Terms of Service
Version 1 · effective 30 Sep 2026 · All versions
An earlier version. Read the current one.
Effective date: [EFFECTIVE DATE]
Draft status: this is a starting draft for review by a UK solicitor. Items in square brackets are placeholders or points to confirm. It is not legal advice.
1. About these terms
1.1 These Terms of Service ("Terms") govern your use of Bubbl, a location-based engagement platform provided by [COMPANY LEGAL NAME], a company registered in England and Wales under company number [COMPANY NUMBER], whose registered office is at [REGISTERED ADDRESS] ("Bubbl", "we", "us", "our").
1.2 "You" and "Customer" mean the business, organisation or other entity that creates a Bubbl workspace or signs an order with us. The individual who accepts these Terms confirms that they have authority to bind that entity.
1.3 Bubbl is provided to businesses only. It is not offered to consumers. By accepting these Terms you confirm that you are acting for the purposes of your trade, business, craft or profession.
1.4 These Terms incorporate our Data Processing Agreement ("DPA") and refer to our Privacy Policy and Sub-processor list. [CONFIRM THE FINAL URLS OF THESE PAGES.]
1.5 You accept these Terms by ticking the acceptance box when you create your workspace, by signing an order that refers to them, or by using the Service. [CONFIRM: the sign-up form does not currently include a terms acceptance step.]
2. Definitions
In these Terms:
- "Service" means the Bubbl web dashboard, the Bubbl device API, the Bubbl SDK, the Showcase app and any related documentation, support and services we provide.
- "Workspace" means your account on the Service, identified by your company, and all of its settings and content.
- "Authorised User" means an individual you, or someone acting for you, invite to or allow to use your Workspace through the dashboard.
- "SDK" means the Bubbl software development kits for Android, iOS, Flutter and React Native, including any updates we make available.
- "Customer App" means a mobile application you publish or operate in which you embed the SDK.
- "End User" means an individual who uses a Customer App.
- "Showcase" means Bubbl's own demonstration app, which can be paired to a Workspace to preview campaigns on a phone.
- "Customer Data" means all data, including personal data, that is submitted to the Service by you, your Authorised Users or, through the SDK, your Customer Apps and End Users.
- "Customer Content" means the campaigns, geofences, notifications, surveys, images, video, audio, links and other material you upload to or create in the Service.
- "Billable Device" has the meaning in clause 6.3.
- "Fees" means the charges payable for the Service under clause 6.
3. The Service
3.1 The Service lets you define geographic areas ("geofences", as circles or polygons), build campaigns, and send push notifications and surveys to End Users of your Customer Apps, and to view reports about delivery and engagement.
3.2 The SDK, once embedded in a Customer App and started, registers each installation with a per-install credential and reports to the Service:
- device information (platform, operating system version, device model, manufacturer, app identifier and version, SDK version, locale, country and time zone);
- the push notification token;
- the status of notification and location permissions, including whether precise location is allowed, and the End User's consent state where your app uses the SDK's consent option;
- geofence entry and exit events, with the position and accuracy reported by the device;
- notification events (for example received, displayed, opened, dismissed, call-to-action clicked, media viewed) and survey answers; and
- any segments and custom events your Customer App sets through the SDK.
3.3 Decisions about whether to show a notification are made by the Service, based on your campaign settings, delivery limits, quiet hours and cooldowns.
3.4 Push notifications are delivered through third-party push services: on Android, Firebase Cloud Messaging using the Firebase project whose credentials you provide; on iOS, the Apple Push Notification service using the APNs key you provide for each app. Your use of those services is also subject to Google's and Apple's own terms, which are between you and them.
3.5 We may change, improve or withdraw features of the Service from time to time. We will not make a change that materially reduces the core functionality of a paid plan during a paid billing period without giving you at least [30] days' notice. [CONFIRM NOTICE PERIOD.]
3.6 We may publish a minimum supported SDK version. An SDK older than that version stops tracking and contacting the Service (other than to check its configuration) until the Customer App is updated. We will give reasonable notice before raising the minimum version, except where an urgent change is needed for security or to prevent harm.
3.7 Features we describe as "beta", "preview" or similar are provided as-is, may change or be withdrawn at any time, and are excluded from any service commitments.
4. Your Workspace and Authorised Users
4.1 You must give accurate information when you create your Workspace and keep it up to date, including your legal name, billing address and billing email.
4.2 You are responsible for your Authorised Users and for everything done in your Workspace using their credentials. You must ensure that they keep their passwords, passkeys and two-factor authentication methods secure, and you must remove access promptly for anyone who should no longer have it.
4.3 Your Workspace has a public SDK API key that ships inside your Customer App. It identifies your Workspace; it is not a secret. Each installation then receives its own credential. You must tell us promptly if you believe your Workspace or any credential has been misused.
