B
/Privacy Policy
Updated September 9, 2026
01

Introduction

Brainerce, Inc. ("Brainerce," "we," "us," or "our") operates a headless commerce platform that provides merchants, developers, and businesses ("Merchants") with the infrastructure to build and run online stores, process payments, manage inventory, and leverage AI-powered commerce tools (the "Platform").

This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our Platform, including our web application at brainerce.com, our backend API, our JavaScript SDK, our mobile SDKs, and all related services (collectively, the "Services").

Two roles, two relationships:

RoleWhoGoverning Document
ControllerBrainerce, with respect to data about Merchants and their authorized usersThis Privacy Policy
ProcessorBrainerce, with respect to personal data that Merchants submit about their own end-customersOur Data Processing Agreement

If you are a Merchant's end-customer (i.e., you shopped at a store powered by Brainerce), your personal data is controlled and managed exclusively by that Merchant, not by Brainerce. Brainerce provides infrastructure tools, but we do not have access to, visibility into, or control over the specific end-customer data managed by Merchants within their independent dashboards.

Accordingly, Brainerce cannot process, modify, or delete end-customer data, nor can we forward requests to Merchants. If you wish to exercise any privacy rights, you must contact the Merchant from whom you made the purchase directly.

02

Information We Collect

2.1 Information You Provide Directly (Merchants and Authorized Users)

When you register for or use the Platform as a Merchant or authorized user, we collect:

  • Account Information: Name, business name, email address, phone number, billing address, avatar/profile image, locale and language preference. Authentication and password management are handled by our identity provider (Clerk); we do not store your dashboard password ourselves. Storefront end-customers who register accounts have their passwords stored only as a salted hash, never in plaintext.
  • Team and Collaboration Data: Team member identities, roles (Owner, Manager, Staff, Viewer), and invitations (including the email address of invitees and who invited them).
  • Billing Data: We do not store full card or bank account numbers. Subscription billing is processed by Stripe; we retain only billing references such as your Stripe customer ID, subscription ID, plan, and billing status.
  • Profile and Preferences: Dashboard settings, store configuration, notification preferences, saved filters and views.
  • Payment-Acceptance Credentials: When you connect a payment provider (Stripe Connect, Cardcom, Grow/Meshulam, PayPal, Takbull) to accept payments from your shoppers, we store the resulting access tokens, connected-account identifiers, and configuration. These are encrypted at rest (AES-256-GCM). We never receive or store your shoppers' full card numbers.
  • Migration/Import Credentials: If you import data from another platform (e.g., Shopify, WooCommerce, or a custom API), the credentials you provide (store domain, access token, API keys) are stored encrypted at rest for the duration of the import connection.
  • Communications: Emails, support tickets, contact-form submissions, chat messages, and feedback you send us. We may retain these to provide support, improve our Services, resolve technical disputes, and for legal compliance.
  • Identity Verification: Where identity verification (KYC) is required to accept payments, that process is performed directly by our payment partners (e.g., Stripe, Cardcom, Grow). Brainerce does not collect or store your government-issued identification documents; we store only the verification status reported back to us by the payment partner.

2.2 Information We Collect Automatically (Merchant Dashboard and API)

When you access or interact with the Platform as a Merchant or developer, we and our service providers automatically collect:

  • Log Data: IP address, browser type and version, operating system, referring URL, pages visited, timestamps, HTTP response codes, and user-agent data.
  • Device Information: Device type, identifiers, screen resolution, and hardware model where relevant to rendering, performance optimization, or security.
  • Usage and Telemetry Data: Features accessed, API calls made (endpoint, response time, error codes, and data payload metadata), dashboard interactions, and navigation paths within the admin interface.
  • Authentication and API Security Events: Login attempts (successful and failed), session events, multi-factor authentication events, and API key usage — including the IP address, user agent, and timestamp of key creation, rotation, revocation, and authentication attempts, retained as an audit trail.
  • Cookies and Similar Technologies: See Section 10 below.

2.3 Information from Third Parties

We may receive information about you from:

  • Payment Processors: Transaction status, fraud signals, payout/Connect account status, and verification results from Stripe, PayPal, Cardcom, Grow/Meshulam, and Takbull.
  • Single Sign-On (SSO) / OAuth Providers: If you (or, on Merchant storefronts, a shopper) authenticate via a third-party provider such as Google, Facebook, or GitHub, we receive the profile information authorized by that provider (typically name, email, and profile photo).
  • Integration and Migration Partners: If you connect a third-party platform (e.g., Shopify, WooCommerce) to migrate or sync data, we receive the specific datasets transferred in that operation.
  • Sales Channel Partners: If you connect an external sales channel (e.g., Google Merchant Center / Shopping / YouTube, Meta, TikTok Shop), we exchange product, inventory, and order data with that channel as needed to operate the integration. The processing of this data is also subject to the respective privacy policies and terms of those third-party channels.
  • Public Sources: Publicly available business registries or databases used to verify business information and corporate compliance.

