Privacy Policy

Last updated: April 21, 2026

Brand Power Index (“BPI,” “we,” “us,” or “our”) is a product of Ventiq, LLC, a Utah limited liability company. We operate the website at brandpowerindex.com and related services (collectively, the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the choices you have. It applies to all visitors, registered users, and paying business customers.

By creating an account or otherwise using the Service, you acknowledge the practices described in this Policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Information you provide directly

  • Account registration: email address, password, and optionally a display name. We generate a username automatically from the local part of your email and a random suffix; you can change it later.
  • Phone number: if you voluntarily complete phone verification to increase your vote weight. We use Twilio to deliver a one-time code (OTP). We store the verified phone number in plain text in our user database, together with a flag indicating verification is complete. The one-time code itself is hashed (SHA-256) and consumed after a single use; unused codes expire after 10 minutes.
  • Identity verification: if you purchase the voter-verification tier, Stripe Identity collects and verifies government ID and a selfie. We do not receive or store the ID document or selfie image; we receive only a pass/fail result and a Stripe verification session ID. On success we set an id_verified flag on your account.
  • Payment information: if you subscribe to a paid Business tier or the voter-verification tier, payment details are collected and processed directly by Stripe. We never see or store raw card numbers; we receive only a Stripe customer ID, subscription status, and the plan you purchased.
  • Profile content: optional bio and avatar URL you set on your profile, and the industry familiarity ratings you self-report during onboarding.
  • Brand submissions: brand name, website URL, and industry category when you submit a new brand, plus your user ID so we can credit and audit the submission.
  • Brand claims: company name, role, company email, and company website when you submit a claim to represent a brand.
  • Support & feedback: your name, email, selected category, subject, and message when you contact us through the Support or Feedback forms. If you are logged in when you submit, we also associate the submission with your user ID.
  • Newsletter / waitlist: your email address (and, for the business waitlist, company name) if you subscribe to updates or join a waitlist.

1.2 Information generated by your activity

  • Votes: each brand score (0–10) you submit, along with a timestamp and your account ID. Aggregated scores are public; your individual vote scores are private and are not displayed alongside your profile.
  • Vote signals: for abuse detection, we store the IP address and a truncated user-agent string (first 200 characters) associated with each vote. These signals are retained for integrity analysis and removed on account deletion via cascade.
  • Favorites: which brands you bookmark.
  • Onboarding preferences: industries you selected and your self-reported familiarity levels, used to tune your voting stream and weight eligible votes.
  • API usage: for Business subscribers, we log each API request (endpoint, timestamp, response code, API-key ID) to enforce quota limits and detect abuse.

1.3 Information collected automatically

  • Log data: IP address, browser type, operating system, referring URL, pages visited, and timestamps. Retained for up to 90 days for security, rate limiting, and abuse prevention.
  • Session cookie: an HTTP-only, secure cookie named bpi_session that stores a cryptographically random session token. It contains no personal data and is used solely to keep you logged in. It expires 30 days after issuance and is deleted when you log out.
  • CAPTCHA signals: we use Cloudflare Turnstile on signup, on unauthenticated support/feedback submissions, and on every tenth vote edit per user. Turnstile may collect anonymised browser characteristics. See Cloudflare's privacy policy.
  • Product analytics (PostHog): when configured, we load PostHog to measure aggregate usage (page views, clicks, conversion funnels). PostHog is set to identified-only person profiles — anonymous visitors generate events but not persistent profiles. PostHog may set first-party cookies in your browser. If you prefer not to be analysed, you can block third-party scripts or use a browser that sends Do Not Track or Global Privacy Control signals.

2. How We Use Your Information

  • Provide the Service: process votes, compute Brand Power Index scores, serve rankings, and deliver API data to Business subscribers.
  • Account management: authenticate you, deliver verification emails and password-reset links, and maintain your preferences.
  • Vote integrity: weight votes using your verification tier (see Section 2.1 below), your self-reported industry familiarity, and vote recency, and detect and suppress fraudulent or coordinated voting.
  • Billing: process subscription payments, manage plan upgrades and cancellations, and send invoices via Stripe.
  • Support: respond to your support tickets and feedback.
  • Communications: send transactional emails (verification, password reset, billing receipts, onboarding reminders) and, if you opt in, newsletter updates. You may unsubscribe from newsletters at any time via the link in any email.
  • Safety and security: detect abuse, enforce rate limits, investigate suspicious activity, and comply with legal obligations.
  • Product improvement: analyse aggregate usage patterns to improve features and fix bugs. We do not sell your personal information, and we do not use individual vote data to build advertising profiles.

