Store data stays connected to the work.
This page summarizes how Branch & Button handles merchant information during an engagement. A separate data-processing agreement can be added when required.
Effective September 16, 2026Purpose and instructions
We process authorized merchant information only to evaluate, plan, perform, secure, measure, and document the agreed work, or as required by law. The written scope and documented merchant approvals define the instructions for an engagement.
Data minimization
Provide only the information needed for the buying question under review. Customer feedback should be redacted or aggregated where individual identity is not necessary. Do not provide passwords, full payment-card information, or sensitive personal information unless a separate written process expressly requires and protects it.
Access and security
Access is limited to authorized people and service providers who need it for the engagement. Store access should use role-based, revocable permissions. Reasonable administrative and technical safeguards are used, but no internet service can promise absolute security.
Service providers
Hosting, business-email, payment, store-platform, and approved analysis providers may process limited information on our behalf. We remain responsible for selecting providers appropriate to the task and documenting material changes where required.
Retention and deletion
Project information is retained only as long as reasonably needed for delivery, support, security, dispute resolution, and legal records. On a verified request, information will be returned or deleted when reasonably possible, subject to backup cycles and legal obligations.
Incidents and requests
We will investigate suspected unauthorized access and notify affected merchants when required by applicable law or contract. Privacy or data-handling requests can be sent through the Legal Contact page.