2.4 Merchant-Submitted End-Customer Data (Processor Role)

In providing the Platform's backend infrastructure, Merchants upload, sync, or generate data about their own customers. As a data processor, we store and handle the following categories on Merchants' behalf, strictly in an automated manner:

  • Customer records: names, email addresses, phone numbers, marketing-consent flags, preferred locale, and any custom attributes the Merchant captures.
  • Addresses: shipping and billing addresses (name, company, street, city, region, postal code, country, phone).
  • Carts and checkouts: guest session identifiers, contact details entered at checkout, custom form fields, and abandoned-checkout recovery tokens used to email a shopper a link back to their cart.
  • Orders and order history: line items, totals, status history, notes, and locale.
  • Payment metadata: for saved/tokenized payment methods, only the card brand, last four digits, and expiry (display-only); the underlying payment credential is an encrypted, opaque token held by the payment provider — full card numbers are never stored.
  • Reviews, contact inquiries, and messages submitted by shoppers.
  • Shipment data: origin and destination addresses and customs information, shared with shipping carriers to obtain rates and tracking (see Section 4).
  • Storefront chat conversations: messages and any text/data exchanged between a shopper and the Merchant's AI storefront assistant (see Section 9).

We act strictly as a data processor for this data. Our automated processing is limited to backend storage, hosting, and programmatic API routing. Our use is strictly governed by our Data Processing Agreement (DPA) and the Merchant's instructions. We do not own, access manually, or use end-customer personal data for our own commercial purposes, and we do not use it to train our own independent AI models.

03

How We Use Information

We use the information we collect for the following purposes, relying on the legal bases noted (relevant under GDPR; analogous bases apply under Israeli PPL):

PurposeLegal Basis
Providing, operating, and maintaining the Platform's core backend infrastructurePerformance of contract; Legitimate interests
Account creation, multi-factor authentication, security logging, and API credential managementPerformance of contract; Legal obligation
Processing subscription payments, invoicing, tax compliance, and financial reportingPerformance of contract; Legal obligation
Enabling Merchants to programmatically accept payments, fulfill orders, and integrate with shipping/logistics carriersPerformance of contract (with the Merchant); Processor instructions
Operating backend AI features and processing contextual store operations that the Merchant chooses to deployPerformance of contract; Legitimate interests
Sending critical transactional communications, operational alerts, service downtime notices, and API deprecation updatesPerformance of contract
Sending product updates, newsletters, and feature announcementsLegitimate interests; Consent where required by local law (e.g., Israeli Spam Law)
Preventing fraud, platform abuse, runaway spend, cyberattacks (such as SQL injections or DDoS), and unauthorized API accessLegitimate interests; Legal obligation
Debugging, network performance monitoring, API telemetry analysis, and database capacity planningLegitimate interests
Training, benchmarking, and improving our internal AI features using strictly aggregated, anonymized, and de-identified technical usage metadata (excluding any raw personal data or end-customer chat contents)Legitimate interests
Complying with legal obligations, court orders, and law enforcement or regulatory financial requestsLegal obligation
Enforcing our Terms of Service, protecting our intellectual property, and resolving business disputesLegitimate interests
Internal analytics, telemetry trend analysis, and business intelligence (fully aggregated and anonymized)Legitimate interests

We do not sell your personal information or the personal data of your end-customers. We do not use personal information for fully automated decision-making that produces legal or similarly significant effects on you, except for automated security or fraud-screening mechanisms designed to protect the Platform. AI Agent actions that modify a Merchant's store configurations are subject to that Merchant's review, configuration, and approval within their dashboard (see Section 9). If your account is restricted by an automated security check, you have the right to request a human review by contacting us at [email protected].

