Privacy Policy

Effective date: 7 September 2026

This policy explains how Jugraj Solutions LLP ("we", "us"), the operator of Brand Scalers, collects, uses, stores and deletes personal data. It covers our website at https://brandscalers.in, our web application, and the services we provide through them. We have written it in plain language on purpose. If anything is unclear, write to kushagra@brandscalers.in and we will explain.

1. Who we are

Brand Scalers is a marketing platform operated by Jugraj Solutions LLP, based in India. For the purposes of applicable data protection law, including India's Digital Personal Data Protection Act, 2023, Jugraj Solutions LLP is the data fiduciary for data collected through this website, and processes customer campaign data on our customers' instructions.

2. What data we collect

Data you give us directly

  • Contact details when you fill a form or book a demo: name, phone number, email, business type and anything you write in a message.
  • Account details when you sign up: name, email, business name and password (stored only in hashed form).
  • Billing details when you subscribe: plan, invoices and payment status. Card and bank details are handled by our payment processor and never touch our servers.

Data from connected platform accounts

When you connect your Amazon, Meta or Google accounts to the platform, we access data through their official APIs, only with your explicit authorisation and only to provide the service:

  • Ad account structure: campaigns, ad sets, ads, budgets and settings.
  • Performance metrics: impressions, clicks, spend, conversions and similar statistics.
  • Lead data submitted by your potential customers through lead forms you run, which we deliver to you.
  • Page and business profile information needed to run campaigns on your behalf.

Amazon seller data

If you connect an Amazon seller or advertising account, we use Amazon's official APIs to retrieve only the data needed for the features you enable. The initial service does not request restricted Orders roles or Amazon buyer personally identifiable information.

  • Seller account and marketplace identifiers needed to maintain the authorised connection.
  • Catalog and listing data, including SKUs, ASINs, titles, attributes and listing status.
  • Inventory quantities, prices and fulfilment or availability status.
  • Advertising campaign structure, budgets, status and aggregated performance metrics.
  • Aggregated business and product-performance reports made available by the permissions you approve.

We use Amazon data only to show your own reports and to perform actions you explicitly request or approve. We do not sell it, use it to advertise unrelated products, build profiles of Amazon buyers, or share one seller's data with another seller. Disconnecting the integration stops new API access; you can also revoke authorisation in Amazon Seller Central.

We request the minimum permissions needed for the features you use. An available Disconnect control removes the credential stored by Brand Scalers and stops new API access by our product; it does not cancel the permission at the connected platform. You can revoke that permission in the platform's account settings. If a connection has no Disconnect control, or you want associated stored data deleted, use our data deletion process.

Enquiries on tenant business websites

A contact form on a website built with BrandScalers identifies the receiving business. It collects your name, email, optional phone number and message, and stores them as that business's leads in its BrandScalers CRM for handling your enquiry. BrandScalers supplies the platform and processes these leads to provide that service; the business is responsible for its lawful collection, use and follow-up communications. Sending an enquiry does not opt you into promotional messages, and this form does not send automated advertising or marketing messages.

Do not submit sensitive medical, financial or legal information, passwords, payment details or emergencies. To ask about access, correction or deletion, contact the receiving business or follow our data deletion process. You do not need a BrandScalers account to request deletion of an enquiry. We may need to verify the request.

Data collected automatically

  • Basic usage data: pages visited, features used, approximate location from IP address, browser and device type.
  • Cookies as described in our cookie policy.

3. How we use data

  • To provide the service: planning, running and reporting on your campaigns.
  • To deliver leads from your campaigns to you quickly.
  • To respond to enquiries and provide support.
  • To bill you and maintain business records required by law.
  • To improve the platform, using aggregated and de-identified information wherever possible.
  • To keep the service secure and prevent abuse.

We do not sell personal data. We do not use your customers' lead data for anything except delivering it to you and showing you your own reporting.

4. Platform-specific commitments

Amazon seller data is handled in accordance with the Amazon Selling Partner API policies and Acceptable Use Policy. Amazon credentials are encrypted separately from application data, access is logged, and only authorised members of your workspace can view or act on the connected account. Brand Scalers is an independent service and is not endorsed by or affiliated with Amazon.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide user-facing features of the platform, is never sold, and is never used for advertising unrelated to the service you asked us to provide.

