Privacy Policy
Introduction
Brand Bento ("Brand Bento," "we," "our," or "us") provides a web-based app for creating, managing, publishing, and sharing online brand guidelines and related brand assets.
This Privacy Policy explains what information we collect, how we use it, when we share it, and the choices and rights you may have when using Brand Bento.
By using Brand Bento, you acknowledge that your information will be handled as described in this Privacy Policy.
Who We Are
Brand Bento is operated by Hamdi Designs.
For privacy-related questions or requests, contact us at Brand Bento, brandbentoapp@gmail.com.
Information We Collect
We collect information you provide directly, information created through your use of the app, and limited technical information needed to operate, secure, and improve Brand Bento.
Information You Provide
- Name
- Email address
- Profile information, such as avatar, username, and timezone
- Account credentials and authentication information
- Brand guide content you create, edit, save, publish, or share
- Project details, including project names, descriptions, slugs, thumbnails, cover images, guide settings, template settings, draft settings, publication settings, and custom domains
- Files you upload, including logos, fonts, images, photography, icons, downloadable assets, favicons, Open Graph images, footer logos, header logos, profile photos, and other brand assets
- Custom fonts and font metadata
- Public-guide passwords and protected-guide access settings
- Feedback, support messages, bug reports, screenshots, attachments, or other information you submit through support or feedback tools
- Instructions, project context, current draft text, and other content you submit when using Bento AI or other AI-assisted writing features
Information Created Through Your Use of the App
- Project and brand guide records
- Builder v1 and builder v2 draft content, page structures, blocks, themes, uploaded asset references, publication snapshots, and publication history
- Guide status information, such as draft, live, unpublished, archived, protected, or public
- User preferences, such as onboarding visibility, builder onboarding visibility, app theme, autosave, default template, and notification preferences
- Billing entitlement information, such as plan, subscription status, billing interval, access expiration, grace period, cancellation status, and related Stripe identifiers
- Operational records related to uploads, file verification, file deletion, cleanup queues, account deletion, authentication actions, rate limits, and security checks
- Product analytics events, such as signup, login, builder, publishing, support, feedback, billing, and navigation events
- Public aggregate stats, such as total users, total guides, live guides, and templates
Technical and Device Information
- IP address
- Browser type and version
- Device type
- Operating system
- Referring pages
- Pages viewed
- Dates and times of access
- Session activity and page interactions
- Error, diagnostic, and security logs
- Approximate location inferred from IP address
Authentication and Sign-In
Brand Bento currently supports:
- Email and password registration and login
- Google sign-in
If you sign in using Google, we may receive basic profile information associated with your Google account, such as your name, email address, avatar, and authentication provider details. Brand Bento uses Supabase Auth to manage authentication, sessions, password changes, email changes, and account deletion.
How We Use Your Information
We use your information to:
- Create and manage your account
- Authenticate users and maintain secure sessions
- Provide the core functionality of Brand Bento
- Store, edit, autosave, publish, unpublish, and display brand guides
- Store, manage, verify, serve, and delete uploaded files
- Provide public, unpublished, and password-protected guide access
- Support draft and published guide behavior
- Manage custom guide settings, templates, fonts, pages, blocks, downloadable files, and brand assets
- Provide billing, subscription, entitlement, upgrade, cancellation, grace-period, and invoice-related functionality
- Process payments and subscription events through Stripe
- Provide AI-assisted brand guideline writing when you choose to use Bento AI
- Respond to support, feedback, bug reports, and product requests
- Analyze product usage, diagnose issues, improve performance, and understand which features are working
- Prevent abuse, rate-limit sensitive actions, detect errors, enforce our terms, and secure the app
- Send account-related communications, such as authentication, security, billing, service, and policy notices
- Send product updates, tips, or marketing messages where permitted and based on your preferences
- Comply with legal obligations and protect the rights, safety, and integrity of Brand Bento, our users, and others
Public Guides, Protected Guides, and Uploaded Files
Brand Bento is designed to help users publish brand guides for sharing with clients, teams, vendors, and other third parties.
Because of that:
- Published guides may be publicly accessible on the web.
- Anyone with the public guide link may be able to view a public guide.
- Password-protected guides may be accessible to anyone with the link and password.
- Protected-guide access uses a cookie so visitors do not need to re-enter the password on every page.
- Uploaded files used in guides may be publicly accessible by URL, including files that support guide display or downloads.
- Published guide snapshots may preserve the version of content and assets that were live at the time of publication.
- If you share a guide link, download link, password, or asset URL with someone else, that person may further share it.
You should only upload, publish, or share content that you have the right to upload, store, display, publish, and distribute.
Files, Fonts, and User Content
You are responsible for the content you upload to Brand Bento, including logos, images, fonts, copy, color palettes, downloadable files, brand strategy material, and other assets.
