LEGAL
Privacy Policy
This Privacy Policy explains how BPI VENTURES GLOBAL – FZCO ("dtcpilot", "we", "us" or "our") collects, uses, shares and protects personal data when you visit our website at dtcpilot.io, apply for or enquire about our services, create or use an account on the dtcpilot platform at app.dtcpilot.io, or otherwise interact with us as a customer, prospect, partner or supplier.
dtcpilot is the AI operating system for direct-to-consumer brands. It is a business-to-business platform that helps brands generate ad creative with AI, launch and manage advertising on Meta, TikTok and Google, run funnels and checkout, manage subscriptions and retention (including a customer portal and failed-payment recovery), operate orders (including refunds, fulfilment and fraud and reseller detection) and analyze profit. We take the privacy of the people whose data passes through our platform seriously, and this Policy is written to be read, not skimmed past.
This Policy should be read together with our Terms of Service, our Data Processing Addendum, our list of Sub-processors, our Cookie Policy and our Acceptable Use Policy.
1. Who we are
BPI VENTURES GLOBAL – FZCO is a free zone company registered in the IFZA free zone in Dubai, United Arab Emirates. It operates the dtcpilot website and platform and is the controller of the personal data described in this Policy, except where Section 2 explains that we act as a processor on behalf of our customers.
BPI VENTURES GLOBAL – FZCOIFZA Business Park, Building A1, Dubai Digital Park,
Dubai Silicon Oasis, Dubai, United Arab Emirates
Email: [email protected]
We have not appointed a data protection officer. All privacy enquiries, including requests to exercise your rights, are handled by our team at [email protected]. Please use the subject line "Privacy request" so that your message is routed promptly.
2. Scope of this Policy
What this Policy covers
This Policy applies to personal data that we process for our own purposes as a controller, namely:
- Website visitors: people who browse dtcpilot.io.
- Prospects and enquirers: people who submit our "Get started" application, join our email list, or contact us.
- Account users: the employees, contractors and agents of our customers who are invited to and use the dtcpilot platform.
- Business contacts: billing contacts, partners, suppliers and other people we deal with in the course of running our business.
What this Policy does not cover
Our customers are brands that use dtcpilot to run their own businesses. When a brand connects its stores, payment providers, ad accounts and other tools, or uses dtcpilot to run its funnels, checkout, subscriptions and customer portal, the platform processes personal data about that brand's own customers, subscribers and leads, such as shoppers' names, email addresses, postal addresses, phone numbers, order history, payment tokens and payment metadata, device and fraud signals, subscription status and support messages. We call this "Customer Data".
For Customer Data, the brand is the controller and dtcpilot acts as a processor (or "service provider") that processes the data only on the brand's documented instructions, under our Terms of Service and our Data Processing Addendum. The brand's own privacy policy governs how it collects and uses that data. If you are a shopper or subscriber of a brand that uses dtcpilot and you have a question about your data, please contact that brand directly. If you contact us instead, we will pass your request to the relevant brand and support it in responding, as the law and our contract with the brand require.
This Policy also does not cover third-party websites, platforms or services that we link to or that our customers connect to dtcpilot. Those services are governed by their own privacy policies.
3. Personal data we collect
3.1 Information you give us
- "Get started" application: your name, company name, work email address, role, the revenue band of your business and the description you provide of your business and needs.
- Email capture: the email address you submit to receive updates from us.
- Account information: your name, work email address, company, role, password (stored only in hashed form), team membership, permissions and account settings.
- Billing information: billing contact name and email, billing address, tax or VAT identifiers, subscription plan and payment history. Card details for our subscription billing are collected and stored by our payment processor, Stripe; we receive only limited information such as the card brand, last four digits and expiry date.
- Communications: the content of emails, support requests, attachments, call notes and feedback you send us, and your communication preferences.
- Content you create in the platform: prompts, briefs, brand guidelines, product information, creative assets, configuration and other content you enter or upload. Where this content relates to your own business it is part of your account; where it contains personal data about your end customers it is Customer Data (see Section 2).
