1. Who is responsible
Brandligo is the data controller for the personal data described here.
Brandligo is our directory at https://www.brandligo.com.
Privacy questions and requests go to
[email protected].
A person reads that inbox.
The blog is part of the same domain but a separate application. Pages under
/blog are served by WordPress, which sets its own cookies and keeps its own
comment records. Where this policy describes something specific to the directory, it does not
describe the blog.
2. What we collect
2.1 If you only read
No account, no name, no email. Your browser sends an IP address and a user-agent string with
every request, as it does to every website; our server and our host record those in ordinary
request logs. We set a session cookie, and we count page views in aggregate
(section 6).
2.2 Your account
-
Name and email address, which you give us when you register. The email
address is your sign-in identifier and where we send everything.
-
A phone number, if you choose to add one.
-
Your password, hashed. We store a one-way hash, never the password. We
cannot read it and cannot tell it to you.
-
Whether and when you confirmed your email address, and a “remember
me” token if you ask to stay signed in.
2.3 What you publish
Listings you submit — companies, brands, products — with everything attached to
them: descriptions, logos and images you upload, website and social links, business email
address and phone number, physical location, size and founding year, team members, portfolio
entries and pricing information. Reviews and owner replies you write, and the rating you give.
All of this is published, under your display name, once it is approved. Do not
put anything in a listing or a review that you would not want indexed by a search engine.
2.4 Extra detail on a company review
When you review a company you may optionally tell us your role, the type of engagement, what it
cost, what came out of it, and a LinkedIn profile. These fields exist so a reader can judge how
much weight a review deserves.
The LinkedIn profile is the exception and is never published. It is verification
material: an administrator sees it while moderating and nobody else does. It is not shown on the
review, not shown to the company being reviewed, not included in the structured data we publish,
and it is excluded from our internal audit log.
2.5 Claiming a listing
When you claim a listing we record which method you used, when, and whether it succeeded. A
one-time code sent to you is stored only as a hash, is burned when used, expires,
and allows a small fixed number of attempts. DNS and meta-tag checks read only the public record
or the public page at the domain already recorded on the listing.
2.6 Shortlists, comparisons and briefs
Shortlists are private to your account, including any notes you add to an entry. Comparisons are
held in your session and are not tied to an account at all. If you turn a shortlist into a shared
brief, the link you create shows the listings to anyone who has it; your notes are
excluded unless you explicitly opt in, and you can revoke the link at any time.
2.7 When you contact us
The contact form and the enquiry form on a company page collect your name, email address, the
message and, for an enquiry, the company you are contacting. A company enquiry is forwarded to
that company, which is the point of it. Both forms also carry an anti-automation check, which
works from a signed token in the page and does not profile you.
2.8 Payment records
If you buy a placement we record which plan, the price agreed, the term, the dates, the status,
and a reference supplied by the payment provider. No card number, expiry date or security
code ever reaches our servers — see section 9.
2.9 Security and audit records
We keep an audit log of actions taken in the application — sign-in, failed sign-in, lockout,
registration, password reset, and creating, editing, approving or deleting a record. Each entry
records who did it, what changed, and the IP address, user-agent, HTTP method and URL of the
request. Secrets and passwords are redacted before an entry is written.
The audit log is visible to administrators only. There is no owner-facing view of
it and no way to export a filtered slice of it, because entries span every account and even a
narrow slice would expose other people's activity.
2.10 Email delivery records
Our email provider tells us when a message hard-bounces or is marked as spam. We record the
address and the reason on a suppression list and stop sending to it. That list is consulted
before every outgoing message.
3. What is public and what is not
This distinction matters more here than on most sites, so it is set out plainly.
| Public, indexable | Never public |
| Your display name on a listing, a review or a reply |
Your account email address and phone number |
| Everything in an approved listing, including a business email address or phone
number you chose to publish in it |
Your password, in any form |
| Review text, ratings, the date, and the optional role, engagement, budget and
outcome fields |
The LinkedIn profile on a review |
| Owner replies once approved |
Shortlists and the notes in them |
| A shared brief, to anyone holding the link |
Messages you send through the contact form |
| Aggregate view counts shown on a page |
Audit-log entries, IP addresses and user agents |
You can review as a guest without an account, in which case no account is linked to what you
wrote.
