Privacy Standard • Version 1.0.0

Privacy Policy

Last revised: October 1, 2026 • Version 1.0.0

1

Information We Collect & Ingest

Branchstory collects and processes information solely to provide multi-location customer reputation operations and issue resolution management. This information falls into three categories:

  • Account & Profile Information: When an administrator registers or invites team members, we collect names, corporate email addresses, encrypted password hashes, organization names, and location assignments.
  • External Platform Data (Google Business Profile): When an organization authorizes our Google integration, we ingest location account IDs, branch names, street addresses, star ratings, customer review timestamps, review commentary, reviewer public names, and existing merchant replies.
  • Operational & Resolution Metadata: Internal issue statuses (open, in progress, resolved, verified), root-cause tags, assigned manager IDs, resolution proof notes, and operational timestamps generated within the Branchstory dashboard.
2

Multi-Tenant Isolation & Cryptographic Storage

Branchstory is engineered with rigorous architectural boundaries to protect the confidentiality of organizational data:

Zero Cross-Tenant Leakage

Every database query authoritatively enforces the verified organization ID from server-side sessions. Cross-tenant access is architecturally prevented.

AES-256-GCM Token Encryption

All OAuth integration tokens, API secrets, and sensitive credentials are encrypted at rest with AES-256-GCM and unique initialization vectors.

Passwords are cryptographically hashed using bcrypt (12 rounds) or Argon2id. We never log, store, or transmit plaintext credentials. Sessions are managed using cryptographically random 64-character tokens stored exclusively in secure, HTTP-only, SameSite cookies.

3

Google API Limited Use Policy Disclosure

Strict Adherence to Google Limited Use Standards:

Branchstory's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only request permissions strictly required to synchronize customer reviews and publish authorized responses on behalf of the location owner.
  • We do not transfer or sell Google user data to third parties, advertising networks, data brokers, or information resellers.
  • We do not use Google user data to serve targeted advertisements or personalized advertising profiles.
  • Humans do not read your Google user data unless you provide explicit consent to investigate a technical issue or as strictly required for security/legal compliance.
4

AI Analysis & Processing Boundaries

When customer review text is processed through our multi-provider AI pipeline (for problem classification, sentiment extraction, and suggested draft replies):

  • Review data is processed transiently and is never used to train public machine learning foundation models.
  • Internal operational metrics, employee identities, and billing records are never submitted to third-party AI provider inference APIs.
  • All AI outputs are labeled as hypotheses and require explicit human manager authorization before execution or publishing.
5

Right to Deletion, Access & Data Portability

Under applicable data protection laws (including GDPR and CCPA), you possess explicit rights regarding your organizational and personal information:

  • Right to Deletion ("Forget Me"): You may request complete erasure of your user profile, organization account, and all ingested operational data by contacting privacy@branchstory.com or clicking "Delete Organization" under Account Settings. Upon request, all data is permanently scrubbed from our production databases within thirty (30) days.
  • Right to Export: Administrators may export all review records, issue audit trails, and location logs in structured JSON/CSV format at any time.
  • OAuth Revocation: You may instantly sever Google Business Profile synchronization from the Integrations page, which triggers automatic deletion of stored access and refresh tokens.
6

Security Governance & Privacy Inquiries

We deploy strict physical, electronic, and administrative safeguards to protect your information against unauthorized alteration, disclosure, or destruction. We maintain continuous automated rate-limiting, CSP/HSTS transport security, and automated indexing safeguards.

For privacy inquiries, data subject access requests, or regulatory questions, reach our Data Protection Officer at:

Branchstory Data Protection Officer
Email: privacy@branchstory.com
Subject: Data Privacy & Security Governance Request
© 2026 Branchstory. All rights reserved.