Privacy Policy
Version 1 · effective 30 Sep 2026 · All versions
An earlier version. Read the current one.
Effective date: [EFFECTIVE DATE]
Draft status: this is a starting draft for review by a UK solicitor. Items in square brackets are placeholders or points to confirm. It is not legal advice.
1. Who we are
Bubbl is a location-based engagement platform for businesses. It is provided by [COMPANY LEGAL NAME], a company registered in England and Wales under company number [COMPANY NUMBER], whose registered office is at [REGISTERED ADDRESS] ("Bubbl", "we", "us").
We are registered with the Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER].
You can contact us about privacy at [PRIVACY CONTACT EMAIL] or by post at the address above. [CONFIRM whether a Data Protection Officer is appointed. If not, remove any reference to a DPO.]
2. What this policy covers
This policy explains how we handle personal data where we decide why and how it is used (as a "controller"). That covers:
- dashboard users: people who sign up for, are invited to, or use the Bubbl dashboard;
- billing contacts: people whose details are given to us for invoicing and payment;
- people who contact us, including through the dashboard's support function;
- Showcase users: people who use Bubbl's own demonstration app, Showcase, and pair it to a workspace; and
- email recipients of messages we send about the Service.
If you use an app that contains the Bubbl SDK
Businesses embed the Bubbl SDK in their own mobile apps. If you use one of those apps, the business that publishes the app is the controller of your data, and we process it only on their behalf and on their instructions (as a "processor"). This policy does not describe that processing. Please read that app's privacy notice, and contact the app's publisher to exercise your rights. If you contact us, we will pass your request to the relevant business where we can identify it.
3. Personal data we collect
Dashboard users
- Account details: name, email address, password (stored only as a one-way hash), time zone, profile picture if you upload one.
- Security details: two-factor authentication settings (the secret and recovery codes are stored encrypted), passkeys you register, your last sign-in and last activity times.
- Workspace membership: the workspaces you belong to, your role and permissions, and invitations you send or receive.
- Session and device information: your IP address and browser user agent, stored with your signed-in session. We also include the IP address and a summary of the browser in the "new sign-in" security email we send you.
- Activity records: actions taken by Bubbl administrators in the admin area are recorded in an audit log with the administrator's name, email, IP address and user agent.
- Content you create: campaigns, notifications, surveys, locations and media you upload. This mostly relates to your organisation rather than to you personally.
Billing contacts
- Company name and legal name, billing email, billing address, telephone number, VAT number.
- Payment details: payments are handled by Stripe. We do not see or store your full card number; we receive and store the card type and the last four digits, and Stripe's customer reference.
- Invoices, payment history and plan changes.
Support conversations
- The messages you send through the dashboard's support function, with your name, email and workspace. Each message is also emailed to our support team.
Showcase users
When you install Showcase and pair it with a workspace (by scanning a QR code, typing a short code or entering a demo PIN), we collect:
- Device information: platform, operating system version, device model, manufacturer, app version, SDK version, locale, country and time zone, and an optional device name.
- An install identifier and credential used to authenticate the app to our servers.
- Push token (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS).
- Permission status: whether notifications and location are allowed, and whether precise location is allowed.
- Location data: when you enter or leave a geofence belonging to the workspace, the time, the geofence, and your position and its accuracy as reported by your phone. Showcase also sends your approximate position when it asks our servers for nearby geofences. [CONFIRM: Showcase currently uses SDK 4.1.7. Check the exact data that version sends.]
- Interactions: notifications received, displayed, opened or dismissed, links tapped, media viewed, and any survey answers you give.
Important: a Showcase device is paired to a specific workspace. Members of that workspace can see the device and its activity in their dashboard, and the workspace's retention settings apply to it.
Showcase displays maps using Google Maps, and receives push notifications through Firebase Cloud Messaging on Android. Google receives information from your device when those features are used.
Email recipients
We send email through Amazon Simple Email Service from info@bubbl.tech. We record delivery events such as bounces and spam complaints so that we stop sending to addresses that bounce or complain.
4. Why we use your data and our lawful bases
| Purpose | Data | Lawful basis |
|---|---|---|
| Creating and running your account and workspace | Account details, workspace membership | Contract with you, or our legitimate interest in providing the Service to your organisation where the contract is with your employer |
| Keeping accounts secure (two-factor authentication, sign-in alerts, rate limiting, audit logs) | Security details, session and device information | Legitimate interests (protecting our users and the Service) |
| Preventing automated sign-ups | IP address, browser and interaction data processed by Google reCAPTCHA on the sign-up page | Legitimate interests (preventing abuse) |
| Billing and collecting payment | Billing contact details, payment details | Contract; legal obligation (accounting and tax records) |
| Sending service emails (invitations, verification, password resets, receipts, payment failures, campaign start and end notices, export ready) | Name, email | Contract; legitimate interests |
| Answering support requests | Support conversations | Legitimate interests; contract |
| Operating Showcase so you can preview a workspace's campaigns | Showcase user data | Legitimate interests (demonstrating the Service at your request); consent for location and notification permissions, which you give through your phone's prompts |
| Monitoring performance and fixing errors | Technical data about requests, errors and jobs, which may include identifiers of the signed-in user | Legitimate interests (keeping the Service reliable) |
| Complying with law and defending legal claims | Any relevant data | Legal obligation; legitimate interests |
We do not use your personal data for advertising, we do not sell it, and we do not send marketing email. [CONFIRM: if marketing email is introduced, add a lawful basis and an unsubscribe mechanism.] We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
Where we rely on legitimate interests, you can ask us for details of the balancing test we carried out.
