Return

Privacy Policy

Privacy Policy

Effective February 13, 2026, updated for legal entity review on May 20, 2026

This Privacy Policy explains how Ecombrain Solution LLC, a Wyoming limited liability company, collects, uses, shares, retains, and protects personal data across the website, autonomous commerce platform, integrations, support, billing, AI features, and partner program.

1. Controller, processor, and contact

Ecombrain Solution LLC, a Wyoming limited liability company, operates EcomBrain. For account, billing, website, support, partner, sales, and marketing data, EcomBrain acts as controller or business under applicable privacy laws.

For merchant customer, order, product, advertising, email, analytics, and connected commerce data processed through merchant integrations, EcomBrain generally acts as processor, service provider, or sub-processor on behalf of the merchant. The merchant remains responsible for its own customer notices, lawful basis, consent, platform permissions, and instructions to EcomBrain.

Privacy requests may be sent to privacy@ecombrain.io. Legal notices may be sent to legal@ecombrain.io or by mail to Ecombrain Solution LLC, 30 N Gould St Ste 5240, Sheridan, WY 82801, United States.

2. Scope and applicable laws

This Policy is intended to cover privacy obligations where applicable under GDPR, UK GDPR, the Swiss FADP, California privacy laws including CCPA/CPRA-style rights, and other US state or international privacy laws that may apply to EcomBrain or its customers.

If a customer signs a Data Processing Agreement, order form, or enterprise agreement with EcomBrain, that agreement controls where it conflicts with this public Policy for processor activities.

3. Personal data we collect

We collect account and contact data, billing and subscription data, usage data, technical data, communication data, partner application data, security data, and consent records.

When a merchant connects third-party tools, we may process commerce data from those tools, including product catalogs, order history, customer segments, advertising campaigns, email performance, analytics data, inventory data, margins, refunds, support records, trust-level settings, approval workflows, and autonomous action logs.

  • Shopify
  • Meta Ads
  • Google Ads
  • TikTok Ads
  • Klaviyo
  • GA4
  • Stripe
  • Support and logistics tools

4. How we use data

We use data to provide the Service, authenticate users, connect integrations, run first analysis and execution workflows, analyze commerce performance, identify revenue opportunities, generate recommendations, execute authorized actions, maintain security, prevent fraud and abuse, provide support, process payments, communicate with users, improve reliability, and comply with legal obligations.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising unless a customer has expressly configured or authorized such use through connected advertising tools and applicable law permits it.

6. AI processing and no-training commitment

EcomBrain uses AI systems and third-party AI subprocessors to analyze commerce data, generate insights, classify issues, surface margin leaks, draft actions, and power autonomous workflows. AI outputs are probabilistic and may be incomplete or inaccurate.

We do not use merchant data, customer data, derived data, or aggregated merchant/customer data to train, fine-tune, or improve general-purpose AI or ML models. Third-party AI subprocessors may process prompts, outputs, and related data only to provide inference services under contractual restrictions, and not for model training except as expressly authorized by the merchant and permitted by applicable platform rules and law.

  • OpenAI
  • Anthropic
  • Other AI subprocessors added only after policy/subprocessor updates

7. Cookies, consent, and tracking

Strictly necessary technologies may be used for security, fraud prevention, consent storage, form protection, authentication, load balancing, and service operation. These do not require opt-in consent where applicable law permits essential use.

Consistent with the live privacy policy, EcomBrain should not use advertising cookies, retargeting pixels, ad-network tracking, or cross-site browsing data. Optional analytics, heatmaps, chat widgets, social embeds, and other non-essential scripts should not run for EU, UK, or Swiss visitors unless the relevant consent category has been accepted.

Cloudflare Turnstile or similar anti-abuse tooling may be treated as necessary where used to protect forms, but it must still be disclosed.

  • Strictly necessary
  • Analytics
  • Functional embeds
  • No advertising cookies

8. Processors and subprocessors

EcomBrain uses subprocessors for hosting, database/storage, AI inference, payments, email, support, security, analytics, form protection, and connected integrations. A production-ready version should maintain a current subprocessor table listing name, purpose, location, data categories, and transfer mechanism.

Customers should be notified of material subprocessor changes where required by law or contract.

  • Hosting/CDN
  • Database/storage
  • OpenAI/Anthropic-style AI providers
  • Stripe-style payment processors
  • Email providers
  • Cloudflare Turnstile-style security
  • GA4 if enabled

9. International transfers

Data may be processed in the United States, European Economic Area, United Kingdom, Switzerland, or other countries where EcomBrain or subprocessors operate. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses, the UK IDTA/Addendum, Swiss SCC adaptations, data processing agreements, and supplementary safeguards.

10. Retention

We retain data only as long as needed for the purposes described in this Policy, contractual obligations, security, legal compliance, tax/accounting duties, dispute resolution, and backup integrity.

Account and commerce data is generally retained for the active account period plus a reasonable deletion/export window. Billing records may be retained for tax/accounting periods. Security logs, action logs, and audit logs may be retained longer where needed to investigate abuse, verify actions, or comply with law.

11. Your rights

Depending on your location and role, you may have rights to access, delete, correct, port, restrict, object to processing, withdraw consent, opt out of sale/share, limit sensitive personal information, and avoid discrimination for exercising privacy rights.

Requests about a merchant's own customers may be redirected to the merchant unless EcomBrain independently acts as controller for that data. We may verify identity and authority before fulfilling a request.

12. Security

We use administrative, technical, and organizational safeguards designed to protect data, including encryption in transit, access controls, audit logging, tenant separation, least-privilege practices, and security monitoring.

No system is perfectly secure. Customers are responsible for account credentials, integration permissions, and internal access management.

13. Children

EcomBrain is intended for businesses and is not directed to children under 18. We do not knowingly collect personal data from children.

14. Changes

We may update this Policy as our service, subprocessors, legal obligations, or data practices change. Material changes will be communicated where required by law or contract.

Questions or notices

Send legal or privacy requests to the correct EcomBrain inbox so they can be tracked.

privacy@ecombrain.io

Privacy choices

We use necessary technology to keep EcomBrain secure and remember your choices. Optional analytics, support widgets, and functional embeds only run when you allow them. EcomBrain does not use advertising cookies.