Last updated September 2026. What we access, what we store, what we never touch — and how to reach us about your data.
BrandPatrol's monitoring is built on public data only: search-engine results pages and the public ad-transparency record that ad platforms are already required to publish. A scan reads what a searcher would see, or what a network discloses publicly about an ad — nothing else.
We never log into a client's ad accounts, affiliate platform, CRM, or analytics tools to do this work. There's no OAuth grant, no read-only API key, no account access requested from you for detection to run.
For each brand under monitoring, your workspace holds:
All of this is scoped to the brand it was collected for. It doesn't mix across workspaces, and an agency's client brands never see each other's data.
Nothing BrandPatrol monitors involves an end customer. We don't collect shopper identities, payment details, order history, or any other personal data belonging to the people who click the ads we're watching — that data isn't visible from a public SERP or the ad-transparency record, and we have no reason to look for it elsewhere.
The marketing site you're reading now sets no advertising or tracking cookies. The signed-in workspace uses a single session cookie, required to keep you logged in — nothing else.
To run your workspace we hold what you give us directly when you sign up or get invited: your name, work email, and the brand(s) you've been granted access to. Passwords are never stored in plain text.
Case evidence and workspace data for a brand are visible only to accounts that brand has explicitly granted access to. An agency account managing several client brands keeps each client in its own separate workspace — one client's cases, roster, and keywords are never visible from another client's workspace.
Case evidence and account data are kept for as long as your workspace stays active — that's what lets you review a case months after a scan first flagged it. If you close your account or want a specific brand's data removed, email us at the address below; we'll confirm exactly what was deleted and when.
Running BrandPatrol requires ordinary infrastructure and email-delivery providers to host the service and send you account notifications — nothing unusual for a hosted web application. We don't sell case evidence or workspace data, and we don't share it with third parties for marketing purposes.
At any time, you can ask us to:
Reach us at [email protected] for any of the above.
If this policy changes, we'll update it on this page and change the "last updated" date above. We don't send a separate notice for minor clarifications; changes to what we collect or how we use it will be reflected here.
Questions about this policy or a specific data request: [email protected].