Scope and who is responsible
This Privacy Policy explains how Bundl collects, uses, discloses, and protects personal data when you visit or use our website, builder, public profiles, analytics, audience tools, and related services (the “Service”). It applies to account holders, people building guest drafts, public-profile visitors, subscribers, and people who contact us.
bundl is the controller when we decide why and how personal data is used—for example, for accounts, security, billing, and our own service analytics. When a creator uses a bundl form to collect information from their visitors, that creator generally decides the purpose and use of the submission. In that context, the creator is the controller and bundl processes the data on the creator's instructions.
If your question concerns information you submitted to a creator, contact that creator first. We will assist creators with verified requests where required.
Information we collect
- Account data: name, email address, password hash, email-verification status, profile image, account identifiers, and authentication-provider details.
- Workspace and profile data: handles, biography, links, blocks, designs, schedules, social destinations, uploaded files, published versions, and settings.
- Billing data: billing name, email, address, country, VAT information, plan, subscription status, and payment-provider identifiers. bundl does not store full payment-card numbers.
- Audience data: form responses, subscriber email, optional name or phone, consent text and status, tags, submission time, and the profile or block that collected the response.
- Usage and analytics data: page views, block clicks, form events, referrer host and referring page path, campaign parameters, approximate country or region, device category, browser, operating system, locale, and timestamps. Query parameters and URL fragments are removed from referring-page URLs before storage.
- Security and technical data: IP address, user agent, session records, fraud signals, rate-limit data, and diagnostic logs. Analytics identifiers and IP addresses used for visitor reporting are pseudonymized before storage.
- Communications: messages, support requests, feedback, and information supplied when exercising a legal right.
How we receive information
We receive information directly from you when you create an account, build or publish a page, upload an image, choose a plan, submit a form, or contact us. We also collect limited technical data automatically when you use the Service, subject to the analytics and cookie choices described below.
We may receive information from services you choose to connect or embed, payment and authentication providers, infrastructure vendors, and public web pages used to generate link previews. A guest draft is saved locally in your browser until you choose to sign in and persist it to bundl.
How and why we use information
- provide accounts, the builder, publishing, forms, analytics, exports, uploads, and support;
- process subscriptions, keep billing records, and prevent payment fraud;
- authenticate users, secure the Service, enforce limits, and investigate abuse;
- render link previews and embeds and connect visitors to selected destinations;
- measure performance and improve usability, reliability, and product decisions;
- send service, security, verification, billing, and requested marketing messages;
- comply with law, respond to valid legal requests, and protect rights and safety; and
- establish, exercise, or defend legal claims.
Where applicable, our legal bases are performance of our contract with you, our legitimate interests in operating and protecting the Service, your consent, and compliance with legal obligations. When we rely on legitimate interests, we consider the impact on your rights.
Public profiles and creator-controlled data
Published profiles are public by design. Their handle, display name, biography, links, images, social destinations, and visible blocks can be viewed and reshared by anyone with access to the URL. Do not publish information you want to keep private.
A creator can view, filter, update, export, and delete responses and subscriber records gathered through their forms. Creators must give their visitors an appropriate privacy notice, collect valid consent where required, use responses only for disclosed purposes, and handle requests to access, correct, unsubscribe, or delete data. bundl does not sell a creator's form submissions or use their contents for our own advertising.
International transfers
bundl and our service providers may process information in countries other than where you live. Where data-protection law requires it, we use an approved transfer mechanism such as standard contractual clauses, adequacy decisions, or another lawful safeguard. You can contact us for more information about safeguards relevant to your data.
How long we keep information
We keep personal data only for as long as needed for the purposes in this policy, to provide the Service, and to meet security, accounting, tax, dispute, and legal obligations. Specific periods depend on the data and your plan or settings.
- Guest drafts remain in your browser until you clear or replace them.
- Account and published-profile data remains while the account is active and for a limited period after deletion where legally necessary.
- Raw analytics events are normally retained for 90 days on Starter and 365 days on Pro, subject to shorter account settings.
- Audience records are normally retained for 730 days on Starter and 1,825 days on Pro, subject to shorter account settings and deletion requests.
- Completed analytics export files expire and are removed automatically.
- Deletion logs may retain a minimal record that a request was completed, without retaining the deleted content.
We may retain de-identified or aggregated information that no longer identifies a person.
Security
We use technical and organizational safeguards designed for the nature of the data, including access controls, scoped storage keys, signed upload and download URLs, hashed analytics identifiers, transport encryption, rate limits, logging, and separation between workspaces. No online service can guarantee absolute security.
Use a unique password, protect your devices, and notify support@bundl.link if you believe your account has been compromised.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; obtain a portable copy; withdraw consent; opt out of certain sharing or targeted advertising; and appeal or complain to a regulator. We will not discriminate against you for exercising a privacy right.
Account holders can use in-product controls to update profile data, export analytics or form responses where available, delete audience or analytics records, and delete their account. Marketing emails include an unsubscribe method; service messages may still be necessary.
To make a verified request, email support@bundl.link. We may ask for information needed to verify your identity and authority. If the request concerns a creator's form, identify the public profile and form involved.
Children
bundl is not directed to children who cannot lawfully consent to the processing described here, and our paid and business features are intended for adults. Do not use bundl forms to knowingly collect children's personal data without the consent and safeguards required by law. Contact us if you believe a child provided data unlawfully.
Regional disclosures
Residents of the EEA, United Kingdom, and similar jurisdictions may contact their local data-protection authority. Residents of U.S. states with comprehensive privacy laws may request the categories and specific pieces of personal data we hold, correction, deletion, and portability, and may opt out of a legally defined sale, sharing, or targeted advertising. bundl does not sell personal data for money.
Authorized agents may submit a request where local law permits it. We may require proof of authorization and direct identity verification.
Changes and contact
We may update this policy when the Service, our providers, or the law changes. We will post the revised version and update its effective date. If a change materially affects your rights, we will provide reasonable additional notice.
Questions, complaints, and privacy requests can be sent to support@bundl.link. You can also review our Terms and Cookie Policy.
