NewCheck out Claude MCP for AI Venue Intelligence.Explore AI Venue Intelligence
Smart SegmentsDocumentation & trust

Privacy Policy

Last updated: 2 September 2026

1. Who we are

This Privacy Policy is issued by Smart Segments Pty. Ltd. (“Smart Segments”, “we”, “us”, or “our”), a company incorporated in Australia with its registered address at 81-83 Campbell Street, Surry Hills NSW 2010, Australia.

This Privacy Policy explains how we collect, use, disclose, and protect personal data. It applies to our website, our software-as-a-service products (the “Service”), and the Smart Segments Model Context Protocol (MCP) server described in Section 7 below.

This Privacy Policy works alongside two other documents:

  • Our Terms of Service, which govern your use of the Service.
  • Our Data Processing Addendum (“DPA”), which governs our processing of personal data on behalf of our business customers (“Customers”) and takes precedence over this Privacy Policy for any conflict specifically concerning that processing.

2. Two roles: when we are a controller, and when we are a processor

Smart Segments acts in two different capacities, and it matters which one applies to your data:

As a Data Controller, we decide why and how we process personal data about our own customers, prospective customers, website visitors, and business contacts — for example, the details you give us when you sign up for an account or contact us. Section 3 below describes this.

As a Data Processor, we process personal data on behalf of a Customer, strictly on their documented instructions, as part of providing the Service (for example, booking and attendance data a Customer’s venue-management system sends to us). We do not decide why or how that data is processed — the Customer does, as the data controller of that information. This processing is governed by the DPA, not by this Privacy Policy. If you are an end customer, guest, or website visitor of one of our business Customers, and you have a question about how your personal data is used, please contact that business directly — we are not able to respond to individual requests about data we hold only as a processor without the Customer’s involvement.

3. Information we collect and process as a Data Controller

When you sign up for the Service, register interest, or otherwise interact with us directly (for example, by visiting our website or contacting our team), we collect:

  • Identity and contact information you provide, such as your name, business name, email address, and postal address.
  • Account and billing information needed to set up and administer your account and process payments.
  • Technical data collected automatically from your device and browser when you visit our website, such as IP address, browser type, device information, and pages visited.
  • Communications you send us, such as support requests and correspondence.

We use this information to: perform our contract with you (setting up and running your account); provide customer support; process invoices and payments; maintain the security of our systems; communicate with you about the Service, including service and security notices; and, where you have agreed to receive it, send you marketing communications about our own products (which you can opt out of at any time).

We retain this information for as long as your account is active and for a reasonable period afterward to meet legal, accounting, tax, and dispute-resolution requirements, after which it is deleted or anonymised.

4. Recipients of information we hold as a Data Controller

To run our own business, we share limited personal data with the following categories of service providers, acting as our own processors:

  • Billing and payments: Stripe and/or PayPal, to process subscription payments and invoices.
  • Internal communications and support tooling: Slack, and similar tools, for our own team communications and customer support workflows.
  • Our own marketing and analytics: Google Analytics, Google Ads, LinkedIn Ads, and Facebook Ads, to understand and market the Service to prospective customers (this is distinct from the analytics data we process on your behalf as a processor, described in Section 5 below).
  • Infrastructure: Google Cloud Platform, which underlies our own business systems as well as the Service itself.

These providers may receive your name, email address, and technical data such as your IP address, but not Customer Data you process through the Service.

5. Information we process as a Data Processor (Customer Data)

Where we process personal data on your behalf as a data processor in connection with the Service, that processing — including what data categories are involved, the subprocessors we engage, security measures, breach notification, international transfers, and deletion on termination — is set out in full in our Data Processing Addendum.

In summary: personal data is hosted in EU Google Cloud regions by default for customers established in the EEA; a breach affecting your Customer Data is notified to you within 48 hours of us becoming aware of it; and Customer Data in live systems is deleted within 14 days of termination of your account, with backup copies aging out within our standard rotation cycle. The DPA is the authoritative source for these and all other processor-side commitments, and prevails over this summary in the event of any inconsistency.

The subprocessors we currently engage as your processor are published and kept up to date at smartsegments.ai/subprocessors. As of the date of this Privacy Policy, they are Google Cloud (infrastructure, including Firebase Authentication), dbt Labs (data transformation orchestration), and Anthropic, PBC (Claude, used only by our own staff to assist with support and debugging on the minimum data necessary — never to operate the Service generally, and never to train Anthropic’s models).

When acting as your data processor, we do not sell Customer Data and we do not use it for our own purposes. We disclose it only: to the subprocessors listed above; to authorised Smart Segments personnel (including staff located in Australia, under Standard Contractual Clauses) who need access to configure, operate, support, or secure your account; and to the third-party integrations you configure your account to use, described in Section 6.

