Skip to content
Search Sign in List your company
Legal

Privacy Policy

What we collect, why we collect it, who else sees it, how long we keep it, and what you can ask us to do about it.

Effective 22 August 2026. This policy covers https://www.brandligo.com and the emails we send. It does not cover the websites of the businesses listed here, which have their own policies.

The short version: you can read the whole directory without an account and without telling us who you are. An account needs an email address. Everything you publish here is public by design. We do not sell personal data, and we never see your card details.

1. Who is responsible

Brandligo is the data controller for the personal data described here. Brandligo is our directory at https://www.brandligo.com.

Privacy questions and requests go to [email protected]. A person reads that inbox.

The blog is part of the same domain but a separate application. Pages under /blog are served by WordPress, which sets its own cookies and keeps its own comment records. Where this policy describes something specific to the directory, it does not describe the blog.

2. What we collect

2.1 If you only read

No account, no name, no email. Your browser sends an IP address and a user-agent string with every request, as it does to every website; our server and our host record those in ordinary request logs. We set a session cookie, and we count page views in aggregate (section 6).

2.2 Your account

  • Name and email address, which you give us when you register. The email address is your sign-in identifier and where we send everything.
  • A phone number, if you choose to add one.
  • Your password, hashed. We store a one-way hash, never the password. We cannot read it and cannot tell it to you.
  • Whether and when you confirmed your email address, and a “remember me” token if you ask to stay signed in.

2.3 What you publish

Listings you submit — companies, brands, products — with everything attached to them: descriptions, logos and images you upload, website and social links, business email address and phone number, physical location, size and founding year, team members, portfolio entries and pricing information. Reviews and owner replies you write, and the rating you give.

All of this is published, under your display name, once it is approved. Do not put anything in a listing or a review that you would not want indexed by a search engine.

2.4 Extra detail on a company review

When you review a company you may optionally tell us your role, the type of engagement, what it cost, what came out of it, and a LinkedIn profile. These fields exist so a reader can judge how much weight a review deserves.

The LinkedIn profile is the exception and is never published. It is verification material: an administrator sees it while moderating and nobody else does. It is not shown on the review, not shown to the company being reviewed, not included in the structured data we publish, and it is excluded from our internal audit log.

2.5 Claiming a listing

When you claim a listing we record which method you used, when, and whether it succeeded. A one-time code sent to you is stored only as a hash, is burned when used, expires, and allows a small fixed number of attempts. DNS and meta-tag checks read only the public record or the public page at the domain already recorded on the listing.

2.6 Shortlists, comparisons and briefs

Shortlists are private to your account, including any notes you add to an entry. Comparisons are held in your session and are not tied to an account at all. If you turn a shortlist into a shared brief, the link you create shows the listings to anyone who has it; your notes are excluded unless you explicitly opt in, and you can revoke the link at any time.

2.7 When you contact us

The contact form and the enquiry form on a company page collect your name, email address, the message and, for an enquiry, the company you are contacting. A company enquiry is forwarded to that company, which is the point of it. Both forms also carry an anti-automation check, which works from a signed token in the page and does not profile you.

2.8 Payment records

If you buy a placement we record which plan, the price agreed, the term, the dates, the status, and a reference supplied by the payment provider. No card number, expiry date or security code ever reaches our servers — see section 9.

2.9 Security and audit records

We keep an audit log of actions taken in the application — sign-in, failed sign-in, lockout, registration, password reset, and creating, editing, approving or deleting a record. Each entry records who did it, what changed, and the IP address, user-agent, HTTP method and URL of the request. Secrets and passwords are redacted before an entry is written.

The audit log is visible to administrators only. There is no owner-facing view of it and no way to export a filtered slice of it, because entries span every account and even a narrow slice would expose other people's activity.

2.10 Email delivery records

Our email provider tells us when a message hard-bounces or is marked as spam. We record the address and the reason on a suppression list and stop sending to it. That list is consulted before every outgoing message.

3. What is public and what is not

This distinction matters more here than on most sites, so it is set out plainly.

