Skip to content
GBNOX
AboutProductsPrinciplesLegalContact
Home/Legal & Trust/Privacy Policy

Legal

Privacy Policy

This policy explains what personal data GBNOX LLC collects, why we collect it, who we share it with, and the rights you can exercise — wherever in the world you are.

Last updated August 29, 2026·Effective immediately upon posting

On this page

  1. 01Who we are
  2. 02Scope of this policy
  3. 03The personal data we collect
  4. 04How we use personal data, and our legal basis
  5. 05Cookies and similar technologies
  6. 06When we share personal data
  7. 07International data transfers
  8. 08How long we keep data
  9. 09How we protect personal data
  10. 10Your rights
  11. 11If you are in the EEA, the UK or Switzerland
  12. 12If you are in the United States
  13. 13If you are elsewhere
  14. 14Automated decision-making and AI
  15. 15Children's privacy
  16. 16Third-party services and links
  17. 17Changes to this policy
  18. 18Contact and complaints

01Who we are

GBNOX LLC ("GBNOX", "we", "us", "our") is a software company registered in the State of Florida, United States of America. We build commerce intelligence products for online sellers, brands and agencies.

For personal data we collect through this website and through our own business operations, GBNOX is the data controller — we decide why and how that data is processed.

When a customer uses a GBNOX product to process data about their own customers, employees or listings, that customer is the controller and GBNOX acts as a data processor on their instructions. Our processor obligations are set out in the Data Processing Addendum.

How to reach us

GBNOX LLC5005 W Laurel StTampa, FL 33607United StatesPrivacy: the contact formData protection contact: the contact form

02Scope of this policy

This policy applies to gbnox.com, to our marketing and sales activity, and to the accounts we operate for GBNOX products — wherever those products are hosted. GBNOX LLC is the controller for all of them, so there is one privacy policy rather than a separate one per product domain.

A product may publish its own privacy notice covering details specific to it. Such a notice supplements this policy; it does not replace it, and nothing in it reduces the rights set out here.

This policy does not apply to:

  • Third-party websites, marketplaces or apps we link to — each has its own policy, and we do not control them.
  • Data a customer processes inside a GBNOX product about their own end users. That is governed by the customer's own privacy notice and by our Data Processing Addendum.
  • Anonymised or aggregated statistics that can no longer identify anyone. We may use these freely, including to improve our products.

03The personal data we collect

We try to collect as little as the job requires. In practice that falls into five buckets.

CategoryExamplesWhere it comes from
Contact dataName, email address, company name, the content of a message you send usDirectly from you, via our contact form or email
Account dataLogin identifier, hashed password or federated identity, workspace and role, subscription tierDirectly from you when you register for a GBNOX product
Billing dataBilling name, billing address, tax identifiers, invoice history, last four digits and brand of a cardFrom you and from our payment processor. We never receive or store full card numbers.
Usage and device dataIP address, browser and device type, operating system, pages viewed, referring URL, timestamps, error diagnosticsAutomatically, from your browser and our servers
Integration dataMarketplace or platform account identifiers, listing and catalogue data, API tokens you authoriseFrom the third-party services you explicitly connect to a GBNOX product

We do not knowingly collect special categories of data (health, biometrics, race, religion, political opinions, trade union membership, sex life or sexual orientation), and we ask that you do not send them to us. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

04How we use personal data, and our legal basis

Under the GDPR and UK GDPR we must have a lawful basis for every processing purpose. The table below sets ours out.

What we doWhyLawful basis
Answer your enquiryYou contacted us and expect a reply. Sending the form triggers an automated acknowledgement to your address from ; the answer itself comes from .Legitimate interests; steps prior to entering a contract
Create and run your accountTo deliver the product you signed up forPerformance of a contract
Take payment and issue invoicesTo be paid, and to meet tax and accounting dutiesPerformance of a contract; legal obligation
Keep the service secureAbuse prevention, rate limiting, fraud detection, audit loggingLegitimate interests; legal obligation
Diagnose faults and improve the productError reports and aggregated usage tell us what is brokenLegitimate interests
Send service messagesOutages, security notices, material changes to termsPerformance of a contract; legal obligation
Send marketing emailTo tell you about GBNOX productsConsent, or legitimate interests where the law allows it for existing customers
Analytics on our websiteTo understand which pages are usefulConsent where required; otherwise legitimate interests
Defend legal claims and comply with lawCourt orders, regulatory requests, disputesLegal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is proportionate. You can ask us for that assessment, and you can object at any time — see Your rights.

