Privacy Policy
This Privacy Policy describes how your personal information is collected, used, and shared.
Last updated: August 24, 2026
This Privacy Policy describes how your personal information is collected, used, and shared when you visit suremembers.com, when you use SureMembers on a site we operate (including our account portal at my.suremembers.com), and when you install the SureMembers plugin on a WordPress site of your own.
When a membership site built with SureMembers appears on someone else’s website, that website’s owner decides what their site collects from its own members and visitors and is responsible for their own privacy policy. This policy covers our own sites, and it covers the specific points where our own services sit in the data path on a site you run. Those points are described under Using SureMembers On Your Own Website below.
Who We Are
We are Brainstorm Force US LLC. You can find more information about us, including our full address, on our company website.
Contact for all privacy matters: [email protected]
What Personal Information We Collect
When you visit our website, we automatically collect information about your device, including your web browser type, IP address, and time zone. As you browse the Site, we also collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site.
Cookies and Similar Technologies
Cookies are small data files placed on your device, often including an anonymous unique identifier. We use cookies and similar technologies (such as pixels and tags) across our sites for the following purposes:
- Essential required for core site functionality, including security, load balancing, and keeping the cookie-preference tool itself working
- Functional remember your preferences and settings
- Analytics help us understand how visitors use our sites and test improvements to site design
- Marketing used for advertising measurement and remarketing
Our consent system is configured to prevent non-essential analytics and marketing technologies from running until the required consent has been provided through our cookie preference banner (powered by SureCookie). Functional technologies are handled according to their purpose and the applicable consent requirements. You can change your preferences at any time by clicking Cookie Preferences in the footer.
We honor the Global Privacy Control (GPC) signal where required by law. If your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information.
Our Cookie Policy contains the current list of cookies and tracking technologies identified by our consent-management scans and configuration, linked from the cookie preference banner. The list is updated when scans or configuration changes identify new technologies. As of this writing it lists, among others: surecookie_session_id (essential); Google Tag Manager’s gtm_auth, Google reCAPTCHA’s _GRECAPTCHA, and YouTube’s PREF (functional); _ga/_ga_* and Google’s FPID/FPLC (analytics); and our own sigmize_redirect_tracker, Facebook/Meta’s _fbp/_fbc/fr, and YouTube’s VISITOR_INFO1_LIVE/YSC/VISITOR_PRIVACY_METADATA (marketing).
Retention: Records of your cookie consent choices are retained for up to 365 days, or less if manually cleared sooner, so we can demonstrate compliance with applicable consent requirements and honor your prior preferences on return visits.
Cookies We Set Ourselves
The SureMembers plugin manages access using your WordPress login session and does not set additional bespoke cookies of its own for most features. Where features such as Login Restriction or concurrent-session management rely on cookies, they use the site’s existing WordPress authentication/session mechanisms rather than a separate Brainstorm Force-operated cookie service.
Third-party services loaded on pages inside a membership site such as YouTube (for embedded lesson videos), Google reCAPTCHA (spam protection on registration/login forms), or a payment processor (for a paid membership) may set their own cookies once they run, under their own privacy policies.
Third-Party Services Loaded On Our Pages
Some pages on our Site load files from other companies. When your browser fetches one of those files, that company receives your IP address and basic details about your browser. The services below load only on pages that use the feature they belong to.
| Service | Why it loads | When it loads | Basis |
|---|---|---|---|
| Google reCAPTCHA (Google LLC) gstatic.com, google.com | Spam and abuse protection on our forms | Pages with a reCAPTCHA-protected form | Loads with the page, as fraud and abuse prevention |
| Google Tag Manager (Google LLC) | Loads and manages our other tags, and reads your consent status to decide which may run | Sitewide | Service provider; loads before you answer the banner in order to evaluate your choice (Google Consent Mode) |
| Google Analytics (GA4) (Google LLC) | Understand site usage | Sitewide, only after consent | Analytics, only after consent |
| Google Ads / remarketing (Google LLC) | Ad performance measurement and remarketing | Sitewide, only after marketing consent | Shared for cross-context behavioral advertising, only after consent |
| Meta Pixel (Meta Platforms, Inc.) | Ad performance measurement and remarketing | Sitewide, only after marketing consent (per the live Cookie Policy’s _fbp/_fbc/fr disclosure) | Shared for cross-context behavioral advertising, only after consent |
| YouTube (Google LLC) | Displays an embedded product video | Pages with a YouTube embed (e.g., our changelog) | Loads with the page; sets marketing/functional cookies only after consent |
| Sigmize (our own A/B-testing product) | On-site experimentation and redirect tracking | Sitewide, only after consent | Analytics, only after consent |
| ConvertBox | Popup lead-capture / email opt-in widget | Sitewide, only after consent | Marketing, only after consent |
| Polyfill.io (via Fastly) | Supplies missing JavaScript features for older browsers | Sitewide, only after functional consent | Loads only after functional consent, per our Cookie Policy’s categorization; treated as a compatibility script, not tracking |
| SureCart, Inc. js.surecart.com | Affiliate-program tracking; checkout and license purchases | Sitewide (affiliate script); checkout pages (full flow) | Service provider, not sold or shared |
| ShortPixel cdn.shortpixel.ai | Serves optimized images | Sitewide | Essential to page rendering; loads before you answer the banner |
| Powerful Docs app.powerfuldocs.com | Knowledge Base search widget and the “Ask AI” chat assistant | Sitewide | Service provider; the AI chat only sends your message content, and your name/email if you provide it, once you start a conversation |
| Bunny.net | Video or file streaming/delivery | Sitewide | Service provider, not sold or shared |
| Cloudflare, Inc. | Site performance, security, bot mitigation, and anonymized Web Analytics | Sitewide | Service provider, not sold or shared |
These services are used only on pages where the relevant feature is enabled. Their loading behavior and consent treatment depend on the function they provide and our site configuration. We do not use these services ourselves for advertising or behavioral profiling unless separately disclosed in this policy.
Information We Send To Third Parties From Our Servers
Spam checks. When you submit a protected form, the token generated by reCAPTCHA is sent to Google to be verified, together with your IP address.
Payments. Payment details you enter to purchase or renew a SureMembers license are sent to SureCart, Stripe, or PayPal to process the payment, as described under Purchase below.
Forms You Submit On Our Site
When you submit a form on our Site (for example, a pre-sales or support request on our Contact page), we store the answers you gave. Alongside those answers we may also record technical details about the submission, so we can tell genuine submissions from spam and troubleshoot problems:
- The name of your browser and the operating system or device you used
- The address of the page the form was submitted from
- Your IP address, where IP logging is switched on for that form
Separately from the record we store, a copy of your IP address may be included in the notification email a form sends to us. Notification emails are retained with the rest of our email records.
We use your IP address for a short anti-abuse check on each submission. For that check, the address is converted using a one-way hashing process, and the original address used for that check is discarded within one minute. The hash is not stored with the form submission.
Comments
When you leave comments on our blog, we collect the data shown in the comments form, along with your IP address and browser user-agent string, to help with spam detection.
An anonymized string created from your email address (a hash) may be shared with the Gravatar service to check if you are using it. Gravatar’s privacy policy is available here. After your comment is approved, your profile picture is visible to the public alongside your comment.
Contact Forms
Information submitted through contact forms on our Site is sent to our self-hosted support desk. We may collect information including (but not limited to) your first and last name and email address. This information may be shared with our email marketing services, including our self-hosted CRM.
Support
To help with our products, we may ask for temporary access to your website, either your live site or a staging copy, whichever you prefer, such as an admin login or FTP/database credentials. We may also ask you to share a license key, name, or email address.
Troubleshooting typically takes place directly on your site itself, and in these cases we do not transfer, export, or store your site’s data on our own servers. We recommend a staging copy where practical, but understand this is not always feasible for every customer.
In some cases, particularly for more complex issues, we may create a copy of your website on our own servers to investigate the problem. Any such copy is used only for that investigation and is deleted once the issue is resolved.
A few important points about access shared with our support team:
- We use any access you provide strictly for debugging your specific issue, on your site itself
- We do not copy or retain your site’s data on our own systems, except where you authorize us to create a temporary troubleshooting copy as described above
- We do not share access or data with anyone outside the company
- We cannot be held responsible for loss of private information from your database or website. If you are able to share a staging site and keep a working backup of anything shared with us, we recommend doing so
Retention: Where we have created a copy of your site on our own servers for investigation, we delete that copy once the issue is resolved. We retain support ticket records, including any screenshots, logs, or other materials shared as part of a ticket, for 3 years from the date the ticket is closed.
