Effective Privacy Principles
1. Service Operator & Scope
This Privacy Policy describes the policies and practices of Analytics Brain AI ("Platform", "we", "us") regarding the collection, processing, and protection of data from website visitors, account holders, organization members, and integrated third-party platforms.
Analytics Brain AI provides multi-tenant business intelligence for commercial organizations and business entities.
2. Information You Provide
We collect information provided directly by account administrators and organization members, including:
- Account Contact Details: Full name, email address, and account registration credentials.
- Organization & Workspace Information: Business entity name, organization identifiers, and workspace parameters.
- Support Communications: Inquiries, tickets, and feedback submitted to technical or security teams.
- Integration Choices: Resource selections, selected property IDs, and preferred display settings.
3. Authentication & Technical Data
To preserve system integrity, manage secure user sessions, and enforce tenant security boundaries, our infrastructure processes:
- Cryptographic authentication identifiers and session tokens managed via Supabase Auth.
- Short-lived anti-CSRF state verification cookies for Google, Meta, and Shopify OAuth flows.
- Operational server logs, sync status snapshots, and diagnostic trace records.
4. Connected Platform Data
Upon explicit OAuth authorization, Analytics Brain AI connects to external business tools and processes specified data categories:
5. Future Connectors Framework
Our architecture maintains a public platform roadmap for upcoming connectors including TikTok, Snapchat, Microsoft Ads, LinkedIn Ads, Amazon, WooCommerce, Stripe, and Klaviyo.
We explicitly affirm that roadmap platforms are not accessed until fully implemented, documented, and authorized via individual user consent.
6. Purposes of Data Processing
We process collected and synchronized data strictly for the following purposes:
- Authenticating user access, validating organization membership, and managing secure user sessions.
- Executing scheduled background syncs to fetch and normalize sales and advertising metrics.
- Populating unified analytics dashboards, channel comparisons, and metric breakdowns.
- Powering AI advisor modules to generate budget optimization recommendations and diagnostic alerts.
- Complying with applicable legal obligations, audit requirements, and infrastructure security.
7. Google API User Data & Limited Use Disclosure
Google API Limited Use Compliance
Specific Disclosures Regarding Google API Data:
- Explicit Authorization: Google data is accessed only after the user explicitly grants OAuth 2.0 authorization for specified scopes.
- User-Facing Functionality: Google API data is used solely to provide user-facing analytics, performance reporting, cross-channel sync, and AI advisor insights.
- No Data Sale: Google user data is never sold, leased, or commercialized to third parties.
- No Targeted Advertising: Google API data is never used by Analytics Brain AI for serving targeted advertisements or retargeting profiles.
- No Unauthorized Transfers: Google user data is not transferred to external parties except to secure infrastructure providers strictly necessary for hosting.
- Restricted Human Access: Human employees cannot read Google user data unless required for technical support requested by the user, security incident resolution, or legal compliance.
8. Meta Platform Data Handling
Meta Ads data processing strictly follows granted business permissions:
- Campaign performance metrics are fetched to present ad performance dashboards and creative breakdowns.
- Meta ad metrics are never sold or shared with competing ad networks.
- Users can revoke Meta permissions at any time via in-app disconnect or Meta Business Settings.
9. Shopify Integration Data Handling
Shopify store analytics are fetched using minimal authorized app scopes (read_products, read_orders, read_inventory, read_locations):
- Sales data is processed to calculate net revenue, order volume, and inventory velocity.
- Store merchants can uninstall the application or disconnect integration credentials via Shopify Admin.
10. Data Sharing & Infrastructure Providers
We share data exclusively with trusted technical infrastructure providers required to operate our service:
- Supabase: Managed database hosting, Row Level Security enforcement, and authentication services.
- Vercel: Application deployment, serverless execution, and global CDN routing.
- Google Gemini API (@google/genai): AI analysis for generating natural language business advisor recommendations via Google Gemini API (@google/genai).
11. Security Architecture Summary
We enforce HTTPS/TLS 1.3 encryption in transit, AES-256-GCM credential encryption at rest, and Supabase Row Level Security (RLS) for complete multi-tenant database isolation.
12. Data Retention & Erasure
Integrated platform metrics are retained while the tenant account remains active. Upon disconnection or deletion request, tokens are invalidated and operational records are purged.
13. User Data Rights & Choices
Users reserve full rights to access, inspect, export, disconnect, or request permanent deletion of their business analytics data.
14. Children's Privacy Notice
Analytics Brain AI is designed exclusively for commercial business users and is not directed to children under 18.
15. Updates & Policy Contact
We may update this policy periodically. For privacy inquiries, contact our team at: ahmedomran12622@gmail.com