Privacy Policy

Last updated: July 23, 2026

Welcome to the use of products and/or services provided by HeroDash! We understand the importance of user information to you, and your trust is crucial to us. We will strictly comply with legal requirements and take appropriate security measures to ensure the security of user information and privacy. HeroDash is operated by Callnovo USA, Inc. (formerly Upcross Solutions, Inc.), 13010 Morris Road, Building 1, Suite 600, Alpharetta, GA 30004, USA (“we”, “us”, or “our”).

By agreeing to this policy, you acknowledge your understanding of the products and/or services we provide, as well as the necessary user information required for the operation of the corresponding products and/or services (please note that the user information described in this policy may include personal information and/or sensitive personal information, which will not be reiterated below), and give consent for the collection and use of such information.

1. Scope of Information Collection

We may collect and process the following types of information:

• Personal Information: such as name, email address, and contact details.

• Device Information: such as device model and operating system version.

• Interaction Information: such as call records and message records.

• Network Activity Information: such as IP address, time zone, access times, device information, page clicks, and duration of stay.

• Merchant and Platform Data: where we act as a service provider to e-commerce platforms (including TikTok Shop) and their sellers, we may process customer and order data strictly on their behalf and only as needed to provide the contracted services.

2. Purpose of Information Use

The information we collect will be used for the following purposes:

• Providing customer service and support.

• Processing requests and feedback.

• Improving the quality of products and services.

• Analyzing user behavior to optimize user experience.

We process personal data only for the purposes described in this policy or as instructed by the merchants and platforms on whose behalf we act.

3. How We Share Information and Sub-processors

We do not sell, rent, or trade your personal information.

We disclose personal information only in the following limited circumstances: (i) to vetted sub-processors who help us deliver our services (for example, cloud hosting, infrastructure, and communication providers); (ii) where required to comply with applicable law, regulation, legal process, or a binding governmental request; or (iii) with your explicit consent.

All sub-processors are bound by written agreements (including Data Processing Agreements where applicable) that require them to protect personal data and to use it only for the purposes we specify. A current list of sub-processors is available on request from our Data Protection Officer.

4. Information Security Measures

We operate an Information Security Management System (ISMS) aligned with the ISO/IEC 27001 standard, and we maintain documented security policies covering information security, access control, data classification, incident response, and vulnerability management. Our security program includes, among others:

• Encryption: personal data is encrypted in transit using TLS 1.2 or higher, and sensitive data is encrypted at rest using industry-standard algorithms (such as AES-256).

• Access control: access to personal data is restricted on a least-privilege, need-to-know basis, enforced through role-based access controls and multi-factor authentication.

• Network protection: we enforce network segregation and continuously monitor our environment to detect and prevent network threats.

• Endpoint protection: company endpoints are protected with anti-virus / endpoint security software and a security baseline (including screen locking and password policies).

• Logging and monitoring: security-relevant events are logged and monitored to support detection, investigation, and response.

• Vulnerability management: we maintain a vulnerability and patch management process, and conduct periodic security testing.

• Personnel: employees receive security awareness training and are bound by confidentiality obligations.

Further detail is available in our Information Security Policy at https://www.herodash.ai/en/security.

5. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfil the purposes described in this policy, to provide our services, and to comply with our legal and contractual obligations.

When data is no longer required, or upon a valid deletion request, or at the end of the relevant contractual relationship, we will securely delete or anonymize the data within a reasonable period.

Where we process data on behalf of a merchant or platform (including TikTok Shop and Amazon), we will assist them in responding to data deletion, update, and access requests, and will return or delete customer data at the end of the engagement in accordance with their instructions.

6. Your Rights

Subject to applicable law (including the GDPR and the CCPA/CPRA), you have the right to access, correct, update, and delete your personal information, and to request restriction of or object to certain processing, as well as data portability.

Where we rely on consent, you may withdraw it at any time. If you are a California resident, you also have the right not to receive discriminatory treatment for exercising your privacy rights. We do not sell personal information.

To exercise any of these rights, please contact our Data Protection Officer using the details in the 'Data Protection Officer and Contact' section. We will respond within the timeframes required by applicable law.

7. Cookies and Tracking Technologies

We may use cookies or other tracking technologies to enhance user experience. You can manage the use of cookies in your browser settings.

8. Legal Basis for Processing

Where applicable law requires a legal basis for processing personal data, we rely on one or more of the following: your consent; the performance of a contract with you; compliance with a legal obligation; or our legitimate interests in operating, securing, and improving our services, balanced against your rights and interests.

9. International Data Transfers and Storage Location

Personal data processed in connection with our TikTok Shop and Amazon services is primarily stored and processed in the United States of America.

Where personal data is transferred across borders, we implement appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms, where applicable) to ensure that the data continues to receive an adequate level of protection.

10. Data Breach Notification

We maintain an incident response process designed to identify, contain, and remediate security incidents. In the event of a personal data breach, we will notify affected merchants, platforms, and, where required, the relevant individuals and supervisory authorities without undue delay and in accordance with applicable law and our contractual commitments.

11. Children's Privacy

Our services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will delete it promptly.

12. Privacy Policy Updates

We reserve the right to update this privacy policy at any time and will notify users of any material changes through appropriate means. The 'Last updated' date at the top of this policy indicates when it was last revised. Users are advised to review this policy periodically.

13. Amazon Selling Partner Data

Where you connect your Amazon seller account to HeroDash, we access data through the Amazon Selling Partner API (SP-API) solely to provide the features you have enabled, such as order management, buyer messaging, and customer service workflows.

We handle Amazon data (including any buyer personal information) in accordance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy. We do not use Amazon data for advertising, marketing, or any purpose unrelated to providing our services, and we do not sell Amazon data.

Amazon data is retained only for as long as needed to provide the service. Buyer personal information and other Amazon data are retained and deleted in accordance with the timeframes required by the Amazon Data Protection Policy and applicable law, including when you disconnect your Amazon account or terminate your subscription.

14. Data Protection Officer and Contact

If you have any questions about this policy or wish to exercise your rights, you can contact us at:

• Data Protection Officer: Manny — hello@herodash.ai

• General inquiries: hello@herodash.ai