Privacy Policy
Last updated: 3 October 2026
This policy explains what personal data Retail Brands collects when you visit the site or use the service, why, who receives it and what rights you have. It applies to retailbrands.global and the Retail Brands application.
1. Who is responsible for your data
The data controller is the company operating Retail Brands:
- Company: Real Softwares
- Registered office: 78 Avenue des Champs Elysées, 75008 Paris, France
Contact for privacy questions: privacy@retailbrands.global.
2. Data we collect
- Account data: your name, email address, company or brand name, account type (Pro, Teams, Brand) and your password (stored only as a secure hash by our authentication provider). If you sign in with Google, we receive your name and email from Google.
- Subscription and billing data: your plan, seats, trial and subscription status, and Stripe customer and subscription identifiers. Your card number is entered on Stripe’s payment page and is never seen or stored by us. We keep a non-reversible card fingerprint provided by Stripe, solely to apply the rule of one free trial per card.
- Usage data: your watchlist, saved signals, alerts and dashboard preferences, and the invitations and team memberships of your organization.
- Brand claim data: the role, proof of affiliation, message and optional PDF document you submit when you claim a brand, and the result of the verification.
- Messages you send us: contact and lead forms, and replies to our emails.
- Technical data: IP address, browser type and request logs generated when you use the service, kept for security and troubleshooting.
3. Why we use it, and the legal basis
- To create and run your account, provide the service and manage your subscription (performance of the contract).
- To process payments, prevent trial abuse and keep accounting records (contract, legal obligation, and our legitimate interest in preventing fraud).
- To send service emails: account verification, invitations, trial and billing notices, security messages and claim decisions (contract and legitimate interest).
- To verify brand claims, which requires reviewing the information and documents you provide (legitimate interest in protecting brands and customers).
- To secure the service, diagnose errors and prevent abuse (legitimate interest).
- To answer your enquiries (legitimate interest). Marketing emails, such as the Weekly Flash, are sent only with your consent, and you can unsubscribe at any time.
4. Who receives your data
We share data only with service providers that help us operate Retail Brands, under written data-processing terms:
- Supabase: database and authentication (our database is hosted in the European Union, in Ireland).
- Vercel: application hosting and delivery.
- Stripe: payments and subscription billing.
- Resend: sending transactional emails.
- PostHog: product analytics and error reporting (hosted in the United States).
- Cloudflare: bot protection (Turnstile) on the sign-in, sign-up and contact forms.
- Google: sign-in with Google, if you choose to use it.
We do not sell your personal data. Within a Teams or Brand organization, the account owner and administrators can see the members, roles and seats of their organization.
5. Transfers outside the European Economic Area
Some providers, such as Vercel, Stripe, Resend, PostHog and Cloudflare, may process data in the United States. Where that happens, the transfer relies on the European Commission’s standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework.
6. How long we keep it
- Account data: for as long as your account exists, then deleted or anonymised within a reasonable period after closure.
- Billing and accounting records: as required by law (generally up to 10 years).
- Brand claim documents: while the claim is processed and for as long as the claimed brand remains linked to your account.
- Technical logs: a limited period, normally no more than a few months.
7. Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction, portability, and object to processing based on legitimate interest. You can withdraw consent at any time. To exercise a right, email privacy@retailbrands.global. We may ask you to confirm your identity. You also have the right to lodge a complaint with your data-protection authority; in France, the CNIL (cnil.fr).
8. Cookies and similar technologies
Retail Brands uses only what is needed to run the service: authentication cookies that keep you signed in, security cookies, and small items in your browser storage that remember your preferences (such as which news or signals you chose to see). We do not use advertising cookies. If you arrive through a link from one of our sales partners, we set a cookie for up to 180 days to remember the partner so they can be credited if you become a customer; it contains only the partner’s code. We use PostHog (hosted in the United States) to measure how the service is used, for example which pages are visited and where people stop during sign-up or checkout. Visitors who are not signed in are measured without a personal profile; once you have an account, usage events are linked to your account (your name and email) so we can improve the product and support you. We do not record screens or keystrokes, and we do not use this data for advertising. Where the law requires your consent for this measurement, we will ask for it.
9. Security
We use encryption in transit, access controls and separation of private and public data. No system is completely secure; if a breach affects your data, we will notify you and the authorities as the law requires.
10. Who the service is for
Retail Brands is a professional service intended for adults acting in a business capacity. It is not directed at children.
11. Changes to this policy
We may update this policy. The date at the top shows the latest version, and we will notify account holders of material changes.