Products
Sign in

LEGAL DOCUMENTS

Privacy Policy

Last updated:

This document was written in Portuguese. This English version is a translation provided for convenience; in case of any conflict between the two, the Portuguese version prevails.

This Policy explains how BK Products processes personal data when you visit our website and use the web app, the Chrome extension and our e-mails. It follows Brazil’s General Data Protection Law (Law No. 13,709/2018, the LGPD).

Your use of the service is also governed by the Terms of Use. If you have any questions, write to [email protected].

1.Who we are and how to reach us

BK Products is a service of Bk Reviews LTDA, registered under CNPJ No. 54.734.121/0001-96, headquartered at Rua Mistral (Jd. Bom Clima), 332, Edif. The Point, Sala 209A, Despraiado, Cuiabá/MT, CEP 78048-222, Brazil. In this Policy, “BK Products”, “we”, “us” and “our” refer to that company, which is the controller of the personal data processed in the service.

The channel of our data protection officer (encarregado) is the e-mail [email protected]. Use it for any request or question about your data.

For any other question about the service, our e-mail support is described in the support section of our website.

2.The data we process

We process only the data needed to provide the service:

  • Account data: your e-mail address and your name. When you do not give a name, we use the part of the e-mail before the “@”.
  • Access data: when you sign in, we record the session with the date, the IP address and the browser identification (user agent) it was opened from.
  • Content you import and create: the address and content of the product page you choose to import — text, prices, variants, images and the page’s structured data — and the products, images and descriptions you create, edit or generate in the service.
  • Connected stores: the store’s address, language and currency, and the access credentials Shopify or Wix provide when you authorize the connection.
  • Payments: the plan you subscribe to, invoices, payments and refunds and, of the saved card, only the brand, the last four digits, the expiry date and the card’s reference at the payment processor. We never receive the full card number or the security code.
  • Service usage: the usage counters of each plan, such as imports and publications, and technical records of operation and errors.
  • Communications: the messages you send us by e-mail.

We do not ask for a tax ID (CPF), address or phone number to create an account or subscribe to a plan — the card and billing details Stripe’s payment page asks for stay with Stripe —, and we do not knowingly collect sensitive personal data.

3.The Chrome extension

The extension has no login of its own: it uses the web app session open in your browser. To show the import button on product pages, it loads on the pages you visit and analyzes each page inside your own browser, without sending anything to us.

A page is captured and sent to our servers only when you click to import. At that moment, the extension sends the page’s address, its content (without scripts, styles and vector images), the structured product data and the image addresses. When you import a collection, it also opens, from the source store itself, the pages of the collection’s products to capture them.

The capture reproduces the page as it appears to you. If the page shows personal information — for example, your name when you are signed in to the source site —, it may be part of the capture. We use the capture only to build the imported product.

The extension does not read your cookies, does not take screenshots and does not access your browsing history. In the browser, it keeps only a temporary marker, which expires in 30 minutes, used when the app asks it to continue an import on a page.

4.Why we use the data and on what legal basis

  • Creating and keeping your account, authenticating your access and providing the service — importing, organizing, generating and publishing products and connecting stores: performance of a contract (LGPD art. 7, V).
  • Charging subscriptions, issuing invoices and receipts and processing refunds: performance of a contract and compliance with a legal obligation (art. 7, II and V).
  • Sending the e-mails the service needs — the sign-in link, the subscription confirmation, receipts and billing notices: performance of a contract (art. 7, V).
  • Protecting the service and the accounts, limiting abusive access attempts, investigating errors and preventing fraud: legitimate interest (art. 7, IX).
  • Complying with legal and regulatory obligations and exercising rights in judicial, administrative or arbitration proceedings (art. 7, II and VI).

We do not sell personal data, do not use it for advertising and do not send marketing e-mails: every e-mail we send belongs to the service itself.

5.Artificial intelligence features

Some features use artificial intelligence — such as image variation generation, text suggestions, image organization and description generation. They are available according to your plan and to each feature’s release, and they run only when you use them.

When you use one of these features, we send the AI provider the product content the task needs — such as title, category, description, attributes, the source page’s address and the image addresses — and the messages you write. The providers are Anthropic and OpenRouter, which routes requests to third-party models such as Google’s Gemini image models.

We do not send your e-mail address or your payment data to AI providers.

6.International transfer

Some of the vendors that run the service for us process or store data outside Brazil — our API servers and database, for example, are in the United States. These transfers are necessary to perform the contract with you (LGPD art. 33, IX) and are made only with the vendors listed above.

7.How long we keep the data

  • Account data and the content you create are kept for as long as your account exists.
  • The access session expires after 7 days without use and ends when you sign out.
  • Invoices, payments and refunds are kept for the period tax and accounting laws require, even after the account is closed.
  • If you ask us to delete your account, we delete or anonymize your personal data, except what we must keep to comply with legal obligations or exercise rights in proceedings, for the period the law sets.

8.How we protect the data

  • All communication between your browser, the extension and our servers uses encrypted connections (HTTPS).
  • Each account only reaches its own data: every query is limited to the account of the open session.
  • We limit sign-in attempts to make abuse harder.
  • Card data is typed directly into Stripe’s payment page and never goes through our servers.
  • The temporary secrets used while connecting a store are encrypted (AES-256) and erased when the connection finishes. The connected store’s credentials are kept in our database, are not exposed by our API and are used only to run the service on your store.

No system is completely secure. If a security incident occurs that may bring you relevant risk or harm, we will notify you and the ANPD, as the LGPD requires.

9.Cookies and browser storage

Our public website does not use cookies, audience analytics, advertising or third-party trackers.

The web app uses a single cookie, essential to keep you signed in: the session cookie, protected (HttpOnly, Secure and SameSite=Lax) and sent only to our server. Because it is strictly necessary for the service to work, it does not depend on consent.

The app also keeps a few usage preferences in your browser’s local storage — the interface language, the state of the side menu and the import in progress. They stay in your browser only, and you can erase them in its settings.

Our e-mails use a font served by Google Fonts: when you open an e-mail, your e-mail program may fetch that font from Google’s servers.

10.Your rights

Under the LGPD, you may at any time:

  • confirm whether we process your data and access it;
  • correct incomplete, inaccurate or outdated data;
  • ask for the anonymization, blocking or deletion of data that is unnecessary, excessive or processed in breach of the law;
  • ask for the portability of the data to another provider, under the ANPD’s regulations;
  • ask for the deletion of data processed with your consent, where applicable, and revoke that consent;
  • know which entities we share your data with;
  • ask for a review of decisions made solely on the basis of automated processing that affect your interests.

To exercise any of these rights, including asking us to delete your account, write to [email protected] from the e-mail address of your account. We may ask for information to confirm your identity before acting, and we will answer within the deadlines the LGPD sets.

You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD).

11.Minors

The service is meant for people aged 18 or over. We do not knowingly collect data from children or teenagers; if we learn that an account belongs to someone under 18, we may close it.

12.Changes to this Policy

We may update this Policy to reflect changes in the service or in the law. The date of the last update is at the top of this page. When a change is relevant, we will let you know by e-mail or in the app before it takes effect.