Privacy Policy
This Privacy Policy describes how Bringits ("we", "us"), a company organized under the laws of the State of Israel, processes personal data when you visit bringits.com, register for an account, or use the Bringits platform (the "Service"). It applies to processing for which Bringits is the controller.
For personal data that you submit to the Service or instruct the Service to process on your behalf (for example, content collected by the Service in response to your API requests), Bringits acts as your processor. That processing is governed by the Bringits Data Processing Addendum ("DPA"), incorporated by reference into the Terms of Service; this Privacy Policy does not describe it.
1. Personal data we collect
1.1 Account data
When you register for the Service, we collect:
- Email address — primary contact and login identifier.
- Company or team name — used as your tenant display name.
- Use-case selection — chosen from a fixed dropdown (e.g. e-commerce pricing, market research, SEO/SERP, ad verification, sports data, other) for product analytics and abuse prevention.
- Consent metadata — the version of the Terms of Service, AUP, and Privacy Policy you accepted, and the timestamp of acceptance.
- Authentication factors — password hash, optional TOTP secret, social-login identifiers (Google or GitHub) if you use single sign-on. Authentication is handled by our authentication provider.
1.2 Usage and operational data
While you use the Service, we automatically collect:
- Request metadata — tenant identifier, API token identifier (not the secret), timestamp, target hostname, response status code, request size, response size, geographic region.
- Dashboard activity — pages viewed, features used, errors encountered.
- Network identifiers — IP address, user agent, country derived from IP, for security and rate-limiting purposes.
- Server logs — diagnostic logs from our internal services for operational and security purposes.
We do not retain the content of API requests or responses beyond the time necessary to deliver them. Operational metadata (tenant ID, hostname, status, byte counts) is retained for billing, quota enforcement, and abuse investigation.
1.3 Billing data
Paid subscriptions are billed by Bringits. When you subscribe, payment instrument, billing address, and tax-residency information are collected at checkout. Bringits receives limited billing identifiers (subscription ID, transaction ID, plan tier, last-four card digits, billing country) — never the full card number, CVV, or bank account number.
1.4 Marketing data
When we enable our customer-relationship and product-analytics integrations, we may additionally process: lifecycle stage (Lead → Customer), email engagement (open/click on transactional and product emails you have not opted out of), in-product event data (signup, first API call, tier upgrade) for the purpose of measuring product activation and offering relevant assistance. These integrations are optional from your side: you can unsubscribe from non-transactional email at any time, and we will still deliver service-critical messages (billing, security, policy changes).
1.5 Cookies and similar technologies
On the public website (bringits.com) and the in-product dashboard, we set:
- Preference cookies — remember UI choices like theme.
- Analytics cookies (Phase 2 onwards) — first-party product analytics measured via Mixpanel, with IP-anonymisation applied.
We do not currently use third-party advertising or cross-site tracking cookies. A cookie banner is presented on first visit from EU/UK/Israel jurisdictions where legally required.
2. Retention
| Category | Retention |
|---|---|
| Account data | Lifetime of account, plus 90 days after deletion (for reactivation), then permanently deleted or anonymised. |
| Operational logs (request metadata) | 90 days rolling. After 90 days, only aggregated, non-identifying counts are retained. |
| Billing records | 7 years from the end of the relevant tax year, in line with Israeli and counterparty tax-record obligations. |
| Abuse-investigation records | 2 years from case closure. |
| Diagnostic application logs | 30 days rolling in Datadog. |
| Marketing engagement (Phase 2) | 3 years from last engagement, then deleted. |
3. Your rights
Depending on where you are located, you have some or all of the following rights in respect of personal data we hold about you as a controller:
- Access — confirm whether we process personal data about you and obtain a copy.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion, subject to retention obligations in Section 2 and our legitimate basis for continued processing.
- Restriction — limit processing in defined circumstances.
- Objection — object to processing based on our legitimate interests; we will weigh your objection against those interests.
- Portability — receive a structured, machine-readable copy of data you have provided.
- Withdraw consent — for any processing based on consent, without affecting prior lawful processing.
- Complaint — lodge a complaint with your local data-protection authority. EU residents may complain to their national supervisory authority; UK residents to the ICO; Israeli residents to the Privacy Protection Authority.
To exercise any of these rights, email privacy@bringits.com from the email address associated with your account, or use the in-product data-export and delete-account controls (available in the dashboard account-settings page once that surface ships in P2). We respond within thirty (30) days; complex requests may take up to ninety (90) days, in which case we will tell you within the first thirty.
We may need to verify your identity before responding (typically by confirming control of the account email). For requests directed at personal data we process as a processor on behalf of a customer, we will refer you to that customer, who is the controller for that data.
4. Security
We maintain administrative, technical, and organizational safeguards appropriate to the sensitivity of the data we process, including: encryption in transit (TLS 1.2+) and at rest, role-based access control with audit logging, principle-of-least-privilege for production access, regular vulnerability scanning, and an incident-response process aligned with industry practice. No internet-facing system is perfectly secure, and we do not warrant that our safeguards will defeat every attack.
If you believe you have discovered a security vulnerability in the Service, please report it to security@bringits.com. We follow coordinated-disclosure practice and do not pursue legal action against good-faith researchers.
5. Region-specific notices
5.1 California (CCPA / CPRA)
California residents have the rights described in Section 3 plus the right to opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined in the CCPA / CPRA, and we do not use sensitive personal information for purposes other than as permitted under the statute. Categories of personal information we collect are described in Section 1 of this Policy.
5.2 EU / EEA / UK
We process personal data only where we have a lawful basis under applicable data-protection law. Our EU / UK representative for the purposes of GDPR Article 27, where applicable, will be designated by notice once we determine the appointment is required for the volume and nature of EU/UK data we process; until then, you may contact us directly at the addresses in Section 7.
5.3 Israel
We comply with the Protection of Privacy Law, 5741-1981, and the Privacy Protection Regulations (Data Security), 5777-2017. The Service does not currently fall within the registration thresholds for a database under §8 of the Law that would require registration with the Privacy Protection Authority; we re-evaluate this position periodically.
6. Changes to this Policy
We may update this Privacy Policy from time to time. For material changes (new categories of personal data or new purposes outside the original scope), we will notify you by email at least thirty (30) days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the change; if you do not accept, you may close your account under the Terms of Service.
7. Contact us
Bringits
Privacy and data-subject requests:
privacy@bringits.com
Security reports:
security@bringits.com
Abuse reports:
abuse@bringits.com
General legal inquiries:
legal@bringits.com
Postal address and registered company details to be inserted on publication.