Each Google connection is optional and limited to the account and resource you select. Depending on the tools you enable, we use Google API data as follows:

  • Google Ads: list accessible advertiser accounts, read campaign and performance data, and carry out campaign actions you review and confirm. See the complete Google Ads API use disclosure.
  • Google Analytics 4: list the properties you can access, read aggregated acquisition, landing-page and key-event reports, and, only after separate permission and confirmation, create or update a key event in the selected property.
  • Google Tag Manager: list and audit containers, tags, triggers, variables and versions, and, only after separate permission and confirmation, create an unpublished workspace/version or publish an exactly reviewed version in the selected container.
  • Google Search Console: list verified properties and read search and indexing data, and, only after separate permission and confirmation, submit an exact sitemap URL for the selected property.
  • Google Business Profile: list manageable locations; read profile, performance and review information; and carry out supported profile, post or review-reply actions you review and confirm for the selected location.
  • YouTube: identify an owned channel and, for the modes you choose, read channel/video analytics and comments, upload an explicitly reviewed private test video, or publish an exactly reviewed reply to an existing comment on an owned video.

We request read access by default where Google offers it and ask for additional permissions only when you enable a feature that needs them. We store the selected resource identifiers and an encrypted OAuth refresh token. We do not request Gmail, Drive, contacts, Merchant Center or unrelated Google data. Google Ads, Google Analytics and Tag Manager, Business Profile, and YouTube provide in-product Disconnect controls that delete their stored OAuth credentials. A Search Console connection can also be removed with its Disconnect control when that control is available in your deployed version. Otherwise, use our data deletion process or email kushagra@brandscalers.in to ask us to delete its stored credential. Separately, you can revoke Brand Scalers' permission from your Google Account to invalidate the Google grant and stop future Google API access. Provider revocation does not itself delete data already stored by Brand Scalers.

Our use of Meta Platform data complies with the Meta Platform Terms. Lead data retrieved from Meta lead ads is delivered to the business that ran the campaign and is not shared with or sold to anyone else.

5. When we share data

We share data only with:

  • Service providers we use to run the platform, such as cloud hosting, database and email providers, bound by their own confidentiality and data protection obligations.
  • The advertising platforms you connect, to the extent needed to run your campaigns.
  • Authorities, if the law requires it and the request is valid.

6. How long we keep data

  • Enquiry form data submitted directly to BrandScalers for its own sales or support: up to 24 months after last contact, then deleted.
  • Account and campaign data: for as long as your account is active, then deleted within 90 days of account closure, except records we must keep for tax and accounting law.
  • Lead data belonging to your customers: retained while your account is active so your reports stay accurate, deleted on the same schedule, and earlier if you or the person concerned asks.
  • Enquiries through tenant-generated websites are tenant-owned leads under that account schedule, including after the originating website is archived or deleted. Source attribution remains in the tenant CRM. A tenant can delete an enquiry there; valid visitor requests follow our deletion process. Deleting a website alone does not delete its leads.
  • Amazon non-personal seller data: retained only while needed to provide the service and never longer than 18 months, unless law requires a specific record to be kept.
  • Amazon credentials: deleted when you disconnect the integration or close your account. If Amazon directs us to delete Amazon data, we complete the deletion within 30 days.
  • Google OAuth credentials: deleted when you use an available in-product Disconnect control, when we complete a verified deletion request, or when you close your account. Cached Google reporting data and selected resource identifiers follow the account-data schedule above. Revoking permission in your Google Account stops future Google API access but does not itself delete data already stored by Brand Scalers.
  • Security audit records: retained for 12 months or longer where required for investigation, without storing Amazon buyer PII or access tokens in logs.

7. Your rights

You can, at any time:

  • Ask what personal data we hold about you.
  • Ask us to correct it.
  • Ask us to delete it. See our data deletion page for the exact steps and timelines.
  • Withdraw consent for any processing based on consent.
  • Complain to the relevant data protection authority.

To exercise any of these, email kushagra@brandscalers.in. We respond within 7 business days and complete verified requests within 30 days.

8. Security

Data is encrypted in transit, access is restricted to people who need it for their work, and API credentials for your connected accounts are stored encrypted. More detail is on our security page. No system is perfectly secure; if a breach ever affects your data, we will inform you promptly and honestly.

9. Children

The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.

10. Changes to this policy

If we change this policy, we will update the effective date at the top and, for significant changes, notify account holders by email before the change takes effect.

11. Contact

Jugraj Solutions LLP
3, Teja 309, My Home Navadweepa, Hitech City Road, HITEC City, Hyderabad, Rangareddy, Telangana, 500081, India
Email: kushagra@brandscalers.in
General contact: getintouch@brandscalers.in