Privacy Policy
Effective date: 14 May 2026 / Last updated: 19 August 2026
This Privacy Policy explains how Brksoft LTD (“Brksoft”, “we”, “our”, or “us”) collects, uses, and protects information when you visit our website at brksoft.com or use our products, including the BrikPanel and BrikMentor WordPress plugins.
We respect your privacy. We collect only what we need to operate our website and provide our products, we do not sell personal data, and we do not use personal data for advertising profiling.
1. Who we are
Brksoft LTD is a company registered in England and Wales, company number 15199721, at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We publish the free BrikPanel WordPress plugin distributed on wordpress.org and the paid BrikMentor email automation plugin. You can contact us at any time at info@brksoft.com.
2. Information we collect
2.1 Information you provide directly
- If you send us an email or contact form message, we receive the email address and the contents of the message.
- If you create an account on brksoft.com (where offered), we receive the username, email address, and any profile fields you choose to fill in.
2.2 Information collected automatically when you visit brksoft.com
- Standard server log data such as IP address, user agent, referring URL, and timestamp. This is used to operate and secure the website and is automatically deleted after a short retention period.
- If we use cookies, only essential cookies are set by default. Any non-essential analytics or marketing cookies are loaded only after explicit consent through our cookie banner.
2.3 Information processed when you use BrikPanel
BrikPanel is a self-hosted WordPress plugin. The data BrikPanel processes (your store orders, customers, products) stays inside your own WordPress database on your own hosting and is never transmitted to Brksoft. We do not have access to it. BrikMentor works differently, because it sends email on your behalf: see 2.4 below.
BrikPanel contacts brksoft.com only in the following scenarios:
- OAuth proxy: If you connect a Google Ads or Meta Ads account inside the plugin, the OAuth handshake is routed through our proxy at
https://brksoft.com/wp-json/brikpanel-ads-proxy/v1/. We host this proxy centrally to keep API credentials (OAuth client_secret, Google Ads developer_token, Meta app_secret) out of the publicly distributed plugin source. The proxy is stateless for API calls: it exchanges the OAuth authorization code, hands the resulting access and refresh tokens back to your WordPress site through a one-time PKCE-verified handoff token, and forwards subsequent read-only API requests. The proxy does not log, store, or persist your OAuth tokens, your ad spend data, or any other data returned by the Google Ads or Meta Marketing APIs. Short-lived transients used only for the OAuth state and handoff are deleted automatically within 10 minutes. - Plugin update checks: Standard wordpress.org update checks may surface the website URL that runs the plugin. This is handled by WordPress itself, not by Brksoft.
- Optional anonymous telemetry: If you opt in inside the plugin settings, anonymized aggregate usage statistics (counts of features used, plugin version, WordPress version) may be sent to us so we can prioritize development. We never receive store data, customer data, or personally identifying information through this channel.
2.4 Information processed when you use BrikMentor
BrikMentor is a paid plugin that sends email on your behalf. Unlike BrikPanel, it cannot do its job without transmitting data to us.
Roles. For the personal data of your own customers, you are the controller and Brksoft LTD is your processor: we process it only to deliver the messages your flows produce, on your instructions, and never for our own purposes. For your account, billing and licence data, we are the controller.
What reaches us. When one of your flows sends a message, our relay receives the recipient’s email address, the name your store holds for them where one exists, the subject line and the rendered message. The message itself is used to deliver and is not stored. We keep a delivery log (recipient address, subject line, timestamp and delivery outcome) so that sending can be diagnosed and rate-limited, and a suppression list of addresses that unsubscribed, bounced or reported spam. The suppression list is retained after a contact is deleted, because it is the only way to guarantee we never write to that person again.
How long we keep it. After 90 days the delivery log is stripped of personal data: the recipient address is reduced to its domain and the subject line is cleared, leaving only the counts. The rows themselves are deleted after 400 days. On request we can erase a specific address from the log ahead of that schedule.
What does not reach us. Your orders, products, revenue figures and customer analytics stay in your own WordPress database. We do not receive them.
Our lawful basis. We process this data to perform our contract with you (delivering the email you ask us to send), and on our legitimate interest in keeping the service secure, preventing abuse, and protecting delivery for every store that shares our sending infrastructure. Your own lawful basis for writing to your customers is yours to determine; our Terms and Conditions set out what we require of you.
Sub-processors. Message delivery is carried out by Amazon Web Services (Amazon SES) in the eu-north-1 region. Our relay and website are hosted by Hostinger. These providers process the data on our behalf under data processing terms and may not use it for their own purposes.
