PRIVACY POLICY

Last updated: May 1, 2025

This Privacy Policy describes how BPS (Business Performance Score) collects, uses, and protects your information when you use our service.

SECTION 1 — INFORMATION WE COLLECT

Account Information: When you register we collect your email address and password (stored securely via Supabase Auth).

Profile Information: Store name, TikTok handle, and profile photo if you choose to provide them.

Onboarding Data: Ad spend range, product category, TikTok reach, affiliate usage, and time selling — used to calibrate your score.

Phone Number: Collected during onboarding for score update notifications if you opt in.

Shopify Store Data: Orders, revenue, customer data, and fulfillment information accessed via read-only Shopify API to calculate your score.

Payment Information: Processed entirely by Stripe. BPS never stores your card details.

SECTION 2 — HOW WE USE YOUR INFORMATION

We use your information to:

· Calculate and display your Business Performance Score

· Generate personalized insights and recommendations

· Send score update notifications if you opt in

· Improve our scoring algorithms and benchmarks

· Provide customer support

· Comply with legal obligations

We do not sell your personal information. We do not use your data for advertising purposes.

SECTION 3 — DATA SHARING

We share your data only with:

Supabase — our database and authentication provider. Data is stored in secure US-based data centers.

Stripe— payment processing. Subject to Stripe's privacy policy.

Anthropic — AI recommendations for Growth and Pro subscribers. Only anonymized KPI scores are sent, never personal information.

Shopify — to authenticate your store connection.

We do not share your data with any other third parties.

SECTION 4 — DATA SECURITY

We protect your data using:

· Encrypted connections (HTTPS) on all pages

· Row-level security on our database

· Read-only Shopify access tokens

· Secure password hashing via Supabase Auth

· Regular security reviews

No method of transmission over the internet is 100% secure. We strive to protect your data but cannot guarantee absolute security.

SECTION 5 — YOUR RIGHTS

You have the right to:

· Access the personal data we hold about you

· Correct inaccurate data

· Request deletion of your data

· Export your data

· Withdraw consent at any time

To exercise these rights, delete your account from Settings or contact us at support@bpscore.app

SECTION 6 — COOKIES

BPS uses essential cookies only for authentication and session management. We do not use tracking or advertising cookies.

We do not use third-party analytics that track you across websites.

SECTION 7 — DATA RETENTION

We retain your data for as long as your account is active. If you delete your account your data is permanently deleted within 30 days.

Score history and analytics data may be retained in anonymized, aggregated form to improve our benchmarks.

SECTION 8 — CHILDREN

BPS is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from minors.

SECTION 9 — CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via an announcement in your dashboard.

SECTION 10 — CONTACT

For privacy questions or data requests: support@bpscore.app