Legal
Privacy Policy
Last updated: February 22, 2026
1. Introduction
Brookfield Digital, LLC, doing business as Picket ("we," "us," or "our"), operates the Picket platform, a hosted storefront service for cottage businesses. This Privacy Policy describes how we collect, use, store, and share information when you use our website and services (collectively, the "Service").
This policy applies to all users of the Service, including merchants who create storefronts ("Merchants") and customers who place orders through those storefronts ("Customers"). By using the Service, you agree to the practices described in this policy.
2. Information We Collect
Merchant Account Information
When you create a Picket account, we collect:
- Name and email address
- Password (stored in hashed form only — we never store plaintext passwords)
- Business name, address, and phone number
- Profile and branding information (logo, colors, custom domain preferences)
Merchant Content
We store the content you create on the Service, including:
- Product listings (names, descriptions, prices, images, categories)
- Page content created with the page builder
- Delivery zone configurations
- Discount codes and promotional settings
- Email templates and notification settings
Customer Order Data
When Customers place orders through a Merchant's storefront, we collect on behalf of the Merchant:
- Name, email address, and phone number
- Delivery address
- Order details (items, quantities, prices)
- Subscription preferences and delivery schedule selections
Payment Information
We do not directly collect or store credit card numbers or full payment credentials. Payment processing is handled by our third-party payment processors:
- Stripe processes all payments on the platform — both Customer payments on Merchant storefronts (via Stripe Connected Accounts) and Merchant subscription billing for Picket service fees. Stripe collects and stores payment card information directly.
We store transaction identifiers, amounts, payment status, and related metadata returned by these processors.
Usage and Technical Data
We automatically collect certain information when you use the Service:
- IP address and approximate geographic location
- Browser type, device type, and operating system
- Pages visited, features used, and actions taken
- Login timestamps and session duration
- Referring URLs and search terms
Media and AI-Generated Data
When Merchants upload images to the Service, we may use artificial intelligence (Anthropic Claude) to automatically generate descriptive tags, alt text, and content descriptions for those images. This AI-generated metadata is stored alongside the original images to improve the Merchant's experience.
Instagram Account Data (Merchant Opt-In)
If a Merchant chooses to connect an Instagram account to display recent posts on their storefront, we store an Instagram access token, the connected account's Instagram user ID and username, and cached post content (captions, media URLs, and timestamps). This only applies to Merchants who connect Instagram; it does not affect Merchants who do not use this feature.
3. How We Use Information
We use the information we collect to:
- Operate the Service: Process orders, manage subscriptions, deliver storefronts, send notifications, and provide all platform features.
- Process billing: Charge subscription fees and service fees through Stripe.
- Send transactional communications: Order confirmations, delivery updates, billing receipts, and account notifications via email.
- Provide AI-powered features: Analyze uploaded media for automatic tagging and description generation.
- Improve the Service: Analyze usage patterns, diagnose technical issues, and develop new features.
- Ensure security: Detect and prevent fraud, abuse, and unauthorized access.
- Communicate with you: Send service updates, security alerts, and policy change notifications.
- Comply with legal obligations: Respond to legal requests and enforce our Terms of Service.
4. Third-Party Services
We share information with the following third-party services as necessary to operate the platform. We do not sell your personal information to any third party.
Stripe (Payment Processing)
Stripe processes all payments on the platform. Customer payments on Merchant storefronts are processed through Stripe Connected Accounts — when a Customer makes a purchase, Stripe receives the Customer's payment card information, name, email, and delivery address for payment processing and fraud prevention. Stripe also processes Merchant subscription payments and service fee invoicing, receiving Merchant billing information (name, email, payment method). Stripe's handling of this data is governed by Stripe's Privacy Policy.
Neon (Database Hosting)
All platform data is stored in PostgreSQL databases hosted by Neon. Each Merchant's data is isolated in a separate database project for security. Neon's handling of data is governed by Neon's Privacy Policy.
Cloudflare (CDN, Hosting, and Storage)
Cloudflare provides content delivery, website hosting, and media storage (Cloudflare R2) for the Service. Cloudflare processes request data (IP addresses, URLs) for delivery and security purposes. Uploaded media files are stored on Cloudflare R2. Cloudflare's handling of data is governed by Cloudflare's Privacy Policy.
