Privacy Policy
This notice explains how BrandGuard uses personal data when you visit our website, create an account, use the application, connect integrations, contact us, or pay for our services.
Effective date: 23 July 2026
- Controller: BrandGuard
- Contact: [email protected]
- Website: https://usebrandguard.co.uk
- Review status: Draft for product preview; final legal review required before public launch
1. Who We Are
BrandGuard operates this service under the BrandGuard name. We are the data controller for the personal data described in this notice unless we say otherwise.
- Registered office
- Registered office details will be confirmed before public launch
- Company number
- Company registration details will be confirmed before public launch
- VAT number
- VAT status will be confirmed on customer invoices
- Privacy contact
- [email protected]
- DPO or privacy lead
- Privacy requests can be sent to [email protected]
- ICO registration
- ICO registration details will be published where required
2. The Personal Data We Collect
We collect information that we need to run BrandGuard, manage customer accounts, provide support, improve the product, keep the service secure, and meet legal obligations.
- Identity and contact details, such as name, email address, login method, profile information, and workspace role.
- Account and organisation information, such as workspace names, invited users, permissions, billing owner details, plan information, and subscription status.
- Integration data, including Google Ads account identifiers, account names, hierarchy information, campaign selections, monitoring configuration, OAuth token status, and related reporting data where you connect Google Ads.
- Optional browser usage data, where you allow it, such as pages viewed, features used, reports opened, feature evaluations, browser diagnostics, and session information.
- Service activity, operational, and security records, such as authenticated settings changes, authentication events, workspace audit logs, monitoring and report job status, billing actions, abuse prevention signals, and server-side failures.
- Payment and billing records, such as Stripe customer IDs, subscription IDs, invoice status, plan changes, and billing support messages.
- Website and device data, such as IP address, browser, device type, approximate location, cookie identifiers, consent choices, and analytics events.
- Support and communication data, including messages you send us, attachments, feedback, and records of our replies.
3. How We Use Personal Data
- Purpose
- Provide and manage BrandGuard
- Examples
- Create accounts, authenticate users, manage workspaces, run monitoring, produce reports, and provide requested features.
- Lawful basis
- Contract and legitimate interests.
- Purpose
- Provide integrations
- Examples
- Connect Google Ads, refresh access, read account data, show campaign options, monitor selected terms, and apply user-approved automation.
- Lawful basis
- Contract, legitimate interests, and user authorisation through Google OAuth.
- Purpose
- Take payment and administer plans
- Examples
- Process checkout, manage subscriptions, invoices, cancellations, upgrades, downgrades, and plan limits.
- Lawful basis
- Contract, legal obligation, and legitimate interests.
- Purpose
- Optional product improvement
- Examples
- Measure browser usage, evaluate product changes, diagnose browser errors, and review privacy-masked session replays where you enable each purpose.
- Lawful basis
- Consent.
- Purpose
- Operate and secure the service
- Examples
- Keep audit records, run monitoring and report jobs, investigate incidents, prevent misuse, and record server-side failures.
- Lawful basis
- Contract, legal obligation, and legitimate interests, depending on the record and purpose.
- Purpose
- Communicate with you
- Examples
- Send service messages, support replies, billing notices, security notices, and product updates.
- Lawful basis
- Contract, legitimate interests, consent where required, and legal obligation.
- Purpose
- Comply with law
- Examples
- Keep required records, respond to lawful requests, resolve disputes, and enforce our terms.
- Lawful basis
- Legal obligation and legitimate interests.
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide and manage BrandGuard | Create accounts, authenticate users, manage workspaces, run monitoring, produce reports, and provide requested features. | Contract and legitimate interests. |
| Provide integrations | Connect Google Ads, refresh access, read account data, show campaign options, monitor selected terms, and apply user-approved automation. | Contract, legitimate interests, and user authorisation through Google OAuth. |
| Take payment and administer plans | Process checkout, manage subscriptions, invoices, cancellations, upgrades, downgrades, and plan limits. | Contract, legal obligation, and legitimate interests. |
| Optional product improvement | Measure browser usage, evaluate product changes, diagnose browser errors, and review privacy-masked session replays where you enable each purpose. | Consent. |
| Operate and secure the service | Keep audit records, run monitoring and report jobs, investigate incidents, prevent misuse, and record server-side failures. | Contract, legal obligation, and legitimate interests, depending on the record and purpose. |
| Communicate with you | Send service messages, support replies, billing notices, security notices, and product updates. | Contract, legitimate interests, consent where required, and legal obligation. |
| Comply with law | Keep required records, respond to lawful requests, resolve disputes, and enforce our terms. | Legal obligation and legitimate interests. |
4. Google Ads and Google API Data
If you connect Google Ads, BrandGuard will use Google user data only to provide and improve user-facing features you request, such as account linking, account discovery, monitoring, reporting, token health checks, and approved campaign actions.
- We do not sell Google user data.
- We do not use Google user data for advertising, data broker services, credit decisions, or training general AI models.
- We share Google user data only with service providers that help us operate, secure, support, or legally protect BrandGuard.
- You can revoke Google access through your Google account and should be able to disconnect integrations in BrandGuard where supported.
These disclosures are intended to support the Google API Services User Data Policy and Google OAuth requirements.
