Trust & data security
How BrandBinder protects brand and dealer data.
BrandBinder hosts dealer-ready product, pricing, asset, access, and communication workflows for brand teams. This page summarizes the operational safeguards, backup posture, app-device behavior, and compliance support available today.
Short version: brands own their data; BrandBinder does not sell it, share private workspace data with other brands, or use it for outside sales or unrelated commercial purposes. Each workspace has a separate tenant database, and access is permissioned, logged, and revocable.
Data we host
BrandBinder may store workspace settings, staff users, dealer companies and contacts, addresses, product catalogs, pricing, hosted files, published pages, feed settings, form submissions, campaign activity, app pairing records, support requests, and application logs needed to operate the service.
Access controls
Brand teams control which staff, reps, dealers, and app-paired devices can see workspace resources. Dealer and rep access can be narrowed or revoked from the web workspace, and app pairings use scoped device tokens rather than a shared password.
Workspace isolation
Every BrandBinder workspace uses its own tenant database. Shared identity, authentication, billing, and workspace routing remain in a central control layer so authorized users can work across approved workspaces. Tenant databases run on shared BrandBinder infrastructure; this is database isolation, not a claim that every customer has a dedicated physical server.
Commercial-use firewall
BrandBinder does not sell customer or dealer information. Private workspace data is not disclosed to another brand unless the customer explicitly authorizes that workflow, and BrandBinder's owner will not use it for outside representation, prospecting, pricing intelligence, account targeting, or any unrelated business purpose.
Encryption and transport
BrandBinder uses HTTPS/TLS for browser, portal, and app traffic. Production storage controls are reviewed before stronger storage-security claims are published; we do not market zero-knowledge or end-to-end encryption because the service needs to preview, index, publish, and route authorized content.
Backups and recovery
We maintain daily database recovery points, weekly full recovery points, encrypted off-site snapshots, and an additional operational backup copy. Backup health and restore evidence are tracked internally, but customers should keep original source files outside BrandBinder because hosted assets are a distribution library, not a self-serve archive or disaster-recovery product.
Mac and iPhone apps
Approved Mac and iPhone apps may cache selected resources locally for faster access or offline use. Revoking an app pairing stops future access through BrandBinder, but files intentionally downloaded, exported, shared, or copied outside the app may remain on that device or in that user's storage.
Data location
Unless a customer agreement says otherwise, BrandBinder uses its standard production hosting environment. EU or dedicated-region hosting is not currently a self-serve feature; customers with data-residency requirements should discuss them during setup so the right agreement and deployment plan can be confirmed.
GDPR and international transfers
For customer workspace data, BrandBinder generally operates as a service provider or processor under the customer's instructions. Customers needing regulated-data handling, a negotiated DPA, fixed residency, or specific transfer safeguards must raise that requirement before launch so the supported terms can be confirmed.
Subprocessors and vendors
BrandBinder currently uses Contabo infrastructure, Dropbox for an additional backup copy, and its own mail service. PayPal, Apple, OpenAI, and customer-selected connectors apply only when their related features are used. Current details are available during onboarding or security review.
Retention, deletion, and export
Workspace data is retained while an account is active and needed to provide the service. Verified export, deletion, and account-close requests are handled according to the applicable agreement, legal obligations, integrity needs, and documented backup rotations. A fixed period for every operational record is not promised.
Security contact
Report suspected security issues to security@brandbinder.app and privacy or data requests to privacy@brandbinder.app. General support remains available at hello@brandbinder.app.