Privacy Policy
Last updated: 4 May 2026
This Privacy Policy ("Policy") describes how Bleep Design Private Limited, a company incorporated under the laws of India, operating under the trade name NOW Media ("Company", "we", "us", or "our"), collects, uses, stores, and protects your personal information when you use the BrandAuditor platform at www.brandauditor.ai and all associated services (the "Service").
By using the Service, you consent to the data practices described in this Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information you provide
| Data | When collected | Purpose |
|---|---|---|
| Email address | Account registration (OTP or password sign-up) | Authentication, transactional emails, marketing communications |
| Name (optional) | Password sign-up or profile update | Personalisation, payment pre-fill, quote correspondence |
| Password (hashed) | Password sign-up | Authentication only; stored as a bcrypt hash, never in plaintext |
| Brand names queried | Each audit | Delivering audit results, usage analytics, product improvement |
| Payment information | Credit pack purchase | Payment processing via Razorpay; we do not store card details |
| Quote enquiry details | "Get a quote" form submission | Following up on your enquiry |
1.2 Information collected automatically
- Device and browser information: IP address, browser type and version, operating system, device type, screen resolution.
- Usage data: Pages visited, features used, audit counts, timestamps, referral source.
- Analytics: We use PostHog for product analytics. PostHog processes data on our behalf and does not sell or share your data with third parties.
- Bot protection: We use Cloudflare Turnstile to verify that sign-up requests originate from real users. Turnstile processes minimal device signals and does not use tracking cookies.
2. How We Use Your Information
- Service delivery: To authenticate you, run audits, deliver results, process payments, and provide customer support.
- Transactional communications: To send OTP codes, payment confirmations, credit-expiry reminders, trademark watch alerts, and quote acknowledgments. These emails are essential to the Service and are sent regardless of your marketing preferences.
- Marketing communications: We may send you product updates, feature announcements, tips for your branding journey, and information about complementary services offered by NOW Media or BrandAuditor. Every marketing email includes a one-click unsubscribe link. You can opt out at any time and we will honour your preference promptly.
- Product improvement: To analyse usage patterns, diagnose issues, improve the quality of audit results, and develop new features.
- Legal compliance: To comply with applicable laws, regulations, or legal process, including tax invoicing requirements under Indian GST law.
3. What We Do Not Do
- We do not sell your personal data to third parties. Our primary business is branding services for businesses, not data brokerage.
- We do not share your data with unrelated third-party advertisers or data brokers.
- Any commercial communications you receive will originate only from BrandAuditor or NOW Media - never from a third party who purchased your data from us.
4. Data Sharing
We share your personal information only in the following limited circumstances:
- Payment processor (Razorpay): To process your payments securely. Razorpay is PCI-DSS compliant and operates under its own privacy policy.
- Email provider (Resend): To deliver transactional and marketing emails on our behalf. Resend acts as a data processor and does not use your data for its own purposes.
- Analytics (PostHog): To track anonymised product usage. PostHog acts as a data processor.
- Legal obligations: If required by law, court order, or government request, we may disclose information as necessary to comply.
- Business transfer: In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity, subject to the same privacy commitments.
5. Data Retention
- Account data: Retained for as long as your account is active, plus a reasonable period to allow for reactivation.
- Audit results: Retained for up to 2 years to support historical comparison and product improvement, then anonymised or deleted.
- Payment records: Retained for a minimum of 8 financial years as required by Indian tax law.
- Marketing preferences: Your unsubscribe choice is retained indefinitely to ensure we continue to respect it.
6. Data Security
We implement industry-standard security measures to protect your personal information, including:
- Encrypted data transmission (HTTPS/TLS) on all connections.
- Passwords stored using bcrypt hashing with a cost factor of 12.
- Payment processing delegated to PCI-DSS-compliant Razorpay; no card details stored on our servers.
- Access controls limiting employee access to personal data on a need-to-know basis.
While we take reasonable precautions, no system is completely secure. We cannot guarantee the absolute security of your data.
7. Cookies and Tracking
BrandAuditor uses minimal cookies and local storage:
- Authentication token: Stored in browser local storage to keep you signed in across sessions.
- Theme preference: Stored in local storage to remember your dark/light mode choice.
- Analytics: PostHog may set first-party cookies for session tracking. No third-party advertising cookies are used.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated personal data (subject to legal retention requirements).
- Opt out of marketing communications at any time via the unsubscribe link in any email or by contacting us directly.
- Data portability: Request a copy of your data in a machine-readable format.
To exercise any of these rights, email us at hello@brandauditor.ai. We will respond within 30 days.
9. Children
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. International Users
The Service is operated from India. If you access the Service from outside India, you consent to the transfer of your information to India, where data protection laws may differ from those in your jurisdiction. We will take reasonable steps to ensure your data receives an adequate level of protection.
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated via the email address associated with your account or through a notice on the Service. Your continued use of the Service after such changes constitutes acceptance of the revised Policy.
12. Contact
For questions or concerns about this Privacy Policy or our data practices, contact us at: hello@brandauditor.ai
Bleep Design Private Limited (trading as NOW Media)
Kochi, Kerala, India