2.1 How vote weighting actually works

Email verification is required to vote at all — unverified accounts cannot submit votes. Once your email is verified, your vote weight is determined by the strongest verification tier on your account:

  • Email-verified only: 0.5× base weight.
  • Phone-verified (Twilio OTP): 1.0× base weight.
  • ID-verified (Stripe Identity, paid tier): 2.0× base weight.

The final weight is also multiplied by a per-industry familiarity factor (0.3× to 1.5×) and a recency decay. Weights are computed at query time from your current account flags, so completing phone or ID verification retroactively re-weights your existing votes.

3. Legal Bases for Processing (EEA / UK users)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under GDPR / UK GDPR:

  • Contract performance: processing necessary to provide the Service you signed up for (account creation, voting, billing, customer support).
  • Legitimate interests: security, fraud and abuse prevention, vote integrity, product analytics, and operating our business, where these interests are not overridden by your rights and freedoms.
  • Consent: newsletter subscriptions and optional phone and identity verification.
  • Legal obligation: retaining billing and tax records as required by law.

4. How We Share Your Information

We do not sell your personal information. We share it only as described below, and only to the extent necessary for the stated purpose.

  • Stripe: payment processing, subscription management, billing portal, and (for the voter-verification tier) Stripe Identity ID verification. Stripe is a PCI-DSS Level 1 certified processor. See Stripe's privacy policy.
  • Resend: transactional email delivery (verification links, password resets, receipts, onboarding). Resend processes email addresses and message content to route and deliver email. See Resend's privacy policy.
  • Twilio: phone OTP delivery when you opt into phone verification. Twilio receives your phone number, the message body, and metadata required for delivery. See Twilio's privacy policy.
  • Cloudflare: CAPTCHA (Turnstile) and network-layer protection. Cloudflare may process IP addresses and browser signals to distinguish humans from bots.
  • Turso: our primary database provider. Your data is stored in encrypted SQLite databases hosted on Turso and is accessible only via authenticated application-layer code.
  • Vercel: our hosting and edge-network provider. Vercel processes HTTP requests and may log IP addresses for routing and DDoS mitigation.
  • PostHog: aggregate product analytics, as described in Section 1.3.
  • Professional advisors: accountants, auditors, and attorneys, where necessary for legal, tax, or compliance purposes, under appropriate confidentiality obligations.
  • Law enforcement and legal process: we may disclose information if required by a valid subpoena, court order, warrant, or other lawful process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of BPI, Ventiq, LLC, our users, or the public.
  • Corporate transactions: if BPI or Ventiq, LLC is acquired, merges with another company, or sells substantially all of its assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

5. Public Information

The following information is publicly visible on the Service and is not subject to the same confidentiality protections as private data:

  • Your display name and username on your public profile page.
  • Your profile bio and avatar (if set).
  • Whether you hold a Verified badge (phone-verified or ID-verified).
  • Aggregate statistics on your profile (e.g., “this user has ranked 42 brands”). Individual vote scores remain private.
  • Your position on the Top Voices leaderboard, which ranks users by aggregate weighted vote influence.

6. Data Retention

  • Account data: retained for the life of your account. After account deletion (see Section 7), personal account fields are purged within 30 days.
  • Support and feedback submissions: after account deletion, the email and name fields on your submissions are scrubbed and the user-account link is removed, but the message body and metadata are retained for up to 2 years to preserve our response history and institutional knowledge. You may request full deletion of a specific message by emailing privacy@brandpowerindex.com.
  • Vote contributions: on account deletion, your votes are deleted in full, which reduces the aggregate vote mass on affected brands.
  • Session tokens: expire 30 days after issuance and are revoked on logout.
  • Email verification tokens: expire 24 hours after issuance.
  • Password reset tokens: expire 1 hour after issuance.
  • Phone OTP codes: expire 10 minutes after issuance; single-use.
  • Billing records: retained by Stripe and by us for 7 years as required by applicable tax and accounting law.
  • Server logs: retained for up to 90 days.
  • Admin audit logs: retained indefinitely for security and compliance; the account link is nulled when a deleted admin is removed.