Support ticket records are not shared with any third party.
If your membership site contains your own members’ or visitors’ personal data that we may view while troubleshooting on your site, we access that data only as necessary to resolve your issue and do not retain or use it beyond that purpose. You remain responsible for your own compliance obligations toward your members and visitors.
Purchase
If you purchase a SureMembers license, our payment gateway provider (SureCart, which may route to Stripe or PayPal) requires your credit card and billing information to process the transaction. Credit card details are not stored by us on any internal or external database accessible to us.
All direct payment gateways adhere to PCI-DSS standards, managed by the PCI Security Standards Council, which help ensure secure handling of card information.
When you make or attempt a purchase, we verify your card through a payment gateway and collect information including your name, billing address, shipping address, payment information, email address, and phone number.
Retention: Billing and transaction records are retained for as long as your license remains active, including to support renewals. Because we are subject to tax, accounting, and audit-related legal obligations, financial records are retained for the period required by applicable law even after account deactivation or a data deletion request.
Information We Receive When You Set Up the Plugin
When you complete the SureMembers setup wizard on your website, the plugin may send us your email address, first name, last name, and the domain of the site you are setting up. We use this information to provide product onboarding and service-related communications. We only use it for promotional marketing where we have an appropriate basis to do so, including consent where required, as described under Newsletter Emails below.
Retention: These records are retained for as long as we have a relationship with you, and you can ask us to delete them at any time by writing to [email protected].
Information About Your Website and Server Configuration
When you use SureMembers, and only if you have opted in to usage tracking, we may receive website and technical usage information, including (but not limited to) whether SSL is installed, Curl/PHP/MySQL versions, PHP ini settings, server software, WordPress version and language, timezone, whether the site is a Multisite installation, debug settings, site URL, active plugins and theme, and BSF Updater version.
This is switched off unless you turn it on, and you can turn it off again at any time.
License Keys
A license key is required to validate your purchase and unlock benefits like automatic updates, support, and extra resources. When you activate a license key, we receive your website URL, name, and email address, and we keep records of every website URL where the key has been activated.
Retention: License activation records are retained while the license is active and afterwards for the period reasonably necessary for support, renewal, fraud prevention, and tax/accounting obligations.
Using SureMembers On Your Own Website
When you run SureMembers on a site of your own, you decide what your membership site collects from its members and visitors, and you are responsible for the privacy policy shown to them. Almost everything the plugin does access rules, role assignment, content protection, content dripping, and member management runs natively on your own WordPress install and never reaches us. A few points are worth calling out specifically:
- SureCart integration. If you connect SureMembers to SureCart to automatically grant, renew, or revoke membership on purchase, cancellation, or renewal, that connection runs between your own SureCart account and your own WordPress site. We do not receive a copy of your members’ payment or purchase data through this integration.
- LMS and role-sync integrations. If you connect SureMembers to a course/LMS plugin or sync roles with another plugin in your stack, that processing happens entirely on your own server.
- Secure file delivery. If your “Members-Only Downloads” feature is backed by Bunny.net, your site connects directly to your own Bunny.net account. Files are stored and delivered through the Bunny.net account connected by the site owner, and Brainstorm Force does not broker the connection or receive or store the files through a Brainstorm Force-operated service.
- Team accounts and CSV import. If you create team accounts or bulk-import members via CSV, that data is processed and stored on your own server; we do not receive a copy.
- Automation integrations. If you connect SureMembers to an automation tool (such as OttoKit) or an email marketing platform to trigger onboarding/offboarding workflows, information flows directly between your site and your own account with that provider, using your own credentials.
- Setup. The setup wizard sends us your own name, email address, and site domain, as described under Information We Receive When You Set Up the Plugin above. This is about you as our customer, not about your members.
Who We Share Your Data With
We do not sell or trade your personal information for money.
