Privacy Policy - Brainstorm Force - Store

Privacy Policy

This Privacy Policy describes how your personal information is collected, used, and shared.

This privacy policy applies to all visitors, website users, members, and customers using or accessing our websites, including brainstormforce.com, ultimatebeaver.com, ultimateelementor.com, convertpro.net, wpschema.com, wpportfolio.net, wpastra.com, wpspectra.com, skilljet.io, startertemplates.com, store.brainstormforce.com, support.brainstormforce.com, and ultimate.brainstormforce.com (collectively, the “Site”).

Who We Are

We are Brainstorm Force US LLC. You can find more information about us, including our full address, on our company website.

What Personal Information We Collect

When you visit our website, we automatically collect information about your device, including your web browser type, IP address, and time zone. As you browse the Site, we also collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site.

Cookies and Similar Technologies

“Cookies” are small data files placed on your device, often including an anonymous unique identifier. We use cookies and similar technologies (such as pixels and tags) across our sites for the following purposes:

  • Essential – required for core site functionality (e.g., security, load balancing)
  • Functional – remember your preferences and settings
  • Analytics – help us understand how visitors use our sites and test improvements to site design (e.g., Microsoft Clarity, Sigmize, Matomo)
  • Marketing – used for advertising measurement and remarketing (e.g., Meta Pixel, Google Ads, Google Analytics)

Non-essential cookies (Functional, Analytics, and Marketing) are only set after you provide consent through our cookie preference banner. You can change your preferences at any time by clicking Cookie Preferences.

We honor the Global Privacy Control (GPC) signal where required by law: if your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information, and this preference is respected on both cached and uncached versions of our pages.

Retention: Records of your cookie consent choices are retained for up to 365 days, or less if manually cleared sooner, so we can demonstrate compliance with applicable consent requirements and honor your prior preferences on return visits.

Comments

When you leave comments on the site, we collect the data shown in the comments form, along with your IP address and browser user-agent string, to help with spam detection.

An anonymized string created from your email address (a “hash”) may be shared with the Gravatar service to check if you’re using it. Gravatar’s privacy policy is available here. After your comment is approved, your profile picture is visible to the public alongside your comment.

Contact Forms

Information submitted through contact forms on our Site is sent to our self-hosted support desk.

We may collect information submitted through contact forms, including (but not limited to) your first and last name and email address. This information may be shared with our email marketing services, including our self-hosted CRM.

Support

To help with our products, we may ask for temporary access to your website – either your live site or a staging copy, whichever you prefer – such as an admin login or FTP/database credentials. Troubleshooting typically takes place directly on your site itself, and in these cases we do not transfer, export, or store your site’s data on our own servers. We recommend a staging copy where practical, but understand this isn’t always feasible for every customer.

In some cases, particularly for more complex issues, we may create a copy of your website on our own servers to investigate the problem. Once the issue is resolved, we delete these copies from our systems.

Information submitted through support forms is managed through our self-hosted support portal.

A few important points about access shared with our support team:

  • We use any access you provide strictly for debugging your specific issue, on your site itself.
  • We do not copy or retain your site’s data on our own systems.
  • We do not share access or data with anyone outside the company.
  • We cannot be held responsible for loss of private information from your database or website. If you’re able to share a staging site and keep a working backup of anything shared with us, we recommend doing so.

Retention: Where troubleshooting happens on your site directly rather than on data transferred to us, there is no site-data copy for us to retain, and you are responsible for rotating or revoking any login, FTP, or database credentials you shared with us once your issue is resolved – we have no further use for them once the support ticket closes. Where we’ve created a copy of your site on our own servers for investigation, we delete that copy once the issue is resolved.

We retain support ticket records, including any screenshots, logs, or other materials shared as part of a ticket, for 3 years from the date the ticket is closed. We do this so we can refer back to how a past issue was resolved if it recurs, and to analyze recurring issues internally to improve our products and reduce future support volume. Support ticket records are not shared with any third party – they remain strictly between you and us.

