← Back to home

Privacy Policy

Effective date: April 15, 2026 · Last updated: April 15, 2026

1. Introduction

This Privacy Policy describes how brik.consulting ("we", "us", "our") collects, uses, stores, and protects information from users of our products, website, and associated services ("Services"), including brik.channel, brik.stock, brik.listing, brik.order, brik.price, and brik.media — our multi-channel e-commerce platform.

2. What We Collect

2.1 Information You Provide

2.2 Information from Connected Platforms

We only access data required for inventory synchronization within the scopes explicitly approved by the merchant during OAuth authorization.

2.3 Information Collected Automatically

2.4 Information We Do NOT Collect

3. How We Use Information

PurposeLegal Basis
Synchronize inventory between platformsContractual necessity
Authenticate users and manage sessionsContractual necessity
Customer supportContractual necessity
Security monitoring and abuse preventionLegitimate interest
Service improvementLegitimate interest
Compliance with legal obligationsLegal obligation

4. Data Sharing

We share data only with the following categories of recipients:

RecipientDataPurpose
Supabase (hosting, EU — Ireland)Account and connection dataDatabase hosting
Vercel (hosting)Request logsApplication hosting
Shopify, Amazon, TikTok Shop, eBay, Walmart, and other marketplace APIsProduct, inventory, order, and pricing dataSynchronization and order management
ShipStation / EasyPost APIsShipping and tracking dataShipping label and rate management
QuickBooks APIFinancial dataAccounting integration

We do not sell personal data, share data with third parties for advertising, or use data for automated decision-making.

5. Data Retention

Data TypeRetention
Account dataDuration of active account + 30 days
OAuth tokens (platform connections)Until user disconnects the platform
Sync event logs90 days, then auto-purged
Product mapping dataDuration of active sync pair
IP / security logs90 days

6. Data Security

We implement industry-standard security measures including TLS 1.2+ encryption for all data in transit, encrypted storage at rest (AES-256), OAuth 2.0 authentication, HMAC-SHA256 webhook verification, and least-privilege access controls. See our Security Practices page for details.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights, contact: support@brik.consulting

We will assist sellers and platform operators to fulfill data subject access requests (access, correction, deletion) within 30 days of receipt.

8. International Transfers

Primary data storage is in the EU (Supabase, West EU — Ireland). Application hosting is provided by Vercel with edge nodes globally. Data may be processed in the EU and US.

9. Data Breach Notification

In the event of a data breach affecting personal data, we will notify affected users, sellers, platform partners, and applicable regulatory authorities within 72 hours of discovery, in accordance with GDPR Article 33 requirements.

10. Data Deletion on Contract Termination

Upon termination of the contractual relationship, all collected customer data in our possession will be deleted within 30 days, unless retention is required by law. OAuth tokens are revoked immediately upon disconnection.

11. Children

The Services are not directed at persons under 18. We do not knowingly collect data from minors.

12. Data Protection Contact

Data Protection Officer: Yevhen Sharonov
Email: dpo@brik.consulting

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by email or via an in-app notice.