Skip to content

Privacy Policy

Last updated 29 September 2026

Draft under legal review. This page describes how Brandlane works today, but the wording hasn’t been reviewed by a lawyer yet and may change. Questions: getbrandlane@gmail.com.

This policy explains what personal data Brandlane (“Brandlane”, “we”, “us”) handles, why, who it is shared with, how long it is kept, and the choices you have. Brandlane is operated from Coimbatore, Tamil Nadu, India.

Two kinds of data, two roles

  • Our customers’ account data. When a business signs up (a “customer”), we decide how their account data is used. For this data we are responsible for it.
  • Our customers’ contacts. Customers store their own contacts in Brandlane (for example people who fill in their lead forms). The customer decides why and how those contacts are used; we process that data on the customer’s behalf and only to provide the service. If you are someone’s contact and want your data changed or removed, contact that business first. You can also write to us and we will pass your request on and help them act on it.

What we collect

From customers and their team members

  • Name, email address and password (the password is handled by our sign-in provider; we never see it).
  • Workspace details: business name, time zone, country, plan and team roles.
  • WhatsApp Business connection details received from Meta when you connect a number (account and number IDs, and an access token stored encrypted).
  • Records of actions in your workspace needed to run it, such as imports and bulk actions.

Contacts customers store in Brandlane

  • Phone number, name, and any tags or custom fields the customer adds.
  • Consent records: whether a person opted in or out, when, how, and for form sign-ups the exact wording they saw, its version and the page they were on.
  • For lead forms: what the person typed, which form and page it came from, and campaign (UTM) tags in the page address.

From people who fill in a Brandlane lead form

  • What they type into the form.
  • A one-way, daily-changing code derived from their IP address (not the address itself), used only to spot abuse. It is deleted after 30 days. Raw IP addresses are used only briefly to apply rate limits and are not stored.
  • Forms are protected by Cloudflare Turnstile, which checks the visitor’s browser to tell people from bots. Cloudflare processes that data under its own privacy policy.

This website

brandlane.online does not use analytics, advertising or tracking cookies, and loads no third-party scripts except the early-access form (a Brandlane lead form). Its fonts are served from our own site.

Why we use it

  • To provide the service: sign-in, workspaces, contacts, lead forms and connecting WhatsApp numbers.
  • To keep it secure and stop abuse, such as spam submissions.
  • To contact customers about their account, and to reply to early-access requests.
  • To meet legal obligations.

We do not sell personal data, and we do not use customers’ contacts for our own marketing.

WhatsApp messages

Brandlane is built for Meta’s WhatsApp Business Platform (Cloud API). When WhatsApp messaging is enabled for a customer, message content passes through Meta’s systems and is also subject to Meta’s terms and policies. Brandlane never sends messages to a customer’s contacts on its own: the customer decides what is sent and to whom, and opted-out contacts are excluded.

Who we share data with

We use these providers to run Brandlane, only for the purposes above:

  • Supabase: database and sign-in. Our database is hosted in the AWS Mumbai region (India).
  • Resend: sends account emails such as sign-up confirmations, password resets and team invitations.
  • Cloudflare: website hosting and security, network protection, and Turnstile spam checks on forms.
  • Meta Platforms: the WhatsApp Business Platform, and Facebook Login when you connect a WhatsApp Business account.

Some of these providers may process data outside India. Before we start using any new provider that handles personal data (for example a payment provider when paid plans begin, or file storage for media), we will add it to this list.

How long we keep data

  • Account and workspace data: for as long as the account is open, then deleted on request unless we must keep it by law.
  • Contacts: until the customer deletes them. When a contact is deleted, what they typed into lead forms is erased. Their phone number and consent history are kept so that, if the number is added again, an earlier opt-out is still respected.
  • Lead-form sign-ups held back by a customer’s limits, and blocked spam: deleted after 30 days.
  • The daily IP-derived code on form submissions: cleared after 30 days.

Your choices and rights

You can ask to see, correct or delete personal data we hold about you, or withdraw consent you gave us, by emailing getbrandlane@gmail.com. We will confirm who you are before acting and reply within a reasonable time. If your data is held by one of our customers, we will help that business act on your request.

Security

Data is encrypted in transit, access tokens are encrypted at rest, each workspace’s data is kept separate from every other workspace, and access is limited to what is needed to run the service.

Children

Brandlane is a business service and is not meant for children.

Changes

If we change this policy, we will update the date at the top and, for significant changes, tell customers by email.

Contact

Questions or requests about privacy: getbrandlane@gmail.com, Brandlane, Coimbatore, Tamil Nadu, India.