Legal
Privacy Policy
Effective August 26, 2026
This policy explains what Brand Refinery collects when you use this website, why we collect it, who it is shared with, and what you can ask us to do about it.
It is written to be read rather than skimmed past. If anything here is unclear, email us and we will explain it in plain terms.
1Who we are
Brand Refinery is a consumer packaged goods and FMCG brand consultancy operating from Atlanta, Georgia and Dallas, Texas. For the purposes of data protection law, Brand Refinery is the controller of the personal information described in this policy.
You can reach us at itai@cpg-advisory.com or (424) 397-3047 about anything in this document, including a request to access or delete your information.
2Information you give us
The enquiry form on our contact page is the only place this website asks you for information. When you submit it, we receive:
- Your name and email address, which are required so we can reply.
- Your company or brand name, phone number, and the service you are interested in, if you choose to provide them.
- The message you write describing your brand and what you need.
That submission is delivered to us by email and is also used to send you an automatic acknowledgement confirming we received it. We do not use it for anything else unless you become a client and we agree otherwise in writing.
If you email or call us directly, we hold whatever you choose to tell us in that correspondence for as long as it is useful to the conversation.
3Information collected automatically
Our server records limited technical information about requests to this site. This is a normal part of running a website securely, and it is deliberately narrow:
- Your IP address, which we use to rate limit the enquiry form so it cannot be flooded by automated submissions.
- Your browser's user agent string and the time of the request, recorded alongside enquiry form submissions so we can investigate abuse or a delivery failure.
This information is used for security, abuse prevention and diagnosing faults. It is not used to build a profile of you, and it is not combined with any advertising or analytics system.
4What we do not do
This section exists because most privacy policies quietly imply the opposite. On this website:
- We do not use analytics software. There is no Google Analytics, no Meta pixel, no LinkedIn insight tag and no equivalent on any page.
- We do not set tracking or advertising cookies. The site does not need a cookie consent banner because it does not set cookies that would require one.
- We do not sell, rent or share your personal information, and we do not process it for targeted advertising or profiling.
- We do not buy contact lists, and we do not enrich what you send us with data purchased from third parties.
- We do not send marketing newsletters from this website. If you hear from us, it is because you contacted us or because we are working together.
If any of this changes, this policy will be updated before the change takes effect, and the effective date at the top will move.
5Why we are allowed to use it
Where the UK GDPR or EU GDPR applies to you, our lawful bases are:
- Steps taken at your request prior to entering into a contract, under Article 6(1)(b), for the enquiry you submit and our reply to it.
- Our legitimate interests, under Article 6(1)(f), in keeping this website secure and available, which covers the rate limiting and abuse prevention described above.
We do not rely on consent for anything on this site, because nothing on it is optional tracking that would require consent.
7Confidentiality of what you send us
Brands often describe sensitive commercial detail in a first enquiry: formulations, margins, retailer conversations, launch timing. We treat what you send us as commercially confidential and we do not disclose it outside our firm.
That said, submitting the enquiry form does not by itself create a non-disclosure agreement between us. If you need contractual confidentiality before you share something, tell us and we will sign an NDA first. We do this routinely and we would rather you asked.
8How long we keep it
Enquiry correspondence is kept while the conversation is live and for a reasonable period afterwards, so that we can pick up a thread if you come back to us months later. Where an enquiry becomes an engagement, records are kept for as long as we need them for the engagement and for the period required by our tax and professional obligations.
Technical logs of the kind described above are short-lived and are retained only as long as they are useful for security and diagnostics.
You can ask us to delete your information sooner, and we will unless we are required to keep it.
9Security
This site is served exclusively over an encrypted connection. Enquiry submissions are rate limited and validated on the server. Access to enquiry correspondence is limited to the people at our firm who need it.
No system is perfectly secure and we will not claim otherwise. We maintain commercially reasonable administrative, technical and physical safeguards appropriate to a firm of our size and to the kind of information we hold.
10Your rights
Wherever you are, you can ask us to:
- Tell you what personal information we hold about you and provide a copy of it.
- Correct anything inaccurate.
- Delete it.
- Stop using it, or restrict how we use it.
- Provide it in a portable, machine-readable format.
Depending on where you live, some of these may be legal entitlements rather than courtesies, including under the Georgia Consumer Privacy Protection Act, the Texas Data Privacy and Security Act, the California Consumer Privacy Act, the UK and EU GDPR, and the Australian Privacy Act 1988. We do not make you prove which one applies. Email us and we will honour the request regardless.
We will respond within 30 days. We will not charge you or treat you differently for asking. If you are in the UK or EU and you are unhappy with our response, you can complain to your national supervisory authority, and in the UK to the Information Commissioner's Office.
11Visitors outside the United States
We are based in the United States and our service providers process information here. A meaningful share of our enquiries come from Australia, the United Kingdom and the European Union, so it is worth being explicit: if you contact us from outside the United States, the information you send will be transferred to and processed in the United States, where privacy law differs from your own.
Where we transfer personal information out of the UK or the European Economic Area, we rely on appropriate safeguards for that transfer. The rights described in the previous section are available to you either way.
12Children
This is a business-to-business website and it is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has sent us information, contact us and we will delete it.
13Links to other sites
Where we link to another organisation's website, that site's own privacy practices apply once you leave ours. We are not responsible for what other operators do with your information.
14Changes to this policy
If we change this policy we will update the effective date shown at the top of the page. Where a change materially affects how we handle information you have already given us, we will tell you directly rather than relying on you to re-read the page.
15Contact us
Questions, requests and complaints about this policy all go to the same place: itai@cpg-advisory.com, or (424) 397-3047. A person reads it.