
Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how Brilliantship LLC ("Brilliantship," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our websites, business-management platform, APIs, hosted storefront technology, mobile experiences, and related services (collectively, the "Services").
It also explains the choices and rights that may be available to you. If you do not agree with this Policy, please do not use the Services.
1. Scope and our role
Brilliantship provides a multitenant software platform used by jewelry and diamond businesses (each, an "Organization") to manage inventory, users, customers, orders, data connections, websites, and other sales channels.
Brilliantship acts as a controller or "business" for personal information we determine how to use, such as information about our Organization accounts, billing contacts, website visitors, and direct support interactions.
When an Organization submits or collects information through the Services and determines why and how that information is used, Brilliantship generally acts as its processor or service provider. This includes information about an Organization's customers, prospects, employees, products, orders, and communications ("Organization Data"). The Organization's privacy notice governs its own practices. If your request concerns Organization Data, contact the relevant Organization first. We will assist the Organization as required by law and our agreement with it.
This Policy does not govern an Organization's independent practices, third-party websites or services, or information processed under a separate written agreement that expressly supersedes this Policy.
2. Information we collect
The information we collect depends on how you use the Services.
| Category | Examples |
|---|---|
| Account and contact information | Name, business name, job title, email address, telephone number, mailing address, account role, organization, and profile details. |
| Authentication and security information | Login identifiers, session identifiers, authentication tokens, sign-in method, passkey public-key and device details, verification records, and security events. Authentication providers process passwords; Brilliantship does not need your plaintext password. |
| Billing and transaction information | Billing contact and address, subscription, invoices, payment status, transaction identifiers, tax information, and limited payment-method details. Payment card data is submitted to our payment provider, and we generally receive a token and limited card details rather than the full card number. |
| Organization Data and content | Product inventory, images and videos, pricing, customer and user records, order and fulfillment details, shipping and billing addresses, inquiries, messages, files, website content, configurations, and information imported from connected systems. |
| Communications and support | Support requests, feedback, survey responses, emails, messages, call details, and other communications with us or, when enabled by an Organization, through the Services. |
| Connected-service information | Account identifiers, access tokens, business profile details, catalog details, connection settings, and data exchanged with services you choose to connect, such as Google, Meta, WhatsApp, Stripe, SFTP/FTP, APIs, and other sales or data channels. |
| Device, log, and usage information | IP address, browser and device type, operating system, approximate location derived from IP, referring page, pages and features used, searches and filters, wishlist activity, timestamps, diagnostic data, and error logs. |
| Preferences and inferences | Language, notification and display settings, saved filters, product interests, and preferences inferred from use of the Services. |
Sensitive information
The Services are not designed for health information, government identifiers, precise geolocation, biometric templates, or other specially protected data. Please do not submit sensitive personal information unless it is necessary, lawful, and expressly permitted by your agreement with us. Account credentials and connected-service tokens are used only to authenticate, secure, and provide the requested Services.
3. Sources of information
We collect personal information from:
- You, including when you register, purchase, upload, or contact us.
- Organizations, their administrators, and other users who provide information about authorized users, customers, or business contacts.
- Visitors and customers who interact with Organization storefronts, forms, checkout, customer accounts, or communication channels.
- Connected services at your or an Organization's direction, including identity, payment, marketplace, messaging, data-feed, and social-platform providers.
- Your browser, device, and use of the Services through cookies, local storage, logs, and similar technologies.
- Service providers, business partners, and publicly available sources, where permitted by law.
4. How we use information
We use personal information to:
- Provide, operate, maintain, and personalize the Services.
- Create and administer accounts, authenticate users, and manage permissions.
- Process subscriptions, credits, invoices, payments, orders, and related transactions.
- Host Organization websites and content; synchronize data; and operate connected sales, data, and messaging channels.
- Provide support, respond to requests, send service notices, and communicate about the Services.
- Analyze performance and usage, troubleshoot, develop features, and improve usability.
- Protect accounts and the Services, prevent fraud and abuse, enforce agreements, and investigate security incidents.
- Comply with law, legal process, tax and accounting obligations, and lawful requests from authorities.
- Send marketing communications where permitted. You may opt out at any time using the unsubscribe link or by contacting us.
- Carry out another purpose disclosed when information is collected, with your consent where required.
Legal bases for EEA, UK, and similar laws
Where applicable, we rely on performance of a contract, our legitimate interests (including operating, securing, and improving the Services and communicating with business users), compliance with legal obligations, and consent. You may withdraw consent at any time, but withdrawal does not affect processing that was already lawful.
5. How we disclose information
We may disclose personal information to:
- Organizations and authorized users. Information is made available within the applicable Organization and according to its roles, settings, storefronts, and connected channels.
- Infrastructure and operations providers. These include cloud hosting, storage, content delivery, database, authentication, email, communications, monitoring, support, and security providers.
- Payment providers. Payment and billing information is disclosed to providers such as Stripe to process platform subscriptions and, where configured, Organization storefront transactions.
- Analytics and advertising providers. We use Google Tag Manager and may use analytics or advertising services configured through it to understand use of the Services and measure campaigns. These providers may collect device and usage data as described in their own notices.
