Privacy Policy
On this page
Last updated: 8 July 2026
This Privacy Policy explains how SolutionInBit Limited, trading as Bundus (Bundus, we, us, our), collects, uses, shares, and protects personal data when you use our websites, web application, mobile applications, and related services (collectively, the Services).
SolutionInBit Limited is a private limited company registered in England and Wales (company number 16545056) with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX.
For privacy enquiries or to exercise your data rights, contact hello@usebundus.com (subject line: Privacy).
1. Scope#
This Privacy Policy applies to:
| Surface | Typical URL or app | Who it covers |
|---|---|---|
| Marketing website | usebundus.com | Visitors and prospective customers |
| Operator web app | app.usebundus.com | Business users who register and operate a Bundus account |
| Operator mobile app | Bundus on Apple App Store and Google Play | Same business users on iOS and Android |
| Storefront platform | {business}.usebundus.online and connected custom domains | End Customers who browse or submit forms on a Business’s published site |
| Storefront marketing site | usebundus.online (where applicable) | Visitors learning about Bundus storefronts |
This policy does not govern how independent Businesses use End Customer data after receiving it through Bundus. Each Business is responsible for its own privacy notice and lawful basis for dealing with its customers.
2. Our roles: controller and processor#
| Context | Bundus role | Summary |
|---|---|---|
| Account registration, billing, platform security, product analytics, marketing to you | Controller | We decide how to operate Bundus as a SaaS business |
| Business Data you enter (bookings, clients, invoices, inventory, quotes) | Controller (for platform operation); you are controller for your customer relationships | We host and process your operational data to provide the Services |
| End Customer inquiries and booking requests on your Storefront | Processor (on your behalf) | We collect and relay data to you; you decide how to use it |
Where we act as a processor, processing is governed by these Terms, this Privacy Policy, and your instructions through use of the Services.
3. Personal data we collect#
3.1 Account data
When you create or use a Bundus account, we collect:
- business name;
- your first and last name;
- email address;
- password (stored in hashed form only);
- phone number;
- optional operating country (ISO country code);
- email verification status;
- authentication tokens, session metadata, and last login information;
- team membership, role, and permission settings (where multi-user features are enabled).
3.2 Business profile and settings
You may provide:
- business address and contact details (including business phone);
- timezone, currency, and regional preferences;
- tax registration identifiers and default tax rates;
- bank account details for display on invoices (not used to pull payments from your bank through Bundus unless a specific integrated feature says otherwise);
- business logo and uploaded media;
- invoice preferences, legal footer text, contract templates, and storefront configuration;
- website theme, page content, and publish settings.
3.3 Business Data you enter
Through the Operator App (web or mobile), we process operational data you submit, including:
- Clients and contacts — names, emails, phone numbers, addresses, and notes;
- Inventory — item names, descriptions, categories, quantities, costs, rates, and images;
- Bookings — event names, client details, venues, dates, times, notes, allocations, discounts, and deposit settings;
- Quotes and invoices — line items, amounts, tax, status, PDF content, and payment records;
- Bundles, services, and fee templates — catalog structures and pricing;
- Fulfillment records — checkpoints, photos, and signatures where you use those features;
- Contracts — generated or uploaded contract content linked to bookings;
- Performance and ROI metrics — derived from your operational data.
This data may include personal data about your clients, staff, or other contacts. You are responsible for ensuring you have a lawful basis to enter that data into Bundus.
3.4 Photos and media
If you use camera or photo-library features (including on mobile), we process images and files you choose to upload for inventory, bookings, fulfillment, logos, and storefront content. We store these in our hosting infrastructure. We do not access your device camera or library except when you initiate upload or capture in the app.
3.5 Storefront and End Customer data
When an End Customer interacts with your Storefront, we may collect on your behalf:
Inquiry forms: name, email, optional phone, message content.
Booking request forms (where enabled): name, email, phone, requested dates, selected items and quantities, optional message.
We store these records in your Business tenant and may send notification emails to addresses you configure.