If you upload custom fonts or other licensed materials, you are responsible for ensuring that you have the necessary rights, licenses, permissions, and authority to use and share them through Brand Bento, including through public or password-protected guides.
Please do not upload sensitive personal information, confidential client materials, or regulated information unless you are authorized to do so and understand how the app publishes, stores, and shares content.
Payments and Billing
Brand Bento uses Stripe to process subscriptions, checkout, billing portal access, payment status, invoices, renewals, cancellations, failed payments, and related billing events.
When you start checkout or manage billing, Stripe may collect and process payment information, billing details, transaction information, fraud-prevention information, device information, tax-related information, and other information required to provide payment and subscription services.
Brand Bento does not store full payment card numbers. We store limited billing-related records needed to manage your subscription, such as Stripe customer ID, subscription ID, product ID, price ID, billing interval, subscription status, access dates, cancellation status, and webhook event records.
Stripe may process your information as an independent controller and/or as our service provider, depending on the activity. Your use of Stripe-powered checkout and billing features may also be subject to Stripe's own privacy terms.
Analytics and Session Information
Brand Bento uses PostHog to understand how users interact with the app, identify product issues, improve the builder experience, and measure important product events.
PostHog may collect product analytics and session information, including page views, page leave events, interactions, user identifiers, email address, name, device information, browser information, IP address, and session activity. Brand Bento identifies logged-in users in PostHog using account information such as user ID, email address, and name.
Brand Bento may use session replay or similar diagnostic tools to understand bugs, friction, and product behavior. We attempt to avoid intentionally collecting passwords and sensitive fields through analytics. You should still avoid entering sensitive personal information into fields where it is not requested.
We do not use analytics to sell your personal information.
Feedback and Support
Brand Bento uses Userback to collect feedback, support requests, bug reports, feature requests, screenshots, and related product feedback.
When the feedback widget is available and you use it, Userback may receive information such as your name, email address, user ID, feedback text, screenshots, attachments, page URL, browser and device information, screen size, IP address, approximate location, console logs, network information, and other context depending on the widget configuration and what you choose to submit.
We use this information to respond to support requests, reproduce bugs, improve the product, and prioritize product work.
AI-Assisted Writing
Brand Bento offers AI-assisted writing features through Bento AI. These features are optional and are available only when you choose to use them.
When you use Bento AI, Brand Bento sends relevant request information to OpenAI through the OpenAI API, such as your instruction, current draft text, field label, block title, block type, and project context. This may include brand guide content or uploaded text you have added to your project.
We use this information to generate suggested brand guideline copy and return it to you in the app. You are responsible for reviewing AI-generated output before saving, publishing, or sharing it.
OpenAI's API data practices may apply to content processed through Bento AI.
Cookies and Similar Technologies
Brand Bento uses cookies, local storage, and similar technologies as needed to:
- Keep you signed in
- Maintain secure sessions
- Complete authentication and redirects
- Support protected public-guide access
- Remember app and builder preferences
- Operate core app functionality
- Provide analytics, diagnostics, and product improvement
- Support feedback tools
- Support checkout and billing functionality
Brand Bento does not currently use third-party advertising cookies for cross-site advertising. You can control cookies through your browser settings, but disabling cookies may prevent login, protected-guide access, checkout, or other app features from working properly.
Third-Party Services
Brand Bento relies on third-party service providers to operate, secure, improve, and commercialize the app. These providers may process information on our behalf or as independent controllers depending on the service and activity.
Current service providers and integrations include:
- Supabase for authentication, database, file storage, server-side access, and related infrastructure
- Stripe for checkout, subscriptions, billing portal, invoices, payment processing, and fraud prevention
- PostHog for product analytics, usage events, session diagnostics, and product improvement
- Userback for feedback collection, screenshots, support context, and bug reporting
- OpenAI for optional AI-assisted writing features
- Google for Google sign-in, Google Fonts API, and Google Fonts delivery where selected in a guide
- Hosting, infrastructure, and deployment providers used to run Brand Bento, currently Vercel
We may add, replace, or remove service providers as Brand Bento evolves.
How We Share Information
We do not sell your personal information.
We may share information only in the following situations:
- With service providers who help us operate, host, secure, analyze, support, and improve Brand Bento
- With Stripe and related payment providers as needed to process subscriptions, payments, invoices, fraud prevention, and billing support
- With OpenAI when you choose to use Bento AI
- With Userback when you submit feedback or interact with the feedback widget
- With Google when you use Google sign-in or select Google Fonts in a guide
- When you intentionally publish, share, or provide access to a guide, file, asset, password, custom domain, or public link
- With public-guide visitors to display guide content and downloadable assets you have published
- With professional advisors, vendors, or contractors who help us run the business under appropriate confidentiality obligations
- When required by law, regulation, court order, subpoena, or legal process
- When needed to protect the security, rights, property, or integrity of Brand Bento, our users, or others
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of the business
Data Retention
We retain information for as long as needed to provide Brand Bento, operate and secure the app, comply with legal obligations, resolve disputes, enforce agreements, and maintain appropriate business records.