Resend (Email Delivery)
Resend delivers transactional emails on our behalf, including order confirmations, delivery updates, and account notifications. Resend receives recipient email addresses and email content. Resend's handling of data is governed by Resend's Privacy Policy.
Anthropic (AI Analysis)
Anthropic provides AI services (Claude) for automatic image tagging and description generation. When a Merchant uploads an image, it may be sent to Anthropic for analysis. Anthropic processes the image and returns descriptive metadata. Images are not retained by Anthropic beyond the processing request, in accordance with Anthropic's Privacy Policy.
Meta / Instagram Graph API
Merchants can optionally connect an Instagram account so recent posts display on their storefront through the page builder's Instagram gallery block. This feature is opt-in — only Merchants who choose to connect Instagram are affected. When a Merchant connects an account, we store a long-lived Instagram access token, the connected account's Instagram user ID and username, and a cached copy of recent posts (captions, media URLs, and timestamps) to display in the gallery.
Merchants can disconnect Instagram at any time from Settings › Integrations in their Picket admin, which immediately deletes the stored access token, account identifiers, and cached posts. If a Merchant instead removes Picket's access from within Instagram, Meta notifies us automatically and we delete the same data through our data deletion callback at mypicket.app/api/data-deletion/instagram. Meta's handling of this data is governed by Meta's Privacy Policy.
Fly.io (Application Hosting)
Fly.io hosts the Picket application servers. Request data (IP addresses, headers) is processed by Fly.io infrastructure. Fly.io's handling of data is governed by Fly.io's Privacy Policy.
5. Data Storage and Security
We take the security of your data seriously and implement appropriate technical and organizational measures to protect it:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
- Encryption at rest: Databases and storage systems encrypt data at rest.
- Password security: Passwords are hashed using bcrypt before storage. We never store plaintext passwords.
- Tenant isolation: Each Merchant's data is stored in a separate, isolated database. One Merchant's data is never accessible to another.
- Access controls: Role-based access controls limit who can access what data within a Merchant's account.
While we use commercially reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Active accounts: Data is retained for as long as your account remains active.
- Cancelled accounts: After account cancellation, data is retained for 30 days to allow data export, then permanently deleted.
- Transaction records: Order and payment records are retained for 7 years for tax and legal compliance purposes.
- Email delivery logs: Retained for 90 days.
- Usage analytics: Individual usage data is aggregated and anonymized after 12 months.
7. Merchants as Data Controllers
When Merchants collect personal data from their Customers through their Picket storefront (names, emails, delivery addresses, order history, subscription preferences), the Merchant is the data controller for that Customer data. Picket acts as a data processor on the Merchant's behalf.
This means:
- Merchants are responsible for having their own privacy policy that discloses how they use Customer data.
- Merchants are responsible for obtaining any required consent from their Customers.
- Merchants should inform their Customers that Picket processes data on their behalf.
- Customer data access, correction, or deletion requests should be directed to the relevant Merchant. Merchants can manage Customer data through their Picket dashboard.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data and account.
- Data portability: Request your data in a standard, machine-readable format.
- Objection: Object to certain types of data processing.
- Restriction: Request that we limit how we use your data in certain circumstances.
To exercise any of these rights, contact us at hello@mypicket.app. We will respond to your request within 30 days.
For Customers: If you placed an order through a Merchant's Picket storefront and wish to exercise your data rights, please contact the Merchant directly. The Merchant is the data controller for your order information.
9. Cookies and Tracking
Marketing Site
The Picket marketing site uses minimal cookies. We may use Cloudflare analytics for basic, privacy-respecting traffic measurement. No third-party advertising or tracking cookies are used.
Application
The Picket application uses:
- Session cookies: Required for authentication and maintaining your login state.
- Preference cookies: Store your display preferences and settings.
We do not use third-party advertising cookies, cross-site tracking pixels, or behavioral advertising technologies. We do not participate in ad networks or sell data for advertising purposes.
10. Children's Privacy
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at hello@mypicket.app.
11. International Data Transfers
The Service is hosted and operated in the United States. If you are located outside the United States, please be aware that your data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.
By using the Service, you consent to the transfer of your data to the United States. We take appropriate measures to ensure your data receives an adequate level of protection regardless of where it is processed.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by email or through the Service at least 30 days before they take effect.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
13. Contact
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: hello@mypicket.app