3.6 Subscription and payment data
Bundus offers paid subscriptions through more than one channel. We do not store full payment card numbers.
| Channel | Who processes payment | What Bundus receives |
|---|---|---|
| Web (Stripe) | Stripe | Stripe customer and subscription IDs; plan tier; billing interval; payment status; limited billing contact details |
| iOS (Apple In-App Purchase) | Apple | Subscription status, product identifiers, transaction references, and renewal metadata via RevenueCat — not your Apple ID password or full payment credentials |
| Android (Google Play Billing) | Same categories as iOS — subscription status and transaction metadata via RevenueCat |
RevenueCat links your Bundus business account (using your business identifier) to store receipts so entitlements work across web and mobile. RevenueCat receives purchase events, product IDs, and subscription lifecycle data from Apple and Google.
For mobile subscriptions, payment is charged to your Apple ID or Google Play account. Refunds and payment disputes for those purchases are handled by Apple or Google under their policies.
3.7 Marketing and support communications
When you contact us, we may collect your name, email, business type, message content, and communication preferences where you opt in to marketing.
We send transactional emails (verification, password reset, billing, inquiry notifications) through our email infrastructure.
3.8 Technical, usage, and diagnostic data
We automatically collect certain technical data when you use the Services:
- IP address and approximate location derived from IP;
- browser type, device type, operating system, and app version;
- pages or screens viewed, features used, and timestamps;
- API request logs, error reports, and security audit events;
- device identifiers and push notification tokens (if push is enabled);
- cookies and similar technologies as described in Section 13.
Product analytics: When enabled, we use PostHog to understand how the marketing site and Operator App are used. The marketing site uses privacy-preserving cookieless measurement where configured. The Operator App may associate usage events with your account to improve the product. We configure analytics for B2B use under our contract with you and applicable privacy law.
Crash and error reporting: We may use application logs and, if enabled, third-party crash reporting tools to diagnose failures. These may include device type, app version, and error stack traces.
We do not sell personal data. We do not use your Business Data to train public AI models.
4. How we collect personal data#
- Directly from you — registration, profile settings, content you upload, support enquiries, subscription actions;
- From authorised users — colleagues you invite to your Account;
- From End Customers — forms submitted on your Storefront;
- From third parties — payment and subscription status from Stripe, Apple, Google, and RevenueCat; email delivery reports; fraud-prevention signals;
- Automatically — through logs, cookies, mobile SDKs, and infrastructure monitoring.
5. How we use personal data#
| Purpose | Examples |
|---|---|
| Provide the Services | Account creation, authentication, hosting Business Data, publishing Storefronts, invoices, availability checks, mobile app functionality |
| Process subscriptions | Trial management, billing across web and mobile channels, plan enforcement, read-only mode after expiry |
| Communicate with you | Service emails, security alerts, product updates, support |
| Facilitate End Customer submissions | Receive inquiries and booking requests and notify your Business |
| Secure the Platform | Fraud detection, access controls, tenant isolation, rate limiting |
| Improve the Services | Analytics (when enabled), debugging, aggregated usage trends |
| Comply with law | Tax records, lawful requests, enforcement of our Terms |
| Marketing (where permitted) | Information about Bundus features and pricing |
6. Legal bases (UK GDPR / EU GDPR)#
Where UK or EU GDPR applies:
| Legal basis | Processing activities |
|---|---|
| Contract | Providing the Services; account management; billing |
| Legitimate interests | Securing the Platform; improving features; minimal analytics; B2B marketing to existing users; fraud prevention — balanced against your rights |
| Consent | Optional marketing; non-essential cookies where required |
| Legal obligation | Tax, accounting, regulatory compliance, lawful requests |
For End Customer data we process as a processor, you must establish the appropriate legal basis with your customers.