- AI providers. Information you choose to submit to an AI feature may be disclosed to providers such as OpenAI or Google to generate requested text or images.
- Connected services. We exchange information with services an Organization or user directs us to connect, including Google, Meta, WhatsApp, Stripe, Firebase, APIs, and data-transfer services.
- Professional advisers and authorities. We may disclose information to auditors, insurers, lawyers, accountants, regulators, law enforcement, or courts when reasonably necessary and legally permitted.
- Corporate transactions. Information may be disclosed as part of a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate protections.
- With your direction or consent. We disclose information for other purposes you request or authorize.
We do not sell personal information for money. Some jurisdictions define "sale," "sharing," or targeted advertising broadly enough to cover certain advertising or analytics disclosures. Where those laws apply and we engage in such activity, we will provide the required notice and opt-out method. We do not knowingly sell or share the personal information of individuals under 18.
6. Cookies and similar technologies
We use cookies, local storage, pixels, tags, and similar technologies to keep you signed in, remember settings, maintain carts and other features, secure the Services, diagnose errors, understand usage, and measure communications or campaigns. Some are set by providers whose technology appears in the Services, including Google and Stripe.
You can control cookies through your browser and any cookie controls we make available. Blocking essential storage may prevent login, checkout, or other features from working. Because there is not a uniform industry response to browser "Do Not Track" signals, we do not currently respond to them. This does not affect any opt-out preference signal that we are legally required to honor.
7. AI features and integrations
Optional AI features can generate or edit product text, website content, and images. Prompts, product details, and reference images selected for a request are sent to the configured AI provider. Do not include confidential or personal information in a prompt unless you are authorized to do so and it is necessary for the requested output. AI output may be inaccurate and should be reviewed before use.
When you connect a third-party service, we process the credentials and information needed to establish and operate that connection. The third party's terms and privacy notice also apply. You can disconnect integrations through available settings or by contacting us, though the third party may retain information it already received.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain the integrity of business records, comply with legal, tax, accounting, and contractual obligations, resolve disputes, enforce agreements, and protect the Services.
Retention depends on the type of information, the Organization's instructions and account status, the sensitivity of the information, applicable limitation periods, and legal requirements. Information may remain for a limited period in backups or security logs after deletion from active systems. We may retain deidentified or aggregated information where it can no longer reasonably identify an individual.
9. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including access controls, encrypted transport, authentication controls, monitoring, and data isolation measures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting account credentials, using appropriate permissions, and notifying us promptly of suspected unauthorized access.
10. International transfers
Brilliantship is based in the United States, and we and our providers may process information in the United States and other countries that may have different data-protection laws. Where required, we use an approved transfer mechanism, such as standard contractual clauses, and supplementary safeguards appropriate to the transfer.
11. Your rights and choices
Depending on where you live and subject to applicable exceptions, you may have the right to request access, correction, deletion, restriction, portability, or a copy of personal information; object to or opt out of certain processing; withdraw consent; appeal a decision; and not receive discriminatory treatment for exercising a privacy right.
To exercise a right concerning information Brilliantship controls, email contact@brilliantship.com with the subject "Privacy Request" or write to the address in the Contact section. You may also update certain account information in the Services. We may verify your identity and authority to protect the account and other individuals. An authorized agent may submit a request where permitted by law, subject to verification of the authorization.
For Organization Data, contact the Organization that controls the relevant storefront, account, or communication. If you contact us, we may refer the request to that Organization.
You may opt out of marketing emails using the unsubscribe link in the message. You will still receive transactional, security, billing, and other non-marketing communications when necessary.
If you are in the EEA or UK, you may lodge a complaint with your local data-protection authority. We encourage you to contact us first so we can try to address the concern.
12. United States disclosures
This section supplements the rest of the Policy for residents of US states with comprehensive privacy laws. Whether a particular law applies to Brilliantship depends on statutory thresholds and the context in which we process the information.
During the preceding 12 months, we may have collected the following statutory categories: identifiers; customer-record information; commercial information; internet or other electronic-network activity; professional or employment-related information; geolocation at the approximate level; audio, electronic, visual, or similar information; inferences; and sensitive personal information limited to account credentials and information needed to access a connected service. We collect these categories from the sources in Section 3, use them for the purposes in Section 4, and disclose them to the recipient categories in Section 5.
We do not use or disclose sensitive personal information to infer characteristics about an individual. We do not offer financial incentives in exchange for personal information. We do not sell personal information for money. As explained above, certain advertising or analytics activity may be treated as a "sale" or "sharing" under some laws; when applicable, the relevant opt-out rights and controls will be made available.
California's "Shine the Light" law may permit California residents with an established business relationship to request information about certain disclosures for third parties' direct-marketing purposes. Submit requests using the Contact section below.
13. Children
The Services are intended for businesses and adults and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided information to us in violation of this Policy, contact us so we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy as our Services or legal obligations change. We will post the updated version and revise the "Last updated" date. If changes are material, we will provide additional notice where required, such as through the Services or by email. We encourage you to review this Policy periodically.
15. Contact us
Questions, complaints, and privacy requests may be sent to:
Brilliantship LLC1301 N BROADWAY STE 91014
LOS ANGELES, CA 90012
United States
Email: contact@brilliantship.com