1. Who we are
BrickTrace ("BrickTrace", "we", "us") provides software that syncs offline retail transactions from point-of-sale (POS) sources to advertising and marketing platforms such as Meta, TikTok, and Klaviyo, and provides related analytics.
For the personal data of your customers that you bring into the service, you (the merchant) are the data controller and BrickTrace acts as a data processor that handles that data on your behalf and under your instructions. For account and billing data of the people who sign in to BrickTrace, we act as the controller.
2. Information we collect
Account information
When you or a teammate create an account, we collect a name, email address, company name, and a securely hashed password.
Retail transaction data
When you connect a POS source, we retrieve completed transactions. This can include purchase amount and currency, date and time, store identifier, line items (product, SKU, quantity, price), and customer details captured at the register — such as email, phone number, name, and location fields.
Connection credentials
To send conversions on your behalf, we store the access tokens and API keys for the platforms you connect. These are encrypted at rest (see Security).
Usage and technical data
We keep operational logs of sync activity (records received, matched, and sent, and any errors) to run and support the service.
3. How we use information
- To match in-store purchases to advertising conversions and send them to the platforms you connect.
- To provide analytics and reporting, such as return on ad spend, campaign performance, and match rate.
- To operate, secure, maintain, and support the service.
- To communicate with you about your account, security, and service changes.
We do not sell personal data, and we do not use your customers' data for our own advertising or to build cross-merchant profiles.
4. Hashing and data minimization
Before a conversion is sent to any advertising platform, direct identifiers such as email and phone are hashed with SHA-256. Platforms match on the hash; they do not receive raw contact details from us. We send only the fields a platform needs to match a conversion (for example, hashed identifiers, purchase value, and event time), and only to the destinations you have enabled.
5. How we share information
Advertising platforms you connect
When you enable a destination, we transmit conversion data (including hashed identifiers) to that platform so it can attribute and report conversions. Each platform's own terms and privacy policy then govern its use of that data:
- Meta (Conversions API)
- TikTok
- Klaviyo
Data shared with TikTok is used solely to report conversions through TikTok's business APIs for the advertiser account you connect, in accordance with TikTok's business-product terms and developer requirements. We request only the access needed for reporting and event delivery.
Service providers
We use infrastructure providers for hosting, databases, email, and payments. They process data on our behalf under contract and only as needed to run the service.
Legal
We may disclose information if required by law or to protect the rights, safety, and security of BrickTrace, our customers, or the public.
6. Security
- Platform tokens and API keys are encrypted at rest using AES-256-GCM and decrypted only in memory at sync time.
- Data is scoped and isolated per company; tenants cannot access one another's data.
- Data is transmitted over encrypted connections (TLS).
- Passwords are stored only as salted hashes.
7. Data retention
We retain transaction and account data for as long as your account is active and as needed to provide the service. You can disconnect a destination at any time to stop further sharing, and you can request deletion of your account and associated data (see Your rights).
8. Your rights
Depending on your location, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing. Because much of the customer data in BrickTrace is controlled by the merchant, requests from an individual consumer are generally directed to the merchant; we will assist merchants in fulfilling them. To exercise a right or make a request, email support@bricktraceapp.com.
9. Cookies
This website and the app use only essential cookies required to keep you signed in and to operate the service. We do not use third-party advertising cookies on this site.
10. Children
BrickTrace is a business tool and is not directed to children, and we do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
12. Contact
Questions or requests: support@bricktraceapp.com. See also our Terms of Service.