04

How We Share Information

We do not sell, rent, or trade personal information. We share information only as follows:

4.1 Service Providers and Sub-Processors

We engage vetted third-party vendors and sub-processors to operate, secure, and support the Platform. Our current sub-processors are:

CategoryProviderPurposePersonal Data Involved
Object StorageCloudflare R2Storing product images, media, generated assets, and secure data backups/exportsFiles; export archives may contain Merchant and end-customer personal data
Database & InfrastructureSelf-hosted PostgreSQL, MongoDB (event logs), and Redis on cloud infrastructure orchestrated via CoolifyPrimary data storage, system event logging, caching, and background job queuesAll categories described in Section 2
Content Delivery / DNSCloudflareContent delivery network (CDN), caching, network protection, and DDoS mitigationIP addresses, request metadata, and user-agent string
Payment BillingStripeProcessing Platform subscription billing and invoicing for MerchantsMerchant account and billing identifiers
Payment Acceptance (Merchant Payouts)Stripe Connect, PayPal, Cardcom, Grow/Meshulam, TakbullAPI routing and orchestration for processing shopper payments to MerchantsEncrypted transaction metadata and payout credentials
Email DeliveryAmazon Web Services (Amazon SES)Dispatching transactional emails, system alerts, and system notificationsRecipient email addresses and message content
Shipping & LogisticsEasyPostFetching carrier rates, generating shipping labels, and tracking fulfillmentShipper and recipient names, physical addresses, and customs declarations
AI / LLM ServicesOpenAIPowering the AI Agent, storefront chat assistant, and contextual text/image generation toolsProgrammatic prompts and anonymized store context (see Section 9)
Authentication & IdentityClerkUser identity management, secure session token verification, and multi-factor authentication for Merchant accountsName, email address, profile metadata, and session tokens

We may engage additional or replacement sub-processors as the Platform evolves (for example, additional LLM providers such as Anthropic). Where required by our Data Processing Agreement (DPA), we will provide notice of new sub-processors or changes to this list. All sub-processors are contractually bound by data processing agreements that restrict their use of data strictly to providing services to us and require them to maintain equivalent security standards.

4.2 Payment Processors

When a Merchant processes a shopper transaction through the Platform, relevant transaction data is shared directly with the applicable payment processor (Stripe, PayPal, Cardcom, Grow/Meshulam, or Takbull) via our integrated API routes. Each processor's data practices are governed by its own respective privacy policy and terms. Brainerce stores only tokenized references and display metadata (card brand, last four digits, expiry) — full payment card numbers are never processed or stored on our infrastructure.

4.3 Shipping Carriers

To provide real-time shipping rates, printable labels, and shipment tracking, order origin/destination addresses and any legally required customs information are shared with our shipping aggregation provider (EasyPost) and the specific fulfillment carriers it connects to (e.g., UPS, FedEx, DHL, Israel Post).

4.4 External Sales Channels (Merchant-Initiated)

Where a Merchant connects and enables an external sales channel (e.g., Google Merchant Center / Shopping / YouTube, Meta, TikTok Shop), product, inventory, pricing, and order data necessary to operate that channel are automatically exchanged with the relevant platform. Once data is transmitted to an external channel, its processing is subject to that platform's terms and privacy policies. These integrations are disabled by default and are only active upon explicit configuration by the Merchant.

4.5 Migration and Import (Merchant-Initiated)

When a Merchant imports data from another ecommerce platform (Shopify, WooCommerce, or a custom API), data flows from the source platform into Brainerce at the Merchant's direction. The Brainerce migration tool operates via read-only access with respect to the source environment. Merchants are responsible for ensuring they have the legal right to migrate such data.

4.6 Business Transfers

In connection with any merger, acquisition, asset sale, financing, corporate restructuring, or reorganization, user and Merchant information may be transferred to the acquiring or successor entity, subject to strict confidentiality obligations. We will provide notice before your personal information is transferred or becomes subject to a materially different privacy policy.

4.7 Legal Disclosures and Law Enforcement

We may disclose information if we believe in good faith that doing so is necessary to: (a) comply with applicable law, regulation, subpoena, court order, or legal process; (b) protect the personal safety of any person; (c) protect Brainerce's intellectual property, legal rights, and platform security; or (d) respond to a verified government or regulatory request. Where legally permitted, we will attempt to notify the Merchant before disclosing their data.

4.8 With Your Consent

We may share information with third parties when you have provided us with explicit consent to do so.

4.9 Aggregated or De-identified Data

We may share fully aggregated, anonymized, and de-identified data (e.g., industry benchmark reports, platform uptime statistics, or macro-level usage trends) that cannot reasonably be used to identify any individual or specific Merchant.

4.10 ChatGPT and Other AI-Assistant Connectors (Merchant-Initiated)

A Merchant may choose to connect their Brainerce store to a third-party AI assistant platform (such as OpenAI's ChatGPT) via our Model Context Protocol (MCP) connector, so that the Merchant can manage their store through natural-language conversation instead of the dashboard. This is a distinct relationship from Section 9's discussion of Brainerce's own AI Agent — here, the AI assistant platform is the client calling into Brainerce's infrastructure on the Merchant's explicit instruction, not a sub-processor Brainerce itself engages.