Public, indexableNever public
Your display name on a listing, a review or a reply Your account email address and phone number
Everything in an approved listing, including a business email address or phone number you chose to publish in it Your password, in any form
Review text, ratings, the date, and the optional role, engagement, budget and outcome fields The LinkedIn profile on a review
Owner replies once approved Shortlists and the notes in them
A shared brief, to anyone holding the link Messages you send through the contact form
Aggregate view counts shown on a page Audit-log entries, IP addresses and user agents

You can review as a guest without an account, in which case no account is linked to what you wrote.

4. Why we use it, and our lawful basis

Where the UK GDPR or EU GDPR applies, we rely on the bases below. Where it does not, the same list describes what we do and why.

What forBasis
Creating and running your account; publishing what you submit; delivering a placement you bought Contract — we cannot provide the service without it
Transactional email: address confirmation, password reset, moderation outcomes, receipts Contract
Moderating listings and reviews; preventing fake reviews, fraud and abuse; the audit log; rate limits and anti-automation checks Legitimate interests — keeping the directory trustworthy and the site secure
Aggregate analytics about how listings perform Legitimate interests — running and improving the directory, using data that identifies no visitor
Inviting a business to claim an editorial listing about it Legitimate interests — business-to-business contact, with an unsubscribe link in every message
Third-party analytics and advertising cookies Consent, where the law of your country requires it — see section 5
Keeping records for tax, accounting and legal claims Legal obligation and legitimate interests

Where we rely on legitimate interests we have considered whether they override your interests and rights. You can object — see section 14.

5. Cookies and local storage

We use as few as the site can work with.

WhatPurposeLifetime
Session cookie Keeps you signed in and holds your comparison tray and recently-viewed trail. Strictly necessary. Until the session expires
CSRF token cookie Stops another site submitting a form as you. Strictly necessary. Session
“Remember me” cookie Set only if you ask to stay signed in. Up to 5 years, or until you sign out
Theme preference Remembers light or dark mode. Stored in your browser's local storage, not sent to us at all. Until you clear it
Google Analytics Aggregate traffic measurement. See section 6. Up to 2 years
Google AdSense and its partners Serving and measuring advertisements. See section 7. Set by Google

You can block or delete cookies in your browser. Blocking the strictly necessary ones will stop you signing in. Blocking the rest costs you nothing on this site.

6. Analytics

We measure in two different ways, and they are worth separating.

Our own listing analytics are aggregate by construction. We count impressions, profile views and outbound clicks per listing per day, and store them as a running total: one row per listing, per metric, per day. There is no row per visitor and no visitor identifier anywhere in it, so the table grows with the size of the directory rather than with traffic and cannot be turned back into a record of what any one person looked at. These are the numbers a listing owner sees on their dashboard.

Google Analytics 4 is also loaded on public pages. It is a third-party service that sets its own cookies and processes data on Google's own terms; we use it for aggregate traffic reporting and we have not enabled any advertising features in it. You can opt out for every site with Google's browser add-on.

7. Advertising

Public pages carry Google AdSense units, capped at three per page. Google and its partners may set cookies and use identifiers to select and measure advertisements, including personalised ones where you have allowed it. We do not choose which advertisements you see, we receive no personal data back from Google about you, and no advertiser can influence where a listing appears in the directory.

You can control this at Google My Ad Center and read how Google uses data at policies.google.com/technologies/partner-sites.

8. Who we share it with

We do not sell personal data and we do not share it for anyone else's marketing. We use the following processors and services to run the site:

WhoWhat forWhat they get
Hostinger Hosting and the database Everything stored by the site, plus server request logs
Amazon Web Services (SES) Sending email Recipient address, subject and message content; bounce and complaint reports back to us
Lemon Squeezy Payments, as merchant of record Your billing details and card data, which they collect directly. See section 9
Google (Analytics, AdSense, Fonts) Traffic measurement, advertising, typefaces IP address, user agent, pages viewed, advertising identifiers
An AI model provider, only if one is enabled Structuring text you paste into the listing assistant Only the text you submitted. See section 10

We may also disclose data:

  • to a company you contact through its listing — your name, email address and message, which is the purpose of that form;
  • where the law requires it, or to establish, exercise or defend a legal claim, or to protect someone's safety;
  • to a buyer, if the site is ever sold or merged, under this policy or one no less protective.

