BrandGuard
Privacy policy

Privacy Policy

This notice explains how BrandGuard uses personal data when you visit our website, create an account, use the application, connect integrations, contact us, or pay for our services.

Effective date: 23 July 2026

  • Controller: BrandGuard
  • Contact: [email protected]
  • Website: https://usebrandguard.co.uk
  • Review status: Draft for product preview; final legal review required before public launch

1. Who We Are

BrandGuard operates this service under the BrandGuard name. We are the data controller for the personal data described in this notice unless we say otherwise.

Registered office
Registered office details will be confirmed before public launch
Company number
Company registration details will be confirmed before public launch
VAT number
VAT status will be confirmed on customer invoices
Privacy contact
[email protected]
DPO or privacy lead
Privacy requests can be sent to [email protected]
ICO registration
ICO registration details will be published where required

2. The Personal Data We Collect

We collect information that we need to run BrandGuard, manage customer accounts, provide support, improve the product, keep the service secure, and meet legal obligations.

  • Identity and contact details, such as name, email address, login method, profile information, and workspace role.
  • Account and organisation information, such as workspace names, invited users, permissions, billing owner details, plan information, and subscription status.
  • Integration data, including Google Ads account identifiers, account names, hierarchy information, campaign selections, monitoring configuration, OAuth token status, and related reporting data where you connect Google Ads.
  • Optional browser usage data, where you allow it, such as pages viewed, features used, reports opened, feature evaluations, browser diagnostics, and session information.
  • Service activity, operational, and security records, such as authenticated settings changes, authentication events, workspace audit logs, monitoring and report job status, billing actions, abuse prevention signals, and server-side failures.
  • Payment and billing records, such as Stripe customer IDs, subscription IDs, invoice status, plan changes, and billing support messages.
  • Website and device data, such as IP address, browser, device type, approximate location, cookie identifiers, consent choices, and analytics events.
  • Support and communication data, including messages you send us, attachments, feedback, and records of our replies.

3. How We Use Personal Data

Purpose
Provide and manage BrandGuard
Examples
Create accounts, authenticate users, manage workspaces, run monitoring, produce reports, and provide requested features.
Lawful basis
Contract and legitimate interests.
Purpose
Provide integrations
Examples
Connect Google Ads, refresh access, read account data, show campaign options, monitor selected terms, and apply user-approved automation.
Lawful basis
Contract, legitimate interests, and user authorisation through Google OAuth.
Purpose
Take payment and administer plans
Examples
Process checkout, manage subscriptions, invoices, cancellations, upgrades, downgrades, and plan limits.
Lawful basis
Contract, legal obligation, and legitimate interests.
Purpose
Optional product improvement
Examples
Measure browser usage, evaluate product changes, diagnose browser errors, and review privacy-masked session replays where you enable each purpose.
Lawful basis
Consent.
Purpose
Operate and secure the service
Examples
Keep audit records, run monitoring and report jobs, investigate incidents, prevent misuse, and record server-side failures.
Lawful basis
Contract, legal obligation, and legitimate interests, depending on the record and purpose.
Purpose
Communicate with you
Examples
Send service messages, support replies, billing notices, security notices, and product updates.
Lawful basis
Contract, legitimate interests, consent where required, and legal obligation.
Purpose
Comply with law
Examples
Keep required records, respond to lawful requests, resolve disputes, and enforce our terms.
Lawful basis
Legal obligation and legitimate interests.

4. Google Ads and Google API Data

If you connect Google Ads, BrandGuard will use Google user data only to provide and improve user-facing features you request, such as account linking, account discovery, monitoring, reporting, token health checks, and approved campaign actions.

  • We do not sell Google user data.
  • We do not use Google user data for advertising, data broker services, credit decisions, or training general AI models.
  • We share Google user data only with service providers that help us operate, secure, support, or legally protect BrandGuard.
  • You can revoke Google access through your Google account and should be able to disconnect integrations in BrandGuard where supported.

These disclosures are intended to support the Google API Services User Data Policy and Google OAuth requirements.

