Privacy Policy

Effective date: 14 May 2026 / Last updated: 14 May 2026

This Privacy Policy explains how Brksoft E-commerce Systems (“Brksoft”, “we”, “our”, or “us”) collects, uses, and protects information when you visit our website at brksoft.com or use our products, including the BrikPanel WordPress plugin.

We respect your privacy. We collect only what we need to operate our website and provide our products, we do not sell personal data, and we do not use personal data for advertising profiling.

1. Who we are

Brksoft E-commerce Systems is the publisher of the free BrikPanel WordPress plugin distributed on wordpress.org. You can contact us at any time at info@brksoft.com.

2. Information we collect

2.1 Information you provide directly

  • If you send us an email or contact form message, we receive the email address and the contents of the message.
  • If you create an account on brksoft.com (where offered), we receive the username, email address, and any profile fields you choose to fill in.

2.2 Information collected automatically when you visit brksoft.com

  • Standard server log data such as IP address, user agent, referring URL, and timestamp. This is used to operate and secure the website and is automatically deleted after a short retention period.
  • If we use cookies, only essential cookies are set by default. Any non-essential analytics or marketing cookies are loaded only after explicit consent through our cookie banner.

2.3 Information processed when you use BrikPanel

BrikPanel is a self-hosted WordPress plugin. Most of the data the plugin processes (your store orders, customers, products) stays inside your own WordPress database on your own hosting and is never transmitted to Brksoft. We do not have access to it.

The plugin contacts brksoft.com only in the following scenarios:

  • OAuth proxy: If you connect a Google Ads or Meta Ads account inside the plugin, the OAuth handshake is routed through our proxy at https://brksoft.com/wp-json/brikpanel-ads-proxy/v1/. We host this proxy centrally to keep API credentials (OAuth client_secret, Google Ads developer_token, Meta app_secret) out of the publicly distributed plugin source. The proxy is stateless for API calls: it exchanges the OAuth authorization code, hands the resulting access and refresh tokens back to your WordPress site through a one-time PKCE-verified handoff token, and forwards subsequent read-only API requests. The proxy does not log, store, or persist your OAuth tokens, your ad spend data, or any other data returned by the Google Ads or Meta Marketing APIs. Short-lived transients used only for the OAuth state and handoff are deleted automatically within 10 minutes.
  • Plugin update checks: Standard wordpress.org update checks may surface the website URL that runs the plugin. This is handled by WordPress itself, not by Brksoft.
  • Optional anonymous telemetry: If you opt in inside the plugin settings, anonymized aggregate usage statistics (counts of features used, plugin version, WordPress version) may be sent to us so we can prioritize development. We never receive store data, customer data, or personally identifying information through this channel.

3. How we use information

  • To operate, maintain, and secure brksoft.com and the BrikPanel update infrastructure.
  • To respond to support emails and feedback.
  • To process the OAuth handshake between your WordPress site and Google or Meta when you choose to connect those services.
  • To comply with legal obligations.

We do not use your data for advertising profiling. We do not sell your data. We do not share your data with data brokers.

4. Google API Services User Data Policy

BrikPanel’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect a Google Ads account inside BrikPanel:

  • We request only the scopes strictly necessary to display your ad spend and performance: https://www.googleapis.com/auth/adwordsopenid, and email.
  • Access and refresh tokens are stored encrypted inside your own WordPress database, on your own hosting. Brksoft never has a copy.
  • Data retrieved from the Google Ads API (daily spend, impressions, clicks, conversions, account name, currency) is stored only inside your own WordPress database and is shown back only to you, the connected store owner, inside your WordPress admin.
  • We never transfer this data to third parties. We never use it for advertising or profiling. We never use it to train any generalized machine learning or AI model. We never sell it.
  • Read-only access only. BrikPanel never creates, modifies, pauses, removes, or otherwise changes any Google Ads entity.

You can revoke BrikPanel’s access to your Google Ads account at any time by visiting https://myaccount.google.com/permissions and removing BrikPanel from the list of connected apps, or by clicking “Disconnect” inside the BrikPanel plugin settings.

5. Meta Platform data use

When you connect a Meta (Facebook) Ads account inside BrikPanel:

  • We request only the ads_reademail, and public_profile permissions.
  • Access tokens are stored encrypted inside your own WordPress database. Brksoft never has a copy.
  • Data retrieved from the Meta Marketing API is stored only inside your own WordPress database and shown back only to you.
  • We never transfer this data to third parties, never use it for advertising or profiling, never use it to train AI models, and never sell it.
  • Read-only access only. BrikPanel never creates, modifies, pauses, or removes any Meta ad entity.

You can revoke BrikPanel’s access to your Meta account at any time by visiting Facebook Business Integrations and removing BrikPanel, or by clicking “Disconnect” inside the BrikPanel plugin settings.

6. Data sharing

We do not sell personal data. We share personal data only in the following limited cases:

  • Service providers: Our website hosting, transactional email, and similar infrastructure providers process data on our behalf under appropriate data processing agreements. They cannot use the data for their own purposes.
  • Legal requirements: If we are required by law, court order, or government regulator to disclose information, we will comply only to the extent legally required.
  • Business transfers: If Brksoft is involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.

7. Data security

We use industry-standard technical and organizational measures to protect information, including HTTPS encryption in transit, hardened server configurations, restricted internal access, and per-IP rate limiting on all proxy endpoints. No system is perfectly secure, but we treat security seriously and respond promptly to reported vulnerabilities. If you discover a security issue, please email info@brksoft.com.

8. Data retention

  • Website server logs: up to 30 days.
  • Contact emails: retained while the related conversation is active, then archived for a reasonable period (typically up to 24 months) for support continuity.
  • OAuth proxy transients: automatically deleted within 10 minutes.
  • Ad spend and other API data: not retained by us. It is stored only inside your own WordPress database, which you control and can delete at any time by uninstalling the plugin or clearing the relevant tables.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data.
  • Restrict or object to certain processing.
  • Request a portable copy of your data.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email us at info@brksoft.com. We respond within 30 days.

10. International transfers

Brksoft is based in Turkey. If you access our website or use BrikPanel from outside Turkey, please be aware that information we collect may be processed in Turkey and other countries where our service providers operate. Where required by law, we rely on appropriate safeguards such as Standard Contractual Clauses to ensure your data continues to be protected.

11. Children’s privacy

Brksoft’s website and products are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will always reflect the latest version. If we make material changes, we will give reasonable notice on brksoft.com or through other appropriate channels before the changes take effect.

13. Contact

Brksoft E-commerce Systems
Email: info@brksoft.com
Website: https://brksoft.com