3.2 Information collected automatically
- Website request data: when you visit dtcpilot.io, our hosting and content delivery provider, Cloudflare, processes your IP address, the pages you request, the time of the request, your browser user agent and the referring URL, in order to deliver the site and protect it from abuse. Our marketing website does not use cookies, analytics tools or advertising trackers. See our Cookie Policy.
- Platform usage and log data: when you use app.dtcpilot.io, we record IP address, device and browser information, sign-in events, the features and pages you use, actions you take (such as launching a campaign or issuing a refund), errors and performance data. We use this to operate, secure and support the platform and to maintain audit logs for your company.
- Cookies and local storage in the app: strictly necessary session, authentication and security cookies, and local storage for preferences such as your selected company. See our Cookie Policy.
3.3 Information we receive from third parties
- Connected platforms: when you or your team connect a third-party service to dtcpilot, typically by OAuth or an API key (for example Shopify, Stripe, PayPal, Meta, Google Ads, TikTok, Klaviyo, ShipStation, TaxJar, Cloudflare, Slack, Triple Whale or CheckoutChamp), we receive the data you authorize, which may include your account identifiers, the name and email address associated with the connected account, access tokens and the business and Customer Data held in that service. Access tokens are stored encrypted.
- Our payment processor: Stripe provides us with payment status, transaction records and fraud-screening results for our own subscription billing.
- Business sources: we may receive business contact information from people who refer you to us, from partners and resellers, and from publicly available professional sources such as company websites and professional networking profiles, where you have made that information public for business purposes.
We do not intentionally collect special categories of personal data (such as health, biometric, religious or political data) about the people covered by this Policy, and we ask that you do not send it to us.
4. How we use personal data and our legal bases
We use personal data only for the purposes described below. Where the EU General Data Protection Regulation ("GDPR") or the UK GDPR applies, we rely on the legal bases shown. Under the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"), we rely on the corresponding grounds recognized by that law, including performance of a contract, compliance with legal obligations, protection of our legitimate business interests where permitted, and consent where required.
| Purpose | Examples | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Respond to applications and enquiries and assess fit | Reviewing your "Get started" application, replying to your email, scheduling a call | Steps taken at your request before entering into a contract; legitimate interests in responding to business enquiries |
| Provide the platform | Creating and administering accounts, authenticating users, running the features your company uses, syncing connected platforms | Performance of our contract with your company; legitimate interests in providing the service to the users our customer authorizes |
| Customer support | Answering support tickets, troubleshooting, onboarding and training | Performance of contract; legitimate interests |
| Billing and account management | Invoicing, collecting subscription fees, managing plans and renewals | Performance of contract; legal obligation |
| Security, fraud prevention and integrity | Detecting suspicious sign-ins, preventing abuse, maintaining audit logs, investigating incidents | Legitimate interests in protecting our platform, customers and users; legal obligation |
| Service communications | Security alerts, changes to features, terms or sub-processors, maintenance notices | Performance of contract; legal obligation; legitimate interests |
| Improve and develop the platform | Analyzing aggregated usage and performance, fixing bugs, prioritizing features | Legitimate interests in improving our products |
| Marketing communications | Product news, updates and invitations sent to prospects and customers | Consent where required by law; otherwise legitimate interests in promoting our services to business contacts, always with an easy opt-out |
| Legal compliance and enforcement | Keeping tax and accounting records, responding to lawful requests, enforcing our Terms and Acceptable Use Policy, establishing or defending legal claims | Legal obligation; legitimate interests |
| Corporate transactions | Due diligence and transfer in a merger, financing or sale of assets | Legitimate interests |
Where we rely on legitimate interests, we have considered your interests and fundamental rights and concluded that they are not overridden by ours. You can ask us for more information about that assessment and you have the right to object (see Section 11).
We do not use personal data to make decisions that produce legal or similarly significant effects on you based solely on automated processing. Fraud and reseller detection features in the platform are tools our customers configure and apply to their own orders under their own responsibility as controllers.
