Privacy
This policy explains what personal data Brandsearch collects, why we collect it, who we share it with, how long we keep it, and the choices you have. It covers the brandsearch.co website, the Brandsearch web application, the Brandsearch Chrome extension, and our API and MCP server.
Effective date: 11 September 2026|Last updated: 11 September 2026
Brandsearch is an ecommerce and advertising intelligence platform operated by SPECTRE PRYSM S.à r.l.-S, a company registered in Luxembourg. In this policy, “Brandsearch”, “we”, “us” and “our” mean SPECTRE PRYSM S.à r.l.-S.
For the personal data described here, we act as the data controller. That means we decide what data is collected and why. If you have a question about this policy, or want to exercise any of the rights described in section 11, write to contact@brandsearch.co and we will answer.
Data controller
SPECTRE PRYSM S.à r.l.-S
Simplified Limited Liability Company
Registration number: B300832
28, Op der Haart, 9999 Wemperhardt, Luxembourg
Email: contact@brandsearch.co
We collect only what we need to run the service. The data falls into six groups, listed below by where it comes from.
When you register, we collect your name, your email address, and a password. Passwords are stored only as a bcrypt hash, so we never hold the password itself. We also store the profile and preference settings you choose, such as your display picture, interface language, theme, notification preferences, and the answers you give during onboarding.
If you choose to sign in with Google, we receive a limited set of profile fields from your Google account. Section 3 sets out exactly which fields, why we ask for them, and what we do and do not do with them.
Payments are processed by Stripe. Your card number, expiry date, and security code are entered directly into Stripe and never reach our servers. What we store is the billing information we need to run your subscription: your Stripe customer and subscription identifiers, your plan, your subscription status, renewal dates, and your invoices. If you provide a business name, address, or VAT number for invoicing, we store that too.
As you use Brandsearch we store the content you create and the actions you take, so the product works as you expect between sessions. This includes saved ads, saved brands and products, folders and boards, saved searches and filters, tracked brands, alert settings, exports you generate, and the counters we use to apply your plan limits.
When you visit our website or use the application, we and our analytics providers collect technical data: your IP address, browser and device type, operating system, referring page, pages viewed, the time and duration of your visit, and the actions you take in the interface. Microsoft Clarity records anonymised session replays and heatmaps on our public website. We use this data to understand how the product is used, to diagnose errors, and to detect abuse. It is not used to build advertising profiles about you.
If you contact us by email, through the in-app support widget, or through our Discord community, we keep a record of the conversation and anything you send us in it, so we can follow up and improve our support.
Brandsearch offers Google Sign-In as one way to create and access an account. This section explains exactly what Google user data we access, how we use it, who we share it with, how we protect it, how long we keep it, and how you can take it back. It applies in addition to everything else in this policy.
When you sign in with Google, we request the three scopes below and nothing more. We do not request access to Gmail, Google Calendar, Google Contacts, Google Photos, Google Search Console, Google Ads, or any other Google service.
| Scope requested | Data we receive | Why we need it |
|---|---|---|
| openid | A stable, pseudonymous Google account identifier (the “sub” claim) contained in an ID token. | To recognise that a returning sign-in belongs to the same Google account, so we can log you back into the correct Brandsearch account. |
| https://www.googleapis.com/auth/userinfo.email | Your Google account email address and whether Google has verified it. | To create your Brandsearch account, to use as the unique identifier for that account, to link a Google sign-in to an existing Brandsearch account with the same address, and to send you service and billing email. |
| https://www.googleapis.com/auth/userinfo.profile | Your Google display name and the URL of your Google profile picture. | To pre-fill your Brandsearch profile and to show your own name and picture to you inside the product interface. |
These scopes are read-only. They let us confirm who you are. They do not let us read, create, edit, or delete any content in your Google account.
Google user data is used for authentication and identity only. Specifically, we use it to:
We do not use Google user data for any other purpose. In particular, we do not use it to serve advertising, to build marketing profiles, or to enrich the brand and advertising datasets that Brandsearch sells access to.
Your Google account identifier, email address, display name, and profile picture URL are stored in our PostgreSQL database in the European Union, alongside the rest of your account record. The OAuth tokens issued by Google are held server-side only. They are never sent to your browser, never included in a client-side bundle, and never exposed through our public API. Access to the database is restricted to a small number of engineers who need it to operate the service, and all traffic is encrypted in transit with TLS.
We do not sell, rent, trade, or transfer Google user data. We do not share it with advertisers, data brokers, or any third party for their own purposes. It is not passed to our analytics or marketing tools. The only circumstances in which Google user data leaves our systems are the hosting and database infrastructure we use to run the service, listed in section 6, and a valid, binding legal order that compels disclosure.
Limited Use disclosure
Brandsearch's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
To state this in plain terms, we affirm that Brandsearch does not:
We keep your Google profile data for as long as your Google account stays connected to your Brandsearch account. You can disconnect Brandsearch at any time from your Google account security settings at myaccount.google.com/permissions. Revoking access there stops us from receiving any further data from Google, and invalidates the tokens we hold.
Revoking access does not by itself erase the profile data already stored in your Brandsearch account. To have that deleted, email contact@brandsearch.co and we will delete it within 30 days. If you delete your whole Brandsearch account as described in section 9, all Google user data and tokens associated with it are deleted at the same time.