  • Connection is opt-in and store-scoped: The connector is inactive until the Merchant explicitly authorizes it. Authorization is bound to exactly one store; the resulting credential cannot be used to access any other Merchant's data.
  • Data received from the AI assistant: When the Merchant asks the assistant to perform an action (e.g., "show my pending orders" or "update this product's price"), the assistant platform sends us the corresponding tool-call parameters (the specific action requested and its arguments) over an authenticated connection. We do not receive the Merchant's full conversation transcript or any messages beyond what is needed to execute the requested action.
  • Data returned to the AI assistant: We return the store data necessary to fulfill that specific request — for example, product, order, inventory, or aggregate analytics data — which the assistant platform then uses to compose its response to the Merchant. We apply data minimization to these responses (e.g., paginated list views return summarized fields; full detail is returned only for single-record lookups), and every response is scoped strictly to the one store the credential is bound to.
  • No end-customer-initiated processing: This connector is for Merchant back-office store management only. It is separate from, and does not affect, the customer-facing storefront chat assistant described in Section 9.3.
  • Retention: Request-level metadata (timestamp, the tool invoked, IP address, and authentication outcome) is retained as part of our standard API Security and Audit Logs (see Section 5), for the same retention period. We do not separately store the substantive content of each request/response beyond what is needed to service it, and we do not retain the assistant platform's conversation history — that remains with the AI assistant platform, governed by its own privacy policy.
  • Disconnecting: A Merchant may revoke this connection at any time from their Brainerce dashboard (which immediately invalidates the underlying access credential) or from the AI assistant platform's own connector/integration settings.
  • Third-party governance: Once data reaches the AI assistant platform, its handling of that data (including any use for improving that platform's own models) is governed by that platform's privacy policy and terms, not this Policy — consistent with Section 12's treatment of independent third-party services.
05

Data Retention

We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as permitted or required by applicable financial, tax, and data protection laws. Our retention frameworks are structured as follows:

Data CategoryRetention PeriodLegal / Operational Basis
Active Account & Profile DataDuration of active subscription + up to 90 days post-terminationAccount restoration grace period and platform migration support
Billing, Invoicing & Financial Records7 years from the end of the applicable tax yearStatutory tax, accounting, and anti-money laundering (AML) obligations
Security, Telemetry & API Audit LogsUp to 12 months, unless required longer for an ongoing investigationFraud prevention, platform security audit trail, and system stability
Support & Technical CommunicationsUp to 3 years from ticket closureDispute resolution, quality assurance, and technical continuity
Marketing Consent RecordsRetained until explicit unsubscribe or consent revocationCompliance with direct marketing and spam laws
AI Prompt History & Interaction LogsDuration of active subscription, or until a verified deletion requestService continuity, contextual AI memory, and accurate billing calculation
Database Backups & Snapshot ArchivesUp to 30 days from creation (rolling basis)Disaster recovery, business continuity, and system resilience
Merchant End-Customer Data (Processor)Governed strictly by the DPA; deleted or anonymized upon Merchant instruction or within 30 days of contract terminationCompliance with Processor-Controller obligations

5.2 Deletion Process and System Hardening

When personal data is no longer required under the periods listed above, or upon a verified and legally valid deletion request, Brainerce will either permanently delete, overwrite, or irreversibly anonymize the data so that it can no longer be associated with any identifiable individual.

Please note that for technical and data integrity purposes, data contained within scheduled disaster-recovery backups may persist until those specific backup files are naturally overwritten on our rolling 30-day cycle. Until fully automated system purging is executed across all legacy microservices, Brainerce utilizes a combination of automated tasks and verified manual data-clearing protocols to ensure compliance with these timelines.

06

Specific Provisions under Israeli Law (Privacy Protection Law, 5741-1981)

This section applies strictly to Merchants, authorized users, or data subjects operating within or subject to the jurisdiction of the State of Israel, in accordance with the Israeli Privacy Protection Law (PPL), 5741-1981, including Amendment No. 13.

