Privacy Policy
Last updated: July 15, 2026
1. Who We Are
Brutal Noise ("we", "us", "our") operates the website brutalnoise.net and brutalnoise.bg. We are based in Bulgaria. For any privacy-related questions, contact us at info@brutalnoise.bg.
2. Data We Collect
Account Data
When you create an account we collect your name, email address, and a hashed password. You may optionally upload a profile picture (stored in publicly accessible cloud storage) and enable two-factor authentication. If you sign in with Google, we receive your name, email address and profile picture from your Google account.
Order & Shipping Data
When you place an order we collect your full name, email address, phone number, and the delivery details you choose: either a shipping address (street, city, postal code) or the courier office / parcel locker you selected. We also store the order total and items, the chosen courier and delivery method, payment status, any order notes, and any custom design data you attached (images, text, colours, positions).
Design & File Data
Images and settings you create in our product builders (CD, t-shirt, guitar pick, pin, sticker, hat, tote bag) are uploaded to private cloud storage and are accessible only to you and our production team, through short-lived signed links. If you publish a design to the community gallery, its preview images become publicly accessible; making it private again moves them back to private storage. Audio files uploaded for CD orders are stored with Amazon Web Services. If you save or share a community design, the design data, your user name, and a share link are stored.
Technical Data
When you visit the site we automatically collect your IP address, browser type (user agent), and session timestamps. This data is stored as part of your authentication session and is used to keep you signed in and protect against unauthorized access. Your IP address is also processed for rate limiting to protect the site from abuse.
Analytics Data
If you accept analytics cookies, we use Google Analytics 4 to collect usage data such as pages visited, approximate device/browser information, ecommerce events, searches, and form conversion events. We do not intentionally send names, email addresses, phone numbers, shipping addresses, or message contents to Google Analytics. Analytics cookies are only loaded after you give consent. We also use Vercel Analytics and Speed Insights, which collect anonymous, cookie-free traffic and performance statistics.
Bot Protection Data
When you submit protected public forms, checkout, or order tracking requests, Cloudflare Turnstile checks whether the interaction appears legitimate. We send the Turnstile token and technical request data such as IP address and browser signals to Cloudflare for verification.
Chat Data
When you use our messaging feature, we collect and store message content (text and images), conversation metadata, message timestamps, read receipts (when you last viewed a conversation), and your online/offline status while using the site. Chat images are stored in private cloud storage (Supabase) and served through expiring signed links. If you message our support bot, the messages you send it are processed by our AI provider (OpenRouter) to generate replies. If you enable push notifications, we store your browser's push subscription so we can notify you about new messages.
Gift Card Recipient Data
If you buy a gift card for someone else, we store the recipient's name, email address and your personal message, and we email the gift card to that address on your behalf. It is your responsibility to have the recipient's permission to share their details with us.
3. How We Use Your Data
- To create and manage your account
- To process and fulfil your orders, including passing delivery details to the courier you chose
- To send order confirmation and delivery status emails
- To produce your custom designs (CDs, merch, picks, pins, stickers, hats, totes)
- To display community designs you choose to share publicly
- To improve the site based on aggregated analytics
- To protect against fraud and unauthorized access
- To send you service notifications such as abandoned-cart reminders; these emails include an unsubscribe option and can be turned off in your email preferences
- Enable private messaging between registered users
- Send email notifications when you have unread messages (after 1 hour)
- Display your online status to other users you have conversations with
4. Third-Party Services
We share data only with services that are necessary to operate the site:
- Supabase — hosts our database, file storage, and the realtime infrastructure for chat. Private files (design originals, order artwork, chat images) are served only through expiring signed links. Data may be stored in the EU or US depending on our project region.
- Vercel — hosts the website. As our hosting provider it processes request data such as IP addresses, and provides us with anonymous, cookie-free traffic and performance statistics.
- Stripe — processes payments when card payment is used. We never store your card details; Stripe handles this under PCI-DSS compliance.
- BOX NOW / Econt / Speedy — our delivery couriers receive the data needed to deliver your order: your name, phone number, and delivery address or selected office/locker, plus the amount to collect for cash-on-delivery orders. BOX NOW also receives your email address so it can send you locker pickup codes.
- Resend — sends our transactional and notification emails (order and delivery updates, account emails, gift cards, reminders). Receives the recipient email address and the email content.
- Sentry — error monitoring, hosted on EU servers. When an error occurs we receive technical error reports and a masked replay of the screen (all text hidden, media blocked). We configure Sentry not to attach IP addresses, cookies or request bodies.
- Google Analytics — collects usage and ecommerce analytics only when you accept analytics cookies.
- Cloudflare Turnstile — verifies protected forms and checkout requests to reduce spam, abuse, and automated submissions.
- Google Maps / OpenStreetMap — if you type a delivery address at checkout, address suggestions come from Google Places, which receives the text you type. Maps showing courier offices and lockers load map tiles from OpenStreetMap, so your IP address is visible to OpenStreetMap's servers. City coordinates for the community map are looked up via OpenStreetMap and rounded to about 1 km.
- Amazon Web Services — stores audio files uploaded for CD orders.
- Upstash — provides the rate limiting that protects the site from abuse; it processes your IP address and user id.
- OpenRouter — AI provider that generates the replies of our support chat bot; it receives the messages you send to the bot.
- Web Push — if you enable push notifications, delivery goes through your browser vendor's push service (Google, Mozilla or Apple).
We do not sell your data to anyone.
5. Cookies & Local Storage
We use cookies and browser storage to run the site. For a full breakdown, see our Cookie Policy.
- Essential — session cookie for authentication, localStorage for your cart, IndexedDB for builder cache, and Turnstile tokens for spam protection on sensitive forms.
- Analytics — Google Analytics cookies, loaded only with your consent.
6. Data Retention
We keep your account data for as long as your account is active. Order records are retained for accounting and legal purposes for up to 5 years after the order date, or longer where tax law requires it. Design files are kept until you delete them; files that belong to a placed order are kept with the order so we can handle production, reprints and complaints. Gift card records are kept until the card is used or expires. Activity logs are deleted after 12 months. Session data expires automatically.
Chat data: messages and conversation history are retained while your account is active. When you delete your account, your account, profile and design data are removed; messages you have exchanged with other users may remain visible in their conversations.
7. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability — receive your data in a structured format
- Withdraw consent at any time (e.g. for analytics cookies)
You can download a copy of your data and delete your account at any time from your profile page. To exercise any other rights, email us at info@brutalnoise.bg. We will respond within 30 days.
8. Data Security
Passwords are hashed and never stored in plain text. All data is transmitted over HTTPS. Design, order and chat files are stored in private cloud storage and served only through short-lived signed links. Optional two-factor authentication is available for your account. We limit access to personal data to authorized administrators only.
9. Children
Our services are not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. We encourage you to review this page periodically.
11. Contact
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at info@brutalnoise.bg.