6. Third-party integrations you control

Smart Segments can be configured to send or receive data from third-party platforms of your choosing — for example, marketing and CRM tools, accounting and point-of-sale systems, and workforce-management tools. The current list of supported integrations is published at smartsegments.ai/integrations.

These integrations are activated only at your request, and only for the data fields you configure. The platforms you choose to connect are your own processors or independent recipients, not Smart Segments subprocessors — you remain responsible for your own contractual and lawful-basis obligations with each one, including, where applicable, any obligations relating to the personal data of minors.

7. Smart Segments MCP — Google API Data Access via AI Assistants

This section applies specifically to the Smart Segments Model Context Protocol (MCP) server, which lets AI assistants (such as Claude by Anthropic) access your Google Ads, Google Analytics 4, and Google BigQuery data on your behalf, with your explicit Google OAuth authorization.

Google OAuth scopes requested:bigquery.readonlyanalytics.readonlyadwords. You grant these individually during the Google consent screen and can revoke them at any time from your Google Account’s third-party access settings.

What we access and why: when you ask an AI assistant a question, the assistant calls our server, which uses your own Google OAuth access token to query Google Ads, Google Analytics 4, or BigQuery directly — never a shared or company-wide credential. Retrieved data (e.g. campaign performance, analytics metrics, warehouse rows) is returned to the AI assistant so it can generate a natural-language answer to your question. We do not store or log the content of this retrieved data on our servers.

Third-party AI processing: the retrieved data is processed by the connected AI assistant’s provider (e.g. Anthropic, for Claude) solely to generate a response to your query. This data is not used by us, or to our knowledge by Anthropic under its standard API terms, to train AI models. See Anthropic’s own privacy policy at https://www.anthropic.com/legal/privacy for their data handling practices.

Google API Services User Data Policy: Smart Segments’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data retention: your Google OAuth access token is held only for the duration of your session and discarded when it ends. We retain your selected Google Ads customer ID, GA4 property ID, and BigQuery project ID (linked to your Google identity) in our database solely so you don’t have to re-select them each session. Aggregate, non-content usage metrics (which tool was used, when, by whom) are kept for service reliability and billing-abuse prevention.

This feature is your own choice of AI assistant querying your own Google-connected data — it is separate from, and not part of, the staff-side Anthropic/Claude subprocessor use described in Section 5.

8. Children’s personal data

Our website and our direct relationship with Customers are not directed at children, and we do not knowingly collect personal data directly from children as a data controller.

Some Customers operate venues or services used by families, and may configure the Service to process personal data relating to children (for example, a child’s name or date of birth in connection with a booking) as part of their own Customer Data. Smart Segments processes this only as a data processor, strictly on the Customer’s instructions. The Customer remains the controller of this data and is responsible for establishing an appropriate lawful basis for processing children’s personal data (including any parental consent required under Article 8 GDPR or equivalent law) and for providing appropriate privacy information to data subjects or their guardians. Further detail is set out in our DPA.

9. International data transfers

Personal data we hold as a data controller may be transferred to and processed in countries outside your own, including the United States, by the service providers listed in Section 4. Where required, we rely on Standard Contractual Clauses or equivalent safeguards approved under applicable data protection law.

Personal data we process as a data processor on behalf of Customers is addressed in detail in the DPA, including our EU-hosting commitment for EEA customers and the safeguards that apply to any remaining international transfers (including access by Smart Segments personnel in Australia, and our US-based subprocessors). Enterprise customers may request a Transfer Impact Assessment covering these transfers.

10. Security

We maintain technical and organisational measures designed to protect personal data against unauthorised access, loss, or misuse, including access controls, encryption in transit, and audit logging. The measures applicable to Customer Data processed under the DPA are set out in Annex II of that document, available on request.

11. Cookies and similar technologies

Our website may use cookies and similar technologies to operate correctly and to understand how visitors use it, including some of the analytics and advertising tools listed in Section 4. You can control or disable cookies through your browser settings; doing so may affect some website functionality.

12. Your rights

Subject to applicable law, you may have the right to request access to, correction of, deletion of, or a copy of your personal data, and to object to or request restriction of certain processing. Where we act as a data controller of your information (Section 3), you can exercise these rights by contacting us using the details in Section 13.

If you are an end customer or guest of one of our business Customers, and your personal data has been processed by Smart Segments only as a data processor, please direct your request to that business in the first instance, as they are the data controller responsible for responding to it.

You also have the right to lodge a complaint with your local data protection supervisory authority.

13. Contact us

If you have questions about this Privacy Policy, or wish to exercise a privacy right described above, please contact:

Jeroen Sijl

Smart Segments Pty. Ltd.

81-83 Campbell Street, Surry Hills NSW 2010, Australia

Email: jeroen@smartsegments.ai

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated “Last updated” date, and where changes are material, we will provide reasonable additional notice.