Brand Share
Find PartnersPremium PartnersBlogAboutContactBecome a Partner

Privacy Policy

Last updated: 30 July 2026

Brand Share is a directory where businesses find each other and swap backlinks. This policy explains what we collect, why we collect it, who else sees it, and how to have it removed. If anything here is unclear, email privacy@brandshare.io.

Information We Collect

Information you give us

  • Account details: your name, email address, and password (stored only as a salted hash, never in readable form).
  • Business listing content: business name, website, description, category, location, images, topic tags, and a contact email. This is published on the site, which is the purpose of a listing.
  • Partner searches: the business name, website, description of what you sell, and optional location you enter, plus the results we return. We keep these so your search history survives navigating away, and so we can enforce the free daily limit.
  • Saved items: the search results and listings you star.
  • Backlink invitations: the partner you contacted, the address it went to, and any message you wrote.
  • Messages: anything you send through our contact form.

Information we collect automatically

  • Listing statistics: when a listing appears in the directory, when its page is viewed, and when a visitor clicks through to the business's website. We store these as daily totals per listing. We do not store the IP address, and we do not build a profile of individual visitors. Your own visits to your own listing are excluded.
  • Browser user agent: read at the moment of a request to filter out obvious crawlers, so the counts we show a business mean something. It is not stored.
  • Server logs: our hosting provider records standard request logs, which may include IP addresses, for security and debugging.

Information about businesses we have not met

To suggest partners, we read publicly available pages on business websites, including any contact address published there. We may use a publicly listed business address to send one invitation or introduction. This is business contact information, not personal information about a consumer. If you would rather we did not contact your business, see Opting out of our email below.

Why We Use It

  • To run your account, publish your listing, and verify backlinks between two sites.
  • To find and rank relevant partner businesses when you search.
  • To send transactional email: confirmations, invitations, verification codes, and password resets.
  • To show a business how its listing is performing.
  • To take payment for a placement plan and to keep it in the right position.
  • To enforce free-tier limits, prevent abuse, and protect the platform.

We do not sell your personal information. We do not use your data to train machine-learning or AI models, and we do not use it for advertising or profiling.

Who Else Sees It

We use a small number of service providers, and only for the purpose listed. Each processes data on our behalf.

  • Vercel: hosting, server logs, and image storage.
  • Neon: the PostgreSQL database where the site's data is stored.
  • Stripe: payments. Card details are entered on Stripe's own checkout and never reach our servers. We store only a customer reference and subscription status.
  • Google (Gmail API): delivery of our transactional email. See the Google section below.
  • Brave Search API: when you run a partner search, the words you enter are sent to Brave as a search query.
  • Anthropic: the text you enter in a partner search, plus the public titles and descriptions of the results, are sent to Anthropic's API to sort relevant businesses from irrelevant ones. Your account details are not sent.
  • Unsplash: blog images are served from Unsplash's network, so your browser contacts them when you load an article.
  • DeepL: when a page is viewed in a language other than English, the text on it is sent to DeepL to be translated. That includes the description a business wrote for its own listing and the text of blog posts. Translations are stored so the same text is not sent twice. Account details, email addresses and payment data are never sent.
  • Google (Translate): used only when DeepL is unavailable or its monthly allowance is spent, for the same text and the same purpose.

Anything you publish in a listing is public by design. A contact email on a listing can be hidden, and when hidden it is withheld from the page entirely rather than merely styled out of view. We may also disclose information if we are legally required to.

Opting Out of Our Email

Every introduction email we send carries an unsubscribe link that needs no login. Using it stops contact to your entire domain, not just the one address, and we keep a record of that opt-out so a later run cannot undo it. That record exists purely to keep you off the list. You can also reply to any message and ask us to stop.

How Long We Keep It

  • Account and listing data: until you ask us to delete it.
  • Partner searches and saved items: until you delete them or your account.
  • Listing statistics: kept as daily totals, with no visitor identifiers.
  • Opt-out records: kept indefinitely, because deleting one would let us email you again.
  • Payment records: retained as long as required for tax and accounting.

Your Rights

You can ask us to give you a copy of your data, correct it, or delete it, and you can withdraw consent or object to a use of it. Email privacy@brandshare.io and we will respond within 30 days. Deleting your account removes your listings, searches and saved items; opt-out records and payment records are retained for the reasons above.

We are based outside the EU and UK, so data you send us is processed internationally. Depending on where you live you may have additional rights under laws such as the GDPR, the UK GDPR, or the CCPA, and we will honour them on request.

Cookies

We set one cookie, and only after you sign in: a session cookie that keeps you logged in. We do not use advertising cookies, and we do not run third-party analytics or tracking scripts on the site. The listing statistics described above are counted on our own server and are not tied to a cookie.

Children

Brand Share is a tool for businesses and is not intended for anyone under 16. We do not knowingly collect information from children.

Data Security

Traffic is encrypted with HTTPS, passwords are stored only as salted hashes, and credentials for third-party services are held as encrypted server-side environment variables that never reach the browser. No system is perfectly secure, and we will tell affected users promptly if a breach puts their data at risk.

Google User Data & Google API Services

Brand Share uses Google APIs to send transactional email from a brand mailbox we own and operate. This section describes exactly how our application accesses, uses, stores, shares, and retains Google user data, in compliance with the Google API Services User Data Policy.

Data We Access

We request a single Google OAuth permission: the Gmail send-email scope (https://www.googleapis.com/auth/gmail.send) for one Google account that we own and operate. This permission lets our application send email on behalf of that account. We do not read, download, store, or collect Gmail messages, drafts, contacts, labels, profile information, or any other Google data, and we never access Google accounts belonging to our website visitors or users.

How We Use the Data

We use Gmail send access solely to deliver operational, transactional email, such as contact-form confirmations, business-listing and mutual-backlink request notifications, and direct replies to inquiries. We do not use Google data for advertising, profiling, training machine-learning or AI models, or any purpose unrelated to sending these messages.

Data Sharing

We do not sell, rent, or share Google user data with third parties. The only transfer that occurs is the delivery of each email to its intended recipient through Google's own Gmail servers. We do not transfer Google user data to others except as necessary to provide this sending feature through Google's APIs, to comply with applicable law, or as part of an email you have asked us to send.

Data Storage & Protection

We do not store Gmail messages or Google account content. The OAuth credentials used to authorize sending (a refresh token) are stored as encrypted, server-side environment variables with our hosting provider, are restricted to our application, and are never exposed in client-side code or to the public. We protect all data in transit using HTTPS/TLS encryption and apply industry-standard security controls.

Data Retention & Deletion

Because we do not read or store Google user data, there is no Google user data for us to retain. You can revoke our application's access at any time from your Google Account permissions page at myaccount.google.com/permissions, which immediately ends our access. You may also email us at privacy@brandshare.io to request revocation or deletion of any associated records, and we will honor such requests promptly.

Limited Use

Brand Share's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Changes

If we change how we use your data we will update this page and its date. Material changes will be announced to account holders by email.

Contact Us

Questions, requests, or complaints: privacy@brandshare.io.

Privacy Policy | Brand Share