7. Your Rights and Choices

Depending on your location, you may have some or all of the following rights regarding your personal information:

  • Access: request a copy of the personal data we hold about you.
  • Correction: update inaccurate or incomplete information. You can edit your name, username, bio, and avatar directly on your profile page.
  • Deletion: delete your account and associated personal data. We do not currently offer in-app account deletion. To request deletion, email privacy@brandpowerindex.com from the address on your account. We will confirm your identity and complete deletion within 30 days, subject to the retention exceptions in Section 6.
  • Data portability: request a machine-readable export of your personal data (EEA / UK users).
  • Objection / restriction: object to or restrict processing based on legitimate interests (EEA / UK users).
  • Withdraw consent: unsubscribe from newsletters via the link in any email, or by contacting us.
  • Do Not Track / Global Privacy Control: we honour Global Privacy Control (GPC) signals — when GPC is set we skip the cookie banner entirely and never load analytics, treating the signal as an expressed opt-out. We do not respond to legacy Do Not Track headers because there is no industry standard for how to do so.
  • Complaint: if you believe we have processed your data unlawfully, you may lodge a complaint with your local supervisory authority.

To exercise any of these rights, email privacy@brandpowerindex.com. We will respond within 30 days (45 days where permitted by law for complex requests).

8. Cookies

We use the following cookies and similar technologies:

  • bpi_session (strictly necessary): HTTP-only, secure, first-party session cookie. Required for authentication; cannot be disabled without losing the ability to stay logged in.
  • bpi_consent(strictly necessary): first-party cookie that records whether you accepted or rejected analytics cookies, so we don't ask you on every page load. One-year expiry.
  • Cloudflare Turnstile (security): used to distinguish humans from bots during signup, voting, and unauthenticated support submissions.
  • PostHog analytics (analytics): first-party cookies set by the PostHog script to measure aggregate product usage. The PostHog script only loads after you click Accept in our cookie banner. If you click Reject, or if your browser sends a Global Privacy Control signal, PostHog is never loaded and no analytics cookies are set.
  • Stripe(payments): Stripe may set its own cookies when you load a checkout or billing-portal page. These are governed by Stripe's privacy policy.

You can change your analytics choice at any time via the Cookie preferences link in the site footer. We do not set advertising or cross-site tracking cookies, and we do not participate in ad-targeting networks.

9. Security

We implement reasonable technical and organisational measures to protect your information, including:

  • Passwords are hashed with scrypt (a memory-hard key-derivation function) using a per-user random salt; we never store or log plaintext passwords.
  • Phone OTP codes are hashed with SHA-256 before storage; only the hash is stored, and codes are consumed single-use.
  • All data in transit is encrypted with TLS 1.2 or higher.
  • Session tokens are 256 bits of cryptographically secure randomness, stored server-side and transmitted only via HTTP-only, Secure, SameSite=Lax cookies.
  • Database access is restricted to authenticated application-layer code.
  • Stripe handles all payment data and identity documents — we never store raw card numbers or government ID images.
  • HTTP Strict Transport Security (HSTS) is enforced on all production pages.
  • A Content Security Policy restricts the origins that can execute scripts and open connections.
  • Rate limiting and CAPTCHA protect authentication, voting, and contact endpoints.
  • Admin actions are logged to an append-only audit table.

No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly to security@brandpowerindex.com. We will acknowledge receipt within 48 hours.

10. Children's Privacy

The Service is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact privacy@brandpowerindex.com and we will delete the information promptly.

11. International Transfers

Ventiq, LLC is based in the United States, and the Service is operated from the United States. If you are located outside the US, your information will be transferred to and processed in the United States and other countries where our infrastructure providers operate. Where required by GDPR / UK GDPR, we rely on Standard Contractual Clauses, the EU–US Data Privacy Framework (where applicable), or other lawful transfer mechanisms. Our sub-processors (Stripe, Resend, Twilio, Cloudflare, Turso, Vercel, PostHog) maintain their own compliant transfer mechanisms.

12. California Privacy Rights (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to know what personal information is collected, used, and disclosed.
  • Right to delete personal information, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to limit use and disclosure of sensitive personal information.
  • Right to opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising.
  • Right to non-discrimination for exercising any of these rights.

To submit a verifiable CCPA / CPRA request, email privacy@brandpowerindex.com. An authorised agent may submit a request on your behalf with proof of authorisation.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and by posting the updated policy here with a new “Last updated” date. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy. If you do not agree to a material change, you should stop using the Service and may request account deletion.

14. Contact Us

Questions, requests, or complaints about this Privacy Policy or our data practices: