Privacy Policy
Task Bees LLC · Effective June 1, 2026
Introduction
This Privacy Policy (“Policy”) explains how Task Bees LLC (“Task Bees,” “TaskBees,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with our website at taskbees.ai, the TaskBees AI-powered customer support platform, dashboards, onboarding flows, integrations, billing flows, support, marketing, and related services (collectively, the “Services”).
This Policy applies when TaskBees acts as a controller or business for its own purposes, such as account registration, billing, website analytics, security, sales, marketing, support, and communications with merchant representatives. When a merchant uses TaskBees to process support inquiries, emails, Telegram messages, Shopify records, ShipStation records, Knowledge Base content, and AI Drafts on behalf of that merchant, TaskBees generally acts as a processor or service provider, and the merchant is responsible for its own privacy notices and legal basis for processing.
If you are an End Customer of a merchant using TaskBees, please contact that merchant first regarding privacy requests about your support messages, orders, shipping information, or account data. We assist our merchant customers as required by our agreements and applicable law.
Personal Information We Collect
| Category | Examples |
|---|---|
| Account and contact information | Name, business name, title, email address, phone number, mailing address, username, password or authentication data, role, workspace, and account settings. |
| Billing and subscription information | Plan, trial status, invoices, payment status, billing address, tax information, Stripe customer ID, payment method metadata, and transaction records. Full card numbers are processed by our payment processor, not stored by TaskBees. |
| Integration and connected account information | OAuth tokens, API keys, scopes, account identifiers, email addresses, Telegram bot or chat identifiers, Shopify shop data, ShipStation account/order/shipping references, webhook payloads, and related metadata. |
| Customer support and ticket information | Inbound and outbound messages, email headers, sender/recipient information, customer names, order numbers, tracking information, support history, attachments, merchant edits, approvals, escalations, and final responses. |
| Knowledge Base content | Uploaded PDFs, DOCX files, TXT files, pasted text, URLs, extracted webpage content, product policies, FAQs, merchant policies, embeddings, metadata, and indexed content. |
| AI processing information | Prompts, retrieved context, AI Drafts, summaries, classifications, confidence scores, model selection, token usage, manual edits, approval status, and AI activity logs. |
| Usage, device, and security information | IP address, device identifiers, browser type, operating system, pages viewed, clicks, feature usage, session events, audit logs, webhook logs, authentication events, error logs, rate-limit events, and security signals. |
| Communications | Messages with us, support requests, sales inquiries, feedback, survey responses, call or meeting recordings if recorded with notice or consent where required. |
| Marketing and website information | Cookie identifiers, analytics data, referral source, campaign data, email engagement, event registrations, and preference information. |
Sources of Personal Information
- Directly from you, when you register, complete onboarding, configure settings, connect integrations, upload Knowledge Base content, approve AI Drafts, contact support, or communicate with us.
- From merchants and their Agents, when they use TaskBees to process support workflows and customer communications.
- From End Customers, through merchant-connected channels such as email, Telegram, Shopify, ShipStation, webhooks, and related systems.
- From third-party services and integrations that you authorize, including email providers, e-commerce platforms, shipping platforms, payment processors, and authentication providers.
- Automatically from your browser, device, and use of the Services through logs, cookies, pixels, and similar technologies.
How We Use Personal Information
We use personal information for the following purposes:
- to provide, operate, maintain, secure, troubleshoot, and improve the Services;
- to create and manage accounts, authenticate users, complete onboarding, enforce tenant isolation, and administer workspaces;
- to connect and operate integrations, validate webhooks, retrieve authorized data, store credentials securely, and send approved responses from merchant-owned accounts;
- to ingest, parse, index, embed, search, summarize, and retrieve Knowledge Base content for AI drafting and support workflows;
- to generate AI Drafts, classifications, confidence scores, AI Activity logs, analytics, usage metrics, and knowledge-gap recommendations;
- to process subscriptions, trials, upgrades, downgrades, invoices, taxes, payments, refunds, credits, and billing enforcement;
- to send service communications, security alerts, usage warnings, quota notices, billing notices, onboarding messages, and support responses;
- to provide customer support, diagnose issues, monitor performance, detect abuse, investigate incidents, and maintain audit logs;
- to comply with law, enforce agreements, protect rights, respond to legal process, and prevent fraud, spam, misuse, or security threats;
- to market our Services, personalize website experiences, measure campaign performance, and manage events or promotions where permitted by law;
- for business transfers, financing, mergers, acquisitions, reorganizations, due diligence, or similar corporate transactions; and
- to create aggregated, de-identified, or anonymized data that does not identify an individual, merchant, or End Customer where required by law.
