Privacy Policy
This policy explains which personal data Bouncing Bison processes, where it comes from, why we process it and on what legal basis, who receives it, how long we keep it and what rights you have. It applies to everyone who uses Bouncing Bison, customers and providers.
1. Controller
The controller responsible for your personal data is the company that operates Bouncing Bison:
The company that will operate Bouncing Bison is being set up. Its legal name, registration details, address and representative will be published here before commercial launch.
- Company
- Not yet published
- Registered office
- Not yet published
- Represented by
- Not yet published
- Trade register number
- Not yet published
- Not yet published
2. What we process and where it comes from
- Account data you give us: name, email address and password (stored only as a hash). Optionally a city, bio, business name and profile photo, and for providers the business type and tax ID (CNP or CUI).
- If you sign in with Google or Apple: the account ID, name and email address that the provider sends us.
- Content you create: listings with their photos, prices, location and availability, albums, booking requests and notes, messages, reviews and review photos, favourites, saved searches, schedule blocks and reports.
- Data other users give us about you: the provider you book sees your name and booking details and can message you; a provider can invite you by entering your name and email address; other users can write reviews about a booking with you.
- Membership data for providers: plan, status and period, and the Stripe customer and subscription IDs. You enter card details on Stripe's pages; we never receive them.
- Records of what you accepted: the version of the text, the time, your IP address and your browser's user agent, when you sign up and when a provider accepts the Data Processing Addendum.
- Technical data: your IP address and browser details reach our servers with every request. We use them for security and rate limiting; our request logs do not store IP addresses. If you let your browser share your location for a nearby search, the coordinates are sent with that search and are stored only if you save the search. Cookies and local storage are described in our cookie notice.
3. Purposes and legal bases
We use your data only for the following purposes. The legal basis under the GDPR is given for each.
- Running your account and the marketplace, including listings, bookings, messages, reviews, notifications and transactional email: performance of our contract with you (Article 6(1)(b)).
- Provider memberships and billing through Stripe: performance of the contract (Article 6(1)(b)). Keeping billing records: our legal obligations under tax and accounting law (Article 6(1)(c)).
- Security, preventing abuse and fraud, rate limiting and handling reports: our legitimate interest in keeping the Service and its users safe (Article 6(1)(f)).
- Recording what you accepted: our obligation to be able to demonstrate consent (Article 7(1)) and our legitimate interest in proving what was agreed (Article 6(1)(f)).
- Functional cookies and local storage: your consent (Article 6(1)(a) GDPR and the ePrivacy rules). You can change your choice at any time in the cookie settings.
- Maps from Mapbox, and videos from YouTube or Vimeo on listings: our legitimate interest, and the provider's, in showing where a service is offered and what it looks like (Article 6(1)(f)).
- Contacts a provider imports with the invite feature: we process them on the provider's behalf, as described in our Data Processing Addendum.
4. Who receives your data
Other users see what the marketplace shows them: a provider sees your name and booking details when you book, and anyone can see public listings, provider profiles and reviews. Companies that run parts of the Service for us (hosting, database, file storage, email, payments and maps) receive the data they need for that task. The sub-processor page lists them, with what they do, the data involved and where they process it. We give data to authorities only when the law requires it. We do not sell personal data, and we use no advertising or analytics trackers. Sub-processors
5. Transfers outside the EEA
Our application servers and database run in Frankfurt, Germany, and our file storage is in Cloudflare R2's EU jurisdiction. Some providers, for example Stripe, Mapbox, Google and Apple, may process data outside the European Economic Area. Those transfers rely on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses, as offered by the provider.
6. How long we keep data
- Account and profile data: until you delete your account. Deletion takes effect at once, as the next section describes.
- Listings: until you delete them or your account. A deleted listing disappears from the site at once; its photos are removed from storage when you delete your account.
- Bookings, messages and reviews: as long as the other person involved keeps their account, because they are part of that person's records too. After you delete your account they no longer show your name.
- Membership and billing records: 10 years from the end of the year they relate to, to meet tax and accounting law. Stripe keeps the invoices themselves.
- Records of what you accepted: while your account exists and for 3 years after it is deleted, which is the general limitation period for claims in Romania and Germany.
- Sign-in sessions: 30 days, then deleted automatically.
- Password reset links: valid for 1 hour, and deleted automatically once expired.
- Notifications: read notifications are deleted automatically after 12 months. Unread ones stay until you read them or delete your account.
- Records of payment notifications we have processed from Stripe: 90 days.
- Rate limit counters that include your IP address: up to one hour.
- Backups: deleted data can remain in database backups until those backups expire on our hosting provider's backup schedule.
7. What happens when you delete your account
You can delete your account yourself on the Privacy page of your account settings. When you confirm:
- We delete your name, email address, password, profile photo, bio, city, business name, business type and tax ID, your Google or Apple sign-in link, your sessions, favourites, saved searches, notifications, albums and schedule blocks, and the photos on your listings and reviews.
- Your listings are taken down, and their descriptions, addresses and videos are removed.
- Open bookings that have not started yet are cancelled, and the other party is notified.
- An active membership is cancelled with Stripe at once, with no further charges.
- We keep booking records, messages and reviews, because the other person involved needs them and some have accounting or dispute value. They then show "Deleted user" instead of your name; the text you wrote in them stays as written. We also keep your consent records as proof, and the Stripe customer and subscription IDs that link to the invoices Stripe keeps.
- We send a confirmation to your email address and sign you out.
8. Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict its processing, to receive it in a portable format and to object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time; this does not affect processing that already took place. We answer requests within one month, which can be extended by two further months for complex requests.
You can do most of this yourself:
- Correct your profile in your account settings.
- Download your data or delete your account on the Privacy page of your account.
- Change your cookie choice in the cookie settings.
For anything else, write to us at: Not yet published
9. Complaints
You can complain to a data protection supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro. You can also complain in the EU member state where you live or work, or where the alleged infringement took place. In Germany each federal state has its own authority.
10. Automated decisions
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. Listings are hidden automatically when a provider's membership ends; this follows from the membership terms, and renewing brings them back.
11. Minimum age
Our Terms require users to be at least 18. The Service is not meant for children, and we do not knowingly process data of anyone under 16. If you believe a child under 16 has given us personal data, contact us and we will delete it.
12. Security
We protect your data with encryption in transit, argon2id password hashing, private file storage, access checks on every booking and message, and rate limits. The full list is in the annex to our Data Processing Addendum: technical and organisational measures
13. Cookies
We use only essential cookies by default, plus functional cookies with your consent. Full detail is in our Cookie notice.
14. Changes to this policy
When we change this policy we publish the new version here with a new date. If a change affects how we use data you have already given us, we tell you in the app or by email before it takes effect.
Draft for review: placeholder text to be finalised with legal counsel before launch. · Last updated: 2026-09-29