BRDG
PlatformAboutPricingWatch a demoFree checkup →
Privacy policy

Data with clear boundaries.

This policy explains what BRDG processes across our website, Shopify app, storefront runtime, Agent API, and support channels—and the choices available to merchants and shoppers.

Last updated: July 15, 2026

Legal overviewPrivacyTermsDPACookiesSubprocessors

The short version. BRDG does not sell personal information or use shopper data for cross-context behavioral advertising. Raw shopper contact data stays in the consent-gated storefront and merchant workflows; it does not cross the Agent API or MCP boundary.

1. Who we are and when this policy applies

BRDG is adaptive commerce software for Shopify merchants, operated by Stratesee (collectively, “BRDG,” “we,” “us,” or “our”). This policy applies to getbrdg.ai, the BRDG Shopify app, our storefront software development kit, Agent API and MCP interfaces, store checkups, and related support and communications.

For merchant account, website, commercial, and service-security information, BRDG generally acts as a controller or business. For shopper and customer information processed under a merchant's instructions, the merchant is the controller or business and BRDG acts as its processor or service provider. Our Data Processing Addendum describes those processor obligations.

2. Information we collect

  • Merchant and account information. Store identity, account and admin details, installation state, plan, billing status, permissions, API-key metadata, agent identities, approval history, support messages, and commercial records.
  • Shopify and store information. Data made available through authorized Shopify scopes, such as catalog, product, collection, theme, order, customer, discount, content, and store configuration data. The exact data depends on the features and scopes a merchant enables.
  • Storefront activity. Pseudonymous visitor and session identifiers, page and device context, render decisions, experiment or deployment assignments, exposures, interactions, conversions, attributed orders and revenue, event health, and consent state.
  • Shopper submissions. When a merchant deploys a consent-gated form or workflow, BRDG may process declared fields such as name, email, phone, shipping or project details, product and variant identifiers, quantities, notes, and separate email or SMS consent choices. Undeclared submission fields are not retained by the submission runtime.
  • Developer and agent activity. Registered-tool manifests and bundles, validation reports, proposals, commands, API requests, audit records, outcome events, and technical diagnostics. Agent-facing interfaces are designed to exclude raw shopper PII.
  • Website, checkup, and contact information. Store URLs and public storefront content submitted for a checkup, form responses, booking details, email, and standard request logs such as IP address, user agent, timestamps, and error information.

3. Where information comes from

We receive information from merchants and their authorized agents, Shopify and enabled integrations, shoppers who interact with merchant storefronts, visitors who use our website or checkup, and technical systems that operate and secure the service. A store checkup reads the public storefront URL a visitor submits; it does not require Shopify admin access.

4. How we use information

  • Provide, authenticate, bill, maintain, and support BRDG.
  • Sync and index approved store context, validate tools, make governed render decisions, measure outcomes, attribute value, and generate operational recommendations.
  • Persist and deliver merchant-configured shopper submissions, including permitted Shopify customer or content records and regional notifications.
  • Protect the service, investigate abuse, debug failures, and maintain audit records.
  • Respond to requests and send service communications. We send marketing only where permitted, and channel consent can be withdrawn at any time.
  • Comply with law, enforce agreements, and establish or defend legal claims.

Depending on context and applicable law, we rely on performance of a contract, legitimate interests in operating and securing a business service, consent, and compliance with legal obligations. Where a merchant controls shopper data, the merchant determines the applicable legal basis and instructions.

5. Governed automation and agents

BRDG records deterministic storefront decisions, assignments, eligibility checks, and measurement. External agents may draft or, when a merchant has granted authority, approve certain catalog and brand proposals. A proposal does not bypass BRDG's privacy, entitlement, grounding, consent, audit, pause, or rollback controls. Tool enablement and experiment launch remain merchant-governed workflows.

BRDG does not use shopper data to make decisions that produce legal or similarly significant effects about an individual. Merchants remain responsible for the experiences, audiences, consent notices, and lawful instructions they configure.

6. How we disclose information

We disclose information only as needed for the purposes above, including to:

  • Infrastructure and service providers that host, store, secure, email, index, or support BRDG under contractual restrictions.
  • Shopify to operate the embedded app, billing, authorized Admin API workflows, storefront proxy, and merchant-requested writebacks.
  • Merchant-directed integrations such as Klaviyo, Meta, or a merchant's selected agent provider when the merchant enables and instructs that flow.
  • Professional advisers, authorities, and transaction counterparties when reasonably necessary for legal, safety, financing, reorganization, or acquisition needs.

Our current provider list and purpose descriptions are available on the Subprocessors page.

7. No sale, sharing, or third-party advertising

BRDG does not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use shopper data to advertise BRDG to shoppers. Merchant-directed advertising or audience integrations operate only when enabled and instructed by the merchant, subject to applicable consent and platform requirements.

8. Consent, cookies, and local storage

BRDG's storefront SDK uses persistent identifiers and behavioral event storage only after an affirmative analytics-consent signal from Shopify's Customer Privacy API. If consent is unknown or denied, identity stays in memory for the page session and behavioral transmission is suppressed; revocation purges BRDG's durable browser identifiers on a best-effort basis. See our Cookie Policy for names, purposes, and controls.

Contact capture has separate, explicit email and SMS consent fields. An unchecked choice is treated as not granted, not as consent.

9. Retention and deletion

We retain information only for as long as reasonably necessary to provide and secure the service, meet contractual and legal obligations, resolve disputes, and maintain legitimate audit evidence. Retention varies by record type, merchant configuration, account status, and legal requirements. When information is no longer needed, we delete, de-identify, or aggregate it; limited copies may remain temporarily in protected backups or where law requires retention.

BRDG supports Shopify's required customer-data request, customer-redaction, and shop-redaction workflows. Merchants can also request account export or deletion through support, subject to legal and security verification.

10. Security

We use technical and organizational safeguards appropriate to the nature of the service, including transport encryption, access controls, secret and contact-field encryption, shop-scoped authorization, audit logging, bounded service credentials, validation gates, and incident-response procedures. No system is completely secure, so we cannot guarantee absolute security.

11. International transfers

BRDG and its providers may process information outside the country where it was collected. Where required, we rely on recognized transfer mechanisms, contractual safeguards, and supplementary measures appropriate to the processing.

12. Your rights and choices

Depending on applicable law, you may have rights to know or access, correct, delete, or receive a copy of personal information; object to or restrict processing; withdraw consent; and appeal a decision or complain to a regulator. We do not discriminate for exercising a privacy right.

Shoppers should usually contact the Shopify merchant first because that merchant controls the relationship and can identify the relevant store record. Merchants and website visitors may email hello@getbrdg.ai. We may verify identity and authority before completing a request, and authorized agents may submit requests where law permits.

13. Business use and children

BRDG is a business service and is not directed to children. We do not knowingly collect personal information directly from children under 13 through our website. Merchants must not configure BRDG to collect children's information unless they have a lawful basis, required notices and consents, and have agreed the use with us in writing.

14. Changes and contact

We may update this policy as our service, providers, and legal obligations evolve. We will post the revised version here, change the date above, and provide additional notice where required. Questions, complaints, and privacy requests can be sent to hello@getbrdg.ai.

BRDG
PlatformAboutPricingWatch a demoFree checkupLegalPrivacyTerms
© 2026 BRDG · Carry every customer across.