Skip to main content

Security & Data

Your business data stays under your control.

Expanly combines the commercial and advertising data needed to make a priority decision. Detailed margin, stock, returns and rule logic stay in Expanly. Advertising platforms receive the approved priority signal needed for execution.

Data flow

Business context in. A clear priority signal out.

Expanly keeps the detailed commercial logic inside the service and delivers the minimum signal the advertising setup needs.

Connected sources

Your retail context

Catalog, margin, stock, returns, GA4, Google Ads and the commercial fields your business uses.

Expanly

Rules and priorities

Business Rules combine the data, evaluate the catalog and assign approved High, Standard and Low priorities.

Advertising delivery

The approved signal

Google receives the priority label through Merchant Center. It does not receive the detailed margin, stock or rule logic behind it.

Access and protection

Clear controls for the people and systems using the data.

Security is part of how the workspace, integrations and approval flow are designed.

Encryption

Customer data is encrypted in transit and at rest as part of Expanly's security controls.

Workspace isolation

Workspace boundaries are enforced in the application so users access the retail data and rules assigned to their workspace.

Role-based access

Owner, admin, editor and viewer roles separate organization control, configuration work and read-only access.

Human approval

Automation and Expanly AI can prepare changes. Your team controls what is approved and published.

Data location

EU-based core infrastructure, documented supporting services.

Expanly's production data is hosted in Google Cloud's EU region, and authentication uses an EU Auth0 tenant. Some supporting service providers operate globally. Their processing locations and transfer mechanisms are listed in the Data Processing Agreement.

View subprocessors and locations →

Expanly AI

Expanly AI works with the data available to the customer workspace.

Expanly AI is designed to analyze the synchronized data available in the customer workspace, explain the evidence and prepare reviewable actions. Customer-identifiable data is not used to train AI or machine learning models without the customer's prior written consent.

Access and enabled actions are agreed with each participating customer and can be reviewed with their IT and security teams.

Expanly MCP can connect that workspace data to a compatible AI service approved by the customer. For example, an organization that already uses Microsoft Copilot can ask its IT team to help review and configure the MCP connection inside its approved environment. Access, permissions and available actions are agreed during setup with the Expanly team.

Transparency

Need the contractual detail?

Review the public Terms of Service and Data Processing Agreement, or ask us about your security and data requirements.