Brandblizz

Privacy Policy

Last updated: March 2026

1. Data Controller

The controller responsible for data processing on this platform within the meaning of the General Data Protection Regulation (GDPR) is:


Email:

(hereinafter referred to as “Provider”, “we”, or “us”)

2. Overview of Data Processing

We process personal data only to the extent necessary to provide a functional platform and to deliver our services. The processing of personal data occurs regularly only with the consent of the user or where processing is permitted by statutory regulations.

Types of Data Processed

  • Account data– email address, name, password hash, authentication method
  • Usage data– session identifiers, pages visited, features used, timestamps
  • Device & access data – IP address (anonymized), browser type, operating system, device type, approximate location (country/city level)
  • Payment data– email address shared with Stripe; credit card and billing details are processed exclusively by Stripe and never stored on our servers
  • Content data– brand information, business descriptions, and other inputs submitted by the user for AI-powered analysis

Purposes of Processing

  • Provision and operation of the platform
  • User authentication and account management
  • Processing of payments
  • Delivery of AI-powered brand analysis and related services
  • Sending transactional emails (e.g., confirmation codes, service notifications)
  • Newsletter delivery (with explicit consent)
  • Web analytics for service improvement (first-party, consent-based)
  • Compliance with legal obligations

3. Legal Basis for Data Processing

We process personal data on the following legal bases under the GDPR:

  • Art. 6(1)(a) GDPR – Consent: Where the user has given explicit consent to the processing of their personal data for one or more specific purposes (e.g., newsletter subscription, analytics cookies).
  • Art. 6(1)(b) GDPR – Performance of a contract: Where processing is necessary for the performance of a contract to which the user is a party, or in order to take steps at the request of the user prior to entering into a contract (e.g., account registration, service delivery, payment processing).
  • Art. 6(1)(f) GDPR – Legitimate interest: Where processing is necessary for the purposes of legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the user (e.g., platform security, fraud prevention, service improvement).

4. Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. These include:

  • Transport Layer Security (TLS): All data transmitted between the user’s browser and our servers is encrypted using TLS/HTTPS.
  • Row Level Security (RLS): Database-level access controls ensure that each user can only access their own data.
  • Data minimization: We collect and process only the data strictly necessary for the respective purpose.
  • Access controls: Access to personal data is restricted to authorized personnel on a need-to-know basis. Administrative access is protected by multi-factor authentication.
  • Password security: User passwords are never stored in plaintext; only cryptographic hashes are retained.

5. Data Processing Agreements & International Transfers

We have concluded Data Processing Agreements (DPAs / Auftragsverarbeitungsverträge, “AVVs”) in accordance with Art. 28 GDPR with all third-party processors that handle personal data on our behalf. These agreements ensure that all processors are contractually bound to process data in compliance with GDPR requirements.

Where personal data is transferred to processors located outside the European Economic Area (EEA), we ensure an adequate level of data protection through one or more of the following safeguards:

  • EU-US Data Privacy Framework (DPF): For US-based processors that are certified under the DPF, the European Commission has recognized an adequate level of data protection.
  • Standard Contractual Clauses (SCCs): For transfers to third countries without an adequacy decision, we rely on the Standard Contractual Clauses adopted by the European Commission as supplementary safeguards.

6. Hosting & Infrastructure

Vercel Inc.

Our platform is hosted on Vercel Inc. (440 N Baxter St, Suite 4060, Los Angeles, CA 90036, USA). Vercel provides the frontend hosting, serverless functions, and edge network delivery for our platform. Vercel is certified under the EU-US Data Privacy Framework (DPF).

When you access our platform, your IP address and technical metadata (browser type, operating system) are processed by Vercel’s servers for the purpose of delivering the website. This processing is based on Art. 6(1)(b) and Art. 6(1)(f) GDPR.

Supabase Inc.

Our database and authentication services are provided by Supabase Inc. (970 Toa Payoh North #07-04, Singapore 318992). Our Supabase project is hosted in the EU region eu-central-1 (Frankfurt, Germany), meaning that all user data stored in our database remains within the European Union. Supabase processes data on our behalf under a Data Processing Agreement in accordance with Art. 28 GDPR.

7. Cookies & Consent

Our platform uses cookies and similar technologies. Cookies are small text files stored on your device by your browser. We categorize our cookies as follows:

CategoryCookie NamePurpose
Essentialsb-*Supabase authentication session cookies, required for login and secure access
Essentialbb-consentStores your cookie consent preferences
Analytics / Marketingbb-fbclid, bb-ad-*, bb-utm-*, bb-pv-eid, bb-visit-fired (sessionStorage)Tab-bound stash of the Meta click ID, ad/UTM parameters from the entry URL, and event IDs for browser/server deduplication; attributed once to your account upon registration (see Section 13)
Analytics / Marketing_fbpMeta Pixel – identifies the browser for ad attribution (90 days)
Analytics / Marketing_fbcMeta Pixel – stores the click ID when a user clicks a Meta ad (90 days)

Essential cookies are strictly necessary for the operation of the platform and are set without consent in accordance with Art. 6(1)(b) and Art. 6(1)(f) GDPR. Analytics and marketing cookies are only set after you have given your explicit consent via our cookie banner, in accordance with Art. 6(1)(a) GDPR. You may withdraw your consent at any time by adjusting your preferences through the cookie banner.

8. Registration & Authentication

To use the platform, you must create a user account. During registration, we collect and process the following data:

  • Email address
  • Full name
  • Password hash (for password-based authentication; the password itself is never stored)

We offer the following authentication methods:

  • Email confirmation code: During sign-up we send a one-time confirmation code to your email address to verify ownership of the address.
  • Google OAuth: Authentication via your Google account. We receive your name and email address from Google; we do not access any other Google account data.
  • Password: Traditional email and password authentication. Passwords are cryptographically hashed before storage.

The legal basis for processing registration data is Art. 6(1)(b) GDPR (performance of a contract).

9. Newsletter

You may subscribe to our newsletter to receive updates about new features, brand strategy insights, and platform announcements. We use a double opt-in procedure: after entering your email address, you will receive a confirmation email with a verification link. Your subscription is only activated once you click this link.

The newsletter may include product updates, feature announcements, brand strategy tips, educational content related to brand development, and promotional offers related to Brandblizz services.

You may unsubscribe at any time by clicking the unsubscribe link included in every newsletter email, or by contacting us at .

The legal basis for processing your email address for newsletter purposes is Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal.

10. Payment Processing

Payment processing for paid services is handled by Stripe Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA). When you make a purchase, your email address is shared with Stripe to facilitate the transaction and send payment receipts.

All payment card data (credit card numbers, expiration dates, CVV codes) is processed exclusively by Stripe and is never transmitted to or stored on our servers. Stripe is PCI-DSS compliant (Payment Card Industry Data Security Standard), ensuring the highest level of security for payment data.

Stripe is certified under the EU-US Data Privacy Framework. For more information, please refer to Stripe’s Privacy Policy.

The legal basis for sharing data with Stripe is Art. 6(1)(b) GDPR (performance of a contract).

11. AI-Powered Services

Our platform uses artificial intelligence to deliver brand analysis, strategic recommendations, and creative content. The following AI providers are integrated:

Google Gemini

Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) provides the Gemini AI model used for competitive research and market analysis. Data submitted for processing is not stored permanently and is used solely for generating the requested analysis results.

Anthropic (Claude)

Anthropic PBC (San Francisco, CA, USA) provides the Claude models used for text and strategy generation as part of brand development. User inputs related to brand information are submitted to Anthropic for processing. Data is used for processing only and is not stored permanently by Anthropic under our API agreement.

Ideogram

Ideogram AI, Inc. (Toronto, Canada) is used for AI-powered logo image generation. Brand-related inputs (e.g., brand name, style preferences) are submitted to Ideogram as prompts. Data is used for processing only and is not stored permanently.

Vectorizer.AI

Vectorizer.AI (operated by Cedar Lake Ventures, Inc., USA) is used to convert generated logo images into vector graphics. No personal data is transmitted to Vectorizer.AI; only the generated logo image files are submitted for conversion.

Important note: Data submitted to AI providers is used exclusively for the purpose of generating the requested analysis or content. It is not stored permanently by the AI providers and is not used for training purposes under our enterprise/API agreements.

International transfers: The AI providers listed above are based in the USA or Canada (Ideogram). Data transfers are safeguarded by Standard Contractual Clauses (Art. 46(2)(c) GDPR) or, where the respective provider is certified, by the EU-US Data Privacy Framework.

The legal basis for this processing is Art. 6(1)(b) GDPR (performance of a contract).

12. Third-Party Services

Resend

We use Resend Inc. for sending transactional emails (e.g., email confirmation codes, password resets, service notifications). Your email address and name are shared with Resend for this purpose. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

13. Web Analytics

For analysing the usage of our website we use a first-party, self-hosted analytics system. In addition, we use the Meta Pixel (Facebook Pixel) to measure the effectiveness of our advertising (see Section 13a).

First-party funnel measurement (server-side)

At key steps of our service (completed registration, start of brand generation, start of checkout, purchase) we store an event server-side with timestamp, event type and, where applicable, a pseudonymous user and brand ID in our database (Supabase, EU region Frankfurt). No cookies are set or read for this, no IP address or user agent is stored, and no data is shared with third parties. Legal basis: Art. 6(1)(f) GDPR; for contract events (purchase) also Art. 6(1)(b) GDPR.

Campaign attribution (first touch)

If you arrive via an ad or campaign link, your browser stores the campaign parameters from the entry URL (ad hierarchy, UTM parameters, Meta click ID fbclid, landing page) in sessionStorage— tab-bound, expiring with the browser session (see the table in Section 7). If you then register, we attribute this origin information once to your account to evaluate which campaigns lead to registrations and purchases. Without a registration the information expires with the tab. Legal basis: Art. 6(1)(f) GDPR (ad performance measurement); you may object at any time by email.

Anonymous reach and source counting (visits)

On the first view of our public pages we count the visit server-side: timestamp, landing page, the origin category (e.g. search engine, social network, direct) including the domain of the referring page (the referrer your browser sends anyway), any campaign parameters from the URL (e.g. utm_source), and whether the visit originated from a click on a Meta ad (identified by the click ID fbclid; yes/no). We additionally record the device category (mobile, tablet or desktop), the operating-system family (e.g. iOS, Android, Windows) and the country of origin – each only as a coarse category, derived from the user agent and IP address respectively, neither of which is stored itself. Not collected: IP address (held only briefly in memory for rate limiting, never persisted), session ID, user ID, email address. Legal basis: Art. 6(1)(f) GDPR.

13a. Meta Pixel / Conversions API

Provider:Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland (Privacy Policy).

Purpose: We use the Meta Pixel and Meta Conversions API (CAPI) to measure the effectiveness of our advertising on Instagram and Facebook, create audiences, and track conversions.

Data Collected & Events

Browser-side (Meta Pixel):

  • PageView (page visits)
  • Lead (start of brand generation)
  • InitiateCheckout (start of the purchase process)
  • Purchase (completed purchase)
  • CompleteRegistration (sign-up)

Server-side (Conversions API): The same events are additionally sent to Meta server-side. The following data is transmitted in hashed form: email address, first name, last name. Transmitted unhashed: IP address (anonymised), user agent, click ID (fbc), and browser ID (fbp). A shared event ID (event_id) is used for deduplication.

Server-side transmission without consent

Certain events are transmitted to Meta server-side on the basis of our legitimate interest (Art. 6(1)(f) GDPR) — independent of the cookie banner:

  • PageView– only for visits that carry a Meta click ID (fbclid), i.e. after a click on one of our ads. Used for reach measurement of paid advertising.
  • Lead, InitiateCheckout, CompleteRegistration – active user actions (form submission, registration, start of purchase). Used for conversion attribution of paid advertising.

The following data is transmitted in this context: IP address, user agent, where applicable click ID (fbc), and – for active actions – hashed email, name, and pseudonymous user ID. No cookies are set or read for this transmission. Without this data, we could not meaningfully evaluate the effectiveness of our advertising or make informed budget decisions. You may object to this processing at any time (see “Withdrawal” below); organic and direct traffic (without fbclid) is never transmitted to Meta.

Cookies

  • _fbp– Identifies the browser for ad attribution (retention: 90 days)
  • _fbc– Stores the click ID when a user clicks a Meta ad (retention: 90 days)

Consent: The Meta Pixel (browser script) and the cookies _fbp and _fbc are loaded or set only after your explicit consent via our cookie banner. We also respect the Do Not Track signal sent by your browser. The server-side transmission described above takes place independently of the cookie banner, based on legitimate interest (Art. 6(1)(f) GDPR).

Withdrawal: You can withdraw your consent at any time via the cookie banner (accessible from the website footer). You can also adjust your ad preferences directly with Meta: Meta Ad Preferences.

International transfer: Meta Platforms, Inc. is based in the USA. Data transfers are carried out on the basis of the EU-U.S. Data Privacy Framework (DPF), for which Meta is certified.

Legal basis: Art. 6(1)(a) GDPR (consent) for the browser pixel and cookies; Art. 6(1)(f) GDPR (legitimate interest in measuring advertising effectiveness) for the server-side transmission on paid clicks and active user actions.

14. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): You have the right to obtain confirmation as to whether personal data concerning you is being processed, and to access that data.
  • Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate personal data.
  • Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your personal data, subject to statutory retention obligations.
  • Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing under certain circumstances.
  • Right to data portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object (Art. 21 GDPR): You have the right to object to the processing of your personal data based on legitimate interests at any time.

Data export and account deletion: You can request an export of your data or the permanent deletion of your account and all associated data at any time – an informal email to the address below is sufficient.

To exercise any of your rights, you may also contact us at .

15. Withdrawal of Consent

Where we process your data based on consent (Art. 6(1)(a) GDPR), you have the right to withdraw that consent at any time. The withdrawal of consent does not affect the lawfulness of processing carried out based on consent before its withdrawal.

You may withdraw your consent through the following means:

  • Cookie banner: Adjust your cookie preferences at any time by reopening the cookie consent banner.
  • Email: Contact us at to withdraw any consent.

16. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR (Art. 77 GDPR).

A list of supervisory authorities in Germany is available from the Federal Commissioner for Data Protection and Freedom of Information (BfDI): www.bfdi.bund.de

17. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in our data practices, legal requirements, or platform features. In the event of material changes, we will notify registered users by email.

Last updated: March 2026