Bragerr OS

Privacy Policy

Last updated: September 15, 2026

Bragerr OS builds Shopify apps that help merchants understand and improve their stores. This policy explains what data our apps collect, why, how it's stored, and what rights you and your customers have over it. It applies to every app Bragerr OS operates, including Bragerr OS.

Data we collect from merchants

When you install one of our apps, we sync the store data needed to power that app's features:

  • Store information — shop domain, store name, currency, and timezone
  • Order data — order IDs, amounts, discount codes applied, and financial status
  • Product data — titles, prices, costs, and inventory levels
  • Customer data — Where required for store analysis, we process limited customer information. Customer email addresses are normalized and stored only as one-way SHA-256 hashes. We do not store customer payment information or passwords. Customer names are not stored.
  • Inventory and location data
  • Discount and promotion data

Data we do not collect

  • Customer payment information (card numbers, bank details, or other payment credentials)
  • Customer account passwords
  • Raw customer email addresses — these are hashed with SHA-256 before we store anything
  • Shopify staff account credentials

How we use data

We use the data described above to:

  • Analyze store performance
  • Detect profit and operational opportunities specific to your store
  • Generate AI-powered recommendations

We never sell store or customer data to third parties, and we never use it for advertising — ours or anyone else's.

Data storage and security

  • Data is stored in a PostgreSQL database hosted on Railway
  • Data is encrypted at rest
  • Every table is tenant-isolated by store — your data is never mixed with, or accessible to, another merchant

Data retention

We delete a store's data within 30 days of the app being uninstalled. Merchants can request deletion of their store's data at any time by contacting support@bragerr.com.

Sub-processors

We use the following sub-processors to operate our apps. None of them receive raw customer data beyond what's described below.

CompanyPurposeLocation
RailwayDatabase hostingUnited States
UpstashRedis queuingUnited States
VercelWeb hostingUnited States
AnthropicAI-powered analysis and recommendations. We send opportunity context including product names, discount code names, and aggregate store metrics. We do not send customer names, email addresses, order IDs, or other customer personal data to Anthropic. Bragerr performs all financial calculations independently — AI does not calculate or determine financial values.United States
ResendEmail deliveryUnited States
CloudflareCDN and storageUnited States

Merchant rights

You have the right to:

  • Access the data we hold about your store
  • Request deletion of your data
  • Request a copy of your data in a portable format

To exercise any of these rights, contact support@bragerr.com. See our privacy contact page for details.

Data Breach Notification

Bragerr OS takes data security seriously. In the event of a data breach likely to result in serious harm:

Australian merchants and operations

We will notify affected merchants and report qualifying breaches to the Office of the Australian Information Commissioner (OAIC) as soon as practicable after becoming aware of the breach, in accordance with the Australian Privacy Act 1988 Notifiable Data Breaches scheme.

European merchants (GDPR)

Where required under GDPR, we will notify affected merchants without undue delay and, where practicable, within 72 hours of becoming aware of a qualifying personal data breach.

All merchants

We will notify you directly via email if your store data is involved in a breach. We will tell you:

  • What happened
  • What data was involved
  • What we are doing about it
  • What you can do to protect yourself

To report a suspected breach

support@bragerr.com
Brian Koplick — Owner
bragerr os.com

GDPR

Bragerr OS is committed to complying with applicable privacy and data protection laws, including the GDPR where applicable. Our lawful basis for processing store and customer data is contract performance — you install our app and agree to our Terms of Service, which is the contract under which we act. We practice data minimization and only collect what each app needs to function.

Shopify compliance

Our Shopify apps implement the Shopify-mandated privacy webhooks applicable to the data they process:

  • customers/data_request
  • customers/redact
  • shop/redact

Data protection contact

Privacy Officer & Owner: Brian Koplick
support@bragerr.com
bragerr os.com
ABN: 18322095261

Data Processing Agreement

By installing a Bragerr OS app, a merchant (the data controller for their store's data) and Bragerr OS (the data processor) agree to the following terms for how we process the store's data on the merchant's behalf.

What data is processed

The store, order, product, inventory, discount, and hashed-customer data described above, under “Data we collect from merchants.”

Why it's processed

Solely to provide the features of the installed app — analysis, opportunity detection, and recommendations — described under “How we use data.”

Retention

Deleted within 30 days of uninstall, or sooner on request — see “Data retention” above.

Sub-processors

The companies listed under “Sub-processors” above.

Merchant rights

Access, deletion, and portability, as described under “Merchant rights” above.

Security measures

Encryption at rest, per-store tenant isolation, and the breach notification procedures described above.

Contact

Questions about this policy can be sent to support@bragerr.com.