Privacy Policy
Last updated August 16, 2026
Draft pending legal review. This policy describes how Ghost is built and operated today. It has not yet been reviewed by counsel, and the registered address and entity details below are still to be confirmed.
1. Who we are
Ghost is a business analytics product operated by Superman Services (“we”, “us”). We are based in British Columbia, Canada. This policy explains what we collect, why, how long we keep it, and how you get it deleted.
If you use Ghost because your employer signed up, your employer is the controller of the business data in the account and we process it on their instructions.
2. What we collect
Account data
Your name, email address, hashed password, company name, and the role you hold in that company. You give us this when you sign up or when a colleague invites you.
Connected business data
When you connect an integration, we retrieve the records listed in section 3 and store a copy so that reports load quickly and history is preserved. This can include the contact details of your own customers (a phone number, a name, a service address) because that is what a job record contains.
Credentials for connected accounts
Access tokens, refresh tokens and API keys for the services you connect. These are encrypted at rest and are only decrypted to make a request on your behalf.
Usage data
Pages viewed, features used, and error diagnostics, collected through PostHog so we can find and fix problems. We do not sell this or use it for advertising.
3. Data we obtain from third parties
We only read from an account after you explicitly connect it, and only with the narrowest permission scope that answers the question you asked us to answer. You can disconnect any of these at any time from Settings.
| Source | What we access | Why |
|---|---|---|
| Jobber | Clients, quotes, jobs, invoices and payment status | To measure booked and collected revenue against the leads that produced it. |
| Google Ads | Campaign, ad group and keyword performance; cost; conversions; click identifiers (GCLID) | To report return on ad spend and to upload offline conversions for the jobs you actually won. |
| Google Local Services Ads | Lead volume, lead type, charge status and account reports | To report cost per lead and dispute-eligible leads alongside your other channels. |
| Meta | Ad account, campaign and ad performance and spend; conversion events you send | To report Facebook and Instagram ad performance against booked revenue. |
| CallRail | Call records, tracking numbers, call sources and referring campaign data | To attribute inbound phone calls to the marketing that generated them. |
| OpenPhone | Call metadata, recordings, transcripts and call summaries | To report answer rates and agent performance and to surface call context on a lead. |
4. Google user data and Limited Use
When you connect a Google account, Ghost requests access to your Google Ads and Local Services Ads reporting data, and — if you sign in with Google — your name, email address and profile picture for the purpose of identifying your account.
Ghost’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data obtained from Google APIs is:
- used only to provide and improve the reporting features you can see in the product;
- never sold, and never transferred to others except as needed to provide the service, for security purposes, or to comply with applicable law;
- never used for advertising, ad targeting or building ad profiles;
- never read by a human except with your explicit consent, to investigate a fault you have reported, for security purposes, or where required by law.
You can revoke our access at any time from Settings in Ghost, or from your Google Account permissions page.
5. Meta platform data
When you connect a Meta account, we request access to the ad accounts and Pages you select on Facebook’s own consent screen. We read advertising performance and spend so it can be reported next to your other channels, and — where you have enabled it — we send conversion events for jobs you have won back to your dataset.
We do not access your personal Facebook profile, your friends, your messages or your organic content beyond the Page-level advertising information described above. Meta platform data is not sold, and is not used for any purpose other than producing your reports.
6. How we use data
- To produce the dashboards, reports and alerts you asked for.
- To send offline conversion data back to an ad platform you have connected, when you switch that on.
- To authenticate you and keep the account secure.
- To respond to support requests.
- To diagnose faults and improve reliability.
We do not sell personal information. We do not use your business data to train machine learning models, and we do not pool it with other customers’ data.
7. Who we share it with
We share data only with the processors that run the service on our behalf, each bound to use it only for that purpose:
- Supabase — application database and authentication, hosted in Canada (ca-central-1).
- Vercel — application hosting and delivery.
- PostHog — product analytics and error reporting, hosted in the EU.
We will also disclose data where we are legally required to, or to protect our rights or someone’s safety. If the business is ever sold or merged, we will tell you before your data moves.
8. Where data is stored
Your account and business data are stored in Canada. Usage analytics are stored in the European Union. Some processors may access data from other countries in order to operate their service; where that involves a transfer out of your region, it is done under the contractual protections those providers offer.
9. How long we keep it
- Account data — for as long as the account is open, then 30 days after closure.
- Connected business data — for as long as the integration is connected. Disconnecting stops collection; the historical copy is removed within 30 days of a deletion request.
- Access tokens — destroyed immediately when you disconnect an integration.
- Backups — rolling backups are purged within 90 days.
- Records we must keep by law — for the period the law requires.
10. Security
Traffic is encrypted in transit. Passwords are hashed. Integration credentials are encrypted at rest and decrypted only in order to make a request on your behalf. Every database read is scoped to your organisation, and access to production systems is limited to the people who need it. No system is perfect; if we ever suffer a breach affecting you, we will notify you and the relevant regulator as required.
To report a vulnerability, email seo@supermanservices.ca.
11. Your rights
Depending on where you live, you have the right to access a copy of your personal information, correct it, delete it, restrict or object to how we use it, and to withdraw consent. Canadian users may also complain to the Office of the Privacy Commissioner of Canada. To exercise any of these, email seo@supermanservices.ca. We respond within 30 days.
12. Deleting your data
You can remove your data in three ways, and you do not need to contact us for the first two:
- Disconnect one integration. Go to Settings → Integrations and disconnect the provider. The stored token is destroyed immediately and we stop collecting from it.
- Delete your user account. Go to Settings → Account → Delete account. Your profile and access are removed immediately, and the underlying records are purged within 30 days.
- Delete everything, including company data. Email seo@supermanservices.ca from the address on the account with the subject “Data deletion request”. We confirm within 5 business days and complete the deletion within 30 days, backups included within 90 days.
Deleting data obtained from Google or Meta also revokes our access to those accounts. You can independently revoke access from your Google Account permissions or your Facebook business integrations settings.
13. Children
Ghost is a tool for businesses and is not directed at anyone under 16. We do not knowingly collect information from children.
14. Changes to this policy
If we change this policy in a way that materially affects you, we will email the account owner and update the date at the top of this page before the change takes effect.
15. Contact us
Privacy questions and requests: seo@supermanservices.ca
Everything else: seo@supermanservices.ca
Superman Services, British Columbia, Canada. Registered address to be confirmed.
See also our Terms of Service. Back to home.