05Cookies and similar technologies

This website runs on strictly necessary storage only. We do not deploy advertising cookies, and we do not fingerprint visitors.

Where a GBNOX product needs additional cookies — for example to keep you signed in — those are described in the Cookie Policy, together with how to control them.

Fonts, stylesheets and scripts on this website are served from our own domain. We do not load third-party font or tracking CDNs, so visiting gbnox.com does not disclose your IP address to an advertising network.

06When we share personal data

We share personal data only where there is a reason to, and only with parties bound to protect it.

  • Sub-processors and vendors — hosting, email delivery, payment processing, error monitoring and support tooling. Each is bound by a written contract with confidentiality and security obligations. The current list is published at Sub-processors.
  • Professional advisers — lawyers, accountants and auditors, under professional duties of confidence.
  • Authorities — where a valid legal request compels us. We assess every request, push back on overbroad ones, and notify affected customers unless legally prohibited.
  • A successor entity — if GBNOX is involved in a merger, acquisition or asset sale, data may transfer to the acquirer under the same protections. We will notify you before your data becomes subject to a materially different policy.

We do not sell personal data for money, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act. We have not done so in the preceding twelve months.

07International data transfers

GBNOX is based in the United States and works with customers worldwide, so personal data may be processed outside your country — including in the United States and the European Union.

Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on one or more of the following safeguards:

  • The European Commission Standard Contractual Clauses (Decision 2021/914), and the UK International Data Transfer Addendum where the UK GDPR applies;
  • An adequacy decision covering the destination country;
  • Your explicit consent, where no other mechanism is available and the transfer is occasional.

We also run transfer impact assessments on our material sub-processors and apply supplementary measures — encryption in transit and at rest, access minimisation and a policy of challenging unlawful government access requests. You can request a copy of the relevant clauses from the contact form.

08How long we keep data

We keep personal data only as long as the purpose requires, then delete or anonymise it.

DataRetention
Contact form enquiriesUp to 24 months after the last exchange
Account dataFor the life of the account, then up to 90 days after closure
Billing and tax recordsUp to 7 years, as tax law requires
Security and audit logsUp to 12 months
Marketing consent recordsUntil you withdraw consent, plus a suppression record so we do not contact you again
BackupsRolling window of up to 35 days, after which deleted data ages out

Where a legal hold applies — for example an active dispute — we retain the affected records until the matter closes.

09How we protect personal data

We apply technical and organisational measures appropriate to the risk: encryption in transit and at rest, least-privilege access with multi-factor authentication, tenant isolation, dependency and vulnerability scanning, and logged administrative access.

A fuller description is on our Security page, including how to report a vulnerability responsibly.

No system is perfectly secure. If a personal data breach occurs and it is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware, and notify affected individuals without undue delay where the risk is high.

10Your rights

Depending on where you live, some or all of these rights apply to you. We honour the full set for every person who asks, regardless of jurisdiction, because it is simpler and fairer than checking your passport first.

  • Access — get confirmation of whether we process your data, and a copy of it.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted where we no longer have grounds to keep it.
  • Restriction — have processing paused while a dispute about accuracy or legitimate interests is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another provider where technically feasible.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time and unconditionally.
  • Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect processing already carried out.
  • Non-discrimination — exercise any of these rights without receiving a worse price or level of service.

How to make a request

Use the contact form and tell us what you want. We will respond within 30 days (extendable by a further 60 days for complex requests, in which case we will tell you why within the first 30).

We may need to verify your identity before acting — usually by confirming control of the email address on the account. We will not ask for more identifying data than necessary. Requests are free unless they are manifestly unfounded or excessive, in which case we will tell you the fee before doing the work.

An authorised agent may act for you if you provide written authorisation we can verify.

11If you are in the EEA, the UK or Switzerland

You have the rights listed above under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection.

You also have the right to lodge a complaint with a supervisory authority — normally the one where you live, work, or where the alleged infringement took place. We would appreciate the chance to resolve your concern first, but that is your choice, not a precondition.

We do not currently have an establishment in the EEA or the UK. Where Article 27 GDPR requires us to designate a representative, we will publish those details here.