5. Cookies and Analytics
We use essential cookies and similar technologies to provide the website and application, keep users signed in, protect accounts, remember preferences, and support OAuth and security features.
Optional PostHog browser collection starts only after the relevant permission is saved. Product analytics, browser error diagnostics, and sampled session replay are controlled separately. PostHog may then use cookies, local storage, session storage, or similar browser storage. BrandGuard masks page text and form inputs in session replay.
Separately, BrandGuard sends minimised server-side service events to PostHog without relying on PostHog browser storage. Authenticated actions use the same internal user ID used by BrandGuard; automated work is assigned to a workspace or organisation; public service and reliability events do not create PostHog person profiles. We use these records to operate, secure, understand, and improve the service under the lawful bases described above.
- PostHog project
- Configured per deployment through the PostHog project token and server-side project API key.
- PostHog hosting
- PostHog Cloud EU preferred, hosted in Frankfurt where configured
- Cookie preferences
- /cookie-preferences
6. Who We Share Personal Data With
We do not sell personal data. We share it only where needed to run, secure, support, bill for, improve, or legally protect BrandGuard.
- Cloud hosting, database, email, logging, monitoring, security, and support providers.
- Google, where you use Google sign-in or connect Google Ads.
- Stripe or other payment providers, where you subscribe or make payments.
- PostHog, for minimised server-side service analytics and, where you enable them, browser analytics, diagnostics, or session replay.
- Workspace owners, organisation administrators, agency managers, and invited users according to configured roles and permissions.
- Professional advisers, insurers, regulators, courts, law enforcement, or other parties where required by law or necessary to protect rights.
7. International Transfers
Some providers may process personal data outside the UK. Where this happens, we use appropriate safeguards where required, such as adequacy regulations, UK international data transfer agreements, UK addenda to EU standard contractual clauses, vendor data processing terms, and security controls.
8. How Long We Keep Personal Data
We keep personal data only for as long as we need it for the purposes described in this notice, then delete, anonymise, or aggregate it unless we need to keep it longer for legal, accounting, security, or dispute reasons.
- Data type
- Account and workspace data
- Typical retention
- For the life of the account, then normally up to 24 months after closure unless a longer period is needed for disputes, security, tax, accounting, or legal obligations.
- Data type
- Google Ads and monitoring data
- Typical retention
- For as long as the workspace keeps the Google Ads connection or monitoring configuration active, then normally up to 24 months after disconnection unless retained in audit logs or reports.
- Data type
- Billing and invoice data
- Typical retention
- Normally up to 7 years after the relevant transaction or invoice for tax, accounting, and audit obligations.
- Data type
- Support data
- Typical retention
- Normally up to 24 months after the support request is closed unless it relates to an active account, dispute, or legal obligation.
- Data type
- Security and audit logs
- Typical retention
- Normally up to 24 months from collection unless needed to investigate abuse, fraud, security incidents, or legal claims.
- Data type
- PostHog data
- Typical retention
- PostHog event, group, and person data is retained only while needed for product improvement, service operation, and reliability purposes. Optional browser analytics, diagnostics, and replay follow the permissions you save; server-side service events follow the lawful bases described in this notice. All data remains subject to the deployed project's configured retention and verified deletion requests.
- Data type
- Consent records
- Typical retention
- Consent choices and changes are retained as compliance records while needed to demonstrate and honour those choices and to resolve related legal claims.
| Data type | Typical retention |
|---|---|
| Account and workspace data | For the life of the account, then normally up to 24 months after closure unless a longer period is needed for disputes, security, tax, accounting, or legal obligations. |
| Google Ads and monitoring data | For as long as the workspace keeps the Google Ads connection or monitoring configuration active, then normally up to 24 months after disconnection unless retained in audit logs or reports. |
| Billing and invoice data | Normally up to 7 years after the relevant transaction or invoice for tax, accounting, and audit obligations. |
| Support data | Normally up to 24 months after the support request is closed unless it relates to an active account, dispute, or legal obligation. |
| Security and audit logs | Normally up to 24 months from collection unless needed to investigate abuse, fraud, security incidents, or legal claims. |
| PostHog data | PostHog event, group, and person data is retained only while needed for product improvement, service operation, and reliability purposes. Optional browser analytics, diagnostics, and replay follow the permissions you save; server-side service events follow the lawful bases described in this notice. All data remains subject to the deployed project's configured retention and verified deletion requests. |
| Consent records | Consent choices and changes are retained as compliance records while needed to demonstrate and honour those choices and to resolve related legal claims. |
9. Your Rights
Under UK data protection law, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, and withdraw consent where we rely on consent.
- To make a request, contact [email protected].
- You can change or withdraw optional analytics permissions at any time through the cookie preferences page.
- You can revoke Google OAuth access through your Google account.
- You can complain to the UK Information Commissioner's Office if you are unhappy with how we handle your data.
10. Security
We use technical and organisational measures designed to protect personal data, including access controls, authentication safeguards, encrypted connections, audit logs, vendor controls, and secure handling of integration credentials. No online service can be guaranteed to be completely secure.
11. Children
BrandGuard is not directed at children. Users must be at least 18 or otherwise authorised to use the service on behalf of a customer.
12. Changes to This Notice
We may update this notice from time to time. If we make material changes, we will take reasonable steps to notify users through the website, application, email, or another appropriate method.