Skip to content

Platform review · All providers

Reviewer data-handling summary

Concise map of data BrandMilo receives, why it is stored, and when it is removed. For platform reviewers and privacy readers. No secrets.

Canonical review URL: https://brandmilo.com/review/data-handling

No secrets on this page

Test passwords, access tokens, and private credentials are shared only through the provider’s secure submission channel never published here.

Public use-case statement

BrandMilo processes authorized commerce and social data to generate reviewed drafts and publish through official APIs. This page summarizes categories for reviewers without exposing credentials.

Availability

Applies across current and planned integrations. Retention follows the Privacy Policy category table and public deletion summary.

Scopes / permissions

See each provider review pack for scope tables. This summary focuses on data categories.

OAuth / authorization steps

  1. User authorizes a provider on the provider’s website.
  2. BrandMilo receives tokens and account identifiers.
  3. App stores encrypted credentials and permitted content metadata.
  4. User can disconnect or request deletion at any time.

Reviewer steps

  1. Read this summary alongside the relevant provider review pack.
  2. Confirm Privacy Policy and Data Deletion pages match the described flows.
  3. Confirm no passwords are collected for third-party platforms.

Demo outline

A recorded demo is not published yet

Intended capture sequence:

  1. Privacy Policy footer link
  2. Data Deletion page
  3. Integrations disconnect UI (when implemented)
  4. This data-handling summary

Readiness

Application stage: Data categories for reviewers. Encryption is implemented; live provider traffic still depends on Etsy/Pinterest access.

Implemented today

  • ImplementedOAuth tokens encrypted at rest; serializers omit tokens
  • ImplementedEtsy listing metadata model (no Phase 1 orders/buyers)
  • ImplementedPinterest board records for destination selection
  • ImplementedDrafts, schedules, and publication results in PostgreSQL
  • ImplementedEmail data-deletion path via privacy@

Designed but not enabled

  • Designed, not enabledIn-app self-serve account deletion and data export APIs

Provider-dependent

  • Provider-dependentLive Etsy/Pinterest token traffic after provider grants

Future

  • FutureAutomated retention timers as public promises

Data notes

  • OAuth tokens: maintain API access; encrypted; removed/disabled on disconnect/deletion
  • Shop/account ID: identify authorized resource; removed under deletion rules
  • Etsy listing data: display + draft generation; stored until deletion/retention expiry
  • Product images: compose posts; URL and/or permitted cache; removed with content deletion
  • Pinterest boards: destination selection; removed by resync, disconnect, or deletion
  • Draft content: review and publishing; stored until draft/account deletion
  • Schedule: publication timing; stored until completion, cancellation, or deletion
  • Provider result: status and reconciliation; retained under configured policy
  • Usage logs: security and reliability; limited retention

Reviewer access notes

Support during review: privacy@brandmilo.com

Limitations & disclosures

  • Exact retention windows follow the Privacy Policy (example: BrandMilo retains account and workspace data while an account remains active. After a verified deletion request, applicable records are removed from active production systems through an operator-handled process. Operational, security, and audit logs are retained only as long as reasonably necessary for security, troubleshooting, legal and compliance obligations, and service operations. Exact automated retention periods will be published once those jobs are implemented and enforced.)
  • Subprocessors are listed on /legal/subprocessors

Related links

BrandMilo is an independent software service and is not endorsed by, affiliated with, or sponsored by Etsy, Pinterest, Meta, Facebook, Instagram, TikTok, or any other third-party platform unless explicitly stated. Third-party names and trademarks belong to their respective owners.