Privacy Policy

Privacy Policy

How we protect your information

Last updated July 26, 2026

Strong Security Practices

Encryption in transit, access controls, and industry-standard safeguards

Data Protection

We do not sell your personal data

Transparency

Clear disclosure of how we use and share data with necessary providers

User Control

You can manage preferences and exercise ARCO and other privacy rights

Information We Collect

We collect only what's necessary to provide you with the best service

Personal Information

We collect the following personal information when you use our service:

  • Name and contact information
  • Phone number and WhatsApp number (when provided)—used for your account and support, reservation-related messages, and—when you are a customer of a business on Brilloo—for that business's CRM contact records and email or WhatsApp campaign delivery as described below
  • Account credentials and authentication data
  • Payment information and billing details
  • Vehicle information (brand, model, year, color)
  • Company and business information (for business users)
  • Branch location and service details
  • Reservation and booking history
  • Loyalty program participation and rewards
  • Usage data and preferences
  • Location data (when using map features)
  • Profile pictures and company images
  • Firebase Cloud Messaging (FCM) tokens for push notifications
  • Device information for notification delivery
  • Admin impersonation session data (for administrative purposes)
  • Trial subscription and expiration data
  • Loyalty redeem code usage and transaction history
  • OAuth authentication data from Google and Facebook (when using social login)
  • Google Maps interaction data for location services
  • Business report export data and download history
  • Payment method selection and preferences (card, OXXO, bank transfer)
  • Payment instruction PDF generation and download history
  • Payment reference numbers and expiration dates for manual payment methods
  • Payment status and confirmation data for subscription payments
  • CRM contact records for businesses (for example name, email, phone, optional notes, and link to a customer profile when applicable), created manually, imported, or synced from reservations and profile data
  • Marketing and transactional campaign metadata for business CRM (channel, subject and body content, images, scheduling, recipient delivery status, and error messages)
  • Email and WhatsApp unsubscribe timestamps for business CRM communications
  • Platform admin campaign data when Brilloo sends communications to business accounts
  • Point of Sale (POS) data for businesses: sale records, line items, totals, tender or payment type metadata, tickets or receipt identifiers, register or branch session context, void or adjustment history where logged, cash close-out or reconciliation summaries supported by the platform, and package bundle definitions (name, components, price, and allowed vehicle types) when businesses configure POS packages
  • Customer review and feedback content submitted by users (ratings, text, visit date, publication status, and links to related reservations or services when applicable)
  • Post-service review invitation and reminder metadata (delivery status, channel, and interaction timestamps)
  • Stripe webhook billing and subscription lifecycle event data used for reconciliation, support, and fraud prevention
  • Prompts and business context submitted to AI image and report features (for business users)
  • AI-generated image assets stored under company-scoped paths (services/{companyId}/, campaigns/{companyId}/, products/{companyId}/)
  • AI report inputs and outputs (operational data shared with our AI provider and the generated insights returned to your business)

Usage Data

We automatically collect information about how you use our service:

  • Device information (IP address, browser type, operating system)
  • App usage statistics and performance data
  • Location data (when using map features and geolocation)
  • Crash reports and error logs
  • Service booking patterns and preferences
  • Loyalty program participation and redemption history
  • Payment transaction data and billing history
  • Customer support interactions and communications
  • Email engagement and delivery status
  • WhatsApp message delivery status and communication metadata (when enabled)
  • Map interaction data (when using Google Maps features)
  • Push notification delivery and engagement metrics
  • FCM token registration and management data
  • Service worker usage and offline activity
  • Form interaction and validation data
  • Admin dashboard usage and management activities
  • Trial subscription management and conversion tracking
  • Vercel Web Analytics data (privacy-focused, no cookies or personal identifiers)
  • Google Ads tags and conversion events (for example completed signup and successful subscription checkout) and related campaign measurement data
  • OAuth provider interaction data (Google, Facebook authentication)
  • Excel export generation and business report downloads
  • Employee account management and role-based access tracking
  • Payment method selection and transaction data
  • Payment instruction PDF generation and access logs
  • Manual payment method processing and confirmation tracking
  • CRM and campaign activity (sends, scheduling, subscription plan limits usage) and related recipient or delivery metadata
  • Operational email activity to business accounts (for example pending reservation review reminders)
  • POS usage events (for example sales created or completed, package bundles rung up, sync or pending states, and staff actions tied to checkout when the product logs them)
  • Review lifecycle events (invitations sent, reviews published or rejected, review reports, and customer/business review management actions)
  • Administrative and business reporting metrics used to monitor operations and performance
  • Subscription and payment lifecycle events received through Stripe webhooks
  • AI feature usage (prompts submitted, generated image and report metadata, and provider attribution for Vercel AI Gateway / Google Gemini)