Your customers’ rights. Every message carries a working unsubscribe link and one-click unsubscribe headers, and unsubscribes are honoured immediately and permanently. Requests we receive about a store’s customers are passed to that store, because the store is the controller; we act on the deletion and suppression instructions we receive from you.
3. How we use information
- To operate, maintain, and secure brksoft.com and the BrikPanel update infrastructure.
- To respond to support emails and feedback.
- To process the OAuth handshake between your WordPress site and Google or Meta when you choose to connect those services.
- To comply with legal obligations.
We do not use your data for advertising profiling. We do not sell your data. We do not share your data with data brokers.
4. Google API Services User Data Policy
BrikPanel’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when you connect a Google Ads account inside BrikPanel:
- We request only the scopes strictly necessary to display your ad spend and performance:
https://www.googleapis.com/auth/adwords,openid, andemail. - Access and refresh tokens are stored encrypted inside your own WordPress database, on your own hosting. Brksoft never has a copy.
- Data retrieved from the Google Ads API (daily spend, impressions, clicks, conversions, account name, currency) is stored only inside your own WordPress database and is shown back only to you, the connected store owner, inside your WordPress admin.
- We never transfer this data to third parties. We never use it for advertising or profiling. We never use it to train any generalized machine learning or AI model. We never sell it.
- Read-only access only. BrikPanel never creates, modifies, pauses, removes, or otherwise changes any Google Ads entity.
You can revoke BrikPanel’s access to your Google Ads account at any time by visiting https://myaccount.google.com/permissions and removing BrikPanel from the list of connected apps, or by clicking “Disconnect” inside the BrikPanel plugin settings.
5. Meta Platform data use
When you connect a Meta (Facebook) Ads account inside BrikPanel:
- We request only the
ads_read,email, andpublic_profilepermissions. - Access tokens are stored encrypted inside your own WordPress database. Brksoft never has a copy.
- Data retrieved from the Meta Marketing API is stored only inside your own WordPress database and shown back only to you.
- We never transfer this data to third parties, never use it for advertising or profiling, never use it to train AI models, and never sell it.
- Read-only access only. BrikPanel never creates, modifies, pauses, or removes any Meta ad entity.
You can revoke BrikPanel’s access to your Meta account at any time by visiting Facebook Business Integrations and removing BrikPanel, or by clicking “Disconnect” inside the BrikPanel plugin settings.
6. Data sharing
We do not sell personal data. We share personal data only in the following limited cases:
- Service providers: Our infrastructure providers process data on our behalf under appropriate data processing agreements and cannot use it for their own purposes. These are Hostinger (website and relay hosting) and Amazon Web Services (Amazon SES, email delivery, eu-north-1). BrikMentor’s use of these is described in 2.4.
- Legal requirements: If we are required by law, court order, or government regulator to disclose information, we will comply only to the extent legally required.
- Business transfers: If Brksoft is involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
7. Data security
We use industry-standard technical and organizational measures to protect information, including HTTPS encryption in transit, hardened server configurations, restricted internal access, and per-IP rate limiting on all proxy endpoints. No system is perfectly secure, but we treat security seriously and respond promptly to reported vulnerabilities. If you discover a security issue, please email info@brksoft.com.
8. Data retention
- Website server logs: up to 30 days.
- Contact emails: retained while the related conversation is active, then archived for a reasonable period (typically up to 24 months) for support continuity.
- OAuth proxy transients: automatically deleted within 10 minutes.
- Ad spend and other API data: not retained by us. It is stored only inside your own WordPress database, which you control and can delete at any time by uninstalling the plugin or clearing the relevant tables.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data.
- Restrict or object to certain processing.
- Request a portable copy of your data.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at info@brksoft.com. We respond within 30 days.
10. International transfers
Brksoft LTD is registered in England and Wales and operates from Turkey. Email delivery runs in the European Union (Amazon SES, eu-north-1). If you use our website or our products from elsewhere, please be aware that information we collect may be processed in the United Kingdom, Turkey, the European Union and other countries where our service providers operate. Where required by law, we rely on appropriate safeguards such as Standard Contractual Clauses and the UK International Data Transfer Addendum to ensure your data continues to be protected.
11. Children’s privacy
Brksoft’s website and products are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will always reflect the latest version. If we make material changes, we will give reasonable notice on brksoft.com or through other appropriate channels before the changes take effect.
13. Contact
Brksoft LTD
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Registered in England and Wales, company number 15199721
Email: info@brksoft.com
Website: https://brksoft.com