Introduction
At BehaviorScores, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our coupon optimization platform. Please read this policy carefully to understand our views and practices regarding your personal data.
By using BehaviorScores, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our services.
This policy applies to information collected through our website, applications, and any related services, sales, marketing, or events (collectively, the "Services").
Data Collection & Usage
We collect various types of information to provide and improve our Services. Understanding what data we collect helps you make informed decisions about your use of our platform.
Data We Collect
- Order Information: Transaction values, products purchased, order dates, and conversion data
- Customer Data: Purchase history, order frequency, average order value, and customer identifiers
- Behavioral Signals: Browse patterns, cart abandonment events, and session data (when available)
- Store Configuration: Discount thresholds, coupon settings, and optimization preferences
How We Use Your Data
- Generate purchase propensity scores for each customer
- Apply machine learning algorithms for predictive analytics
- Make automated decisions about discount eligibility
- Provide analytics, insights, and performance metrics
- Improve our algorithms and generate industry benchmarks using aggregated, anonymized data
Automated Processing & AI
Our service relies on automated processing to deliver real-time discount decisions. We use machine learning algorithms and, in some features, artificial intelligence technologies including language models to generate recommendations and insights.
How Automated Decisions Work
When a customer reaches checkout, our system automatically evaluates their behavior score and determines whether they should receive a discount. This decision is based on historical purchase patterns, browsing behavior, and store-specific thresholds you configure.
AI-Powered Features
We may utilize artificial intelligence technologies, including language models, to generate optimization recommendations and insights. When using these AI features:
- No personally identifiable customer data is sent to AI models
- Only aggregated, anonymized statistics are used for analysis
- AI recommendations are suggestions—you maintain full control over implementation
- All AI processing follows our strict data security protocols
Data Security
We implement robust security measures to protect your data from unauthorized access, alteration, disclosure, or destruction. Security is fundamental to our service architecture and operational practices.
Security Measures
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Infrastructure: Cloud-hosted on SOC 2 compliant providers with redundant backups
- Access Controls: Role-based access with multi-factor authentication for all team members
- Monitoring: 24/7 security monitoring, intrusion detection, and audit logging
- Compliance: Regular security audits and penetration testing by third-party firms
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
Data Retention
We retain your data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods
- Account Data: Retained while your account is active, plus 90 days after deletion request
- Transaction Logs: Retained for 365 days for analytics and dispute resolution
- Customer Scores: Updated continuously; historical scores retained for 180 days
- Webhook Events: Retained for 30 days for debugging and audit purposes
- Aggregated Analytics: May be retained indefinitely in anonymized form
Upon account termination, we will delete or anonymize your personal data within the retention periods specified above, unless we are legally required to retain certain information.
Data Sharing & Third Parties
We do not sell, trade, or rent your personal identification information to others. We may share generic aggregated demographic information not linked to any personal identification information with our business partners and advertisers.
When We May Share Data
- Service Providers: Cloud hosting, payment processors (via Shopify), and analytics services
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with mergers, acquisitions, or asset sales
- With Your Consent: For any other purpose with your explicit agreement
Third-Party Services
We integrate with Shopify to provide our services. Your use of Shopify is governed by Shopify's own privacy policy and terms of service. We recommend reviewing their policies to understand how they handle your data.
Your Rights
Depending on your location, you may have certain rights regarding your personal data under applicable privacy laws such as GDPR, CCPA, or similar regulations.
Your Data Rights Include
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Request limitation of processing under certain circumstances
- Objection: Object to processing based on legitimate interests or direct marketing
- Withdraw Consent: Withdraw previously given consent at any time
Note: Exercising certain rights (such as erasure) may impact your ability to use our Services. We will inform you of any such implications before processing your request.
International Data Transfers
Your information may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those of your jurisdiction.
If you are located outside the United States and choose to provide information to us, please note that we transfer the data to the United States and process it there.
For transfers from the European Economic Area (EEA) or United Kingdom, we rely on Standard Contractual Clauses approved by the European Commission or UK equivalent safeguards to ensure adequate protection of your personal data.
Children's Privacy
Our Service is not directed to anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18.
If you are a parent or guardian and you are aware that your Child has provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that information from our servers.
Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this policy.
For material changes, we will provide additional notice such as adding a statement to our homepage or sending you an email notification. We encourage you to review this Privacy Policy periodically for any changes.
Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
Contact Us
If you have any questions about this Privacy Policy, your personal data, or would like to exercise any of your rights, please contact our Privacy Team using the information below.
BehaviorScores Privacy Team
Privacy Inquiries: support@behaviorscores.com
General Support: support@behaviorscores.com
Legal Department: support@behaviorscores.com
Response time: 2-3 business days for general inquiries
Data subject requests: Within 30 days as required by law