  • No Legal Obligation to Provide Data: You hereby acknowledge and agree that you are under no legal obligation to provide us with any personal information. Any information provided by you during account creation, API configuration, or dashboard utilization is done so entirely of your own free will and with your full consent.
  • Database Registration and Use: Personal data collected under this Policy will be stored in Brainerce's databases, maintained and secured in accordance with the Israeli Privacy Protection Regulations (Data Security), 5757-2017. The data will be utilized strictly for the commercial and operational purposes specified in Section 3 of this Policy.
  • Direct Marketing (Section 17C of the PPL): If you register an account, we may utilize your contact details to send you service communications (incidents, security, billing, and breaking changes) , product communications (new or changed functionality within the Services you already subscribe to, containing no offer or solicitation to purchase), and marketing communications. Marketing communications, meaning promotional offers and solicitations to purchase additional or upgraded services, are sent to you as an existing customer in relation to services of the same kind, and you may opt out of them at any time from any such message or from your account settings. These categories, and the separate opt-outs that apply to each, are set out in Section 10.4 of the Terms of Service. You hold the absolute right under Israeli law to request the removal of your information from our direct marketing mailing lists at any time by executing the "unsubscribe" link within our communications or by emailing us at [email protected].
  • Data Breach Notification: In the event of a severe data security breach affecting personal information held in our primary databases, Brainerce will fulfill its mandatory legal reporting obligations to the Israeli Privacy Protection Authority and, where required by law, to the affected data subjects, within the statutory timeframes required under applicable law.
07

Your Privacy Rights

7.1 Rights for All Users (Merchants and Authorized Users)

Regardless of your location, as a Merchant or an authorized platform user, you may exercise the following rights regarding your personal data controlled by Brainerce:

  • Access: Request a copy of the personal information we hold about you within our systems.
  • Correction: Request that we correct inaccurate, outdated, or incomplete data.
  • Deletion: Request deletion of your personal information, subject to our legal financial retention obligations, security audit trails, and technical backup cycles.
  • Data Portability: Request a transfer of your technical account data in a structured, commonly used, and machine-readable format.
  • Objection / Restriction: Object to or ask us to restrict specific processing activities, such as direct marketing communications.

To exercise any of these rights, email [email protected]. We will verify your identity before processing any request. We will not charge a fee unless your request is manifestly unfounded, repetitive, or excessive.

Crucial Notice for End-Customers (Shoppers): Brainerce acts strictly as a data processor for any data related to a Merchant's end-customers or storefront chat interactions. We do not possess the legal authority or technical capability to process, delete, or modify individual shopper data independently. If you are an end-customer, you must direct your request exclusively to the relevant Merchant who controls your data. If you contact us directly, we will decline the request and instruct you to contact the Merchant.

7.2 Rights Under Israeli Privacy Protection Law (PPL, 5741-1981)

If you are located in Israel, or if your data is governed by the PPL, you hold the following statutory rights:

  • Right to Inspect (Section 13 PPL): The right to inspect any personal data held about you in our databases.
  • Right to Amend/Delete (Section 14 PPL): The right to request the correction or deletion of data that is inaccurate, incomplete, or outdated. If we deny a request, you have the right to appeal to the competent Magistrates' Court in accordance with applicable regulations.
  • Response Timelines: In compliance with Israeli law, we will respond to a valid inspection or amendment request within 30 days of receipt, unless an extension is legally permitted.
  • Objection to Direct Marketing: You may object at any time to the use of your data for direct marketing purposes, and we will remove your records from such lists immediately upon request.

7.3 Rights Under GDPR (EEA and UK Residents)

This section applies strictly to data subjects residing within the European Economic Area (EEA) or the United Kingdom (UK) where Brainerce's processing of their personal data falls within the scope of the EU/UK GDPR.

  • Platform Scope and Targeting Disclaimer: Brainerce provides generic, global business-to-business (B2B) cloud infrastructure tools. The Services are not actively targeted, tailored, or marketed to individuals or local commercial entities within specific European Union member states or the United Kingdom.
  • Access, Correction, and Portability: You hold the legal right to request access to your personal account data, demand corrections to inaccurate records, or obtain your structural dataset in a machine-readable format.
  • Withdraw Consent: Where specific data processing is built upon your explicit consent, you retain the absolute right to withdraw such consent at any time, without affecting the lawfulness of processing executed prior to the withdrawal.
  • Lodge a Complaint: You hold the right to file an administrative complaint regarding our data handling with your local National Data Protection Supervisory Authority (such as the CNIL in France, DPC in Ireland, or the ICO in the United Kingdom).
  • Response Timelines: We will evaluate and respond to verified GDPR requests within one calendar month of receipt. This window may be extended by up to two additional months for structurally complex inquiries, subject to providing you with timely operational notice.

7.4 Rights Under CCPA / CPRA (California Residents)

California residents possess specific rights regarding their personal information:

  • Right to Know: Request access to the specific pieces and categories of personal information we have collected, used, and disclosed over the preceding 12 months.
  • Right to Delete & Correct: Request deletion or correction of personal information, subject to statutory business exemptions (e.g., complete transaction execution, security tracking).
  • No Sale or Sharing: Brainerce does not sell personal information, and does not share personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you (e.g., by denying service or altering pricing) for exercising your privacy rights.
  • Shine the Light: We do not disclose personal data to third parties for their own independent direct marketing purposes.
08

International Data Transfers

Brainerce, Inc. is incorporated in the United States and operates principally from the State of Israel. Our technical infrastructure, cloud environments, and service providers operate in various jurisdictions globally. Consequently, personal information controlled or processed by Brainerce may be transferred to, stored, and processed in Israel, the United States, the European Economic Area (EEA), and other jurisdictions where our sub-processors maintain facilities.

