BrandUp Signal
隐私政策 · Privacy Policy
Brandup One Sdn. Bhd.(注册号 202601025801)提供两项 BrandUp Signal 产品,本政策同时涵盖两者:
- A. 预约管理系统(马来西亚市场,中文说明见下)— 商家接收顾客预约。
- B. Signal Autopilot(global SEO subscription, English section below) — connects your own Google Search Console and WordPress.
Part A · 预约管理系统
商家(例如美容院、诊所)使用本系统接收顾客预约;顾客通过商家的预约页提交预约资料。以下说明我们如何处理这些资料。
一、我们收集的资料 · What we collect
顾客提交预约时,我们收集:
- 姓名 · Name
- WhatsApp 号码 · WhatsApp number
- 预约的服务与时间 · Service and appointment time
- 顾客备注(如有)· Optional note
- 广告来源参数(utm_source、utm_campaign、fbclid)· Ad attribution parameters
我们不会收集顾客的电子邮箱地址、身份证号码或付款卡资料。商家账户登录时,我们仅收集登录邮箱地址用于身份验证。
二、资料的用途 · How we use it
- 通过 WhatsApp 向顾客发送预约确认与到店提醒
- 通知商家有新预约,方便人工跟进
- 让商家在管理后台查看与管理自己的预约
- 广告来源参数仅用于让商家了解预约来自哪个广告
我们不会将顾客资料出售给第三方,也不会用于与该商家预约无关的营销用途。
三、储存与安全 · Storage and security
资料储存在 Supabase 托管的 PostgreSQL 数据库,并启用行级安全策略(Row Level Security),确保每个商家只能读取自己的预约资料。WhatsApp 消息通过 Meta 官方 WhatsApp Business Platform (Cloud API) 发送。
四、第三方服务 · Third-party services
- Meta / WhatsApp Business Platform — 发送预约通知
- Supabase — 数据库与登录验证
- Vercel — 应用托管
五、保留期限 · Data retention
预约资料默认保留 24 个月,供商家查询历史记录;超过期限或经要求后会被删除。
六、您的权利 · Your rights
您可以要求查询、更正或删除您的预约资料。请直接联系为您服务的商家,或通过下方邮箱联系我们,我们会在合理时间内处理。
Part B · Signal Autopilot
Signal Autopilot is a subscription that improves one website you own. It reads your site, connects to your Google Search Console with read-only access, prepares one change at a time, and — only after you approve that specific change — publishes it to WordPress if you connected it.
What we collect
- Account: your email address, used for sign-in and service email.
- Website: the URL you add, and publicly available content from its pages, which we fetch the same way a search engine would.
- Google Search Console data (only if you connect it): the list of properties you have access to, and search performance rows — query, page, clicks, impressions, click-through rate and average position. Access is read-only. Signal cannot change anything in your Google account.
- WordPress credentials (only if you connect it): a WordPress Application Password, which you can revoke from WordPress at any time.
- Billing: handled by Stripe. We receive your subscription status and customer identifier. We never receive or store your card number.
- Usage: records of audits, syncs, drafts and publishes, used for cost control and support.
How we use Google user data
Search Console data is used for one purpose: to choose which page and search query are worth improving, to prepare that improvement, and to measure the same query and page afterwards so you can see what changed.
Limited Use: Signal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it to train generalised AI or machine-learning models. Humans do not read your Search Console data except where you ask us for support, or where it is strictly necessary to investigate a fault or a security or legal issue.
AI providers and what reaches them
Signal uses third-party AI services to analyse pages and prepare recommendations. We are specific about what leaves our systems:
- Preparing a recommendation sends the target page URL, publicly readable text from that page, your locale and market, and one Search Console query string — the search term being improved for. No other Search Console data is sent.
- AI visibility checks are optional and off unless you switch them on. When enabled, they send only your domain, your brand name, and the selected buyer questions to configured AI search providers, in order to test whether those engines mention you.
- Never sent to any AI provider: your Google access or refresh tokens, your WordPress credentials, your Stripe or billing data, your email address, or Search Console datasets beyond the single query described above.
Storage and security
Data is stored in a Supabase-hosted PostgreSQL database with row-level security, so each account can only read its own records. Google tokens and WordPress credentials are encrypted with AES-256-GCM before storage and are readable only by server-side code — never by the browser, and never by other customers. Credentials, tokens and payment details are excluded from our logs.
Sharing
We do not sell your data. We share it only with the processors that run the service: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (service email), Google (Search Console API), and the AI providers described above, limited to the data listed there.
Your controls
- Disconnect Search Console inside Signal at any time, or revoke access from your Google account permissions. Disconnecting stops all further reads and deletes the stored token.
- Disconnect WordPress inside Signal, or revoke the Application Password from WordPress. Removing a change Signal published to your site remains available to you even after you cancel your subscription.
- Turn AI visibility off at any time. Doing so stops future checks without affecting Search Console sync, your history, or rollback.
- Request access, correction or deletion of your data by emailing us. Deleting your account removes your sites, connections, stored credentials and history.
Retention
Account, site and search-performance records are kept while your account is open, so that measurement can compare periods over time, and are deleted on request or within 90 days of account deletion. Anonymous audit reports are retained for 12 months. Billing records are kept as long as tax and accounting law requires.
International transfer
Signal Autopilot is available globally and our processors operate internationally, so your data may be processed outside your country, including in the United States and the European Union.
七、联系我们 · Contact
Brandup One Sdn. Bhd.
Registration No. 202601025801 (1687897-X)
Email: sales@brandupdesignmarketing.com