12If you are in the United States

State privacy laws — including the California Consumer Privacy Act as amended by the CPRA, and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and other states as they take effect — give residents rights to know, delete, correct, and opt out of sale, sharing, targeted advertising and certain profiling.

GBNOX does not sell personal information, does not share it for cross-context behavioural advertising, and does not use it for targeted advertising or for profiling that produces legal or similarly significant effects. There is therefore nothing to opt out of, but you can still exercise your access, deletion and correction rights at any time using the process above.

Categories collected, disclosed and retained

For CCPA purposes, the categories in The personal data we collect map to identifiers, commercial information, internet or network activity, and professional or employment-related information. Each is collected for the business purposes in How we use personal data, disclosed only to the service providers listed at Sub-processors, and retained for the periods in How long we keep data.

California residents may also request information under the "Shine the Light" law about disclosures to third parties for their direct marketing purposes. We make no such disclosures.

13If you are elsewhere

We designed this policy so it works in the jurisdictions our customers actually operate in, not just the ones we operate from.

  • Canada — we handle personal information consistently with PIPEDA and provincial equivalents. You may complain to the Office of the Privacy Commissioner of Canada.
  • Brazil — the LGPD rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing are covered by Your rights. Our processing bases map to Article 7 LGPD.
  • Australia — we handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988.
  • Japan — we handle personal information consistently with the Act on the Protection of Personal Information (APPI), including its rules on third-party and cross-border provision.
  • Singapore and Malaysia — consent, notification, access and correction obligations under the PDPA are met through this policy and the request process above.
  • South Africa — POPIA data subject rights, including objection and complaint to the Information Regulator, are available to you.
  • India — we handle personal data consistently with the Digital Personal Data Protection Act, 2023, including its notice, consent and grievance-redressal expectations. Grievances go to the contact form.
  • Everywhere else — write to us and we will apply the strongest applicable standard rather than the weakest.

14Automated decision-making and AI

GBNOX products use machine learning to score, rank and summarise commercial data — for example, how visible a listing is likely to be. Two commitments follow from our principles:

  • Every output traces back to a reason a human can read. We do not ship recommendations we cannot explain.
  • We do not make solely automated decisions that produce legal effects or similarly significant effects on an individual, within the meaning of Article 22 GDPR.

We do not use customer content to train general-purpose foundation models, and we do not sell customer content to anyone who does. Where a GBNOX product uses a third-party model provider to process a request, that provider is listed at Sub-processors and is contractually barred from training on our customers' data.

15Children's privacy

GBNOX products are business tools sold to organisations and adults. They are not directed at children, and we do not knowingly collect personal data from anyone under 16 (or under 13 in the United States, per COPPA).

If you believe a child has given us personal data, use the contact form and we will delete it promptly.

16Third-party services and links

Our products connect to marketplaces, storefronts and platforms at your instruction. Once data leaves our systems for a third party you have authorised, that third party's own terms and privacy policy govern it. We recommend reading them.

Links from this website to external sites are provided for convenience and are not an endorsement.

17Changes to this policy

We update this policy when our practices, our products or the law change. The "last updated" date at the top always reflects the current version.

For material changes — a new purpose, a new category of recipient, or a change that reduces your rights — we will give at least 30 days' notice by email to account holders, or by a prominent notice on this site, before the change takes effect.

18Contact and complaints

Privacy questions, rights requests and complaints all go to the contact form. Our data protection contact is reachable through the same contact form.

If you are not satisfied with our response, you may escalate to your local supervisory authority or data protection regulator. We will cooperate with them fully.

GBNOX LLC5005 W Laurel StTampa, FL 33607United States

Questions about this document?

Send them through the contact form and a real person will answer. Pick the topic that fits — privacy requests, security reports and legal questions each reach the right place.

Contact us
GBNOX

The intelligence layer for modern commerce.

Building deliberately · Two products in the lab

Products

  • GBNOX Radar
  • BeaconPulsar
  • Beaconfrom $19
  • Pulsarfrom $15

Company

  • About
  • Principles
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use

Trust

  • Security
  • Data Processing
  • Sub-processors
  • Accessibility
GBNOX

© 2026 GBNOX LLC. All rights reserved.

Registered in Florida, USA · Built API-first, worldwide.

Legal & TrustPrivacyTermsCookies