8.1 For Users and Data Subject to Israeli Law

Transfers of personal information outside the borders of the State of Israel are executed strictly in accordance with the Israeli Privacy Protection Regulations (Transfer of Data Abroad), 5761-2001. Brainerce ensures that any cross-border transfer of data is legally justified, relying on:

  • The destination country providing a level of data protection that is not lesser than the protection provided under Israeli law;
  • Legal adequacy decisions between jurisdictions (including Israel's adequacy status with the EEA); and
  • Strict contractual obligations executed with our corporate sub-processors ensuring equivalent security and privacy standards.

8.2 For EEA and UK Users

For personal data transferred out of the EEA or the United Kingdom to jurisdictions that have not been granted an adequacy decision by the European Commission, Brainerce implements appropriate safeguards to ensure compliance with the GDPR. These safeguards include:

  • Executing the European Commission's Standard Contractual Clauses (SCCs) embedded within our contracts;
  • Executing the UK International Data Transfer Addendum where applicable; and
  • Verifying that our cloud providers (such as Stripe and Cloudflare) utilize approved transfer frameworks.

You may request further information regarding our specific transfer mechanisms by contacting us at [email protected].

8.3 Merchant-Configured Infrastructure Disclaimer

Where a Merchant utilizes our decentralized APIs or deployment tools (including third-party cloud integrations orchestrated via Coolify) to self-host data environments or route customer payloads to specific geographic regions, the Merchant is solely and exclusively responsible for ensuring that such geographic configurations and cross-border transfers comply with all applicable local data protection and sovereignty laws.

09

AI Features and Automated Processing

The Platform includes AI-powered features designed to assist Merchants in store management and to optimize the end-customer experience. We are committed to transparency regarding how these features operate and how data is processed.

9.1 Providers, Models, and Training Restrictions

Our AI features are primarily powered by third-party large language models (LLMs) and generative tools provided by OpenAI (including GPT-class models for reasoning and text processing, and image-generation models). We may integrate additional vetted AI providers (such as Anthropic) as the Platform evolves.

All integrations are strictly inference-only. Brainerce contractually restricts and does not permit its third-party AI providers to utilize Merchant data or End-Customer personal data to train their public or foundational models. Furthermore, Brainerce does not utilize raw personal data to train or fine-tune its own independent models. We may use strictly aggregated, fully anonymized, and de-identified platform telemetry and structural usage metadata to optimize our programmatic features and evaluate server resource distribution.

9.2 Merchant AI Agent

The Brainerce AI Agent assists Merchants with back-office operations. To execute programmatic actions (e.g., draft product configurations, calculate discount models, or analyze inventory statistics), necessary store context and the Merchant's operational instructions are securely transmitted to the AI provider via encrypted API routes.

Critical Operations Disclaimer: The AI Agent operates under a strict "human-in-the-loop" framework. Any generative action that modifies a Merchant's database, financial settings, live storefront configurations, or pricing models is presented as a proposal within the dashboard and explicitly requires manual Merchant review and approval before execution. Brainerce is not responsible for any financial loss, operational disruptions, or pricing discrepancies resulting from AI-generated suggestions approved by the Merchant. All executions are logged within an immutable dashboard audit trail for security and metering purposes.

9.3 Customer-Facing Storefront Assistant

Merchants may choose to deploy an automated AI storefront chat assistant to interact directly with shoppers. When an end-customer utilizes this chat assistant, the text inputs provided by the customer and relevant public product catalog data are transmitted to the AI provider to generate natural language responses.

  • Data Minimization: No transactional payment data, full customer accounts, plain-text credentials, or sensitive personal fields are ever routed to the AI models.
  • Regulatory Disclosure & AI Disclaimers: Brainerce acts strictly as a data processor for these chat logs under the DPA. Merchants are solely responsible for ensuring that their storefront deployment complies with applicable regulations (such as the EU AI Act and Israeli privacy guidelines), including providing clear notice to shoppers that they are interacting with an automated system. Brainerce disclaims all liability for "hallucinations," inaccurate product descriptions, or offensive outputs generated by the AI assistant. The Merchant retains full capability to audit, monitor, and disable the storefront chat at their sole discretion.