4.4 You may use the Workspace settings to require two-factor authentication, restrict invitations to email domains, sign out idle users, and set how long location events and inactive devices are kept. You are responsible for choosing settings that suit your obligations.
4.5 Bubbl staff may access your Workspace where needed to provide support, investigate a problem, maintain security or comply with law. Such access by our administrators is recorded in an audit log.
5. Plans
5.1 Free plan. The free plan lets you try the Service using the Showcase app only. It does not include using the SDK in your own Customer App: SDK calls from your own app are refused while your Workspace is on the free plan. The free plan has usage limits (for example on users, locations and campaigns) shown in the dashboard. We may change or withdraw the free plan at any time.
5.2 Paid plans. Paid plans include using the SDK in your Customer Apps and the features shown for that plan in the dashboard or your order.
5.3 Showcase. You may pair Showcase to your Workspace to preview your campaigns on a phone. Devices paired through Showcase appear in your Workspace. Our Privacy Policy explains how we handle the personal data of people who use Showcase.
6. Fees, billing and VAT
6.1 Fees for paid plans are charged in pounds sterling (GBP) at the rate of 2.5p per Billable Device per month, unless your order says otherwise. [CONFIRM: see notes.md, the current code bills flat monthly plan prices.]
6.2 Billing is monthly, anchored on the 1st day of each calendar month. The first and last months of a subscription, and any change of plan during a month, are charged pro rata.
6.3 A "Billable Device" is [BILLABLE DEVICE DEFINITION, for example: an installation of a Customer App registered to your Workspace through the SDK that contacted the Service at least once during the billing month]. The following are not Billable Devices:
- installations of development builds of a Customer App [CONFIRM HOW A DEVELOPMENT BUILD IS IDENTIFIED, for example an iOS device registered with the APNs sandbox environment];
- devices paired to your Workspace through Showcase; and
- devices that a Workspace manager has marked as test devices in the dashboard.
6.4 Payments are processed by Stripe. By choosing a paid plan you authorise us, through Stripe, to charge the payment method on file for the Fees when they fall due. We do not store your full card details; we hold only the card type and last four digits.
6.5 Fees are exclusive of VAT. UK VAT, and any other applicable tax, will be added at the prevailing rate. Please provide your VAT number in your Workspace if you have one. Our VAT number is [VAT NUMBER].
6.6 Invoices are payable [on issue / within [NUMBER] days]. [CONFIRM PAYMENT TERMS.] If a payment fails, we will notify your billing contact. If a payment remains outstanding [14] days after we notify you, we may suspend the Service under clause 12 until it is paid. We may charge interest on overdue sums under the Late Payment of Commercial Debts (Interest) Act 1998. [CONFIRM.]
6.7 We may change our prices by giving you at least [30] days' notice by email to your billing contact. The new prices apply from the start of the next billing month after the notice period ends. If you do not agree, you may cancel before the new prices apply.
6.8 Except where required by law or stated in these Terms, Fees are non-refundable. [CONFIRM REFUND POSITION, including for pro rata charges on cancellation.]
7. SDK licence
7.1 Subject to these Terms and to your paying the Fees, we grant you a non-exclusive, non-transferable, non-sublicensable, revocable licence during the term to embed the SDK in your Customer Apps and to distribute it as part of those apps in object code form, solely to use the Service.
7.2 You must not, and must not allow anyone else to:
- modify, reverse engineer, decompile or disassemble the SDK, except to the extent the law permits this despite this restriction;
- remove or alter any proprietary notices;
- use the SDK or the device API with any service other than Bubbl, or to build a competing product;
- circumvent the SDK's request signing, rate limits, consent handling or minimum-version controls; or
- use the SDK in a way that breaches the policies of Apple's App Store or Google Play.
7.3 Parts of the SDK may be subject to open source licences. Those licences apply to those parts and take precedence over this clause to the extent they conflict. [CONFIRM SDK LICENCE; the SDK's own licence file should be checked for consistency with this clause.]
8. Your responsibilities for End Users
8.1 For personal data about End Users collected through the SDK, you are the controller and we are your processor. The DPA applies to that processing.
8.2 You must, in each Customer App:
- provide End Users with a clear privacy notice that explains, at least, that the app uses Bubbl to process their device information, push token, location (including background location where you request "always" permission), notification and survey interactions, and any segments or custom events you set;
- have a lawful basis for that processing, and obtain any consent required by law, including consent under the Privacy and Electronic Communications Regulations 2003 (PECR) for storing and accessing information on the End User's device where required, and any consent required for sending marketing messages;
- request location and notification permissions only in accordance with the operating system's rules and with a clear explanation; where you ask for background location on Android, you must show the prominent disclosure Google Play requires (the SDK's privacy view can do this when enabled in the dashboard) and complete Google Play's location permission declaration;
- where you rely on consent, start the SDK with its consent option (requireConsent) and only call setConsent(true) once the End User has agreed, and provide an easy way to withdraw consent (for example through optOut); and
- provide End Users with a way to ask for their data to be erased, which may be the SDK's deleteMyData function.