Some of our advertising and analytics tools involve sharing personal information with third parties for cross-context behavioral advertising, as that term is defined under California law, meaning those partners may use information about your activity on our sites to show you relevant ads elsewhere. This sharing only happens for the categories marked below, and only after you have provided consent through our cookie preference banner, or is subject to your California opt-out rights described further down.
| Category | Service (domain detected) | What they receive | Purpose | Sale / Share / Service Provider |
|---|---|---|---|---|
| Tag management | Google Tag Manager (googletagmanager.com) | IP address, browser and device information, page URL | Loads and manages our other scripts and tags, and reads your consent status | Service provider, not sold or shared |
| Website analytics | Google Analytics / GA4 | Page views, device and browser identifiers, cookies | Understand site usage | Shared for cross-context behavioral advertising once GA4 audiences feed Google Ads |
| Advertising / remarketing | Google Ads (via our tag manager container) | Device and browser identifiers, cookies, page views | Ad performance measurement, remarketing | Shared for cross-context behavioral advertising, only after consent |
| Advertising / remarketing | Meta Pixel (Meta Platforms, Inc.) | Device and browser identifiers, cookies, page views, and only with consent, hashed contact info via Advanced Matching | Ad performance measurement, remarketing | Shared for cross-context behavioral advertising, only after consent |
| Video embeds | YouTube | Page views, device and browser identifiers, standard platform cookies | Display embedded video content | Shared, only after consent |
| On-site experimentation & redirect tracking | Sigmize (our own product) | Browsing behavior, page interactions, assigned test variant | A/B testing to improve user experience | Service provider, not sold or shared |
| Popup lead capture | ConvertBox | Page views, form submissions, email address if provided | Email opt-in / lead capture | Shared for cross-context behavioral advertising, only after consent, per the live Cookie Policy’s categorization |
| Browser compatibility | Polyfill.io (via Fastly) | IP address, browser information | Supplies missing JavaScript features for older browsers | Service provider, not sold or shared |
| Payments, checkout, affiliates | SureCart, Stripe, PayPal | Billing and payment details, IP address | Take and process payments, manage your license and affiliate referrals | Service provider, not sold or shared |
| Spam protection | Google reCAPTCHA | IP address, interaction/behavior signals | Fraud and abuse prevention | Service provider, not sold or shared |
| AI chat support & Knowledge Base | Powerful Docs (app.powerfuldocs.com) | Chat messages, name/email if provided | AI-powered support assistance and self-serve docs | Service provider, not sold or shared |
| Image optimization CDN | ShortPixel | IP address, request metadata | Serve optimized images; classed as essential | Service provider, not sold or shared |
| Video/file hosting | Bunny.net | IP address, request metadata | For storing data and site offloading | Service provider, not sold or shared |
| Content delivery, security & analytics | Cloudflare | IP address, request metadata | Performance, security, bot mitigation, anonymized Web Analytics | Service provider, not sold or shared |
| Email delivery | Amazon SES | Email address | Transactional and marketing email | Service provider, not sold or shared |
| Profile pictures | Automattic Inc. (Gravatar) | Hashed email address | Show a profile picture next to a blog comment | Service provider, not sold or shared |
Cross-BSF-product tracking: Because Brainstorm Force operates multiple distinctly branded product sites (SureMembers, SureForms, SureDash, Presto Player, Astra, Spectra, CartFlows, OttoKit, and others), each site runs its own independent cookie consent tool. Your consent choice on one BSF site does not carry over to another. If you want to opt out across multiple BSF properties, you will need to do so on each site individually.
How Long We Keep Your Data
- Support ticket records are kept for 3 years from the date the ticket is closed.
- Cookie consent records are kept for up to 365 days.
- Setup and license records are kept for as long as we have a relationship with you, and afterwards for the period our tax and accounting obligations require.
- Purchase and license records are kept for as long as you hold a license with us, and afterwards for the period our tax and accounting obligations require.
- Copies of data delivered to a connected third-party service are retained by that provider under its own rules rather than ours.
You can ask us to delete your data sooner. See What Rights You Have Over Your Data below.
Where Your Data Is Processed
We are based in the United States. Because we and some of our providers operate internationally, personal information may be processed in the United States and other countries outside the European Economic Area, the United Kingdom, and India. Where a restricted international transfer applies, we use the transfer mechanism required for the relevant jurisdiction and provider, such as applicable contractual clauses, adequacy arrangements, or other legally recognized safeguards. You may ask us at [email protected] for details of the safeguard used for a particular transfer.
