Brandsby think201
Terms & ConditionsSign in

Privacy Policy

Effective date: July 14, 2026

Brands by think201 (“Brands”, “we”, “us”, or “our”) is operated by Think201. This Privacy Policy explains what information we collect through the Brands platform (available at brands.think201.in), how we use it, and the choices you have.

Brands is an internal tool. It is built and used exclusively by Think201's own team, to manage the client brands Think201 works with. Access is restricted to Think201 team members and is provisioned by a Think201 administrator — there is no public self-signup, and Brands is not available for use by clients or other external parties at this time. If you did not expect to receive access, please contact whoever invited you.

1. Information We Collect

Account information. When you sign in, we collect your name and email address. You may sign in with a username and password, or with Sign in with Google. If you use Google Sign-In, Google shares your basic profile information (name, email address, and profile photo) with us, limited to the following scopes:

  • userinfo.profile — your name and profile photo
  • userinfo.email — your email address

We use this only to create and authenticate your account. We do not receive your Google password, and we do not get access to your Gmail, Drive, Calendar, or Google Contacts.

Google Ads data (AdPulse module). If your organisation enables the AdPulse module and a workspace admin chooses to connect a Google Ads account, we request the additional scope:

  • https://www.googleapis.com/auth/adwords — read access to the connected Google Ads account, used solely to retrieve campaign and performance data (e.g. spend, clicks, impressions, conversions) for display inside that brand's dashboard

This connection is opt-in per brand and is only initiated by a user with permission to manage that brand's integrations. You can disconnect a Google Ads account at any time from the brand's settings, which revokes our access to that account.

Content you and your team store in Brands. This includes brand briefs, AI context files, tracker items, team and role assignments, and credential vault entries (usernames, passwords, API keys, and similar access details for third-party tools your team uses on behalf of a client). This content is provided directly by your organisation and may include personal data about third parties that your organisation is responsible for having the right to share with us.

Usage and log data. We automatically collect information such as IP address, browser and device type, pages and actions taken within the app, and timestamps, for security, debugging, and audit-trail purposes (e.g. tracking who edited a credential or brand record).

Cookies and local storage. We use browser local storage to keep you signed in (an authentication token) and essential cookies required for the app to function. We do not use third-party advertising or tracking cookies.

2. How We Use Information

  • To create, authenticate, and secure your account.
  • To operate the core features of Brands — brand workspaces, credential vault, AI context files, team permissions, trackers, and the AdPulse dashboard.
  • To enforce the permission model, so people only see brands and modules they've been explicitly granted access to.
  • To display Google Ads performance data inside a connected brand's AdPulse dashboard.
  • To maintain security, detect abuse, and keep an audit trail of sensitive actions (e.g. credential access).
  • To communicate with you about your account or changes to the service.

3. Google User Data & Limited Use

Brands' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google account and Google Ads data is used only to provide and improve the sign-in and AdPulse features described in this policy.
  • We do not sell Google user data.
  • We do not use Google user data for advertising, and we do not allow humans to read this data except as necessary for security purposes (e.g. investigating abuse), to comply with applicable law, or with your explicit consent.
  • Google Ads tokens are stored encrypted and are only used to make authorised API calls on behalf of the connecting brand.

4. How We Share Information

We do not sell your personal information. We share information only with:

  • Your organisation. Content you add is visible to other people in your organisation or brand workspace, according to the roles and permissions your admin has configured.
  • Service providers. Infrastructure providers (hosting, database, and email delivery) who process data on our behalf, under contractual confidentiality obligations, solely to operate Brands.
  • Legal and safety reasons. If required to comply with applicable law, legal process, or to protect the rights, property, or safety of think201, our users, or others.

5. Data Storage & Security

Credential vault entries are encrypted at rest. Access to brands, modules, and individual features is controlled by a two-level role system (organisation role and brand role) combined with per-module permissions, so access is limited to what a person has explicitly been granted. We use industry-standard measures such as encrypted connections (HTTPS), access controls, and authentication token expiry to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. Data Retention

We retain account and workspace data for as long as your organisation's account is active, or as needed to provide the service. If your organisation's access to Brands ends, we retain data for a reasonable period to allow for account recovery and to meet legal or contractual obligations, after which it is deleted or anonymised. Disconnecting a Google Ads account or revoking Google Sign-In immediately stops any further data retrieval from Google.

7. Your Rights & Choices

  • Access and correction. You can review and update your profile information from within the app, or by contacting us.
  • Deletion. You may request deletion of your account and associated personal data by contacting us at hello@think201.com, subject to any records we're required to retain by law or that belong to your organisation's workspace.
  • Revoking Google access. You can revoke Brands' access to your Google account at any time from your Google Account permissions page.
  • Disconnecting Google Ads. A brand admin can disconnect a connected Google Ads account at any time from that brand's AdPulse settings.

8. Children's Privacy

Brands is a business tool intended for use by adults acting on behalf of an organisation. It is not directed at, and we do not knowingly collect information from, children under 18.

9. International Data Transfers

We are based in India, and data may be processed and stored in India or in other countries where our service providers operate. Where required, we take steps to ensure data is protected consistently with this policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we'll update the effective date above and, where appropriate, notify you directly.

11. Contact Us

Questions about this policy or how we handle your data can be sent to hello@think201.com.

Terms & Conditions →