We use personal data for the purposes below. Because we serve users in the European Economic Area, the table also names the legal basis we rely on under the General Data Protection Regulation.
| Purpose | Legal basis |
|---|---|
| Creating your account, authenticating you, and providing the features you subscribe to | Performance of a contract |
| Taking payment, managing subscriptions, invoicing, and handling failed payments | Performance of a contract, and legal obligation for invoicing records |
| Responding to support requests and sending service notices about your account | Performance of a contract, and our legitimate interest in supporting our users |
| Measuring how the product is used so we can fix problems and improve features | Our legitimate interest in operating and improving the service |
| Detecting fraud, abuse, account sharing, and security incidents | Our legitimate interest in keeping the service secure, and legal obligation |
| Sending marketing email and product announcements you have opted into | Your consent, which you can withdraw at any time |
| Keeping accounting and tax records | Legal obligation under Luxembourg law |
Where we rely on your consent, you can withdraw it at any time without affecting anything we did before you withdrew it. Where we rely on legitimate interests, we have weighed those interests against your rights, and you can object as described in section 11.
We are based in Luxembourg and our primary infrastructure is in the European Union. Some of the providers listed in section 6 process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies, together with additional technical safeguards such as encryption in transit and at rest. You can ask us for details of the safeguards that apply to a specific transfer by writing to contact@brandsearch.co.
We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires. In practice that means:
| Type of data | How long we keep it |
|---|---|
| Account data (name, email, password hash, preferences) | For as long as your account is open, then deleted within 30 days of a deletion request. |
| Google profile data and Google OAuth tokens | For as long as your Google account stays connected. Deleted when you revoke access at your Google account, or within 30 days of a deletion request. |
| Saved ads, folders, filters, tracked brands, and other content you create | For as long as your account is open, then deleted with the account. |
| Invoices and accounting records | 10 years from the end of the financial year, as required by Luxembourg accounting law. |
| Product analytics and session analytics | Up to 26 months from collection. |
| Server and security logs | Up to 90 days, unless a log is part of an active security or fraud investigation. |
| Support email and conversations | Up to 24 months after the conversation is closed. |
When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.
You can ask us to delete your Brandsearch account and the personal data associated with it at any time, for any reason, without giving an explanation.
To do this, email contact@brandsearch.co from the address registered on your account, with the subject line “Delete my account”. We will confirm that the request came from you, and then delete your account and its personal data within 30 days. That includes your profile, your Google profile data and OAuth tokens, your saved ads, folders, filters, tracked brands, and your support history.
Two things survive deletion. We keep invoices and accounting records for the period Luxembourg law requires, because we are not permitted to delete them. And we keep a minimal record that an account with your email address was deleted, and when, so we can demonstrate that we honoured your request.
Deleting your account is separate from cancelling your subscription. Cancelling stops future billing and leaves your data in place. If you want both, say so in your email and we will do both.
We take the security of your data seriously, and we apply measures appropriate to the risk:
No system is perfectly secure, and we will not pretend otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by the GDPR, and we will notify you directly where the law requires it.
Under the GDPR you have the right to:
To exercise any of these rights, email contact@brandsearch.co. We answer within one month, and we do not charge for it. If you are unhappy with our response, you can complain to the Luxembourg supervisory authority, the Commission Nationale pour la Protection des Données, or to the authority in the country where you live.
Under the California Consumer Privacy Act, as amended by the CPRA, you have the right to know what personal information we collect and how we use it, to request a copy of it, to request its correction or deletion, and to opt out of the sale or sharing of personal information.
Brandsearch does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. There is therefore nothing to opt out of. We will not discriminate against you for exercising any of your rights. To make a request, email contact@brandsearch.co.
Brandsearch is a business tool intended for professional use. It is not directed at children, and you must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, email contact@brandsearch.co and we will delete it.
Separately from the data we hold about our own users, Brandsearch indexes publicly available information about ecommerce brands and their advertising. This includes advertising creatives and metadata published in public ad transparency libraries operated by platforms such as Meta and TikTok, publicly accessible storefront and product information, and publicly published social media content.
This information is overwhelmingly commercial rather than personal. Where it does contain personal data, for example the name or image of a person appearing in an advertisement, we process it on the basis of our legitimate interest in providing market and competitive research, balanced against the rights of the people concerned. The data is already published by the advertiser or the platform.
If you appear in content indexed by Brandsearch and want it removed, email contact@brandsearch.co with a link to the content and enough detail for us to find it. We review these requests individually. Copyright holders should use the procedure on our DMCA page instead.
The Brandsearch Chrome extension reads publicly visible data on the pages where you activate it, so it can show you Brandsearch insights in context and let you save what you find to your account. It sends us the page or advertisement identifier you are looking at, together with your account token so we know the request is yours.
The extension does not read your browsing history, does not run on pages where you have not activated it, does not capture passwords or form input, and does not access your Google account data. It does not bypass authentication or access content that is not publicly visible to you.
We may update this policy as the product changes or as the law requires. The date at the top of the page always shows when it was last updated, and that version is the one that applies.
If we make a material change, such as collecting a new category of personal data, requesting an additional Google scope, or using your data for a genuinely new purpose, we will tell you before it takes effect, by email or through a notice in the product, and where the law requires it we will ask for your consent.
For any question about this policy, about how we handle your data, or to exercise any of your rights, contact us at contact@brandsearch.co. We read every message and we answer.
Data controller
SPECTRE PRYSM S.à r.l.-S
Simplified Limited Liability Company
Registration number: B300832
28, Op der Haart, 9999 Wemperhardt, Luxembourg
Email: contact@brandsearch.co
Looking for our terms instead? Read the Terms of Service.