5. How we use artificial intelligence
AI is central to dtcpilot. Features such as creative generation, copywriting, analysis and assistant workflows send the relevant inputs to large language and image models operated by our AI model providers, which are listed on our Sub-processors page. This section explains how that works.
- What is sent: when you use an AI feature, we send the provider the prompt or instruction, together with the context needed to fulfil it, such as product information, brand guidelines, creative assets, performance data or, where the feature requires it, extracts of Customer Data. We design features to send the minimum data needed for the task and, where practical, to exclude direct identifiers of end customers.
- No training on your data: we access AI models through the providers' business APIs, under terms that prohibit the providers from using API inputs and outputs to train their models. We do not use Customer Data to train AI models, and we do not use your company's content to train or improve models that are made available to other customers.
- Provider retention: AI providers may retain API inputs and outputs for a limited period solely to provide the service and to monitor for abuse, in accordance with their business terms, after which they are deleted.
- Human oversight: AI output can be inaccurate. The platform lets you review, edit and approve AI-generated creative, copy and recommendations before they are published, launched or sent, and you can configure approval steps for your team. Automated actions, such as launching ads or sending retention offers, run only within the rules and permissions your company sets.
- Human review by us: our staff do not review your prompts or AI outputs except where you ask us to (for example in a support request), where it is necessary to investigate a security incident or a suspected breach of our Acceptable Use Policy, or where required by law.
6. How we share personal data
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We share personal data only as follows:
- Sub-processors and service providers: companies that host our infrastructure, store our databases, deliver email, provide AI model inference and process our subscription payments. They act on our instructions, under written contracts that require them to protect the data and use it only to provide their services to us. The current list, including each provider's purpose and location, is on our Sub-processors page.
- Integrations you connect: when your company connects a third-party service to dtcpilot and instructs the platform to send data to it (for example publishing an ad to Meta, creating a shipment in ShipStation or syncing a profile to Klaviyo), data flows to that service at your direction. Those services are your company's own providers, governed by your agreements with them, and are not our sub-processors.
- Within your company's workspace: other authorized users in your company can see the content, activity and audit logs associated with your account, according to the permissions your company's administrators set.
- Professional advisers: lawyers, accountants, auditors and insurers who need the data to advise or serve us, under duties of confidentiality.
- Authorities and legal process: courts, regulators, law enforcement and other public authorities where we are required to by law, or where disclosure is reasonably necessary to protect the rights, property or safety of dtcpilot, our customers, users or the public. Where permitted, we will notify the affected customer before disclosing its data.
- Corporate transactions: a prospective or actual buyer, investor or successor in connection with a merger, acquisition, financing, reorganization or sale of all or part of our business, subject to confidentiality obligations. If the transaction completes, we will notify you of any change in the controller of your data.
- With your consent: in any other case where you have asked us to or agreed that we may.
We may also share aggregated or de-identified information that cannot reasonably be used to identify you.
7. International transfers
We are established in the United Arab Emirates, and our sub-processors operate infrastructure in the United States and other countries, as shown on our Sub-processors page. This means your personal data may be transferred to and processed in countries other than the one in which you live, which may have different data protection laws.
Whenever we transfer personal data internationally, we put appropriate safeguards in place:
- From the UAE: we transfer personal data outside the UAE in accordance with the cross-border transfer provisions of the PDPL and its implementing regulations, including through contractual protections that require recipients to maintain an adequate level of protection.
- From the EEA: where personal data subject to the GDPR is transferred to a country that has not been recognized by the European Commission as providing adequate protection, we rely on the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) or another lawful transfer mechanism, together with supplementary measures where appropriate.
- From the UK: we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply.
- From other jurisdictions: we rely on equivalent contractual safeguards required by local law.
You can request more information about the safeguards we use by contacting us at the address in Section 15.