4. Why we use it, and our lawful basis
Where the UK GDPR or EU GDPR applies, we rely on the bases below. Where it does not, the same
list describes what we do and why.
| What for | Basis |
| Creating and running your account; publishing what you submit; delivering a
placement you bought |
Contract — we cannot provide the service without it |
| Transactional email: address confirmation, password reset, moderation outcomes,
receipts |
Contract |
| Moderating listings and reviews; preventing fake reviews, fraud and abuse; the
audit log; rate limits and anti-automation checks |
Legitimate interests — keeping the directory trustworthy and
the site secure |
| Aggregate analytics about how listings perform |
Legitimate interests — running and improving the directory,
using data that identifies no visitor |
| Inviting a business to claim an editorial listing about it |
Legitimate interests — business-to-business contact, with an
unsubscribe link in every message |
| Third-party analytics and advertising cookies |
Consent, where the law of your country requires it — see
section 5 |
| Keeping records for tax, accounting and legal claims |
Legal obligation and legitimate interests |
Where we rely on legitimate interests we have considered whether they override your interests
and rights. You can object — see section 14.
5. Cookies and local storage
We use as few as the site can work with.
| What | Purpose | Lifetime |
| Session cookie |
Keeps you signed in and holds your comparison tray and recently-viewed trail.
Strictly necessary. |
Until the session expires |
| CSRF token cookie |
Stops another site submitting a form as you. Strictly necessary. |
Session |
| “Remember me” cookie |
Set only if you ask to stay signed in. |
Up to 5 years, or until you sign out |
| Theme preference |
Remembers light or dark mode. Stored in your browser's local storage, not sent to
us at all. |
Until you clear it |
| Google Analytics |
Aggregate traffic measurement. See section 6. |
Up to 2 years |
| Google AdSense and its partners |
Serving and measuring advertisements. See section 7. |
Set by Google |
You can block or delete cookies in your browser. Blocking the strictly necessary ones will stop
you signing in. Blocking the rest costs you nothing on this site.
6. Analytics
We measure in two different ways, and they are worth separating.
Our own listing analytics are aggregate by construction. We count impressions,
profile views and outbound clicks per listing per day, and store them as a running total: one
row per listing, per metric, per day. There is no row per visitor and no visitor identifier
anywhere in it, so the table grows with the size of the directory rather than with traffic and
cannot be turned back into a record of what any one person looked at. These are the numbers a
listing owner sees on their dashboard.
Google Analytics 4 is also loaded on public pages. It is a third-party service
that sets its own cookies and processes data on Google's own terms; we use it for aggregate
traffic reporting and we have not enabled any advertising features in it. You can opt out for
every site with
Google's browser add-on.
7. Advertising
Public pages carry Google AdSense units, capped at three per page. Google and its partners may
set cookies and use identifiers to select and measure advertisements, including personalised
ones where you have allowed it. We do not choose which advertisements you see, we
receive no personal data back from Google about you, and no advertiser can influence where a
listing appears in the directory.
You can control this at
Google My Ad Center
and read how Google uses data at
policies.google.com/technologies/partner-sites.
8. Who we share it with
We do not sell personal data and we do not share it for anyone else's marketing.
We use the following processors and services to run the site:
| Who | What for | What they get |
| Hostinger |
Hosting and the database |
Everything stored by the site, plus server request logs |
| Amazon Web Services (SES) |
Sending email |
Recipient address, subject and message content; bounce and complaint reports back
to us |
| Lemon Squeezy |
Payments, as merchant of record |
Your billing details and card data, which they collect directly. See
section 9 |
| Google (Analytics, AdSense, Fonts) |
Traffic measurement, advertising, typefaces |
IP address, user agent, pages viewed, advertising identifiers |
| An AI model provider, only if one is enabled |
Structuring text you paste into the listing assistant |
Only the text you submitted. See section 10 |
We may also disclose data:
-
to a company you contact through its listing — your name, email
address and message, which is the purpose of that form;
-
where the law requires it, or to establish, exercise or defend a legal claim, or to protect
someone's safety;
-
to a buyer, if the site is ever sold or merged, under this policy or one no less protective.
9. Payments
Payments are taken by Lemon Squeezy, acting as the merchant of record. You enter
your card details on their checkout, not ours, and they are the controller of that data for the
transaction; their
privacy policy
applies to it. They send us back only what we need to grant and support what you bought: the
plan, the amount, the term, the status and an opaque reference. No card number, expiry
date or security code is ever transmitted to or stored on our servers.