9.4 Other Generative AI Features

The Platform provides specialized utility features, including automated product description drafting, SEO optimization tools, marketing copy generation, and product image rendering. These tools process only the specific merchant-provided assets or textual prompts. AI computational consumption is metered via platform "AI credits" and logged for transparent subscription billing and technical auditing.

9.5 No Sensitive Automated Decision-Making

Brainerce does not utilize AI or automated processing to execute fully automated decision-making processes that yield legal, financial, or similarly significant effects on individuals (such as creditworthiness evaluation, employment screening, or legal compliance determinations).

10

Cookies and Tracking Technologies

10.1 Cookies on the Brainerce Dashboard and Website

We and our third-party service providers utilization cookies, web beacons, pixels, and local storage objects to operate our public marketing website and the authenticated Merchant dashboard interface.

Cookie CategoryOperational PurposeCan You Opt Out?
Essential / Strictly NecessaryAccount authentication (via Clerk), Cross-Site Request Forgery (CSRF) protection, system security, and session management.No. Required for the structural security and execution of the Service.
FunctionalRetaining interface language preferences, dashboard layout configurations, and saved database filters.No. Required to maintain basic account usability.
Analytics & PerformanceCollecting aggregate usage statistics, platform feature adoption rates, API execution metrics, and frontend error tracking.Yes. Via browser configuration adjustments or integrated preference controls.
Marketing & AdvertisingDeployed strictly on the public brainerce.com marketing website to evaluate promotional campaigns; never deployed within the authenticated Merchant admin dashboard.Yes. Via cookie banners or privacy settings.

Disabling essential cookies within your browser environment will impair or fully break your technical ability to access or utilize the Service safely.

10.2 Privacy-Forward Storefront Analytics

For analytical event tracking executed on independent Merchant storefronts, Brainerce utilizes a cookieless, privacy-first infrastructure design. We generate unique storefront session signals derived programmatically from a daily-rotating, cryptographic salted hash, and immediately discard the raw visitor IP address after deriving coarse, non-identifiable geolocation (country or region).

Consequently, individual storefront visitors are not tracked across different days, and no persistent, personally identifiable visitor profiles are compiled or stored on Brainerce servers. Merchants are presented strictly with aggregated, macro-level traffic trends.

10.3 SDK and Client-Side Storage on Merchant Storefronts

The Brainerce JavaScript and server SDKs embedded within Merchant storefronts may set short-lived session identifiers, abandoned cart tokens, or local storage objects on the shopper's device solely on behalf of, and under the instruction of, the Merchant operating that storefront.

  • Controller Status: For all cookies or local storage scripts deployed by our SDKs on user-facing storefronts, the Merchant is the exclusive Data Controller, and Brainerce acts strictly as a technical Data Processor.
  • Merchant Compliance Obligation: Merchants are solely and exclusively responsible for implementing compliant cookie consent banners, managing user opt-out mechanisms, and maintaining legally accurate disclosure notices on their respective storefronts in accordance with applicable local ePrivacy, GDPR, and consumer protection laws. Brainerce disclaims all liability regarding a Merchant's failure to notify or obtain consent from shoppers for SDK-related tracking technologies.
11

Children's Privacy

11.1 Platform Target Audience (Controller Role)

The Platform and Services provided directly by Brainerce are strictly commercial business-to-business (B2B) infrastructure tools directed exclusively to corporate entities, merchants, and adults. Brainerce does not knowingly or intentionally market to, target, or collect personal information directly from children under the age of 16 (or the applicable minimum legal age within your jurisdiction). If you are a parent or legal guardian and believe that we have inadvertently collected personal information from an authorized account user who is a minor, please contact us immediately at [email protected], and we will execute procedures to permanently delete such data from our systems.

11.2 Merchant Compliance Obligations (Processor Role)

As a decentralized backend infrastructure provider, Brainerce acts strictly as a data processor for the data routed into our databases by Merchants.

  • Strict Prohibition: Merchants are strictly prohibited from utilizing the Platform, our APIs, or our SDKs to intentionally collect, store, or process sensitive personal data of children under the age of 16 (or the legal age defined by local jurisdiction, including COPPA standards in the US, GDPR rules in the EU, and the Israeli Privacy Protection Law regulations regarding minors) without obtaining fully compliant, verified parental or legal guardian consent.
  • Indemnification and Liability Disclaimer: The Merchant bears sole, ultimate, and exclusive legal responsibility for ensuring that their storefront, marketing funnels, and data ingestion mechanisms fully comply with all applicable children's online privacy frameworks. Brainerce does not monitor the product catalog configurations or user demographic structures of individual Merchant accounts, and disclaims all liability resulting from a Merchant's unauthorized processing of minors' personal information on our infrastructure.
12

Third-Party Links, Integrations, and Marketplace Applications

12.1 Independent Third-Party Services

The Platform contains programmatic integrations, API endpoints, and links to third-party websites and independent service providers—including but not limited to payment gateways, fraud screening utilities, shipping and logistics carriers, external sales channels, and marketing platforms.