AI and Model Data Use
TaskBees uses AI providers and cloud services to generate draft customer support responses and related workflow outputs. We process prompts, retrieved context, message content, Knowledge Base content, and AI Drafts to provide the Services.
We do not use Customer Data to train third-party foundation models unless the merchant expressly opts in or we provide any legally required notice and obtain any required consent. We may use Usage Data, Aggregate Data, de-identified data, telemetry, error data, and feedback to improve, secure, and develop TaskBees, provided such use complies with our agreements and applicable law.
AI Drafts may be inaccurate or incomplete. Merchants are responsible for reviewing and approving final responses, maintaining their own customer-facing privacy notices, and responding to customer privacy requests.
Google API Services — Limited Use Disclosure
TaskBees' use of information received from Google APIs (including Gmail) adheres to the Google API Services User Data Policy, including the Limited Use requirements.
TaskBees requests the following Gmail OAuth scopes on behalf of merchants who connect their Gmail account:
- gmail.readonly — to list and read inbound customer support emails and fetch full message thread history for AI draft generation.
- gmail.send — to send approved reply messages from the merchant's Gmail account after explicit merchant approval in the TaskBees dashboard.
Our use of Gmail data is limited to the following:
- Gmail data is accessed solely to provide the email-triage and AI-drafting features the merchant has explicitly authorized. It is not used for any other purpose.
- We do not use Gmail data to develop, improve, or train generalized AI or machine learning models.
- We do not sell, transfer, or share Gmail data with third parties for advertising or any purpose unrelated to the merchant's customer support workflow.
- We do not allow humans to read Gmail message content except where the merchant has given explicit permission, as necessary to provide or improve user-facing features, for security investigation, or as required by law.
- No email is sent from a merchant's Gmail account without explicit merchant review and approval in the TaskBees dashboard.
How We Disclose Personal Information
| Recipient | Purpose / Examples |
|---|---|
| Service providers and subprocessors | Cloud hosting, AI processing, storage, databases, monitoring, security, support, analytics, email delivery, billing, payment processing, identity/authentication, customer support, and professional services. |
| Merchant customers | Information processed on behalf of a merchant, including support ticket data, AI Drafts, integration data, logs, and End Customer information, may be made available to that merchant and its authorized Agents. |
| Integration providers | We disclose or transmit data to email providers, Telegram, Shopify, ShipStation, payment processors, and other connected services as directed by the merchant or necessary to operate integrations. |
| Legal, safety, and compliance recipients | Law enforcement, courts, regulators, auditors, legal advisors, or other parties where required by law or reasonably necessary to protect rights, safety, security, or enforce agreements. |
| Business transaction parties | Potential or actual acquirers, investors, lenders, advisors, or successors in connection with due diligence, financing, merger, acquisition, reorganization, bankruptcy, or sale of assets. |
| With consent or direction | Other third parties when you or the merchant direct us to disclose information or consent to the disclosure. |
We do not sell personal information in the traditional sense. If our use of advertising or analytics technologies is considered a “sale,” “share,” or “targeted advertising” under applicable law, we will provide required notices and opt-out mechanisms.
Cookies and Tracking Technologies
We and our service providers may use cookies, pixels, local storage, SDKs, log files, and similar technologies to operate the website and Services, keep users signed in, remember preferences, protect accounts, analyze performance, improve features, and measure marketing. Cookies may be necessary, functional, analytics/performance, or advertising/marketing cookies.
You can control cookies through browser settings and, where provided, our cookie preference tools. Blocking cookies may affect functionality. We will honor legally required opt-out preference signals where required and technically feasible.
Legal Bases for Processing
Where GDPR, UK GDPR, or similar laws apply, our legal bases may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of rights and security. For Customer Data processed on behalf of merchants, the merchant determines the legal basis and TaskBees processes such data under the merchant's instructions and the DPA.
Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain accounts, comply with legal and tax obligations, resolve disputes, enforce agreements, prevent fraud or abuse, maintain security, and support backups and audit logs.
| Data Type | Typical Retention Approach |
|---|---|
| Account and billing records | For the account term plus a period required for tax, accounting, audit, dispute, and legal purposes. |
| Support ticket and AI workflow data | For the merchant's subscription term and configured retention period, unless deletion, export, legal hold, or longer retention is required. |
| Knowledge Base content | Until deleted by the merchant, account termination/deletion, or expiration of retention periods, subject to backup cycles. |
| OAuth tokens/secrets | Until disconnected, revoked, rotated, account deletion, or as needed for security/audit purposes. |
| Security and audit logs | For a reasonable period needed for security, fraud prevention, debugging, compliance, and legal claims. |
| Aggregated or de-identified data | May be retained without a fixed period where it no longer identifies individuals or merchants as required by law. |
Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including tenant isolation, encryption in transit and at rest, access controls, secrets management, logging, rate limiting, vulnerability management, secure development practices, and incident response. No system is completely secure, and we cannot guarantee absolute security. Users should protect credentials, use strong authentication, limit account access, and promptly report suspected unauthorized access.
International Transfers
We are based in the United States and may process and store personal information in the United States and other countries where we or our service providers operate. These countries may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards, such as standard contractual clauses or other lawful transfer mechanisms.
Your Privacy Rights
Depending on your location and relationship to TaskBees, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, appeal of a privacy decision, or opt out of sale, sharing, targeted advertising, or certain profiling. These rights may be limited by law, security, verification requirements, our role as processor/service provider, and the rights of others.
To exercise rights regarding information TaskBees controls, contact hello@taskbees.ai. If you are an End Customer of a merchant, please contact the merchant directly because the merchant controls most support and order information processed through TaskBees. We may verify identity and, where applicable, authority of authorized agents before fulfilling requests.
U.S. State Privacy Disclosures
This section supplements the Policy for residents of U.S. states with comprehensive privacy laws. The exact applicability of each law depends on thresholds, exemptions, processing activities, and business changes. We will update this section as laws change and as our practices evolve.
| Category | Examples Collected / Processed |
|---|---|
| Identifiers | Name, email, account ID, IP address, online identifiers, business contact information. |
| Commercial information | Plan, subscription, invoices, purchase history, usage, trial status, payment metadata. |
| Internet/network activity | Device data, log data, pages viewed, feature usage, security events. |
| Geolocation | Approximate location from IP address or account information. |
| Professional/business information | Company name, role, title, workspace, business contact data. |
| Inferences | Usage patterns, feature preferences, likely support needs, and analytics derived from use. |
| Sensitive personal information | We do not intend to collect sensitive personal information except where Customer Data submitted by a merchant or End Customer contains it. Customers should avoid submitting sensitive data unless necessary and authorized. |
We disclose these categories to service providers, subprocessors, integration providers, merchants, legal/compliance recipients, and business transaction parties as described above. We do not knowingly sell or share personal information of minors under 16. We do not use sensitive personal information to infer characteristics where prohibited by law.
Children
The Services are intended for business users and are not directed to children under 13 or under the age required by applicable law. We do not knowingly collect personal information from children through our website or account registration. Merchant Customer Data may incidentally include information about minors if submitted by a merchant or End Customer; the merchant is responsible for ensuring it has a lawful basis and required consents.
Third-Party Links and Services
The Services may link to or integrate with third-party websites, applications, platforms, and services. Their privacy and security practices are governed by their own policies, not this Policy. We are not responsible for third-party practices, outages, or policy changes.
Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide notice through the Services, by email, or by other legally required means. The updated Policy will be effective when posted unless a later date is stated. Continued use of the Services after the effective date means you acknowledge the updated Policy.
Contact Us
Questions or requests may be sent to: hello@taskbees.ai
Mailing address: Task Bees LLC, 7901 4th St N Ste 300, St. Petersburg, FL 33702
Appendix A — Processor / Service Provider Commitments
- We process Customer Data on behalf of merchant customers according to their documented instructions, the agreement, and applicable law.
- We do not retain, use, or disclose Customer Data except to provide and improve the Services, secure the Services, comply with law, or as otherwise permitted by agreement and applicable law.
- We do not sell Customer Data or share Customer Data for cross-context behavioral advertising unless expressly authorized by the merchant and legally permitted.
- We require personnel and service providers with access to Customer Data to be subject to confidentiality obligations.
- We assist merchants with privacy rights requests, deletion, security, and compliance as required by the DPA and applicable law.
Appendix B — Subprocessor and Integration Categories
| Category | Examples / Purpose |
|---|---|
| Cloud infrastructure | AWS, including compute, storage, databases, security, logging, and secrets management. |
| AI services | AWS Bedrock and supported model providers made available through Bedrock or successor providers. |
| Payments | Stripe or other payment processors for checkout, trials, subscriptions, invoices, payment methods, and customer portal. |
| Email and messaging | Google/Gmail, Microsoft/Outlook, Telegram, and related APIs used at the merchant's direction. |
| Commerce and shipping | Shopify, ShipStation, and related platforms connected by the merchant. |
| Analytics and monitoring | Product analytics, error monitoring, logging, security monitoring, and performance tools. |
| Support and operations | Customer support, CRM, email delivery, documentation, and professional advisors. |