Legal
Privacy Policy
This policy explains what personal data GBNOX LLC collects, why we collect it, who we share it with, and the rights you can exercise — wherever in the world you are.
01Who we are
GBNOX LLC ("GBNOX", "we", "us", "our") is a software company registered in the State of Florida, United States of America. We build commerce intelligence products for online sellers, brands and agencies.
For personal data we collect through this website and through our own business operations, GBNOX is the data controller — we decide why and how that data is processed.
When a customer uses a GBNOX product to process data about their own customers, employees or listings, that customer is the controller and GBNOX acts as a data processor on their instructions. Our processor obligations are set out in the Data Processing Addendum.
How to reach us
GBNOX LLC5005 W Laurel StTampa, FL 33607United StatesPrivacy: the contact formData protection contact: the contact form02Scope of this policy
This policy applies to gbnox.com, to our marketing and sales activity, and to the accounts we operate for GBNOX products — wherever those products are hosted. GBNOX LLC is the controller for all of them, so there is one privacy policy rather than a separate one per product domain.
A product may publish its own privacy notice covering details specific to it. Such a notice supplements this policy; it does not replace it, and nothing in it reduces the rights set out here.
This policy does not apply to:
- Third-party websites, marketplaces or apps we link to — each has its own policy, and we do not control them.
- Data a customer processes inside a GBNOX product about their own end users. That is governed by the customer's own privacy notice and by our Data Processing Addendum.
- Anonymised or aggregated statistics that can no longer identify anyone. We may use these freely, including to improve our products.
03The personal data we collect
We try to collect as little as the job requires. In practice that falls into five buckets.
| Category | Examples | Where it comes from |
|---|---|---|
| Contact data | Name, email address, company name, the content of a message you send us | Directly from you, via our contact form or email |
| Account data | Login identifier, hashed password or federated identity, workspace and role, subscription tier | Directly from you when you register for a GBNOX product |
| Billing data | Billing name, billing address, tax identifiers, invoice history, last four digits and brand of a card | From you and from our payment processor. We never receive or store full card numbers. |
| Usage and device data | IP address, browser and device type, operating system, pages viewed, referring URL, timestamps, error diagnostics | Automatically, from your browser and our servers |
| Integration data | Marketplace or platform account identifiers, listing and catalogue data, API tokens you authorise | From the third-party services you explicitly connect to a GBNOX product |
We do not knowingly collect special categories of data (health, biometrics, race, religion, political opinions, trade union membership, sex life or sexual orientation), and we ask that you do not send them to us. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
04How we use personal data, and our legal basis
Under the GDPR and UK GDPR we must have a lawful basis for every processing purpose. The table below sets ours out.
| What we do | Why | Lawful basis |
|---|---|---|
| Answer your enquiry | You contacted us and expect a reply. Sending the form triggers an automated acknowledgement to your address from ; the answer itself comes from . | Legitimate interests; steps prior to entering a contract |
| Create and run your account | To deliver the product you signed up for | Performance of a contract |
| Take payment and issue invoices | To be paid, and to meet tax and accounting duties | Performance of a contract; legal obligation |
| Keep the service secure | Abuse prevention, rate limiting, fraud detection, audit logging | Legitimate interests; legal obligation |
| Diagnose faults and improve the product | Error reports and aggregated usage tell us what is broken | Legitimate interests |
| Send service messages | Outages, security notices, material changes to terms | Performance of a contract; legal obligation |
| Send marketing email | To tell you about GBNOX products | Consent, or legitimate interests where the law allows it for existing customers |
| Analytics on our website | To understand which pages are useful | Consent where required; otherwise legitimate interests |
| Defend legal claims and comply with law | Court orders, regulatory requests, disputes | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is proportionate. You can ask us for that assessment, and you can object at any time — see Your rights.
07International data transfers
GBNOX is based in the United States and works with customers worldwide, so personal data may be processed outside your country — including in the United States and the European Union.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on one or more of the following safeguards:
- The European Commission Standard Contractual Clauses (Decision 2021/914), and the UK International Data Transfer Addendum where the UK GDPR applies;
- An adequacy decision covering the destination country;
- Your explicit consent, where no other mechanism is available and the transfer is occasional.
We also run transfer impact assessments on our material sub-processors and apply supplementary measures — encryption in transit and at rest, access minimisation and a policy of challenging unlawful government access requests. You can request a copy of the relevant clauses from the contact form.
08How long we keep data
We keep personal data only as long as the purpose requires, then delete or anonymise it.
| Data | Retention |
|---|---|
| Contact form enquiries | Up to 24 months after the last exchange |
| Account data | For the life of the account, then up to 90 days after closure |
| Billing and tax records | Up to 7 years, as tax law requires |
| Security and audit logs | Up to 12 months |
| Marketing consent records | Until you withdraw consent, plus a suppression record so we do not contact you again |
| Backups | Rolling window of up to 35 days, after which deleted data ages out |
Where a legal hold applies — for example an active dispute — we retain the affected records until the matter closes.