10. AI assistance
The registration and listing forms offer an optional assistant that turns pasted text into
structured fields. It is opt-in: it runs only when you press the button, and every field it
produces is shown to you for editing before anything is saved.
The assistant can run in two ways. By default it runs as a rule engine on our own server and
nothing leaves our infrastructure. Where an external model provider is
configured instead, only the text you submitted is sent to that provider to be structured; we
do not send your account details with it, and it is not used to build a profile of you. We will
update this section, and name the provider, before enabling one.
11. International transfers
Some of the providers above are based in, or process data in, countries outside the UK and EEA
— principally the United States. Where personal data is transferred out of the UK or EEA
we rely on the UK International Data Transfer Addendum or the European Commission's Standard
Contractual Clauses, together with the provider's own safeguards, unless the country has an
adequacy decision. You can ask us for details of the safeguards that apply to a particular
transfer.
12. How long we keep it
| What | How long |
| Your account |
Until you close it, or after a long period of inactivity once we have warned you |
| Published listings and reviews |
While they are published; see section 14 for what happens on
deletion |
| Rejected submissions |
Kept while an appeal is possible, then deleted |
| Audit log |
Pruned automatically on a rolling schedule |
| Read notifications |
Pruned weekly. Unread ones are kept, because they may be the only copy of something
you have not seen |
| Aggregate analytics |
Indefinitely — it identifies nobody |
| Payment and subscription records |
As long as tax and accounting law requires, typically six to seven years |
| Suppression list entries |
Indefinitely — the entry exists to stop us emailing you again |
| Contact messages |
As long as needed to deal with the enquiry and any follow-up |
13. Security
The site is served over HTTPS only. Passwords are stored as one-way hashes. One-time claim codes
are hashed, expire, and allow a limited number of attempts. Forms are protected against
cross-site request forgery, and sensitive actions are rate limited. Access to production data is
limited to people who need it, and administrative actions are recorded in the audit log. Uploads
are restricted by type and cannot be executed by the web server.
No system is perfectly secure. If we become aware of a breach affecting your personal data we
will notify you and the relevant supervisory authority where the law requires it. If you think
you have found a vulnerability, please tell us at
[email protected]
before disclosing it publicly.
14. Your rights
Subject to the conditions in the law that applies to you, you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate. Most of it you can edit yourself.
-
Delete your data. See the note on reviews below.
- Restrict or object to our processing, including any
processing based on legitimate interests.
-
Port the data you gave us to another service, in a machine-readable format.
- Withdraw consent at any time, where we relied on consent. That does not
affect what we did before you withdrew it.
On deleting reviews. If you close your account we remove your name from your
reviews. We may keep the review text published without attribution, because allowing reviews to
be withdrawn on demand would let a rating be reset by anyone who did not like it. If you want a
particular review taken down, ask us and explain why; we consider every request and we always
remove one that breaches the rules or that you had a right to withdraw.
To exercise a right, email
[email protected]
from the address on your account. We answer within one month, and will say so if a complex
request needs longer. We do not charge, unless a request is manifestly unfounded or repetitive.
15. If you are in the United States
Residents of California and of other states with comparable laws have the right to know what
personal information is collected and disclosed, to request deletion, to request correction, and
not to be discriminated against for exercising those rights. Use the same contact address above.
We do not sell personal information, and we do not share it for cross-context behavioural
advertising as those terms are defined in the CCPA/CPRA. The advertising cookies
described in section 7 are set by Google under its own terms, and you
can control them through the links in that section. We honour Global Privacy Control signals
where they reach us.
16. Children
This is a business directory and it is not intended for children. We do not knowingly collect
personal data from anyone under 16. If you believe a child has given us data, tell us and we
will delete it.
17. Automated decisions
We do not make decisions about you by automated means that produce legal or similarly
significant effects. Listings and reviews are approved or rejected by a person. Automated checks
— rate limits, the anti-automation question on public forms, and the checks that decide
whether a claim's DNS record or meta tag matches — can block a single submission, and in
every case you can reach a person by emailing us.
18. Changes to this policy
We update this policy when what we do changes. The effective date at the top says when the
current version took effect, and we do not backdate it. Where a change is significant we will
tell account holders by email before it takes effect.
[email protected],
or the contact form.
If you are in the UK or the EEA and you are not satisfied with our answer, you can complain to
your data protection supervisory authority. In the UK that is the Information Commissioner's
Office at
ico.org.uk.
We would rather you came to us first.
Last updated 22 August 2026.
See also the terms of use and
how moderation works.