How We Use Your Information

Your data helps us provide better services and improve your experience

We use the collected information for the following purposes:

To provide and maintain our car wash booking and management platform
To process reservations, payments, and loyalty program transactions
To send booking confirmations, reminders, and loyalty reward notifications
To provide customer support and respond to inquiries
To display your location on maps and help you find nearby car wash services
To manage your vehicle information and service history
To process subscription payments and manage business accounts
To send important service updates and policy changes
To send WhatsApp communications (via YCloud) when enabled or when you interact with WhatsApp-based features
To gather analytics and improve our platform functionality
To detect, prevent, and address technical issues and security threats
To comply with legal obligations and enforce our terms of service
To deliver push notifications for reservations, loyalty rewards, and business updates
To manage Firebase Cloud Messaging tokens and notification delivery
To provide enhanced admin features including user impersonation and company management
To track and manage trial subscriptions with automated expiration notifications
To monitor platform performance and errors using Rollbar integration
To enhance security through Row Level Security (RLS) policies
To improve user experience through form standardization and validation
To provide privacy-focused analytics through Vercel Web Analytics without cookies
To measure advertising effectiveness through Google Ads conversion events when you complete signup or a paid subscription checkout (not merely by visiting marketing pages)
To enable convenient social authentication via Google and Facebook OAuth
To facilitate business data exports and reporting through Excel generation
To manage employee accounts and role-based access for business operations
To implement rate limiting for authentication and API security to prevent abuse
To process subscription payments through multiple payment methods including cards, OXXO, and bank transfers
To generate and provide payment instruction PDFs for manual payment methods
To track payment status and confirmations for subscription activation
To manage payment expiration and retry functionality for manual payment methods
To enable businesses to manage CRM contacts and send email or WhatsApp campaigns through the platform (including images and reply-to where supported), subject to subscription plan limits
To sync or update CRM contact information from customer profiles and reservation data when applicable
To send automated operational emails to business accounts (for example reminders about pending reservations, billing, or account notices)
To honor email and WhatsApp opt-out preferences recorded for business CRM communications
To operate POS features for businesses—including recording sales, supporting tickets and history, aligning completed transactions with loyalty or reservation data when linked, and enabling reporting and audit trails the product provides
To send post-service review invitations and reminders, and to display customer reviews on public and business-facing surfaces according to our policies
To support customer and business review management workflows (including status handling, notifications, and operational traceability)
To generate and present administrative and business reports with aggregated operational metrics
To process subscription, payment, and confirmation events through Stripe webhooks and maintain consistent billing status in the platform
To provide optional AI features for business users, including image generation (via Vercel AI Gateway using Google Gemini models) and AI business reports that summarize operational data
To store AI-generated image and report outputs under the business's company scope and attribute usage to the company for plan-limit and provider-attribution purposes

Sharing Information

We do not sell your personal data; we share it only with providers needed to operate Brilloo

We do not sell, market, or transfer your personal information to third parties except in the following circumstances:

With your explicit consent
To comply with legal obligations and regulatory requirements
To protect and defend our rights and property
With trusted service providers including payment processors, email services, and map providers
With car wash businesses to fulfill your reservations and provide services
In connection with a merger, acquisition, or sale of assets
To prevent fraud and ensure platform security
To provide customer support and resolve disputes
With Firebase for push notification delivery and FCM token management
With YCloud for WhatsApp message delivery (when enabled)
With Rollbar for error tracking and platform monitoring
With trusted analytics providers for service improvement
With administrative users for platform management and support purposes
With Vercel for privacy-focused web analytics (no personal data shared)
With Google for Maps integration, Ads tracking, and OAuth authentication
With Facebook for OAuth authentication when using social login
With employee users within your organization for business management purposes, including access to POS and sales data that their roles permit
With payment processors (Stripe) for secure payment processing, including card payments, OXXO, and bank transfers
Payment instruction PDFs are generated server-side and contain payment reference numbers and bank account details
With email and messaging providers so businesses can send CRM campaigns and so we can deliver operational emails to business accounts
With YCloud for WhatsApp delivery for business-initiated CRM campaigns in addition to user-enabled WhatsApp notifications
When a car wash business uses CRM features, that business and its authorized staff access their own contact lists and decide what to send; Brilloo processes data on their instructions as described in this policy
With Stripe to process payments and subscription events via webhooks, event validation, and billing status reconciliation
With car wash businesses to display and manage reviews linked to their services, and with end users when those reviews are published on public pages under applicable settings
With Vercel AI Gateway and Google (Gemini models) to generate images and business reports when business users use AI features; prompts and related business context are transmitted to these providers for processing
Public business pages, branch pages, blog posts, FAQs, and reviews may be indexed by search engines and AI crawlers; we publish an llms.txt file to guide AI systems on which content may be referenced