These third parties operate entirely independently from Brainerce. Their data collection, processing operations, and privacy frameworks are governed exclusively by their own respective privacy policies and corporate terms of service. Brainerce does not monitor, review, or control the data processing activities of these external entities, and disclaims all legal and financial liability regarding how they handle personal information once transmitted.

12.2 Third-Party Developer Marketplace Applications

Merchants may choose to install, connect, or execute marketplace applications, extensions, or custom integrations built by third-party developers ("Third-Party Apps") within their Platform dashboard or via our public APIs.

  • Data Access Authorization: When a Merchant installs or authorizes a Third-Party App, the Merchant explicitly instructs and authorizes Brainerce to open API access and transfer specific datasets (which may include Merchant account details or raw end-customer transactional data) to that third-party developer's external servers.
  • Merchant Responsibility and Indemnification: Brainerce acts strictly as a technical routing conduit for these merchant-initiated data transfers. We do not vet the code security or verify the privacy compliance of independent third-party developers. The Merchant assumes all operational, legal, and financial risks associated with granting Third-Party Apps access to their store's backend environment. Brainerce disclaims any and all liability for data breaches, corruption, unauthorized deletions, or financial losses resulting from the utilization of Third-Party Apps.

12.3 Google API Services User Data Policy

Brainerce's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When a Merchant connects a Google account (Google Merchant Center, Google Ads, Google Analytics, YouTube, Search Console, or Google Business Profile), Brainerce requests only the specific OAuth permission ('scope') each connected feature needs, one at a time, rather than every permission upfront. The resulting Google account data (e.g., product listing status, ad account identifiers, analytics properties, YouTube channel eligibility) is used exclusively to operate that Merchant-initiated integration—to publish products, report performance, and configure the connected service—and is never used to serve advertising, never sold, and never shared with any third party except as strictly necessary to provide the integration itself (i.e., transmitting the Merchant's own data back to that same Google service on the Merchant's instruction) or to comply with a legal obligation.

A Merchant may revoke Brainerce’s access to their Google account at any time from the Platform dashboard or directly at myaccount.google.com/permissions.

For a plain-language explanation of exactly what each Google connection does and why, see Brainerce's Google Integration.

13

Changes to This Privacy Policy

We reserve the right to review, modify, or update this Privacy Policy at our sole discretion from time to time to reflect modifications in our backend architecture, shifting legal requirements, or evolving regulatory frameworks.

When we execute material revisions to this Policy, we will deploy the following notification procedures prior to the changes taking institutional effect:

  • We will update the "Last Updated" timestamp listed at the vertex of this document.
  • We will dispatch a proactive administrative notification directly to the registered Merchant account email address or render a mandatory procedural broadcast notice within the authenticated admin dashboard.
  • Where explicitly mandated by applicable data sovereignty laws (including the Israeli Privacy Protection Law and the GDPR), we will request your affirmative, explicit consent for specific adjustments regarding novel data ingestion methods.

13.2 Non-Material Changes and Acceptance

For minor, non-material administrative changes (such as grammatical corrections, updates to our corporate sub-processor list in Section 4, or contact configuration updates), your continued interaction with or utilization of the Platform's APIs, dashboard, or SDKs following the designated effective date constitutes your structural acknowledgment and acceptance of the revised terms.

13.3 Non-Agreement Resolution

If you do not agree with the updated terms or parameters of a revised Privacy Policy, you must cease all operational utilization of our APIs, sever your storefront SDK connections, and terminate your account subscription prior to the effective date of the revisions.

14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, our data processing architecture, or your privacy rights, you may contact our dedicated compliance channels:

14.1 Corporate Identity and Data Controller

Mailing Addresses:

  • Principal Operational Headquarters (Israel): Brainerce, Inc., 5 Bartenura Street, Bnei Brak, 5150529, Israel.
  • US Registered Office (Delaware): Brainerce, Inc., 1209 North Orange Street, Wilmington, DE 19801, United States.

14.2 Privacy and Data Protection Office

For exercising user rights (Access, Correction, Deletion) or querying our Data Processing Agreement (DPA):

14.3 Security and Incident Reporting

To report system vulnerabilities, security anomalies, data exposure events, or potential breaches: