Privacy Policy

Who we are

Brightstone Metrics. The service runs at brightstone.app. For anything in this policy, including a request to delete your data, write to [email protected].

What we collect

Your account

Your name, email address, password (stored only as a bcrypt hash, never as text we can read), time zone, language and display currency. Billing is handled by Paddle, who act as the merchant of record — your card details go to them and never reach our servers.

Data from Google

When you connect a Google account, you are asked to grant two read-only permissions. We request nothing beyond them and cannot change anything in your Google accounts:

We store the daily totals these return, plus the access and refresh tokens needed to keep fetching them. Tokens are encrypted at rest with your installation's application key. We never receive your Google password.

Data from other advertising networks

If you connect AdsKeeper or a similar network, we store the API key you provide — encrypted — and the same kind of daily revenue figures.

Data from your own websites

The optional WordPress connector posts a count of people on your site right now, and nothing else. It sends no personal data about your visitors, no IP addresses and no identifiers.

Ordinary service records

Server logs with IP address and browser, kept for up to 30 days for security and debugging. A session cookie so you stay signed in. We do not use advertising cookies and we do not track you across other sites.

How Google user data is used

Data obtained through Google APIs is used for one purpose: to show it to you, and to people you have invited to your own account. Specifically, Brightstone Metrics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. That means we do not:

Who else sees it

Nobody, beyond the processors that make the service run: our hosting provider, Paddle for payments, and an email provider for the messages the service sends you. Each sees only what its job requires. We have never sold customer data and the business does not depend on doing so.

We will disclose data if legally compelled to, and where we are allowed to tell you that has happened, we will.

How long it is kept

Daily revenue and traffic figures are kept for as long as your account exists, because a dashboard with no history is not worth much. Disconnect an integration and its tokens are deleted immediately; the figures already gathered stay until you delete the site or the account.

Delete your account and everything belonging to it — sites, integrations, tokens, figures, targets — is removed within 30 days, apart from records we are legally required to keep, such as invoices.

Taking it back

You can revoke our access to your Google data at any time, either from the integrations page in Brightstone Metrics or directly at myaccount.google.com/permissions. Revoking there stops all future access immediately.

Under the GDPR you may also ask for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Email [email protected] and we will answer within 30 days.

Security

Everything travels over HTTPS. Provider credentials and OAuth tokens are encrypted at rest. Passwords are hashed with bcrypt. Access to production is limited to the people who operate the service. No system is perfect, and if a breach ever affects your data we will tell you and the relevant authority without undue delay.

Children

The service is for businesses and is not directed at anyone under 16. We do not knowingly collect their data.

Changes

If this policy changes in a way that affects what we do with your data, we will email you before it takes effect. The date at the top always reflects the current version.