Privacy Policy

Last updated: 2026-06-08

1. Who we are

This app (the "Service") is operated by Brandzp Ltd ("we", "us"). We provide an analytics dashboard for Shopify store owners (the "Merchant"). The Merchant connects their Shopify store, Meta Ads account, Instagram account, and affiliate platform to our Service, and we surface metrics back to them.

You can reach us at yohad@brandzp.co.il.

2. What data we collect

When a Merchant connects their accounts, we receive and store the following categories of data:

We do not run trackers or analytics on the Service that observe the Merchant's end-customers.

3. How we use it

We never sell data. We never share data with third parties for their own marketing purposes.

4. Where it lives

Data is stored in Supabase (managed PostgreSQL), hosted in the EU (Frankfurt region). Application servers run on Render. Email delivery uses Resend. We do not transfer Merchant data to other third-party services beyond the providers explicitly listed in this policy.

4a. Competitor intelligence (RivalSweeper)

The app can display competitive-intelligence signals (public promotions, advertising activity, and press mentions of competitor websites) supplied by RivalSweeper, a third-party data provider. This integration is strictly one-directional: the only information we send RivalSweeper is the list of competitor domain names the Merchant chose to monitor — public website addresses, not personal data. No store data, order data, customer data, or any other Merchant information is ever transmitted to RivalSweeper or any other data provider.

5. How long we keep it

We retain data for as long as the Merchant maintains an active connection. When the Merchant uninstalls the Shopify app, access credentials are revoked immediately, and upon receiving Shopify's shop/redact notice (sent ~48 hours after uninstall) all store data — orders, customers, products, and derived analytics — is permanently deleted. Customer-level redaction requests (customers/redact) are honored by deleting that customer's personal data while retaining anonymous financial records, and data-access requests (customers/data_request) are logged and fulfilled with the Merchant. For other integrations (e.g. Meta Ads), tokens are deleted within 7 days of disconnection and the underlying data within 90 days, unless the Merchant requests earlier deletion.

We retain backups for up to 30 days, after which they are purged.

6. Your rights

You may request access to, correction of, or deletion of any personal data we hold about you by emailing yohad@brandzp.co.il. We will respond within 30 days.

If you are a Facebook user and want us to delete data we received via the Meta Ads connection, you can also use Facebook's data deletion flow, which automatically triggers our endpoint at /api/meta/data-deletion. See section 9 below.

7. Security

All third-party access tokens are encrypted at rest using AES-GCM with a 256-bit key. All network connections use TLS 1.2 or higher. Database access is restricted to the application server and a small set of named administrators. We log access to sensitive operations.

8. Children

The Service is intended for use by businesses. We do not knowingly collect personal data from individuals under 16.

9. Meta / Facebook data deletion

We comply with the Meta Platform Terms requirement to provide a User Data Deletion mechanism. Submit a deletion request via Facebook's account settings; Facebook will POST a signed request to our endpoint at /api/meta/data-deletion. We respond with a unique confirmation code and a status URL you can use to track completion. Deletion of stored Meta data completes within 7 days.

10. Changes

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced via email to the Merchant contact on file.

11. Contact

Brandzp Ltd · Gil Yam, Herzliya, Israel · yohad@brandzp.co.il

Privacy Policy