Privacy Policy
LAST UPDATED · 2026-09-25
Summary
Brand Protector (“we”, “us”) operates a brand-protection SaaS at brandprotector.io. This Privacy Policy explains what we collect, why we collect it, how long we keep it, and the rights you have over it. We process data in two roles: as a controller for our own account and billing data, and as a processor for the brand-context, scanner credentials, and detection records you upload into your tenant workspace.
What we collect
We collect three buckets of data:
- Account data. Your email address (from Google sign-in or a team account issued by Brand Protector), display name, the tenants you belong to, your role in each tenant, and audit timestamps for your sign-ins and actions.
- Brand & workspace data. Information you upload to configure scanners: your brand name, keywords, domains, marketplace seller IDs, allowlists, contact emails, and counterfeit-listing context. This is “customer data” and you remain its controller.
- Scanner credentials. Per-platform API tokens and refresh tokens (e.g. Amazon SP-API, eBay, Walmart, Slack webhooks) you provide so our scanners can act on your behalf. These are stored in Google Secret Manager under a tenant-scoped naming convention.
- Operational telemetry. Standard server logs (IP, user-agent, timestamps), error reports via Sentry, and usage metrics for capacity planning and abuse detection. Sentry session replay is configured to sample 1% of sessions and 100% of sessions with errors, with all text masked and all media blocked. We do not use analytics or marketing cookies. The marketing site counts page views with Umami, a cookieless analytics service served from our own domain that sets no cookies and identifies no one. The application loads no analytics scripts; during signup and onboarding we count funnel steps (a step was reached, a step was completed) server-side through the same cookieless service, with no cookies and no persistent identifiers stored. Neither surface loads advertising or cross-site tracking scripts.
We do not intentionally collect special-category personal data (health, biometrics, etc.). Brand Protector is a B2B tool; please don't paste sensitive personal data into it.
Free previews
Preventing repeat free previews. We limit free previews to one per workspace and block repeat previews for the same email address or website domain for 180 days. For these checks, we store a keyed, one-way code for each instead of the email address or domain itself. Email and domain codes expire after 180 days; workspace codes do not expire. These codes survive account deletion to prevent repeat claims.
On the payment page, your browser remembers whether you have interacted with the card form, so we can measure whether preview findings appeared first. This flag contains no card details and stays until your browser clears it. We also keep records linked to your workspace of payment-page views, preview statuses, whether examples were opened, and the timing of preview visibility and card-form interaction. We use these records to measure whether previews help customers start a trial.
Why we collect it
- Run scanners. Detect counterfeit listings on the surfaces you select.
- Prepare takedowns. Prepare DMCA, Brand Registry, VeRO, and platform-specific takedown notices, send the ones we transmit on your behalf, and track responses. Where a platform takes notices on its own form, such as Brand Registry, we prepare the notice and you submit it there.
- Operate your account. Authenticate sign-ins, enforce per-tenant access controls, send transactional email (via Resend), bill subscriptions (via Stripe).
- Support. Respond to your support requests and triage bugs.
- Security & abuse prevention. Rate-limit authentication endpoints, detect anomalous activity, and preserve audit trails.
Our legal bases under GDPR are: (a) contract for delivering the service you signed up for; and (b) legitimate interests for operational telemetry and abuse prevention. We currently set strictly-necessary cookies only (no analytics, no marketing trackers), so consent is not the legal basis for any cookie we use today: see our Cookie Policy for the full inventory. If we ever add analytics or marketing cookies, we will switch to a real consent flow before any new cookie is set.
How long we keep it
- Active subscription. All workspace data is retained for as long as your subscription is active.
- Cancellation. When you cancel, your workspace enters a 30-day window during which we can restore it on request. After that window its records and stored credentials are permanently deleted. To have it deleted sooner, email support@brandprotector.io.
- Previews before you subscribe. Preview results include listing titles, sites and links from public marketplaces and search results. We keep them with your workspace. Unused results become eligible for deletion 30 days after the preview starts. We keep results longer if the workspace has cases, takedowns or other records requiring review, or if preview costs remain unsettled. If you start a trial, results stay in your workspace like any other finding. If we have a payment attempt on record, even one that did not go through, we keep them until your workspace is deleted.
- Audit logs. Sign-in records and takedown attestations may be retained for up to 7 years for legal defensibility, with all customer-identifying fields purged after the 30-day window where feasible.
- Recovery. Point-in-time recovery is enabled for our primary database. The seven-year audit archive is kept separately.
- Billing records. Stripe-controlled records are retained per Stripe's policy and applicable tax law (typically 7 years).
Third parties & sub-processors
We use a small set of vetted sub-processors to deliver the service:
- Google Cloud Platform: hosting (Cloud Run), database (Firestore), object storage (GCS), secrets management (Secret Manager). Region: us-central1 (compute), nam5 multi-region (Firestore).
- Google Identity (OAuth): sign-in. We receive your email and basic profile.
- Stripe: subscription billing. Card data never touches our servers.
- Resend: transactional email delivery.
- Sentry: error monitoring and masked session replays. We scrub PII from error reports where practical.
- Umami: cookieless web analytics. Aggregate page-view and click counts on the marketing site (proxied through our own domain) and aggregate signup/onboarding step counts sent server-side; no cookies, no persistent identifiers. The application itself loads no analytics scripts.
- Scanner providers: OpenAI, Anthropic, Perplexity, Google AI, xAI, SerpAPI, and Apify, used to detect counterfeit listings on AI platforms and search engines.
The current list of sub-processors is also referenced in our Data Processing Addendum. We update this list when sub-processors change.
Your rights (GDPR & CCPA)
If you are in the EU/EEA, UK, or California, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete your personal data (subject to limitations, e.g. legal hold or pending takedown actions).
- Export your data in a portable, machine-readable format.
- Restrict or object to processing.
- Withdraw consent where consent is the basis.
- Opt out of “sale” or “sharing” of personal information (CCPA). We do not sell your data.
- Lodge a complaint with your supervisory authority.
To exercise any of these rights, email privacy@brandprotector.io. We respond within 30 days.
Security
We follow industry-standard security practices: encryption in transit (TLS) and at rest, least-privilege IAM scoped per tenant, server-side validation of every cross-tenant boundary, audit logging of admin actions, hard-coded server-only Firestore writes, rate-limiting on authentication, and routine dependency auditing. No system is unbreakable; we describe our incident-response process in the DPA.
International transfers
Our infrastructure is hosted in the United States. If you are in the EU/UK, your data is transferred to the US under the Standard Contractual Clauses (SCCs) attached to our DPA. Sub-processors operate under their own SCC commitments where applicable.
Children's data
Brand Protector is not directed at, and we do not knowingly collect personal data from, children under 16.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced by email to account owners at least 30 days before they take effect, and the “Last updated” date at the top will change.
How to contact us
For privacy questions, data-rights requests, or to report a security issue:
- Email: privacy@brandprotector.io
- Security disclosures: security@brandprotector.io