Bondable

Privacy policy

Last updated July 2026

This policy explains what data Bondable handles, why, and who we share it with. Bondable is a loyalty-card platform for local businesses — built so that guests never have to install an app or hand over personal details.

Who we are

Bondable provides digital loyalty cards that live in Apple Wallet and Google Wallet. We act as the data controller for account data of the businesses that use Bondable, and as a processor for the loyalty programmes they run.

You can reach us at [email protected] for any privacy question or request.

Guests: no personal data — ever

When you add a loyalty card to your wallet, Bondable stores only what the card needs to work: a random card identifier, your stamp count, the reward balance, and the timestamps of your visits.

We never ask for or store your name, email, phone number, or any other identifying detail, and we place no tracking on the claim page. A card cannot be traced back to you as a person.

Businesses using Bondable

For the cafés, barbers, and salons that run cards, we process account data needed to operate the service: the owner's and team members' email addresses, workspace and venue names, program settings, and the billing details required for a subscription.

Cookies

On the web app we use two cookies only: one to keep you signed in (session) and one to remember your language. We set no advertising or cross-site tracking cookies.

Who we share data with

We rely on a small set of processors, each bound by a data-processing agreement and chosen for EU-friendly handling:

  • DigitalOcean — hosting, EU region
  • Resend — transactional email (sign-in codes, team invitations)
  • Stripe — payments (coming soon)
  • PostHog EU — product analytics
  • Sentry — error monitoring

Data retention

Business account data is kept for as long as the account is active and for a short period afterwards to meet legal and accounting obligations. Card data holds no personal information and is retained while the loyalty programme runs.

Your rights

Under the GDPR you can request access to, correction of, or deletion of your personal data, restrict or object to its processing, and receive a copy in a portable format. Because guest cards contain no personal data, these rights mainly concern business accounts.

To exercise any right, or to raise a concern, email [email protected]. You also have the right to lodge a complaint with your local data-protection authority.