questions, data requests, or concerns:

AfterBooth

Toronto, ON, Canada

privacy@afterbooth.com