9. Payments

Payments are taken by Lemon Squeezy, acting as the merchant of record. You enter your card details on their checkout, not ours, and they are the controller of that data for the transaction; their privacy policy applies to it. They send us back only what we need to grant and support what you bought: the plan, the amount, the term, the status and an opaque reference. No card number, expiry date or security code is ever transmitted to or stored on our servers.

10. AI assistance

The registration and listing forms offer an optional assistant that turns pasted text into structured fields. It is opt-in: it runs only when you press the button, and every field it produces is shown to you for editing before anything is saved.

The assistant can run in two ways. By default it runs as a rule engine on our own server and nothing leaves our infrastructure. Where an external model provider is configured instead, only the text you submitted is sent to that provider to be structured; we do not send your account details with it, and it is not used to build a profile of you. We will update this section, and name the provider, before enabling one.

11. International transfers

Some of the providers above are based in, or process data in, countries outside the UK and EEA — principally the United States. Where personal data is transferred out of the UK or EEA we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with the provider's own safeguards, unless the country has an adequacy decision. You can ask us for details of the safeguards that apply to a particular transfer.

12. How long we keep it

WhatHow long
Your account Until you close it, or after a long period of inactivity once we have warned you
Published listings and reviews While they are published; see section 14 for what happens on deletion
Rejected submissions Kept while an appeal is possible, then deleted
Audit log Pruned automatically on a rolling schedule
Read notifications Pruned weekly. Unread ones are kept, because they may be the only copy of something you have not seen
Aggregate analytics Indefinitely — it identifies nobody
Payment and subscription records As long as tax and accounting law requires, typically six to seven years
Suppression list entries Indefinitely — the entry exists to stop us emailing you again
Contact messages As long as needed to deal with the enquiry and any follow-up

13. Security

The site is served over HTTPS only. Passwords are stored as one-way hashes. One-time claim codes are hashed, expire, and allow a limited number of attempts. Forms are protected against cross-site request forgery, and sensitive actions are rate limited. Access to production data is limited to people who need it, and administrative actions are recorded in the audit log. Uploads are restricted by type and cannot be executed by the web server.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant supervisory authority where the law requires it. If you think you have found a vulnerability, please tell us at [email protected] before disclosing it publicly.

14. Your rights

Subject to the conditions in the law that applies to you, you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything inaccurate. Most of it you can edit yourself.
  • Delete your data. See the note on reviews below.
  • Restrict or object to our processing, including any processing based on legitimate interests.
  • Port the data you gave us to another service, in a machine-readable format.
  • Withdraw consent at any time, where we relied on consent. That does not affect what we did before you withdrew it.

On deleting reviews. If you close your account we remove your name from your reviews. We may keep the review text published without attribution, because allowing reviews to be withdrawn on demand would let a rating be reset by anyone who did not like it. If you want a particular review taken down, ask us and explain why; we consider every request and we always remove one that breaches the rules or that you had a right to withdraw.

To exercise a right, email [email protected] from the address on your account. We answer within one month, and will say so if a complex request needs longer. We do not charge, unless a request is manifestly unfounded or repetitive.

15. If you are in the United States

Residents of California and of other states with comparable laws have the right to know what personal information is collected and disclosed, to request deletion, to request correction, and not to be discriminated against for exercising those rights. Use the same contact address above.

We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined in the CCPA/CPRA. The advertising cookies described in section 7 are set by Google under its own terms, and you can control them through the links in that section. We honour Global Privacy Control signals where they reach us.

16. Children

This is a business directory and it is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.

17. Automated decisions

We do not make decisions about you by automated means that produce legal or similarly significant effects. Listings and reviews are approved or rejected by a person. Automated checks — rate limits, the anti-automation question on public forms, and the checks that decide whether a claim's DNS record or meta tag matches — can block a single submission, and in every case you can reach a person by emailing us.

18. Changes to this policy

We update this policy when what we do changes. The effective date at the top says when the current version took effect, and we do not backdate it. Where a change is significant we will tell account holders by email before it takes effect.

19. Contact and complaints

[email protected], or the contact form.

If you are in the UK or the EEA and you are not satisfied with our answer, you can complain to your data protection supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk. We would rather you came to us first.

Last updated 22 August 2026. See also the terms of use and how moderation works.