What this policy covers
This Cookie Policy explains how Bundl uses cookies, local storage, session storage, pixels, and related browser technologies on our website, builder, and public creator profiles. It should be read with our Privacy Policy.
What cookies and browser storage are
Cookies are small text records a website stores in your browser. First-party cookies are set by bundl; third-party cookies may be set by services embedded in a page. Local storage can retain information after the browser closes, while session storage is normally cleared when the tab or browser session ends.
Similar technologies may recognize a browser, remember a choice, protect a session, measure an interaction, or load content from another service. Some are necessary for a feature to work; others are optional.
Technologies we use
Essential
Account sessions, authentication handoffs, fraud prevention, security, rate limits, and interface preferences. These are needed to provide a requested feature and cannot be disabled through our analytics control.
Guest drafts
Local storage keeps the page you build before signing in so it can be edited and later moved to your account. It stays on that browser until replaced or cleared.
Profile analytics
On published profiles, bundl stores a pseudonymous visitor identifier for up to one year, a session identifier, and limited campaign attribution. Identifiers are hashed before analytics records are stored in our database.
Creator tracking
A creator may connect Google Analytics, Meta Pixel, TikTok Pixel, or X Pixel to their published profile. These optional services stay off until you make a choice in that profile's consent prompt.
Bundl marketing
Bundl's landing page uses X Pixel to measure site visits and advertising campaign results for Bundl's own marketing.
Third-party media
YouTube, Spotify, Apple Music, SoundCloud, social platforms, and other linked or embedded services may receive your IP address, browser data, and the page URL and may set their own cookies when their content loads or you interact with it.
How profile analytics works
Bundl's first-party analytics runs on published creator profiles so creators can understand visits and engagement. It does not load Google Analytics, Meta Pixel, TikTok Pixel, or a creator's X Pixel by itself.
Analytics can measure a page view, block interaction, outbound-link click, share, or form submission. Reports can include the referrer host and referring page path, campaign tags, approximate country or region, device category, browser, operating system, and locale. Query parameters and URL fragments are removed from referring-page URLs. We do not store raw IP addresses in the analytics event table; we hash them with a secret before storage.
If a creator enables an optional tracking integration, the public profile displays separate analytics and advertising choices. Google Analytics loads only after analytics consent. Meta Pixel, TikTok Pixel, and X Pixel load only after advertising consent. The choice is stored for that individual profile and can be changed through its Manage cookies control.
Browser controls
Your browser can block or delete cookies and site data. Blocking storage can reduce the accuracy of visitor and session counts. It may also sign you out, remove a guest draft, reset preferences, or prevent embeds from working. Browser settings apply separately to each browser and device.
Third-party services
Creator profiles can contain third-party links and embeds. Those providers may use cookies for playback, authentication, security, personalization, or their own analytics. bundl does not control their storage, retention, or choices. Review the relevant provider's privacy and cookie information before interacting with embedded content.
- Opening an outbound link sends a request to the destination.
- Loading an embed can disclose the profile URL, IP address, and browser information to its provider.
- Signing in with a third-party provider is governed by that provider's settings and policies.
- Stripe may use necessary cookies and fraud signals during checkout.
- With your permission, a creator's Google Analytics, Meta, or TikTok account can receive fixed profile interaction events. A creator's X account can receive site-visit and landing-page-view data from the X base pixel.
How long storage lasts
A pseudonymous visitor identifier can remain for up to one year. The analytics session identifier and campaign attribution are session cookies. Essential authentication cookies expire according to the session configuration or when you sign out. Guest drafts remain until they are replaced or browser site data is cleared.
Optional providers set and retain their own cookies according to the provider's terms and the creator's configuration. Withdrawing consent stops future optional tracking on that profile and Bundl attempts to remove its accessible first-party provider cookies.
Server-side analytics retention is separate from cookie lifetime and is explained in our Privacy Policy.
Updates and contact
We may update this policy as our technology, providers, or legal obligations change. The effective date above shows when this version began to apply.
Send questions to support@bundl.link.