8.3 You must not use the Service to target or knowingly process data about children under 13 [CONFIRM AGE, and whether a higher age should apply given the use of location data] unless you have obtained verified parental consent and complied with the ICO's Age Appropriate Design Code where it applies.
8.4 You must not send special category data (for example health, religion, sexual orientation or political opinions) or criminal offence data to the Service through segments, custom events, survey questions, notification content or otherwise, and must not create geofences or segments whose purpose is to infer such data (for example targeting visitors to a clinic or a place of worship), unless we have agreed in writing that appropriate safeguards are in place.
8.5 You are responsible for the content of your notifications, surveys, media and links, and for complying with advertising, consumer protection and marketing law, including the CAP Code, in relation to them.
9. Acceptable use
You must not use the Service to:
- break any law or regulation, or infringe anyone's rights;
- track an individual without their knowledge, or monitor a specific person's movements covertly;
- send content that is unlawful, misleading, defamatory, discriminatory, harassing, sexually explicit, or that promotes violence or illegal activity;
- send malware, phishing links or spam;
- interfere with or disrupt the Service, attempt to gain unauthorised access to it or to another customer's data, or probe or test its vulnerability without our written permission;
- exceed rate limits, or send automated traffic other than through the SDK and documented APIs; or
- resell or provide the Service to third parties except as part of your own Customer Apps, unless we agree in writing.
10. Customer Data and Customer Content
10.1 You own your Customer Data and Customer Content. You grant us a non-exclusive, worldwide, royalty-free licence during the term to host, copy, process, transmit and display them only as needed to provide, secure and support the Service, and as set out in the DPA.
10.2 You confirm that you have all rights needed to upload Customer Content and to allow us to use it as described, and that it does not infringe anyone's rights. If you link to or embed third-party media (for example YouTube videos), your use of that media is also subject to that third party's terms.
10.3 We may collect and use information about how the Service is used and performs (for example request volumes, error rates and feature usage) to operate, secure, support and improve the Service, and to calculate Fees. [CONFIRM whether Bubbl wishes to reserve the right to use aggregated, anonymised data derived from Customer Data, for example for benchmarking. If so, this needs express wording here and in the DPA.]
10.4 You can export your Workspace data from the dashboard at any time. Export download links expire after 7 days.
11. Data protection
11.1 Each party will comply with the UK GDPR and the Data Protection Act 2018, and PECR, as they apply to it.
11.2 We are controller for personal data about your Authorised Users, billing contacts and support conversations, and for Showcase users, as described in our Privacy Policy.
11.3 We are processor for personal data about End Users collected through the SDK. The DPA forms part of these Terms and governs that processing.
12. Suspension
12.1 We may suspend all or part of the Service, or a Customer App's access to it, if:
- Fees are overdue as described in clause 6.6;
- we reasonably believe that your use breaches clause 8 or clause 9, or creates a security risk or risk of harm to the Service, other customers or End Users; or
- we are required to by law or by a competent authority.
12.2 Where reasonably possible we will give you notice before suspending and will limit the suspension to what is needed. We will restore the Service promptly once the reason for suspension has been resolved.
13. Availability and support
13.1 We will use reasonable skill and care to provide the Service and to keep it available, but we do not guarantee that it will be uninterrupted or error-free. [CONFIRM whether any service level is offered; none is included in this draft.]
13.2 Planned maintenance will, where reasonably possible, be carried out at times of low usage and notified in advance.
13.3 Support is available through the dashboard's support function and by email to [SUPPORT EMAIL] during [SUPPORT HOURS].
14. Confidentiality
14.1 Each party will keep the other's confidential information confidential, use it only to perform or receive the Service, and disclose it only to its employees, contractors and advisers who need to know it and are bound by equivalent obligations, or where required by law.
14.2 This clause does not apply to information that is or becomes public other than through a breach of these Terms, was already lawfully known to the recipient, or is independently developed.
15. Intellectual property
15.1 We and our licensors own all rights in the Service, the SDK, the documentation and any improvements to them. Except for the licences expressly granted in these Terms, no rights are transferred to you.
15.2 If you give us feedback or suggestions, we may use them without restriction or obligation to you.
16. Term, cancellation and deletion
16.1 These Terms apply from when you accept them until your Workspace is deleted.
16.2 You may downgrade or cancel a paid plan at any time from the dashboard. [CONFIRM whether cancellation takes effect immediately or at the end of the billing month.]
