Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how Brazebee (“Brazebee,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit our website, create an account, or use the Brazebee platform and API (the “Services”).
Brazebee is a customer-health monitoring platform. Businesses (“Customers”) send us customer events so we can calculate health scores and route revenue signals to the people who can act on them. This means we act in two different roles:
- As a data controller for the information we collect about visitors to our website and the account holders who use our Services.
- As a data processor for the customer data our Customers send to us through the API. In that role we process data only on our Customers’ documented instructions, under our Data Processing Agreement.
Information we collect
Account information. When you sign up, we collect your name, work email, company, and the credentials needed to authenticate you, including API keys.
Usage and device data. When you use the website or product, we collect log data, IP address, browser and device information, pages viewed, and actions taken, so we can operate, secure, and improve the Services.
Customer-provided event data. When a Customer integrates the API, they send us event data about their own users and accounts, for example a company identifier, a user identifier, email, name, and an event key such as value_action_completed. We process this data on the Customer’s behalf.
Communications. If you contact us, book a demo, or join a beta, we keep the information you provide, such as your email, company, and role.
How we use information
We use personal information to:
- Provide, maintain, secure, and improve the Services
- Authenticate users and manage API access
- Calculate health scores and generate the signals our Customers ask us to produce
- Respond to requests, provide support, and send service-related messages
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with legal obligations
Legal bases (EEA/UK)
Where the GDPR applies, we rely on the following legal bases: performance of a contract with you, our legitimate interests in operating and improving the Services, your consent where required (for example, non-essential cookies), and compliance with legal obligations.
Data we process on behalf of Customers
For customer-provided event data, the Customer is the controller and Brazebee is the processor. We process this data only to provide the Services, in line with our Data Processing Agreement, and we do not sell it or use it for our own marketing. If you are an individual whose data was sent to us by one of our Customers, please direct privacy requests to that Customer; we will support them in responding.
Sub-processors
We use a limited set of vetted sub-processors to run the Services, such as cloud hosting, infrastructure, and communication providers. We require each to protect personal information under obligations no less protective than those in this Policy, and we maintain a current list available on request.
Sharing and disclosure
We do not sell personal information. We share it only with:
- Sub-processors and service providers acting on our behalf
- A successor entity in connection with a merger, acquisition, or asset sale
- Authorities when required by law, or to protect the rights, safety, and security of Brazebee, our Customers, or the public
International transfers
We may transfer and process information in countries other than your own. Where we do, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
Security
We protect data with encryption in transit and at rest, scoped API keys, access controls, and monitoring. No method of transmission or storage is completely secure, but we work continuously to protect your information. See our Compliance page for more detail.
Data retention
We keep personal information for as long as needed to provide the Services and for legitimate business or legal purposes. Customer-provided event data is retained according to the Customer’s configuration and our agreement with them, and deleted or returned on termination.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of “sharing”, note that we do not sell personal information. To exercise a right, email privacy@brazebee.com. We will not discriminate against you for exercising your rights.
Cookies
Our website uses essential cookies for core functionality such as login and preferences, and, with your consent where required, analytics cookies to understand how the site is used. You can control cookies through your browser settings.
Children
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice.
Contact us
Questions about this Policy or your personal information? Email us at privacy@brazebee.com.