7. How we share personal data#
7.1 Service providers (subprocessors)
We use trusted providers who process data on our instructions:
| Provider | Purpose | Typical location |
|---|---|---|
| Cloud hosting and databases | Application hosting, PostgreSQL, backups | UK / EU / US (depending on environment) |
| Amazon Web Services (AWS) | Secrets and configuration management | EU / US |
| Cloudflare | CDN, DDoS protection, Workers/Pages for storefronts, R2 object storage | Global edge network |
| Stripe | Web subscription billing | US / EU |
| Apple | In-App Purchase processing (iOS subscriptions) | Global |
| Google Play Billing (Android subscriptions) | Global | |
| RevenueCat | Mobile subscription validation, entitlement sync, billing webhooks | US |
| ZeptoMail (Zoho) | Transactional and notification email | EU |
| PostHog | Product analytics (when enabled) | EU (default host) |
We require subprocessors to protect personal data under contractual terms consistent with applicable law. We may update this list as our infrastructure evolves; material changes will be reflected in this policy.
7.2 Within your Business
Users authorised on your Account can access Business Data according to product permissions. You control who receives access credentials.
7.3 Public Storefront content
Information you publish on your Storefront (business name, contact details, catalogue) is public by design.
7.4 Legal and business transfers
We may disclose data if required by law, court order, or governmental request, or to protect rights, safety, and security. If Bundus is involved in a merger, acquisition, or asset sale, personal data may transfer subject to this Privacy Policy or notice to you.
8. International transfers#
Bundus is based in the United Kingdom. Subprocessors may process data in the UK, EEA, United States, and other countries.
Where personal data is transferred outside the UK or EEA to countries not deemed adequate, we implement appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses, and supplementary measures where required.
Contact us for information about transfer safeguards where we are permitted to provide them.
9. Data retention#
We retain personal data only as long as necessary for the purposes described in this policy:
| Data category | Typical retention |
|---|---|
| Account and profile data | Duration of Account plus up to 30 days for export after closure; longer where required for legal claims or accounting |
| Business Data | Duration of Account plus post-termination export window; backups may persist for a limited period thereafter |
| End Customer inquiry / booking-request records | Stored in your tenant until you delete them or your Account is closed |
| Billing and transaction records | Up to 7 years where required for tax and accounting law |
| Security and access logs | Typically 90 days to 12 months, unless needed for incident investigation |
| Marketing contact records | Until resolved or you unsubscribe, plus a short suppression period |
We may anonymise or aggregate data for analytics and retain anonymised data without time limit.
10. Security#
We implement technical and organisational measures appropriate to the data we process, including:
- encryption in transit (TLS/HTTPS);
- password hashing and secure authentication tokens;
- tenant isolation and row-level security in our database layer;
- access controls limiting employee access to production systems;
- operational backups and monitoring;
- audit trails for critical business records.
No method of transmission or storage is completely secure. You are responsible for choosing a strong password and safeguarding your credentials.
If we become aware of a personal data breach likely to affect your rights, we will notify you and/or regulators as required by applicable law.
11. Your rights#
Depending on your location, you may have the right to:
- Access — request a copy of personal data we hold about you;
- Rectification — correct inaccurate data (many fields can be updated in the Operator App);
- Erasure — request deletion in certain circumstances;
- Restriction — ask us to limit processing in certain cases;
- Portability — receive data in a structured, machine-readable format where applicable;
- Objection — object to processing based on legitimate interests or direct marketing;
- Withdraw consent — where processing is based on consent;
- Complaint — lodge a complaint with a supervisory authority.
UK residents: Information Commissioner’s Office (ICO) — https://ico.org.uk
EEA residents: Your local data protection authority.
Nigeria: Nigeria Data Protection Commission (NDPC), where the Nigeria Data Protection Act 2023 applies.
To exercise your rights, email hello@usebundus.com with Privacy Request in the subject line. We may need to verify your identity. We respond within one month, extendable where permitted by law.
If you are an End Customer of a Bundus Business, contact that Business directly for requests about how they use your data. We will assist the Business where we act as their processor.
12. Account and data deletion#
You may request deletion of your Account and associated personal data.
How to request deletion
- Email hello@usebundus.com with subject line Account deletion request.
- Send the request from the email address registered on your Account, or provide information we need to verify your identity.