16.3 You may delete your Workspace from the dashboard. Deletion works as follows:
- a 14-day grace period begins: payment collection is paused, running campaigns are paused and SDK calls from your Customer Apps are refused. You can cancel the deletion during the grace period, which restores your Workspace;
- at the end of the grace period your subscription is cancelled and your Workspace is closed; and
- 30 days after closure, your Workspace and all Customer Data and Customer Content in it, including uploaded media and exports, are permanently erased from our live systems. Copies in backups are overwritten in the ordinary backup cycle within 35 days.
16.4 Individual Authorised User accounts are separate from Workspaces: when a Workspace is erased, its members lose access to it, but their user accounts are not automatically deleted. [CONFIRM: there is currently no self-service account deletion; requests are handled through support.]
16.5 Either party may terminate these Terms by written notice if the other commits a material breach that is not remedied within 30 days of notice, or immediately if the other becomes insolvent or enters into any arrangement with its creditors.
16.6 We may terminate these Terms for convenience on [60] days' written notice. [CONFIRM.] If we do, we will refund any Fees paid in advance for the period after termination.
16.7 You should export any data you need before deletion takes effect. Clauses that by their nature should survive termination, including clauses 6 (for unpaid Fees), 10, 14, 15, 17, 18 and 20, survive.
17. Warranties and disclaimers
17.1 Each party warrants that it has the authority to enter into these Terms.
17.2 Location-based features depend on the End User's device, operating system, permissions, battery state, connectivity and the accuracy of location readings. We do not guarantee that any geofence entry or exit will be detected, or that any notification will be delivered, displayed or delivered at a particular time. Operating systems limit how many geofences an app can monitor (for example, 20 per app on iOS, shared with other code in the app).
17.3 Except as expressly set out in these Terms, the Service is provided without any warranty, condition or other term, whether express or implied, including as to satisfactory quality or fitness for a particular purpose, to the fullest extent permitted by law.
18. Liability
18.1 Nothing in these Terms limits or excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot be limited or excluded by law.
18.2 Subject to clause 18.1, neither party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for any loss of profits, revenue, business, goodwill or anticipated savings, or for any indirect or consequential loss.
18.3 Subject to clause 18.1, each party's total aggregate liability arising out of or in connection with these Terms in any 12-month period is limited to [LIABILITY CAP, for example the greater of the Fees paid or payable by you in the 12 months before the event giving rise to the claim and £[AMOUNT]].
18.4 [CONFIRM whether a separate or higher cap should apply to data protection claims, breach of confidentiality, and the indemnity in clause 19.]
18.5 Your obligation to pay the Fees is not limited by this clause.
19. Indemnity
19.1 You will indemnify us against all losses, fines, costs and expenses (including reasonable legal fees) arising from any third-party claim or regulatory action to the extent it results from your breach of clause 8 or clause 9, from your Customer Content, or from your failure to provide End Users with a privacy notice or obtain any consent required by law. [SOLICITOR REVIEW: scope and whether a mutual indemnity is appropriate.]
19.2 We will indemnify you against any third-party claim that your use of the Service in accordance with these Terms infringes that third party's UK intellectual property rights, subject to the limits in clause 18. [CONFIRM.]
20. General
20.1 Changes to these Terms. We may update these Terms. We will give you at least [30] days' notice of material changes by email or in the dashboard. Changes take effect at the end of the notice period. If you do not agree, you may cancel your plan or delete your Workspace before they take effect.
20.2 Notices. We will send notices to the email address of your Workspace owner or billing contact. You may send notices to us at [LEGAL NOTICES EMAIL] or by post to [REGISTERED ADDRESS].
20.3 Assignment. You may not assign or transfer your rights under these Terms without our consent. We may assign them to a successor to all or substantially all of our business, on notice to you.
20.4 Subcontracting. We may use subcontractors to provide the Service. Our use of sub-processors for personal data is governed by the DPA.
20.5 Force majeure. Neither party is liable for any delay or failure caused by events beyond its reasonable control, including failures of third-party hosting, push notification or telecommunications providers. This does not excuse payment of Fees.
20.6 Entire agreement. These Terms, the DPA and any order form are the entire agreement between us about the Service and replace any earlier agreement or understanding. If there is a conflict, the order of precedence is: the DPA (for the processing of personal data), then any signed order form, then these Terms.
20.7 Third-party rights. No one other than you and us has any right under the Contracts (Rights of Third Parties) Act 1999 to enforce these Terms.
20.8 Waiver and severability. A failure to enforce a right is not a waiver of it. If any provision is found to be invalid, the rest remains in force.
20.9 Governing law and jurisdiction. These Terms, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with them, are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.
Contact
[COMPANY LEGAL NAME], [REGISTERED ADDRESS]. Company number [COMPANY NUMBER]. Email: [CONTACT EMAIL].