5. Cookies and similar technologies
The dashboard uses cookies that are strictly necessary for it to work:
- a session cookie, to keep you signed in (encrypted, sent only over HTTPS);
- a security token cookie (XSRF-TOKEN), to protect forms against cross-site request forgery; and
- a "remember me" cookie, if you choose to stay signed in.
The sign-up page loads Google reCAPTCHA v3, which may set or read Google cookies and collects information about your device and how you interact with the page. Google's Privacy Policy and Terms of Service apply.
Maps in the dashboard are provided by Mapbox. When you view a map or search for a place, your browser requests map tiles and search results from Mapbox, which receives your IP address, browser information and your search terms. [CONFIRM whether Mapbox GL telemetry is enabled and whether it stores anything on your device.]
Emails we send load fonts from Google Fonts, which means your email client may contact Google when you open them. [CONFIRM: consider self-hosting the fonts to avoid this.]
[CONFIRM: this policy does not cover the public marketing website at [WEBSITE URL]. If that site uses analytics or other non-essential cookies, add them here with a consent mechanism.]
6. Who we share data with
We use the service providers listed in our Sub-processor list to host and operate the Service, including Amazon Web Services (hosting, database, storage and email), Stripe (billing), Google (Firebase Cloud Messaging and reCAPTCHA), Apple (push notifications), Laravel Nightwatch (application monitoring) and Mapbox (maps). Each is bound by a contract that limits how it may use the data.
We may also share personal data:
- with the workspace you belong to: the owners and managers of your workspace can see your name, email, role and activity in it, and the members of a workspace a Showcase device is paired to can see that device and its activity;
- with our professional advisers (lawyers, accountants, auditors);
- with authorities where the law requires it; and
- with a buyer or successor if our business, or part of it, is sold or reorganised, under equivalent protections.
7. International transfers
Our Service is hosted by Amazon Web Services in the UK (London, eu-west-2), with disaster-recovery backups in Ireland (eu-west-1). The UK recognises the European Economic Area as providing adequate protection, so no additional safeguard is needed for data held in Ireland. [CONFIRM the backup region is in production.]
Some of our providers (for example Stripe, Google, Apple, Laravel and Mapbox) may process data in the United States or elsewhere. Where they do, we rely on:
- the UK Extension to the EU-US Data Privacy Framework (the "UK-US data bridge") where the recipient is certified under it; or
- the International Data Transfer Agreement or the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the ICO.
[CONFIRM the mechanism for each provider; see the sub-processor list.] You can ask us for more information about these safeguards.
8. How long we keep data
| Data | How long |
|---|---|
| Dashboard user account | While you have an account. Leaving or being removed from a workspace does not delete your account. Ask us to delete it at [PRIVACY CONTACT EMAIL]. [CONFIRM a retention period for dormant accounts.] |
| Workspace data, including support conversations and Showcase devices | Until the workspace is deleted. A deleted workspace is closed after a 14-day grace period and permanently erased 30 days after that. |
| Showcase device data | Also subject to the workspace's own retention settings (for example, deleting location events after a set period and removing inactive devices). |
| Signed-in sessions | Until you sign out or the session expires. [CONFIRM: expired session rows are cleared by Laravel's session garbage collection.] |
| Billing and invoice records | [6] years from the end of the financial year they relate to, to meet tax and accounting obligations. [CONFIRM.] |
| Administrator audit log | 2 years. |
| Application logs and monitoring data | 30 days for infrastructure logs. Monitoring data is kept by our monitoring provider for up to 90 days. |
| Email suppression list (bounces and complaints) | [CONFIRM] |
| Backups | Overwritten in the normal backup cycle within 35 days. |
9. How we protect data
We use technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS); encrypted storage of secrets such as device credentials, push credentials and two-factor secrets; encrypted, secure-only session cookies; hashed passwords; optional or enforced two-factor authentication and passkeys; signed requests from devices; rate limiting; strict separation of each workspace's data; restricted, audited administrator access; and hosting in AWS data centres. [CONFIRM encryption at rest for the database, backups and storage in production.]
10. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in some circumstances;
- restrict our use of your data in some circumstances;
- object to our use of your data where we rely on legitimate interests;
- data portability, where we rely on contract or consent and process the data by automated means; and
- withdraw consent at any time, where we rely on consent. For Showcase, you can turn off location or notifications in your phone's settings, or uninstall the app.
To exercise a right, email [PRIVACY CONTACT EMAIL]. We will respond within one month, which may be extended in some cases. We may need to verify your identity.
If you use an app that contains the Bubbl SDK, contact the app's publisher: they are the controller. Apps using the SDK can offer a "delete my data" option that erases your device's data from Bubbl permanently.
11. Complaints
If you are unhappy with how we have handled your data, please contact us first. You also have the right to complain to the Information Commissioner's Office: ico.org.uk, telephone 0303 123 1113.
12. Children
The dashboard is for business use and is not intended for children. Showcase is intended for use by businesses evaluating Bubbl and their staff, and is not intended for anyone under [18]. [CONFIRM age.]
13. Changes to this policy
We may update this policy. We will post the new version here with a new effective date and, if the changes are significant, tell dashboard users by email or in the dashboard.