1. Scope
This Privacy Policy applies to BrizBuilder's website, CRM, dashboards, communications features, automations, support, and connected third-party services. A business or agency that uses BrizBuilder may also have its own privacy notice for information it collects from customers. That business or agency controls its customer relationships and is responsible for providing any notice or consent required by law.
2. Information we collect
Depending on how BrizBuilder is used, we may collect:
- account information such as name, email address, role, login events, organization, and assigned client workspace;
- business and CRM information such as contacts, leads, service requests, tasks, notes, appointments, websites, and workflow settings;
- communications information such as phone numbers, message content, call status, delivery status, consent, and opt-out records;
- connected-account information returned by providers you authorize, including account identifiers, profile details, locations, connection health, and granted permissions; and
- technical and security information such as timestamps, request metadata, audit events, device or browser details, and error logs.
BrizBuilder does not ask for or store the password to a connected Google or Twilio account. Authorization is performed on the provider's own sign-in page.
3. How we use information
We use information to provide and secure the Service, isolate client workspaces, operate requested integrations, send or receive communications authorized by the account owner, troubleshoot errors, maintain audit trails, prevent misuse, and comply with legal obligations. We may also use aggregated or de-identified information to understand reliability and improve the Service when it cannot reasonably identify a person or client.
4. Google user data
When a user chooses Connect Google, BrizBuilder requests the Google Business Profile permission needed to manage business listings the user already owns or manages. Depending on the feature used, BrizBuilder may access authorized account and location identifiers, business names, categories, addresses, phone numbers, websites, service areas, profile status, reviews, and business replies.
Google information is used only to show and manage the authorized business profile inside the correct BrizBuilder client workspace, synchronize requested profile information, display reviews, and perform a profile change or review reply that an authorized user explicitly approves. BrizBuilder does not use Google user data for advertising, sell it, or transfer it to data brokers.
BrizBuilder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google authorization tokens are encrypted before storage. A user can disconnect Google in BrizBuilder or remove BrizBuilder from Google Account permissions at any time.
5. Communications and Twilio data
When Twilio is connected, BrizBuilder uses the connected customer-owned account to provide phone, messaging, status, and automation features requested by that account. The business or agency is responsible for recipient consent, lawful use, sender identification, opt-outs, registration, and retention duties that apply to its communications.
7. Retention and deletion
We retain account and customer data while it is needed to provide the Service, meet the account owner's instructions, maintain security and audit records, resolve disputes, and satisfy legal obligations. Retention periods vary by record type and contract.
Google API content is refreshed when needed and is not cached longer than permitted by Google's policies. Google refresh tokens are retained only while the connection remains active. Disconnecting removes the local token and selected Google profile association; any remaining provider disassociation is completed within seven business days. Backups and legally required records may take longer to expire but are not used for ordinary product activity.
8. Security
BrizBuilder uses access controls, tenant checks, encrypted transport, protected deployment secrets, encrypted provider tokens, audit logging, and least-privilege integration scopes. No system is completely secure, and users must protect their accounts, connected providers, and authorized team access.
9. Your choices and rights
Authorized users can review or update many records in the dashboard, disconnect integrations, and manage team access. To request access, correction, export, restriction, or deletion of information, contact the business that collected the data or email BrizBuilder at brizuelaleads@gmail.com. We may verify the requester's identity and authority before acting.
10. Children
BrizBuilder is a business service and is not directed to children under 13. We do not knowingly collect personal information from children through account registration.
11. Changes to this Policy
We may update this Policy as BrizBuilder, connected providers, or legal requirements change. The date above will be revised when an update is posted. Material changes will be communicated through the Service or another reasonable channel when required.
12. Contact
For privacy questions, Google data questions, or deletion requests, email brizuelaleads@gmail.com and identify the relevant BrizBuilder organization or client workspace.
