DPDPA 2023 CompliantLast updated 6 June 2026

Privacy Policy

BrandOps holds your brand's operational data — orders, influencer records, content campaigns, WhatsApp threads, and team activity. This policy explains exactly what we collect, why, and how you stay in control.

TL;DR — Four things to know

  • Your brand data — orders, influencers, content, tasks — belongs entirely to you.
  • We don't sell your data, use it for ads, or share it beyond what's listed below.
  • AI features send aggregated brand context to Anthropic. No raw customer data.
  • Export or delete everything anytime. Deletion happens within 7 business days.

What we collect

BrandOps stores your real operational data. Here's every category — explained plainly:

Account information

Name, email, and bcrypt-hashed password (we can't see it). Or your name and email from Google OAuth if you sign in with Google.

Brand operations data

Orders from Shopify, Amazon, Instagram, or manual entry — with status, payment method (prepaid / COD), amounts, and logistics notes. Content pieces, packing logs, and shipment records.

Influencer & creator records

Instagram handles, follower counts, niche, outreach status (Reached Out → Reel Posted → Completed), products gifted, agreed fees, reel dates, and performance notes. Entered by your team.

Team member data

Names and work emails of people you invite. They operate within your brand workspace and see only what your role settings allow.

Usage analytics

Features used, pages visited, session duration, error logs. Used to improve BrandOps. Aggregated — never linked to your customer, order, or influencer records.

Payment & billing

Plan name, subscription status, billing dates. Your card, UPI, or bank details go directly to our PCI-compliant processor — we never receive or store them.

Instagram & WhatsApp data

BrandOps includes an Instagram DM module and a WhatsApp business inbox. Here's how those integrations work:

Instagram DMs

Connecting your Instagram account authorises BrandOps to read and send direct messages via Meta's official API. We store message threads relevant to influencer outreach in your workspace. We don't access personal DMs unrelated to your business account.

WhatsApp Business

The WhatsApp inbox displays threads from your connected WhatsApp Business account — messages from customers, suppliers, and logistics partners. We store these to give your team a unified ops inbox. We don't use this data for anything beyond showing it to you.

Instagram content data

When you track influencer reels and posts, we store post URLs, engagement metrics, and performance notes your team enters manually. We don't scrape Instagram or access data beyond what Meta's official APIs provide with your explicit authorisation.

You control the connection

Disconnect Instagram or WhatsApp anytime from Settings → Integrations. Disconnecting stops all future sync. Message history already synced stays in your workspace until you delete it.

How we use your data

We use your data for one primary purpose: running BrandOps for you. Specifically:

  • Run the platformStore, retrieve, and display your orders, influencer records, content calendar, tasks, and analytics so the product works as expected.
  • Authenticate securelyVerify your identity on sign-in and keep your account and workspace protected from unauthorised access.
  • Power the AI assistantGenerate daily briefings, content suggestions, outreach templates, and operational insights using your brand context — see the AI section below for exactly what's shared.
  • Send transactional emailsPassword resets, billing confirmations, team invitations, and critical account alerts. No marketing email unless you opt in.
  • Improve BrandOpsAggregated, anonymised usage data helps us decide which features to build next. We never use your brand data for this — only behavioural patterns.
  • Provide supportWhen you contact us, we access relevant account information to resolve your issue quickly.

AI assistant & Anthropic

BrandOps uses Claude by Anthropic to power the AI assistant — daily briefings, content hook ideas, influencer outreach templates, and the chat interface.

What gets sent to Anthropic

When you trigger an AI feature, a context block is assembled from your brand data and sent to Anthropic's API. This context includes:

  • Revenue and order volume summaries
  • Influencer campaign stage counts and performance summaries
  • Content pipeline stage counts (Idea → Posted)
  • Open task counts by category
  • Your brand name and category

It does not include raw customer names, delivery addresses, full order lists, or personal influencer contact details.

AI requests are made server-side — your browser never talks to Anthropic directly. We don't persist conversation history after the session ends.

Anthropic's handling of API data is governed by Anthropic's Privacy Policy. By using AI features, you acknowledge that aggregated brand context is processed by Anthropic.

AI is opt-in per use

Your brand data is not sent to Anthropic during normal dashboard use. Context is only assembled and sent when you actively trigger an AI feature.

What we share and with whom

We don't sell your data. We share it only where necessary to run BrandOps:

AnthropicAggregated brand context for AI features — only when you actively use them. See the AI section above.
Meta (Instagram / WA)To read and send messages via official APIs. Only active when you've connected your accounts.
Google OAuthYour name and email for sign-in, only if you choose Google as your login method.
Payment processorSubscription billing. We use a PCI-DSS compliant processor and never handle raw card or UPI data ourselves.
Cloud infrastructureServers and databases on which BrandOps runs. Your data is encrypted at rest and in transit.
Legal requirementsIf required by law, court order, or Indian government authority. We'll notify you if we're legally permitted to do so.

Security

We take security seriously for a platform that holds your brand's operational data — orders, creator records, financial summaries.

What we do to protect your data

  • Passwords hashed with bcrypt — we can't see them
  • All data transmitted over HTTPS / TLS
  • Database access restricted, authenticated, and logged
  • Sessions invalidated on sign-out
  • Team role permissions control who sees what within your workspace
  • Regular dependency and security audits

No system is perfectly secure. If we become aware of a breach that affects your account or brand data, we'll notify you by email promptly and within timeframes required by DPDPA 2023.

Cookies

BrandOps uses a single session cookie to keep you signed in. Without it, you'd need to log in on every page.

Cookie namenext-auth.session-tokenPurposeAuthentication — keeps you signed inDurationDeleted when you sign out or the session expiresThird party?No — set and read only by BrandOps

We don't use advertising cookies, third-party analytics cookies, or cross-site tracking of any kind.

Your rights under DPDPA 2023

India's Digital Personal Data Protection Act (DPDPA) 2023 gives you clear rights over your data. BrandOps is designed to make exercising them easy:

Access your data

Export all orders, influencer records, content data, and tasks from Analytics → Export at any time.

Correct your data

Edit or update any record — orders, influencer profiles, content pieces, tasks — directly inside BrandOps.

Delete your account

Email hello@brandops.app. We permanently delete your account and all brand data within 7 business days.

Data portability

Order, influencer, content, and task data can be exported as CSV files from the Analytics dashboard.

Withdraw consent

Disconnect Instagram or WhatsApp from Settings at any time. Opt out of non-transactional emails from account preferences.

Lodge a complaint

Contact us at hello@brandops.app. You also have the right to file a complaint with India's Data Protection Board.

Data retention

Active accountData kept for as long as your account is active and your subscription is in good standing.
After cancellationData stays accessible in read-only mode for 30 days so you can export it. Permanently deleted after 30 days.
Account deletion requestAll data deleted within 7 business days. You'll receive an email confirmation.
Usage analyticsAnonymised, aggregated usage stats may be kept indefinitely to improve the product. They cannot be traced back to your account.

Policy changes

We may update this policy as BrandOps evolves or as regulations change. For material changes, we'll notify you by email at least 7 days before they take effect. Continued use of BrandOps after that date means you accept the updated policy.

The “Last updated” date at the top always reflects the most recent revision. Previous versions are available on request at hello@brandops.app.

Contact us

Questions about this policy, your data, or how to exercise your DPDPA rights? We respond within 2 business days.

hello@brandops.appReply within 2 business days