Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains what data Brim ("the App") collects, how it's used, and your rights regarding that data. Brim is operated by blankSpace, an individual based in California, USA ("we," "us"). This policy applies to merchants who install Brim on their Shopify store.
1. No customer data
Brim only requests the following Shopify OAuth scopes: read_products, read_inventory, write_inventory, and read_locations. We never request access to your customers' or orders' data (read_customers, read_orders, or similar scopes). Brim does not collect or store any shopper/customer personal information — no customer names, emails, addresses, or order details ever pass through the App. This keeps Brim at Shopify's "Protected Customer Data" Level 0.
2. What we collect
a) Merchant/staff account information
When you install Brim, Shopify OAuth provides us your shop domain and basic staff account details for the installing user: user ID, first and last name, email address, locale, and whether the account is an account owner or collaborator. We store an encrypted access token (and refresh token, where applicable) so the App can communicate with your store's Shopify API on your behalf — these tokens are encrypted at rest.
b) Shop and app data
- Product, inventory, and location data synced from your store via Shopify webhooks, so the App can track stock levels;
- Supplier information — names, contact emails, and cost data you enter for your suppliers, used to populate purchase order documents and route notifications;
- Purchase orders and reorder records you create in the App;
- A notification email address you configure in Settings, used only to send you purchase order and reorder alerts — this is always an address you choose, never a customer's;
- Billing state (trial status and dates, subscription ID, billing interval, price, currency, status, and cancellation reason), received via the Shopify Billing API;
- An optional store logo you upload (image files only — SVG uploads are blocked, and files are validated before storage).
c) Logs
We keep webhook and error logs to operate and debug the App. These logs are scrubbed of personal information before storage.
3. How we use your data
We use the data described above solely to operate Brim: syncing inventory, generating purchase orders, sending the notification emails you've configured, and managing your subscription. We do not use your data for advertising, do not run analytics or tracking pixels, do not sell your data, and do not use your data to train AI/ML models.
4. Who we share data with
We share data with the following service providers ("sub-processors") strictly to operate the App:
- Shopify — the platform Brim runs on, and the processor of all billing.
- Supabase — hosts our application database (product, inventory, purchase order, and billing records), on infrastructure providers based in the United States.
- Maileroo — delivers the transactional purchase order/reorder emails you've configured.
We do not share data with ad networks, data brokers, or any other third party, and we do not sell your data.
5. Data retention and deletion
We retain your shop data for as long as the App remains installed on your store. When you uninstall Brim, Shopify notifies us via a mandatory compliance webhook, and all of your shop data is permanently deleted from our systems within 30 days.
Because Brim does not collect customer data, Shopify's customer data-request and customer-redact compliance webhooks are acknowledged automatically — there is no customer data to return or delete.
6. Security
- Shopify access/refresh tokens are encrypted at rest.
- Notification emails are HTML-escaped to prevent injection.
- Uploaded logo images are validated (including SVG rejection) to prevent stored cross-site scripting.
- Personal information is scrubbed from webhook and error logs.
- HTTPS enforcement and network-level rate limiting are provided by our hosting infrastructure.
No system is perfectly secure, and we cannot guarantee absolute security of your data, but we take reasonable measures appropriate to the data we hold.
7. International data transfer
Our infrastructure providers are based in the United States. If you access Brim from outside the United States, your data may be transferred to and processed in the United States.
8. Your rights
You may request access to, correction of, or deletion of the data we hold about your store at any time by contacting us at contact@brims.app. Uninstalling the App also triggers full deletion of your shop data within 30 days, as described above. Depending on your location, you may have additional rights under applicable data protection law (such as the GDPR or CCPA); contact us to exercise them.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
10. Contact
Questions about this Privacy Policy or your data can be sent to contact@brims.app. We're based in California, USA.