Privacy Policy
Effective date: 7 September 2026 · Last updated: 7 September 2026
BrandOS is a marketing decision-intelligence service for ecommerce brands. This Privacy Policy explains what information BrandOS collects and processes, why we use it, how long we retain it, the service providers involved, and the choices and rights available to merchants and their customers.
BrandOS is designed to use the minimum data reasonably necessary to provide its service. BrandOS does not sell merchant or customer personal data and does not use customer personal data to make decisions that have legal or similarly significant effects on individual customers.
1. Who this policy applies to
This policy applies to merchants, merchant staff, agencies and other authorised users who use BrandOS, and to personal data BrandOS may receive about a merchant's customers through connected ecommerce and advertising platforms.
BrandOS acts as the service provider/data processor for merchant customer data processed on a merchant's behalf. Depending on the context, BrandOS may act as a controller for account, security, billing, support and service-administration information relating to BrandOS users.
2. Information we collect
Information from Shopify
When a merchant connects Shopify, BrandOS may receive the minimum data required to provide commercial performance analysis and verification, including:
- store and shop information;
- orders and order-level commercial information;
- refunds and related transaction information;
- checkout information where required for the service;
- product and variant information;
- discount and price-rule information;
- store analytics and related commercial metrics.
BrandOS does not require customer names, email addresses, phone numbers or postal addresses for its core analytics and Decision Memory functionality and does not intentionally use those fields for that purpose.
Information from advertising and analytics platforms
When authorised by a merchant, BrandOS may process account, campaign, creative, advertising-performance, conversion, change-history and analytics information from connected services such as Meta Ads, Google Ads and Google Analytics.
Information provided directly by merchants and users
BrandOS may collect account details, business information, workspace information, support communications, configuration choices and other information that a user provides directly when creating or using an account.
Technical and security information
BrandOS may process limited technical information such as authentication events, service logs, error records, device/browser information and security/audit data required to operate, protect and troubleshoot the service.
Information collected directly from merchants' customers
BrandOS is not a storefront tracking product and does not intentionally place tracking technologies on a merchant's storefront to profile individual shoppers. BrandOS principally receives commercial data from platforms connected by the merchant.
3. Why we use information
BrandOS processes information only for purposes reasonably necessary to provide, secure and improve the service, including to:
- connect authorised merchant accounts and maintain those connections;
- calculate business and marketing performance metrics;
- compare advertising-platform reporting with Shopify commercial outcomes;
- identify material marketing changes and evidence;
- run weekly intelligence synthesis and create Business Health insights, advertising intelligence and Decision Memory;
- answer merchant questions about their own account and evidence;
- maintain security, authentication, auditability and service reliability;
- provide customer support and investigate errors;
- comply with legal, regulatory and platform obligations, including privacy requests.
BrandOS does not use merchant customer personal data for unrelated advertising, does not sell it, and does not disclose it to data brokers.
4. Decision Memory and derived data
BrandOS creates derived records from marketing evidence, decisions, forecasts and commercial outcomes so a merchant can retain institutional knowledge about what was tried and what happened next.
Where derived information remains linked or reasonably linkable to a merchant, store or individual, it is treated in accordance with this policy. BrandOS may retain aggregated or irreversibly anonymised learnings after identifiable data is deleted only where that information can no longer reasonably be used to identify or re-link it to a merchant or individual.
Pseudonymised data that can still be re-linked is not treated as anonymous.
5. Legal bases and merchant instructions
Where UK or European data-protection law applies, BrandOS processes personal data under an appropriate lawful basis depending on the context. For merchant customer data, BrandOS generally processes information on the merchant's documented instructions as a processor/service provider. For BrandOS account administration, service security, support and legal compliance, BrandOS may rely on performance of a contract, legitimate interests or legal obligations as appropriate.
Merchants remain responsible for ensuring that they have an appropriate lawful basis for the personal data they instruct BrandOS to process.
6. Data minimisation and access
BrandOS seeks to collect and process only information necessary for the functionality a merchant uses. Access is restricted to authorised systems and personnel that require it for legitimate service, support, security or compliance purposes.
BrandOS uses read-only platform permissions wherever the product does not need to make changes. BrandOS does not change Shopify stores, advertising budgets, campaigns or other merchant platform settings on a merchant's behalf.