8. How long we keep personal data
We keep personal data only for as long as we need it for the purposes described in this Policy, and then delete or anonymize it. The main retention periods are:
| Category | Retention period |
|---|---|
| Account data and Customer Data | For the life of your company's account. When the subscription ends, your company has 30 days to export its data, after which we delete account data and Customer Data from our production systems within 90 days of the end of the subscription, unless the law requires us to keep it longer. |
| Backups | Encrypted backups are rolled on a schedule, so deleted data is removed from backups within 35 days of deletion from production systems. |
| Billing and transaction records | For at least five years after the transaction, or longer where required by applicable tax and commercial record-keeping laws. |
| Website applications and enquiries | Up to 24 months after our last interaction, if no customer contract results. If you become a customer, the information becomes part of your account data. |
| Email list subscriptions | Until you unsubscribe. We keep a minimal suppression record of your email address so that we do not contact you again. |
| Support communications | For the life of the account and up to 24 months afterward, so we can deal with follow-up questions and claims. |
| Security and application logs | Typically 30 to 90 days, unless needed for longer to investigate a security incident or to comply with a legal obligation. |
| Audit logs within your company's workspace | For the life of the account, so your administrators can review activity, and then deleted with the account. |
We may keep personal data for longer where necessary to establish, exercise or defend legal claims, or where we are legally required to preserve it.
9. How we protect personal data
We maintain administrative, technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These include:
- Encryption in transit: all traffic to our website, platform and APIs is encrypted with TLS.
- Encryption at rest: our databases, backups and object storage are encrypted at rest, and credentials and access tokens for connected platforms are additionally encrypted at the application level.
- Per-company isolation: the platform is multi-tenant, and every company's data is logically isolated so that it can be accessed only by that company's authorized users and by the platform processes acting for that company.
- Access controls and least privilege: role-based permissions within the platform; restricted, need-to-know access for our own personnel; strong authentication for administrative systems; and prompt removal of access when it is no longer needed.
- Audit logging and monitoring: logging of sign-ins and significant actions, and monitoring of our infrastructure for suspicious activity.
- Secure development: code review, separation of development and production environments and management of dependencies and vulnerabilities.
- Payment security: we do not store full card numbers. Payment card data is handled by PCI DSS compliant payment processors, and the platform stores only tokens and limited payment metadata.
- Vendor due diligence: we assess the security and privacy practices of our sub-processors before engaging them and bind them to written data protection terms.
- Incident response: documented procedures to investigate, contain and remediate security incidents and to notify customers, individuals and authorities where required.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential and for the permissions your company grants to its users. If you believe your account or data has been compromised, please contact us immediately at [email protected].
10. Marketing communications
If you join our email list or become a customer, we may send you news about dtcpilot, product updates and invitations. Where the law requires your consent to send these messages, we will ask for it. You can opt out at any time by using the unsubscribe link in any marketing email or by writing to [email protected]. Opting out of marketing does not stop service communications that we need to send you about your account, such as security alerts, billing notices and changes to our terms.
11. Your rights
Depending on where you live and the law that applies, you may have some or all of the rights below. We honor these rights regardless of where you live, subject to the exceptions the applicable law allows.
11.1 Rights under the UAE PDPL
Under the PDPL you have the right to receive information about the personal data we process about you; to request access to it and to a copy of it; to request its correction, completion or updating; to request its erasure; to request that we restrict or stop processing it in the circumstances set out in the law; to object to processing, including for direct marketing and profiling; to data portability where processing is automated; and to withdraw consent where our processing is based on consent. You may also submit a complaint to the UAE Data Office.
11.2 Rights under the GDPR and UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access your personal data and receive information about how we process it;
- Rectify inaccurate or incomplete personal data;
- Erase your personal data in certain circumstances;
- Restrict our processing in certain circumstances;
- Data portability, meaning to receive personal data you provided to us in a structured, commonly used and machine-readable format and to have it transmitted to another controller;
- Object to processing based on our legitimate interests, and to object at any time to processing for direct marketing;
- Withdraw consent at any time, where we rely on consent, without affecting the lawfulness of processing before withdrawal; and
- Complain to a supervisory authority, in particular in the country where you live or work or where an alleged infringement took place. In the UK, this is the Information Commissioner's Office. We would appreciate the chance to address your concern first, so please consider contacting us before you complain.