California Privacy Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, disclose, and if applicable sell or share, and to request a copy of it
- Right to delete personal information we have collected from you, subject to certain exceptions
- Right to correct inaccurate personal information we maintain about you
- Right to opt out of the sale or sharing of your personal information. Based on the categorization above, this specifically means opting out of the advertising/remarketing tools (Google Ads, Meta Pixel, ConvertBox, YouTube marketing cookies) that involve cross-context behavioral advertising
- Right to limit the use and disclosure of sensitive personal information, where applicable
- Right to non-discrimination for exercising any of the above rights
The remaining recipients listed in this policy process data under service-provider or processor terms for the purposes described in the table above.
To opt out of the sale or sharing of your personal information, click Cookie Preferences in the site footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out request.
To exercise your other rights, contact us at [email protected]. We will verify your request and respond within 45 days, as required by law, with a possible 45-day extension for complex requests.
Your Rights Under India’s Digital Personal Data Protection Act (DPDP)
If you are located in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023:
- Right to access a summary of the personal data we hold about you and how we process it
- Right to correction and erasure of your personal data
- Right to grievance redressal, as described below
- Right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before your withdrawal
We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental consent, consistent with the DPDP Act’s requirements for children’s data.
Grievance Officer: Adam Preiser, [email protected]
If you have a grievance regarding how we handle your personal data, you may contact our Grievance Officer at the address above, or write to us at [email protected] and ask for your message to be passed to the Grievance Officer. We aim to acknowledge privacy grievances within 72 hours of receipt. We aim to resolve most matters within 30 days and, where additional investigation is required, within 90 days. These are our internal response targets and may be updated where applicable law requires a different timeline.
How Secure Is My Information
We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Credit card information, when provided, is encrypted using secure socket layer (SSL) technology.
What Rights You Have Over Your Data
To exercise applicable privacy rights, including access, correction, deletion, objection, restriction, or withdrawal of consent where available, contact [email protected]. Some requests may be subject to legal exceptions or may not apply to processing we must continue for legal, security, accounting, contractual, or other permitted purposes.
Legal basis for processing (EEA and UK visitors): Depending on the purpose, we process your data based on your consent (for example, non-essential cookies and marketing communications), the necessity of processing to perform our contract with you (for example, fulfilling a purchase), our legitimate interests (for example, improving our services, spam prevention, and fraud prevention), or compliance with a legal obligation.
If you believe we have not complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority.
Children’s Online Privacy Protection Act Compliance
We do not knowingly collect personal information from children under the age of 13. If we determine we have collected personal information from a child under 13, we will take reasonable measures to remove it from our systems. If you are under 13, please do not submit personal information through the Site, service, or Software.
Third-Party Links
We may include or offer third-party products or services on our website. These third-party sites have separate, independent privacy policies, and we hold no liability or responsibility for their content or activities.
Affiliate Disclosure
Some third-party links on our site may be affiliate links, tracked through our affiliate program. We earn a referral fee when you buy services from companies we recommend. If you purchase after clicking an affiliate link, we receive a commission.
Affiliate tracking cookies are subject to the same consent preferences described in the Cookies section above.
Remarketing and Targeted Advertising
We work with third parties including Google Ads, Google Analytics, and Meta to provide targeted advertisements or marketing communications that may interest you, based on your browsing activity on our sites. This may include cross-context behavioral advertising as defined under California law. For more on how targeted advertising works, see the Network Advertising Initiative’s educational page.
You can opt out of targeted advertising through Google or Meta directly, or by clicking Cookie Preferences in the site footer.
Newsletter Emails
We send product announcements, software updates, and special offers by email where you have subscribed, selected a marketing option, or where another lawful basis permits us to contact you. Where consent is required, we will only send marketing after you have provided it. You can unsubscribe from marketing at any time using the unsubscribe link in every email.
Marketing email is separate from the transactional email we have to send you about a purchase, a license, or a support ticket. Unsubscribing from marketing does not stop those.
If you are in the EEA or the UK, we will only send you marketing email where you have given consent, and we will never make that consent a condition of buying or using our products.
Will This Privacy Policy Ever Change
We may update this Policy when our Site, Software, Services, business, or applicable laws change. We will update the “Last updated” date when we do so and, where required, provide additional notice or request consent before a material change takes effect.
Contact Us
For questions about our privacy practices or to make a complaint, contact us by email at [email protected] or by mail:
Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States
If you are in India and want to raise a grievance under the DPDP Act, you can write to our Grievance Officer, Adam Preiser, at [email protected], or use [email protected] and we will route it.