Privacy Policy
Last updated: September 15, 2026
Bragerr OS builds Shopify apps that help merchants understand and improve their stores. This policy explains what data our apps collect, why, how it's stored, and what rights you and your customers have over it. It applies to every app Bragerr OS operates, including Bragerr OS.
Data we collect from merchants
When you install one of our apps, we sync the store data needed to power that app's features:
- Store information — shop domain, store name, currency, and timezone
- Order data — order IDs, amounts, discount codes applied, and financial status
- Product data — titles, prices, costs, and inventory levels
- Customer data — Where required for store analysis, we process limited customer information. Customer email addresses are normalized and stored only as one-way SHA-256 hashes. We do not store customer payment information or passwords. Customer names are not stored.
- Inventory and location data
- Discount and promotion data
Data we do not collect
- Customer payment information (card numbers, bank details, or other payment credentials)
- Customer account passwords
- Raw customer email addresses — these are hashed with SHA-256 before we store anything
- Shopify staff account credentials
How we use data
We use the data described above to:
- Analyze store performance
- Detect profit and operational opportunities specific to your store
- Generate AI-powered recommendations
We never sell store or customer data to third parties, and we never use it for advertising — ours or anyone else's.
Data storage and security
- Data is stored in a PostgreSQL database hosted on Railway
- Data is encrypted at rest
- Every table is tenant-isolated by store — your data is never mixed with, or accessible to, another merchant
Data retention
We delete a store's data within 30 days of the app being uninstalled. Merchants can request deletion of their store's data at any time by contacting support@bragerr.com.
Sub-processors
We use the following sub-processors to operate our apps. None of them receive raw customer data beyond what's described below.
| Company | Purpose | Location |
|---|---|---|
| Railway | Database hosting | United States |
| Upstash | Redis queuing | United States |
| Vercel | Web hosting | United States |
| Anthropic | AI-powered analysis and recommendations. We send opportunity context including product names, discount code names, and aggregate store metrics. We do not send customer names, email addresses, order IDs, or other customer personal data to Anthropic. Bragerr performs all financial calculations independently — AI does not calculate or determine financial values. | United States |
| Resend | Email delivery | United States |
| Cloudflare | CDN and storage | United States |
Merchant rights
You have the right to:
- Access the data we hold about your store
- Request deletion of your data
- Request a copy of your data in a portable format
To exercise any of these rights, contact support@bragerr.com. See our privacy contact page for details.
Data Breach Notification
Bragerr OS takes data security seriously. In the event of a data breach likely to result in serious harm:
Australian merchants and operations
We will notify affected merchants and report qualifying breaches to the Office of the Australian Information Commissioner (OAIC) as soon as practicable after becoming aware of the breach, in accordance with the Australian Privacy Act 1988 Notifiable Data Breaches scheme.
European merchants (GDPR)
Where required under GDPR, we will notify affected merchants without undue delay and, where practicable, within 72 hours of becoming aware of a qualifying personal data breach.
All merchants
We will notify you directly via email if your store data is involved in a breach. We will tell you:
- What happened
- What data was involved
- What we are doing about it
- What you can do to protect yourself
To report a suspected breach
support@bragerr.com
Brian Koplick — Owner
bragerr os.com
GDPR
Bragerr OS is committed to complying with applicable privacy and data protection laws, including the GDPR where applicable. Our lawful basis for processing store and customer data is contract performance — you install our app and agree to our Terms of Service, which is the contract under which we act. We practice data minimization and only collect what each app needs to function.
Shopify compliance
Our Shopify apps implement the Shopify-mandated privacy webhooks applicable to the data they process:
- customers/data_request
- customers/redact
- shop/redact
Data protection contact
Privacy Officer & Owner: Brian Koplick
support@bragerr.com
bragerr os.com
ABN: 18322095261
Data Processing Agreement
By installing a Bragerr OS app, a merchant (the data controller for their store's data) and Bragerr OS (the data processor) agree to the following terms for how we process the store's data on the merchant's behalf.
What data is processed
The store, order, product, inventory, discount, and hashed-customer data described above, under “Data we collect from merchants.”
Why it's processed
Solely to provide the features of the installed app — analysis, opportunity detection, and recommendations — described under “How we use data.”
Retention
Deleted within 30 days of uninstall, or sooner on request — see “Data retention” above.
Sub-processors
The companies listed under “Sub-processors” above.
Merchant rights
Access, deletion, and portability, as described under “Merchant rights” above.
Security measures
Encryption at rest, per-store tenant isolation, and the breach notification procedures described above.
Contact
Questions about this policy can be sent to support@bragerr.com.