Data Security

Multiple layers of security to keep your information safe

We implement appropriate security measures to protect your personal information:

Encryption of sensitive data in transit and at rest using industry-standard protocols
Regular security audits and vulnerability assessments
Access controls and authentication mechanisms with role-based permissions
Rate limiting for authentication and API endpoints to prevent abuse and enumeration attacks
Secure payment processing with PCI DSS compliance
Employee training on data protection practices
Incident response procedures and breach notification protocols
Regular backups and disaster recovery planning
Secure API endpoints with proper authentication and validation
Location data protection with user consent requirements
Row Level Security (RLS) policies for database-level access control
Enhanced admin security controls and impersonation safeguards
Secure FCM token management and notification delivery
Comprehensive error logging and monitoring through Rollbar
Enhanced form validation and data sanitization
Service worker security and offline data protection
Privacy-focused analytics without cookies or personal tracking
Secure OAuth token management for third-party authentication
Protected business data export with access controls and encryption
Employee account security with role-based permissions and audit logging
Secure payment method processing with PCI DSS compliance for all payment types
Encrypted payment instruction PDFs with secure reference number generation
Payment expiration management and secure retry mechanisms for manual payments
Secure storage of payment status and confirmation data

Your Rights

You have control over your personal information, including ARCO rights under Mexican law

Under Mexican LFPDPPP (ARCO rights) and, where applicable, other privacy laws such as GDPR, you may exercise:

Access (Acceso): Request copies of your personal data
Rectification: Request correction of inaccurate data
Cancellation / Erasure: Request deletion of your personal data when legally applicable
Opposition: Object to processing of your data for specific purposes
Restriction: Request limitation of processing where the law provides
Portability: Request transfer of your data where technically feasible
Notification Preferences: Control push notification settings and FCM token usage
WhatsApp Preferences: Control WhatsApp notification settings and opt out of WhatsApp messages
Admin Access: Request information about administrative actions and impersonation
Trial Management: Control trial subscription data and expiration notifications
Error Data: Request information about error logs and performance data collected
Analytics Opt-out: Limit non-essential analytics or advertising cookies while maintaining core functionality
OAuth Disconnection: Disconnect social authentication and revert to email/password
Export History: Request information about data exports and downloads
Employee Data: Control how your data is shared with employee users in your organization
CRM marketing preferences: Where the platform provides controls, opt out of a business's email or WhatsApp CRM campaigns or update those preferences
Review controls: Request correction, update, or removal of reviews and comments you submitted, subject to platform integrity and moderation rules
AI Features: Opt out of AI image and report features without losing core platform functionality; company owners may request deletion of AI-generated assets stored under their company scope
How to exercise rights: email support@brilloo.app with subject Privacy / ARCO and enough detail to verify your identity; we will respond within the timeframes required by applicable law

Push Notifications and Communications

Our system includes transactional messages, business CRM campaigns, and operational emails to business accounts, delivered via Firebase Cloud Messaging and, when enabled, WhatsApp (via YCloud):

  • Reservation confirmations and status updates
  • Automated reservation reminders (e.g. the day before your appointment)
  • Reservation cancellation notifications (email and, when enabled, WhatsApp) when a booking is cancelled
  • Loyalty reward notifications and redeem code alerts
  • Trial expiration reminders and subscription updates
  • Business updates and service announcements
  • WhatsApp messages may be used for certain reservation and business communications when enabled
  • You can control notification preferences in your account settings
  • FCM tokens are stored securely and managed according to your preferences
  • Notification delivery is optimized for your device and usage patterns
  • Businesses using CRM may send you email or WhatsApp messages for operational or promotional purposes; unsubscribe or preference options apply where we provide them
  • Brilloo may send automated operational emails to business users (for example when reservations need review or for subscription-related notices)
  • We may send post-service review invitations and reminders related to your completed reservation experience

Administrative Features and Security

Enhanced administrative capabilities include:

  • User impersonation for customer support and troubleshooting
  • Company management and business account administration
  • Enhanced security controls and access management
  • Comprehensive audit trails and activity logging
  • Row Level Security policies for data protection
  • All administrative actions are logged and monitored for security

Analytics, Cookies, and Advertising

We separate privacy-focused product analytics from advertising measurement:

  • Vercel Web Analytics for privacy-first website analytics without cookies or personal identifiers
  • Google Ads (gtag) loads on Brilloo pages to measure ad performance; Google may use cookies or similar technologies under Google's policies
  • Primary Google Ads conversion events fire when you complete account signup (lead) or return from a successful Stripe subscription checkout (purchase), not merely by visiting marketing pages or /auth
  • Purchase conversion pixels may be limited until a purchase conversion label is configured; we may still send recommended purchase events for measurement
  • We do not sell your personal data to advertisers; advertising tools help us understand which campaigns led to signup or purchase
  • You can limit advertising cookies through your browser settings, Google Ads settings, or ad-blocking tools; essential service features remain available
  • Vercel Analytics is aggregated; Google Ads measurement is subject to Google's terms and applicable privacy laws in Mexico and other regions where we operate

Social Authentication

When using social login (Google or Facebook):

  • We collect only your basic profile information (name, email, profile picture)
  • Authentication is managed through OAuth 2.0 secure protocols
  • We do not have access to your social media account passwords
  • You can disconnect social authentication at any time from your account settings
  • Social login data is protected with the same security as native accounts
  • We do not post to your social media accounts without explicit permission

AI Features

Brilloo offers optional AI-powered features for business users:

  • AI image generation for services, campaigns, and POS products via the Vercel AI Gateway using Google Gemini models
  • AI-generated business reports that summarize operational data such as reservations, POS activity, reviews, and loyalty
  • Prompts and related business context you submit are sent to our AI provider (Vercel AI Gateway / Google) for processing
  • Generated images and reports are stored in Supabase storage under your company scope and attributed to your company
  • We do not send sensitive payment data, full customer credentials, or unrelated personal data to AI providers
  • AI-generated content may be inaccurate or incomplete; review it before publishing or using it commercially
  • You can choose not to use AI features; core platform functionality remains available

Public Content and AI Crawling

Information about how public content may be discovered:

  • Public business pages, branch pages, blog posts, FAQs, and published reviews may be indexed by search engines and AI crawlers
  • We publish an llms.txt file to guide AI systems on which content may be referenced
  • Structured data (for example FAQ and business schema) may be exposed to help search and AI systems understand public content
  • You may request removal of specific public content through our content removal processes subject to applicable policies

Data Controller

Who is responsible for your personal data on Brilloo:

  • The Brilloo platform operated at brilloo.app is the data controller (responsable) for account, subscription, and platform-operation data
  • Primary market focus: Mexico; we also serve users in other countries where the service is available
  • Privacy requests: contact support@brilloo.app (subject: Privacy / ARCO) or use the contact form on brilloo.app
  • If you need our formal legal entity name or registered address for a legal request, ask support and we will provide the current registered details

Controller and Processor Roles

How roles work when businesses use Brilloo:

  • Brilloo is the controller of platform accounts, authentication, billing for Brilloo subscriptions, security logs, and product analytics we operate
  • When a car wash business manages CRM contacts, POS sales, reservations, reviews, or campaigns about its customers, that business is typically the controller of those customer records; Brilloo processes them as a service provider / processor under the business's instructions and these Terms
  • Business users must have a lawful basis (for example consent or another basis allowed under Mexican LFPDPPP and other applicable laws) for CRM and marketing messages they send
  • End customers may contact either the business or Brilloo depending on the request; we will route or assist as appropriate

Data Retention

How long we keep information:

  • Account and operational data are retained while your account is active and as needed to provide the service
  • After subscription cancellation, business data, customer information held for that company, and related settings are generally retained for about 30 days to allow reactivation or export, then deleted or anonymized unless law requires longer retention
  • Billing, tax, and fraud-prevention records may be kept longer as required by law or Stripe's processing needs
  • Backups and error logs (for example via our monitoring providers) are retained for limited operational periods and then purged on rotation
  • You may request earlier deletion of personal data subject to legal exceptions (for example outstanding billing disputes or security investigations)

International Transfers

Your data may be processed outside Mexico:

  • We use cloud and SaaS providers that may store or process data in the United States or other countries (for example hosting, payments, email, maps, push notifications, AI, and error monitoring)
  • Typical providers include infrastructure and analytics on Vercel, database/auth/storage via Supabase, payments via Stripe, maps and ads via Google, push via Firebase, WhatsApp delivery via YCloud where enabled, email providers, and AI via Vercel AI Gateway / Google
  • These transfers are necessary to operate Brilloo; we select providers with contractual and security safeguards appropriate to the service
  • By using Brilloo you understand that your information may be transferred internationally as described here and in our sharing section

Questions About Your Privacy?

We're here to help. Contact us at support@brilloo.app (Privacy / ARCO) for any questions about how we protect your information.