Privacy

Privacy Policy

How we handle your data.

Plunk processes customer data on behalf of manufacturers and retailers. This page explains what we collect, how we use it, and the controls you have. Last updated September 30, 2026.

Who this covers

This policy applies to the marketing sites at plunk.io, studio.plunk.io, and plunkdigital.com; to the Plunk SaaS platform at app.plunk.io; and to any related services we operate. Plunk Digital (the agency) and Plunk (the platform) are the same company; we treat them as one privacy boundary.

Information we collect

From you, directly. When you request a demo, start a trial, contact sales, or sign up for any account, we collect what you give us: name, work email, company, role, and the context you share about your business.

From your usage of the platform. When you use Plunk to manage your own customer or catalog data, that data flows through our infrastructure. We are a processor of that data, not the controller. Your company controls it; we just operate the tools.

From our marketing sites. Standard analytics: pages visited, referrers, approximate location from IP, device and browser type, and how you got to us. We use a single GA4 property spanning plunk.io, studio.plunk.io, app.plunk.io, and plunkdigital.com for consistent attribution.

From third parties. Enrichment services (such as the Data Marketplace integrated into Plunk) may attach firmographic or contact signals to records you've already provided. We only ingest data from sources that represent it as lawful for our use.

How we use information

  • To operate the Plunk platform and the services you've asked for.
  • To respond to demo requests, sales inquiries, and support questions.
  • To improve our products: aggregated, de-identified usage patterns inform what we build next.
  • To run our own marketing for Plunk, limited to opted-in audiences and our existing customer base.
  • To meet legal and contractual obligations.

We do not sell your data. We do not share it with advertisers outside of campaigns you've configured inside the platform.

How we share information

Subprocessors. We use vetted providers to deliver the platform: cloud hosting and storage, payment processing, transactional email, AI model providers for render generation, and observability vendors. A current list of subprocessors is available on request.

Your own integrations. When you connect Shopify, an ERP, or another tool to Plunk, data flows between Plunk and that system at your direction. Those connections are governed by your agreement with each vendor.

Legal. We will disclose information when required by valid legal process. We will tell you when we receive such a request unless legally prohibited.

Connected accounts and platform data

Plunk Commerce can publish content to accounts you connect: Google (YouTube), Meta (Facebook and Instagram), TikTok, Pinterest, LinkedIn, Google Business Profile, and Shopify. When you connect an account you authorize Plunk, through that platform's own consent screen, to act on your behalf with the specific permissions shown there. We request the minimum permissions the feature needs.

What we access and why. For YouTube we use the permission to upload and manage the videos you publish from Plunk and to read basic channel and video information so we can show you what was posted and how it performed. For the other platforms we access the equivalent: the ability to post the content you approve and to read the posts and their statistics. We do not read your private messages, contacts, or any data beyond what the feature you use requires.

How we use it. Only to provide the publishing and reporting features you use inside your own workspace. Data received from a connected platform is never sold, never used for advertising, never shared with other customers, and never used to train or improve generalized artificial intelligence or machine learning models.

Google API Services. Plunk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting. You can disconnect any account at any time from Plunk Commerce, or revoke Plunk's access from the platform's own account settings (for Google, at myaccount.google.com/permissions). When you disconnect, we delete the stored access credentials for that account immediately. Content records and statistics already in your workspace remain until you delete them or close your account.

How we protect your data

Encryption in transit. All traffic between your browser, the Plunk platform, and connected platforms travels over HTTPS (TLS 1.2 or higher). Plain HTTP is redirected to HTTPS on every Plunk site.

Encryption at rest. The platform runs on Amazon Web Services in the United States. Databases, file storage, and backups are encrypted at rest with AWS-managed keys.

Credentials for connected accounts. The access and refresh tokens that connected platforms issue to Plunk are stored encrypted, either in our database with encryption at rest or in AWS Secrets Manager and Parameter Store protected by AWS Key Management Service. They are never written to logs, never sent to your browser, and never shared with other customers or third parties. They are used only by the service that publishes and reports on your behalf, and they are deleted when you disconnect the account.

Access controls. Every workspace is isolated: users sign in with individual credentials, and an account can only reach the data of its own workspace. Internal access to production systems is limited to a small number of named staff who need it to operate the service, protected by multi-factor authentication and least-privilege roles, and logged. Staff do not access customer data except to provide support you have requested or to keep the service running.

Monitoring, backups, and incident response. We keep audit logs of administrative actions and sign-ins, monitor the platform for abuse and failures, and take encrypted backups so your data can be restored. If we learn of a security incident that affects your data, we will notify affected customers without undue delay and no later than 72 hours after confirming it, and we will tell you what happened and what we are doing about it.

Retention and deletion. Sensitive data, including connected account credentials, is kept only as long as the feature that needs it is in use. When you close your account, your workspace data is deleted after the wind-down period described below, and you can ask for earlier deletion at any time (see "Your rights").

How long we keep it

Customer data in the platform is retained for the life of your account plus a standard wind-down period. Marketing-site analytics are retained for 26 months. Demo and trial inquiries that don't convert are kept for two years and then deleted. You can ask us to delete sooner; see "Your rights" below.

Where we operate

Plunk operates primarily on US infrastructure. If you're contacting us from outside the United States, your data will be transferred to and processed in the US. We rely on standard contractual clauses where required for international transfers.

Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the use of your personal data. To exercise any of these, email privacy@plunk.io from the address associated with your data. We respond within 30 days.

If you're a customer of one of our customers (for example, a shopper whose data is in a retailer's Plunk account), please contact that retailer first; they are the controller of your data. We'll assist them in honoring your request.

Cookies and tracking

We use a small number of cookies for authentication, session continuity, and analytics. We do not run third-party advertising trackers on our marketing sites. The platform itself uses cookies necessary to keep you signed in and to remember your preferences.

Changes to this policy

We will post material changes to this page and update the "Last updated" date at the top. For customer-facing accounts, we will email a notice for material changes before they take effect.

Contact

Privacy questions: privacy@plunk.io
General contact: our contact page