7. How long we retain data
BrandOS applies the following retention periods as its service policy:
- Active merchant account data: retained while the account and relevant connection are active, and only for as long as reasonably necessary to provide the service.
- Following account closure, Shopify app uninstall or a valid deletion request: merchant- and customer-identifiable platform data is scheduled for deletion or irreversible anonymisation within 30 days, unless a shorter period is required by law or platform rules or continued retention is legally required.
- Backups containing deleted identifiable data: retained only until the normal backup rotation completes, no longer than 90 days.
- Security, audit and operational logs: retained for up to 12 months where reasonably necessary for security, fraud prevention, troubleshooting or legal compliance.
- Aggregated or irreversibly anonymised information: may be retained for longer, including indefinitely, where it can no longer reasonably identify or be re-linked to a merchant or individual.
Where a legal obligation, dispute, fraud investigation or security requirement requires longer retention, BrandOS may retain the minimum necessary information for that purpose and delete it when the requirement ends.
8. Shopify privacy requests
BrandOS supports Shopify's mandatory privacy-compliance process for customer data-access requests, customer redaction/deletion requests and shop redaction/deletion requests following app uninstall.
When BrandOS receives a valid authenticated Shopify compliance request, it records and processes the request in accordance with applicable Shopify requirements and this policy. BrandOS verifies Shopify webhook signatures before acting on a request.
Merchants and customers may also contact BrandOS through the Contact page regarding privacy requests. Where a request concerns a merchant's customer, BrandOS may need to coordinate with the relevant merchant to verify and fulfil the request.
9. Sharing and service providers
BrandOS uses carefully selected service providers to host, secure and operate the service and to connect authorised third-party accounts. These may include cloud/database infrastructure, authentication, integration/connectivity providers, hosting, monitoring and AI/model service providers.
Service providers are permitted to process information only as needed to provide their contracted services to BrandOS and are subject to appropriate contractual and security obligations.
BrandOS may also disclose information where required by law, to protect the security or rights of BrandOS, merchants or others, or as part of a corporate transaction subject to appropriate safeguards.
BrandOS does not sell personal data.
10. International processing
BrandOS and its service providers may process information in the United Kingdom, European Economic Area, United States and other countries where service infrastructure or subprocessors operate. Where required, BrandOS uses appropriate safeguards for international transfers of personal data, such as contractual transfer mechanisms and equivalent protections.
11. Security
BrandOS uses reasonable technical and organisational safeguards designed to protect information against unauthorised access, loss, misuse or alteration. Data transmitted between users, BrandOS and connected services is protected using encrypted HTTPS/TLS connections. Production data is stored using managed infrastructure with encryption at rest and access controls.
No online service can guarantee absolute security. Merchants should protect their own account credentials and notify BrandOS promptly of suspected unauthorised access.
12. Customer consent and automated decisions
BrandOS does not use merchant customer personal data to send direct marketing to individual customers, build consumer advertising audiences, sell customer data, or make automated decisions about individual customers that produce legal or similarly significant effects.
If BrandOS introduces functionality in the future that relies on customer consent choices or uses personal data for such decisions, this policy and the relevant product controls will be updated before that processing begins.
13. Individual privacy rights
Depending on applicable law, individuals may have rights relating to their personal data, including rights to access, correct, delete, restrict or object to processing, or request portability.
Where BrandOS processes a merchant's customer data on the merchant's behalf, the merchant is generally responsible for responding to the customer's request and BrandOS will provide reasonable assistance as required.
Privacy enquiries and requests can be submitted through the BrandOS Contact page.
14. Merchant responsibilities
Merchants are responsible for using BrandOS lawfully, providing appropriate privacy notices to their customers where required, obtaining any necessary consents or other lawful basis, and ensuring authorised users and agencies have permission to connect merchant accounts to BrandOS.
15. Changes to this policy
BrandOS may update this Privacy Policy to reflect changes to the service, legal requirements or data practices. The current version will always be published on this page and the Last updated date will be revised when material changes are made.
16. Contact
For privacy questions, requests or concerns, contact BrandOS through the existing Contact page at /contact.
No registered company number, business address or dedicated privacy email has been verified for BrandOS in this repository, so they are omitted rather than invented.