- Include your business name and confirm you are authorised to close the Account. Only the business owner should request workspace deletion; team members may request removal of their own user profile separately.
You can also start a deletion request from:
- Web: Operator App → Settings → Security → Request account deletion (opens your email app with a pre-filled message); or
- Mobile: Settings → Security → Request account deletion (opens your email app with the same pre-filled message).
You must tap Send in your email app to submit the request. Your Account remains active until we confirm deletion, so you can export data during the process described below.
What happens next
- Verification — We confirm your identity and Account ownership (typically within 5 business days).
- Active subscriptions — You must cancel paid subscriptions through the channel where you subscribed (Stripe Customer Portal on web, Apple Subscriptions on iOS, or Google Play Subscriptions on Android). We cannot cancel Apple or Google billing on your behalf.
- Export window — Where available, you may export Business Data during a grace period (typically 30 days after we confirm the request, unless a shorter period is required by law or security policy).
- Deletion — After the export window, we delete or anonymise Account data, Business Data, and associated media from active systems, except where retention is required for legal, accounting, fraud-prevention, or dispute-resolution purposes (for example, billing records kept up to 7 years).
- Confirmation — We email you when deletion from active systems is complete.
Storefronts are unpublished when your Account is closed or your Subscription lapses without renewal, subject to any grace period we communicate.
Team members on your Account lose access when the Account is closed. Individual team members may request deletion of their own user profile separately if the Business Account continues.
13. Cookies and similar technologies#
13.1 Operator App (web and authenticated sessions)
The Operator App uses strictly necessary cookies and local storage for authentication, session management, security, and essential preferences.
When analytics is enabled, the Operator App may use PostHog for product analytics tied to your account.
13.2 Marketing website
Our marketing site (usebundus.com) uses strictly necessary cookies and, when enabled, PostHog in cookieless mode for privacy-preserving page-view measurement without marketing analytics cookies.
13.3 Mobile app
The mobile app stores authentication tokens locally (for example, in the device secure storage) and may use analytics SDKs when enabled. Mobile subscriptions use Apple and Google store frameworks; those platforms may collect data under their own policies.
13.4 Storefronts
Published Business Storefronts may set strictly necessary cookies for routing, security, and form submission.
13.5 Managing cookies
You can control cookies through your browser settings. Blocking strictly necessary cookies may prevent you from using the Operator App.
14. Marketing communications#
We may send:
- Transactional messages — account verification, password resets, billing, security alerts (required while you have an Account);
- Product and marketing messages — feature updates and offers (you may opt out via unsubscribe links or by emailing hello@usebundus.com).
We process marketing preferences in line with UK PECR and similar laws.
15. Children’s privacy#
The Services are intended for business use and are not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.
16. Third-party links and platform terms#
Our Services may link to third-party websites or use third-party payment and app-store platforms (Stripe, Apple App Store, Google Play). We are not responsible for their privacy practices. Review their privacy policies before providing personal data.
Use of the mobile app is also subject to the applicable app store’s terms (Apple Media Services Terms or Google Play Terms of Service) for store billing and device-level data collection.
17. Automated decision-making#
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Availability checks and inventory conflict detection are operational rules applied to your data, not profiling of End Customers for credit or employment purposes.
18. Changes to this Privacy Policy#
We may update this Privacy Policy from time to time. We will post the updated version at https://usebundus.com/privacy with a revised “Last updated” date. For material changes, we will provide notice by email or in-product message where appropriate.
Continued use after the effective date constitutes acceptance of the updated policy.
19. Contact#
SolutionInBit Limited (trading as Bundus) Company number: 16545056 Email: hello@usebundus.com (subject: Privacy) Website: https://usebundus.com Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
We are registered with the UK Information Commissioner’s Office (ICO). Our ICO registration reference is available on request at hello@usebundus.com.
You may contact the ICO directly at https://ico.org.uk if you have concerns about how your personal data is handled.
Questions?
If anything here is unclear, we're happy to talk it through. Reach out at hello@usebundus.com.