Brightcave
  • Services
  • Contact
  • About
  • Clients

Privacy Policy

Effective date: June 5, 2026

This Privacy Policy explains how Brightcave LLC ("Brightcave," "we," "us," or "our") collects, uses, stores, and shares information when you visit our website, create an account, or use our products and services. It covers all of our data practices, including our AI website-editing product and our optional social platform integrations.

Who we are

Brightcave LLC is a multidisciplinary agency based in Lynchburg, Virginia, United States. We provide marketing, software development, consulting, and creative and design services, and we build software products for our clients.

If you have any questions about this policy or how we handle your data, contact us:

  • Email: hello@brightcave.com
  • Mail: Brightcave LLC, Lynchburg, Virginia, United States

For any data covered by this policy, Brightcave is the data controller unless we are processing it on a client's behalf, in which case the client is the controller and Brightcave acts as their processor.

Information we collect

We collect only the information we need to operate our website, provide our services, and meet our legal and contractual obligations. Depending on how you interact with us, this may include:

  • Contact details — your name and email address when you contact us.
  • Account and authentication data — the email address you sign in with, and the session information needed to keep you signed in.
  • Social platform data — when you explicitly authorize it, posts and media from your connected Instagram or Facebook account (see Social platform data below).
  • Usage and technical data — privacy-friendly, aggregate analytics about how our site is used (see Analytics below).

How we use information

We use the information we collect to:

  • Provide, operate, and improve our website, products, and services.
  • Authenticate you and keep your account secure.
  • Process payments and manage subscriptions.
  • Respond to your questions and provide support.
  • Understand, in aggregate, how our site is used so we can improve it.
  • Comply with our legal obligations and enforce our terms.

We do not sell your personal data, and we do not use it for advertising profiling.

Billing

Payments are processed by Stripe, our third-party payment processor. Stripe collects and processes your payment details directly. We never receive or store your full card number or other sensitive payment credentials. Stripe's handling of your payment data is governed by Stripe's Privacy Policy.

Analytics

We use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies and does not collect personal data or cross-site identifiers. It reports only aggregate, anonymized usage statistics.

Social platform data

Some Brightcave services can connect to a business's social media accounts to help power our services. This integration is entirely optional and only ever happens with the business's explicit authorization.

When a business connects an account, here is exactly what we do:

  • What we access. With your explicit authorization, and using Meta's official APIs, we read the posts and media in your Instagram or Facebook feed so we can provide our agreed services.
  • What we store. We store the provenance links back to the original post the event came from, and the OAuth access tokens needed to maintain the connection. Access tokens are stored encrypted.
  • Revoking access. You can revoke Brightcave's authorization at any time — either by contacting us or directly through your Facebook or Instagram settings. See our Data Deletion Instructions for step-by-step guidance.

Our use of information received from Meta's APIs adheres to the Meta Platform Terms and applicable developer policies.

Storage and security

We host our website and store data on Cloudflare infrastructure. Data is stored and transmitted over encrypted connections (HTTPS).

We take reasonable technical and organizational measures to protect your information. In particular, social platform access tokens are encrypted at rest. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.

Who we share data with

We share data only with the service providers (subprocessors) needed to run our business. Each processes data on our behalf under their own terms and privacy commitments:

  • Cloudflare — hosting, storage, and infrastructure.
  • Stripe — payment processing.
  • Postmark — transactional email delivery (for example, sign-in and notification emails).
  • Plausible — privacy-friendly website analytics.
  • Meta — when you connect an Instagram or Facebook account, via Meta's APIs.

We may also disclose information if required to do so by law, or to protect the rights, property, or safety of Brightcave, our clients, or others.

We do not sell your personal data.

Data retention

We keep personal data only for as long as we need it for the purposes described in this policy, or as required by law:

  • Account data is kept while your account is active.
  • OAuth access tokens are deleted when you revoke authorization.

When data is no longer needed, we delete or anonymize it.

Your rights and how to request access or deletion

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing.

To exercise any of these rights — or to request deletion of your data — see our Data Deletion Instructions or email us at hello@brightcave.com. We will respond within a reasonable timeframe.

Cookies

We use cookies sparingly. The only cookie we set is the authentication session cookie that keeps you signed in; it is strictly necessary for the service to work. We do not use advertising or cross-site tracking cookies. Our analytics (Plausible) do not use cookies at all.

Children's privacy

Our services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal data from children.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. Significant changes will be communicated where appropriate. We encourage you to review this page periodically.

Contact us

If you have questions about this policy or your data, contact us at hello@brightcave.com.

© 2026 Brightcave LLC

  • Privacy
  • Data Deletion

brightcave.com