In general:
- Account and profile data are retained while your account is active.
- Project, builder, uploaded file, and guide data are retained while your account or project remains active, unless deleted earlier through available product controls.
- Published guide snapshots and related assets may be retained to support the live guide experience, audit publication behavior, or restore expected published-guide functionality.
- Billing records may be retained as needed for subscription management, accounting, tax, fraud prevention, dispute handling, and legal compliance.
- Analytics, diagnostic, and security logs may be retained for operational, security, and product improvement purposes.
- Backups and logs may persist for a limited period after deletion before being overwritten or deleted according to provider retention schedules.
Account Deletion
Brand Bento includes an account deletion flow. When you delete your account, Brand Bento attempts to remove your account information, profile, user settings, projects, project sections, blocks, project settings, project files, uploaded assets, and Supabase authentication user from active systems.
Some information may be retained where necessary or permitted for:
- Legal compliance
- Billing, tax, accounting, and dispute records
- Security, fraud prevention, and abuse prevention
- Backup, archive, or disaster recovery systems
- Debugging records or operational logs
- Enforcement of our terms or protection of legal rights
Deleting your Brand Bento account does not automatically delete information that has already been copied, downloaded, cached, indexed, or separately stored by people who accessed your public or shared guides.
Data Security
We use reasonable administrative, technical, and organizational measures designed to protect your information. These include authentication controls, server-side authorization checks, row-level security assumptions, signed upload URLs, rate limits for sensitive actions, provider-managed security features, and restricted access to sensitive infrastructure.
However, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
International Use
Brand Bento may be accessed by users and guide visitors in different countries. Your information may be processed in countries other than the one where you live, including the United States and other locations where we or our service providers operate.
These countries may have data protection laws that differ from the laws in your country.
Your Choices and Rights
Depending on your location, you may have rights regarding your personal information, including the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account or personal information
- Request a copy of certain personal information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Opt out of certain communications
- Appeal a privacy rights decision where applicable
You can update some account information directly through your account settings. You can delete your account through the account deletion flow. To make a privacy-related request, contact us at brandbentoapp@gmail.com. We may need to verify your identity before fulfilling a request.
U.S. State Privacy Notice
Depending on your U.S. state of residence, you may have additional rights under state privacy laws.
Brand Bento may collect the following categories of personal information:
- Identifiers, such as name, email address, user ID, IP address, and device identifiers
- Customer records, such as account and billing-related information
- Commercial information, such as subscription plan, billing interval, purchase status, and invoice-related records
- Internet or electronic network activity, such as app usage, pages viewed, interactions, session activity, and diagnostic logs
- Geolocation information, such as approximate location inferred from IP address
- Professional or business information you choose to provide in brand guide content or feedback
- User-generated content, such as projects, guide copy, uploaded files, feedback, screenshots, and AI prompts
- Inferences, such as product usage patterns used to improve the app
We collect and use these categories for the purposes described in this Privacy Policy. We do not sell personal information for money. We do not knowingly sell or share personal information of children under 16. If we begin using information for cross-context behavioral advertising or other activities that legally count as "sharing" or "selling," we will update this Privacy Policy and provide any legally required opt-out mechanism.
European, UK, and Similar Privacy Rights
If you are located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with similar rights, our legal bases for processing may include:
- Performance of a contract, such as providing the Brand Bento app, account, builder, publishing, billing, and support functionality
- Legitimate interests, such as securing the app, improving product quality, preventing abuse, debugging, and understanding product usage
- Consent, where required for certain cookies, communications, or optional features
- Legal obligations, such as tax, accounting, compliance, and lawful requests
You may have rights to access, correct, delete, restrict, object to, or port your personal information, and to withdraw consent where applicable.
Children's Privacy
Brand Bento is intended for professional or business use. It is not directed to children, and we do not knowingly collect personal information from children under 13.
If we learn that we have knowingly collected personal information from a child under 13, we will take reasonable steps to delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time as Brand Bento evolves, laws change, service providers change, or new features are added.
If we make changes, we will update the "Last updated" date above. If changes are material, we may provide additional notice, such as through the app or by email.
Your continued use of Brand Bento after an updated Privacy Policy becomes effective means you acknowledge the revised policy.
Contact Us
If you have questions or requests related to this Privacy Policy, please contact:
Brand Bento
Email: brandbentoapp@gmail.com