09How we protect personal data
We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest, least-privilege access with multi-factor authentication, tenant isolation, dependency and vulnerability scanning, and logged administrative access.
A fuller description is on our Security page, including how to report a vulnerability responsibly.
No system is perfectly secure. If a personal data breach occurs and it is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where the risk is high.
10Your rights
Depending on where you live, some or all of these rights apply to you. We honour the full set for every person who asks, regardless of jurisdiction, because it is simpler and fairer than checking your passport first.
- Access — get confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where we no longer have grounds to keep it.
- Restriction — have processing paused while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another provider where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time and unconditionally.
- Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing already carried out.
- Non-discrimination — exercise any of these rights without receiving a worse price or level of service.
How to make a request
Use the contact form and tell us what you want. We will respond within 30 days (extendable by a further 60 days for complex requests, in which case we will tell you why within the first 30).
We may need to verify your identity before acting — usually by confirming control of the email address on the account. We will not ask for more identifying data than necessary. Requests are free unless they are manifestly unfounded or excessive, in which case we will tell you the fee before doing the work.
An authorised agent may act for you if you provide written authorisation we can verify.
11If you are in the EEA, the UK or Switzerland
You have the rights listed above under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection.
You also have the right to lodge a complaint with a supervisory authority — normally the one where you live, work, or where the alleged infringement took place. We would appreciate the chance to resolve your concern first, but that is your choice, not a precondition.
We do not currently have an establishment in the EEA or the UK. Where Article 27 GDPR requires us to designate a representative, we will publish those details here.
12If you are in the United States
State privacy laws — including the California Consumer Privacy Act as amended by the CPRA, and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and other states as they take effect — give residents rights to know, delete, correct, and opt out of sale, sharing, targeted advertising and certain profiling.
GBNOX does not sell personal information, does not share it for cross-context behavioural advertising, and does not use it for targeted advertising or for profiling that produces legal or similarly significant effects. There is therefore nothing to opt out of, but you can still exercise your access, deletion and correction rights at any time using the process above.
Categories collected, disclosed and retained
For CCPA purposes, the categories in The personal data we collect map to identifiers, commercial information, internet or network activity, and professional or employment-related information. Each is collected for the business purposes in How we use personal data, disclosed only to the service providers listed at Sub-processors, and retained for the periods in How long we keep data.
California residents may also request information under the "Shine the Light" law about disclosures to third parties for their direct marketing purposes. We make no such disclosures.
13If you are elsewhere
We designed this policy so it works in the jurisdictions our customers actually operate in, not just the ones we operate from.
- Canada — we handle personal information consistently with PIPEDA and provincial equivalents. You may complain to the Office of the Privacy Commissioner of Canada.
- Brazil — the LGPD rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing are covered by Your rights. Our processing bases map to Article 7 LGPD.
- Australia — we handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988.
- Japan — we handle personal information consistently with the Act on the Protection of Personal Information (APPI), including its rules on third-party and cross-border provision.
- Singapore and Malaysia — consent, notification, access and correction obligations under the PDPA are met through this policy and the request process above.
- South Africa — POPIA data subject rights, including objection and complaint to the Information Regulator, are available to you.
- India — we handle personal data consistently with the Digital Personal Data Protection Act, 2023, including its notice, consent and grievance-redressal expectations. Grievances go to the contact form.
- Everywhere else — write to us and we will apply the strongest applicable standard rather than the weakest.
14Automated decision-making and AI
GBNOX products use machine learning to score, rank and summarise commercial data — for example, how visible a listing is likely to be. Two commitments follow from our principles:
- Every output traces back to a reason a human can read. We do not ship recommendations we cannot explain.
- We do not make solely automated decisions that produce legal effects or similarly significant effects on an individual, within the meaning of Article 22 GDPR.
We do not use customer content to train general-purpose foundation models, and we do not sell customer content to anyone who does. Where a GBNOX product uses a third-party model provider to process a request, that provider is listed at Sub-processors and is contractually barred from training on our customers' data.
15Children's privacy
GBNOX products are business tools sold to organisations and adults. They are not directed at children, and we do not knowingly collect personal data from anyone under 16 (or under 13 in the United States, per COPPA).
If you believe a child has given us personal data, use the contact form and we will delete it promptly.
16Third-party services and links
Our products connect to marketplaces, storefronts and platforms at your instruction. Once data leaves our systems for a third party you have authorised, that third party's own terms and privacy policy govern it. We recommend reading them.
Links from this website to external sites are provided for convenience and are not an endorsement.
17Changes to this policy
We update this policy when our practices, our products or the law change. The "last updated" date at the top always reflects the current version.
For material changes — a new purpose, a new category of recipient, or a change that reduces your rights — we will give at least 30 days' notice by email to account holders, or by a prominent notice on this site, before the change takes effect.
18Contact and complaints
Privacy questions, rights requests and complaints all go to the contact form. Our data protection contact is reachable through the same contact form.
If you are not satisfied with our response, you may escalate to your local supervisory authority or data protection regulator. We will cooperate with them fully.
GBNOX LLC5005 W Laurel StTampa, FL 33607United States