If your site contains your own customers’ or visitors’ personal data (for example, order or form submissions) that we may view while troubleshooting on your site, we access that data only as necessary to resolve your issue and do not retain or use it beyond that purpose – you remain responsible for your own compliance obligations toward your site’s visitors and customers.

Purchase

If you purchase products or services from us, our payment gateway provider may require your credit card and billing information to process the transaction. Credit card details are not stored by us on any internal or external database accessible to us.

All direct payment gateways adhere to PCI-DSS standards, managed by the PCI Security Standards Council (a joint effort of Visa, MasterCard, American Express, and Discover), which help ensure secure handling of card information.

When you make or attempt a purchase, we verify your card through a payment gateway and collect information including your name, billing address, shipping address, payment information, email address, and phone number.

Retention: Billing and transaction records are retained for as long as your account or license remains active (including to support plan renewals). Because we are subject to tax, accounting, and audit-related legal obligations, financial records are retained for the period required by applicable law even after account deactivation or a data deletion request – this is a standard, legally-recognized exception to deletion rights, not a workaround, and applies specifically to financial/transaction records rather than personal information generally.

Information About Your Website and Server Configuration

When you use our WordPress products, we may receive non-personal information about your website, including (but not limited to): whether SSL is installed, Curl/PHP/MySQL versions, server software, WordPress version and language, timezone, whether the site is a Multisite installation, debug settings, site URL, active plugins and theme, and BSF Updater version. Learn more here.

We collect this non-personal information to develop better, more compatible software and serve our customers more effectively.

License Keys

A license key is required to validate your purchase and unlock benefits like automatic updates, developer support, and extra resources. When you activate a license key, we receive your website URL, name, and email address, and we keep records of every website URL where the key has been activated.

Retention: License activation records are retained for as long as the license remains active, and for a reasonable period thereafter for support and renewal purposes.

Who We Share Your Data With

Some of our advertising and analytics tools involve sharing personal information with third parties for cross-context behavioral advertising, as that term is defined under California law – meaning those partners may use information about your activity on our sites to show you relevant ads elsewhere. This sharing only happens for the categories below, and only after you’ve provided consent through our cookie preference banner (or, where applicable, is subject to your California opt-out rights described in the California Privacy Rights section below).

The categories of third parties we work with, and what they receive, include:

CategoryExamplesWhat they receivePurposeSale / Share / Service Provider
Payment processingPayPal, Paddle (our Merchant of Record)Billing/payment detailsProcess transactionsService provider – not sold or shared
Email deliveryAmazon SESEmail addressTransactional and account emailsService provider – not sold or shared
Tag managementGoogle Tag ManagerIP address, browser/device information, page URL (as part of loading the container script)Loads and manages our other scripts/tags, and reads your consent status to decide which of them may runService provider – not sold or shared. Loads on every visit, including before consent is given, since it needs to evaluate your consent choice before deciding whether to load the tools listed below.
Advertising / conversion measurementMeta (Facebook) Pixel, Google Ads, DoubleClick, Google Analytics (GA4), TikTok, SnapchatPage views, device/browser identifiers, cookies, and – only where you’ve consented – hashed contact information (email, phone, name, etc.) via Meta’s Advanced Matching feature. GA4 data may also be used to build Google Ads audiences via Ads Linking.Ad performance measurement, remarketing, targeted advertisingShared for cross-context behavioral advertising
On-site advertisingGoogle AdSensePage content, browsing behavior, device/browser identifiersNot currently active. Previously used to serve third-party ads on our sites; retained here for transparency in case reintroduced.Shared; only loads after you provide consent
Session analyticsMicrosoft ClaritySession interactions (clicks, scroll, mouse movement)Understand user experience, identify usability issuesService provider – not sold or shared
Independent web analyticsMatomo / PiwikIP address, browsing behavior, device infoUnderstand site usage, separate from Google AnalyticsService provider – not sold or shared
Content delivery / securityCloudflareIP address, request metadataSite performance and securityService provider – not sold or shared
Bot protection / verificationCloudflare Turnstile, Google verification servicesDevice/browser signals for bot-detectionPrevent spam and automated abuseService provider – not sold or shared
WordPress core servicesWordPress.orgBasic request metadataCore WordPress functionality (e.g., emoji support, update checks)Service provider – not sold or shared
AI chat supportPowerful DocsChat messages, name, email (if provided during the conversation)AI-powered chat assistance; only loads after you provide consentService provider – not sold or shared
Live chat / support widgetsHelpScout, SmartsuppName, email, message content, browsing pageProvide live chat and customer supportService provider – not sold or shared
On-site commentsDisqusName, email, comment content, IP addressEnable and moderate visitor commentsService provider – not sold or shared
Social media embedsMeta (Instagram)Page views, device/browser identifiersDisplay embedded social contentShared, consistent with our treatment of other Meta properties
Video embedsYouTube, VimeoPage views, device/browser identifiers, and standard platform cookiesDisplay embedded video contentShared; only loads after you provide consent
On-site experimentationSigmizeBrowsing behavior, page interactions, assigned test variantA/B testing to improve user experience and site designService provider – not sold or shared
Marketing funnel analyticsFunnelyticsBrowsing behavior, page interactionsMarketing funnel visualization and analysisService provider – not sold or shared
Affiliate attributionAffiliateWP cross-domain trackerReferral/click identifiersTrack and pay affiliate referralsService provider – not sold or shared

On Meta’s Advanced Matching specifically: this feature, which lets Meta match hashed contact information to a Meta account for better ad targeting, is only active for visitors who have consented to marketing cookies. Our entire tag container – including the Meta Pixel – is blocked from loading until you explicitly provide consent; nothing in this category reaches Meta, Google, or any other advertising partner beforehand.

Cross-BSF-product tracking: Because Brainstorm Force operates multiple distinctly-branded product sites (Astra, Spectra, ConvertPro, and others), each site runs its own independent cookie consent tool. Your consent choice on one BSF site does not carry over to another – when you visit any BSF-operated site, you’ll see that site’s own cookie banner, and non-essential data collection on that site is blocked until you respond to it. If you want to opt out across multiple BSF properties, you’ll need to do so on each site individually.

California Privacy Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, disclose, and (if applicable) sell or share, and to request a copy of it.
  • Right to delete personal information we’ve collected from you, subject to certain exceptions.
  • Right to correct inaccurate personal information we maintain about you.
  • Right to opt out of the sale or sharing of your personal information. Based on the categorization above, this specifically means opting out of the advertising/conversion-measurement tools (Meta Pixel, Google Ads, DoubleClick, Google Analytics, TikTok, Snapchat, and Meta-owned embeds) that involve cross-context behavioral advertising – the other categories listed above are service-provider relationships and are not sold or shared.
  • Right to limit the use and disclosure of sensitive personal information, where applicable.
  • Right to non-discrimination for exercising any of the above rights.

To opt out of the sale or sharing of your personal information, click on the Cookie Preferences button on the respective site’s footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out request.

To exercise your other rights, contact us at [email protected]. We will verify your request and respond within 45 days, as required by law (with a possible 45-day extension for complex requests, in which case we’ll notify you of the extension and reason).

You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify the agent’s authority to act for you.

Your Rights Under India’s Digital Personal Data Protection Act (DPDP)

If you are located in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023:

  • Right to access a summary of the personal data we hold about you and how we process it.
  • Right to correction and erasure of your personal data.
  • Right to grievance redressal, as described below.
  • Right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before your withdrawal.

We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental consent, consistent with the DPDP Act’s requirements for children’s data.

Grievance Officer:
Pratik Chaskar
CTO, Brainstorm Force,
[email protected]

If you have a grievance regarding how we handle your personal data, you may contact our Grievance Officer at the details above. We will acknowledge your grievance within 72 hours of receipt, including a reference number and expected resolution timeline. We aim to resolve most grievances within 30 days, and in all cases within 90 days, as required under the DPDP Rules, 2025.

How Secure Is My Information

We take reasonable precautions and follow industry best practices to protect your personal information from being inappropriately lost, misused, accessed, disclosed, altered, or destroyed.

Credit card information, when provided, is encrypted using secure socket layer (SSL) technology.

What Rights You Have Over Your Data

If you’d like to confirm what personal data we hold about you, modify it, understand the purpose of collection and processing, or stop data sharing/processing, contact us at [email protected].

You can also request information about the source of your personal data (if not provided directly by you) or how long it will be retained. You have the right to request deletion of data no longer needed for its original purpose, or to cease its processing. Please note that certain records – such as financial and transaction records – may be retained even after a deletion request, where retention is required by applicable tax, accounting, or audit obligations, consistent with the recognized legal exceptions to the right of deletion. You can request we stop using your data for direct marketing purposes, and you may withdraw consent at any time by clicking “unsubscribe” in our emails.

Legal basis for processing (EEA/UK visitors): Depending on the purpose, we process your data based on: your consent (e.g., non-essential cookies, marketing communications), the necessity of processing to perform our contract with you (e.g., fulfilling a purchase), our legitimate interests (e.g., improving our services, fraud prevention), or compliance with a legal obligation.

If you believe we haven’t complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority. Within technical limits, we will provide your personal data to you or your data protection authority upon request.

If we can’t provide requested data within a reasonable timeframe, we will let you know when it will be available; if we deny a request, we will explain why.

Children’s Online Privacy Protection Act Compliance

We do not knowingly collect personal information from children under the age of 13. If we determine we’ve collected personal information from a child under 13, we will take reasonable measures to remove it from our systems. If you are under 13, please do not submit personal information through the Site, service, or Software.

Third-Party Links

We may include or offer third-party products or services on our website. These third-party sites have separate, independent privacy policies, and we hold no liability or responsibility for their content or activities.

Affiliate Disclosure

Some third-party links on our store may be affiliate links. We earn a referral fee when you buy services from companies we recommend. We only recommend products we believe add value to our customers – if you purchase after clicking an affiliate link, we receive a commission.

These affiliate commissions help us generate free content on our blog and free courses on SkillJet.

Affiliate tracking cookies are subject to the same consent preferences described in the Cookies section above.

Remarketing and Targeted Advertising

We work with third parties – including Google Analytics, Google Ads, Meta (Facebook and Instagram), TikTok, Snapchat, and Microsoft Clarity – to provide targeted advertisements or marketing communications that may interest you, based on your browsing activity on our sites. This may include cross-context behavioral advertising as defined under California law. For more on how targeted advertising works, see the Network Advertising Initiative’s educational page.

You can opt out of targeted advertising through:

Or by clicking on the Cookie Preferences button on the respective site’s footer, which applies across all the advertising partners listed in this policy.

Newsletter Emails

By becoming a site user, member, or customer, you acknowledge and agree to be signed up for our newsletter. From time to time, we may contact you about product announcements, software updates, and special offers. You may opt out at any time via the “unsubscribe” link in our emails. We will only send marketing communications to users located in the EEA with their prior consent.

Will This Privacy Policy Ever Change

We may update this Policy to keep pace with changes in our Site, Software, Services, business, and applicable laws. We will always maintain our commitment to respecting your privacy. Continued use of our Site, software, and services after a policy change means you agree to the updated policy.

Contact Us

For questions about our privacy practices or to make a complaint, contact us by email at [email protected] or by mail:

Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States

Last updated: 21 August 2026