11.3 Rights for California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the following rights regarding personal information we process as a business:
- Right to know: to request the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purposes, and the categories of third parties to whom we disclose it. The categories we collect are described in Section 3 (identifiers, commercial information, internet or network activity, professional information and inferences drawn from your use of the platform), the sources in Section 3, the purposes in Section 4 and the recipients in Section 6.
- Right to delete personal information we have collected from you, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
- Right to limit use of sensitive personal information: we use account login credentials only to provide and secure the platform, which is a permitted purpose, and we do not use sensitive personal information to infer characteristics about you.
- Right to non-discrimination: we will not deny you service, charge you different prices or provide a different level of quality because you exercised your privacy rights.
You may use an authorized agent to submit a request on your behalf. We will ask the agent for proof of your written authorization and may ask you to verify your identity directly with us. For Customer Data that we process as a service provider to a brand, please direct your request to that brand.
11.4 Other jurisdictions
If you live in another jurisdiction with data protection laws, such as other US states, Canada, Switzerland, Brazil, Australia or countries in Asia, the Middle East or Africa, you may have similar rights. Contact us and we will respond in accordance with the law that applies to you.
11.5 How to exercise your rights
To exercise any of these rights, email [email protected] with the subject line "Privacy request", telling us which right you wish to exercise and, if you have an account, the email address associated with it. Account users can also view and update much of their account information directly in the platform settings.
- Verification: to protect your data, we will take reasonable steps to verify your identity before acting on your request, usually by confirming control of the email address associated with your account or our correspondence. We may ask for additional information where necessary, and we will use it only for verification.
- Timing: we will respond within 30 days of receiving a verifiable request. Where the law allows and the request is complex or we receive many requests, we may extend this period and will tell you why.
- Cost: we do not charge a fee to handle your request unless it is manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or decline, and will explain why.
- Limits: some rights are subject to exceptions, for example where we must keep data to comply with a legal obligation or to establish or defend legal claims. If we cannot fully meet your request, we will explain the reason.
- Company accounts: if your account is provided by your employer or another organization, some requests (for example deleting your user profile) may need to be coordinated with that organization's administrator, and we may inform them of your request.
If you are dissatisfied with our response, you may appeal by replying to our response with the subject line "Privacy appeal". We will review the decision and reply within the time the applicable law requires.
12. Children
dtcpilot is a service for businesses. It is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18 through our website or platform. If you believe that a person under 18 has provided us with personal data, please contact us and we will delete it. Customers are responsible for ensuring that their own collection of end-customer data through the platform complies with the laws that apply to children's data.
13. Do Not Track and Global Privacy Control
Because we do not use tracking technologies for analytics or advertising on our website or platform, there is no tracking for Do Not Track or Global Privacy Control signals to switch off. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing, which is consistent with our existing practice of not selling or sharing personal information. See our Cookie Policy for details.
14. Changes to this Policy
We may update this Policy from time to time to reflect changes in our services, our practices or the law. When we do, we will post the updated version on this page and change the "Last updated" date above. If we make material changes, we will notify account owners by email or through the platform before the changes take effect. We encourage you to review this Policy periodically.
15. Contact us
If you have questions about this Policy or our privacy practices, or wish to exercise your rights, please contact us:
BPI VENTURES GLOBAL – FZCOIFZA Business Park, Building A1, Dubai Digital Park,
Dubai Silicon Oasis, Dubai, United Arab Emirates
Email: [email protected]
For privacy requests, please use the subject line "Privacy request". Related documents: Terms of Service, Data Processing Addendum, Sub-processors, Cookie Policy, Acceptable Use Policy and Refund & Cancellation Policy.