5. Cookies and Analytics

We use essential cookies and similar technologies to provide the website and application, keep users signed in, protect accounts, remember preferences, and support OAuth and security features.

Optional PostHog browser collection starts only after the relevant permission is saved. Product analytics, browser error diagnostics, and sampled session replay are controlled separately. PostHog may then use cookies, local storage, session storage, or similar browser storage. BrandGuard masks page text and form inputs in session replay.

Separately, BrandGuard sends minimised server-side service events to PostHog without relying on PostHog browser storage. Authenticated actions use the same internal user ID used by BrandGuard; automated work is assigned to a workspace or organisation; public service and reliability events do not create PostHog person profiles. We use these records to operate, secure, understand, and improve the service under the lawful bases described above.

PostHog project
Configured per deployment through the PostHog project token and server-side project API key.
PostHog hosting
PostHog Cloud EU preferred, hosted in Frankfurt where configured
Cookie preferences
/cookie-preferences

6. Who We Share Personal Data With

We do not sell personal data. We share it only where needed to run, secure, support, bill for, improve, or legally protect BrandGuard.

  • Cloud hosting, database, email, logging, monitoring, security, and support providers.
  • Google, where you use Google sign-in or connect Google Ads.
  • Stripe or other payment providers, where you subscribe or make payments.
  • PostHog, for minimised server-side service analytics and, where you enable them, browser analytics, diagnostics, or session replay.
  • Workspace owners, organisation administrators, agency managers, and invited users according to configured roles and permissions.
  • Professional advisers, insurers, regulators, courts, law enforcement, or other parties where required by law or necessary to protect rights.

7. International Transfers

Some providers may process personal data outside the UK. Where this happens, we use appropriate safeguards where required, such as adequacy regulations, UK international data transfer agreements, UK addenda to EU standard contractual clauses, vendor data processing terms, and security controls.

8. How Long We Keep Personal Data

We keep personal data only for as long as we need it for the purposes described in this notice, then delete, anonymise, or aggregate it unless we need to keep it longer for legal, accounting, security, or dispute reasons.

Data type
Account and workspace data
Typical retention
For the life of the account, then normally up to 24 months after closure unless a longer period is needed for disputes, security, tax, accounting, or legal obligations.
Data type
Google Ads and monitoring data
Typical retention
For as long as the workspace keeps the Google Ads connection or monitoring configuration active, then normally up to 24 months after disconnection unless retained in audit logs or reports.
Data type
Billing and invoice data
Typical retention
Normally up to 7 years after the relevant transaction or invoice for tax, accounting, and audit obligations.
Data type
Support data
Typical retention
Normally up to 24 months after the support request is closed unless it relates to an active account, dispute, or legal obligation.
Data type
Security and audit logs
Typical retention
Normally up to 24 months from collection unless needed to investigate abuse, fraud, security incidents, or legal claims.
Data type
PostHog data
Typical retention
PostHog event, group, and person data is retained only while needed for product improvement, service operation, and reliability purposes. Optional browser analytics, diagnostics, and replay follow the permissions you save; server-side service events follow the lawful bases described in this notice. All data remains subject to the deployed project's configured retention and verified deletion requests.
Data type
Consent records
Typical retention
Consent choices and changes are retained as compliance records while needed to demonstrate and honour those choices and to resolve related legal claims.

9. Your Rights

Under UK data protection law, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, and withdraw consent where we rely on consent.

  • To make a request, contact [email protected].
  • You can change or withdraw optional analytics permissions at any time through the cookie preferences page.
  • You can revoke Google OAuth access through your Google account.
  • You can complain to the UK Information Commissioner's Office if you are unhappy with how we handle your data.

10. Security

We use technical and organisational measures designed to protect personal data, including access controls, authentication safeguards, encrypted connections, audit logs, vendor controls, and secure handling of integration credentials. No online service can be guaranteed to be completely secure.

11. Children

BrandGuard is not directed at children. Users must be at least 18 or otherwise authorised to use the service on behalf of a customer.

12. Changes to This Notice

We may update this notice from time to time. If we make material changes, we will take reasonable steps to notify users through the website, application, email, or another appropriate method.