Privacy Policy

How we handle your data.

What we collect, why we collect it, and the rights you have over your information on BashBop.

Last updated: 19 April 2026[email protected]

Introduction

At BashBop, we are committed to protecting your privacy while providing a comprehensive event management and vendor marketplace platform. This Privacy Policy explains how we collect, use, and protect your information across our various features including event management, vendor bookings, AI-powered analytics, payment processing, and real-time communication services.

1. Information We Collect

a. Account Information

  • Authentication Data: JWT tokens, Google OAuth information, and session data
  • Profile Information: Name, email, profile picture, preferences, and role-based access control data
  • Two-Factor Authentication: QR codes and 2FA setup information for enhanced security
  • Social Connections: Information from connected Google accounts

b. Event & Booking Information

  • Event Details: Event names, descriptions, locations, schedules, and capacity information
  • Guest Data: RSVP responses, attendance records, and guest preferences
  • Vendor Bookings: Service requests, vendor applications, job postings, and booking confirmations
  • Location Data: Venue information from Google Maps integration and geolocation data (with permission)
  • QR Codes: Information stored in QR codes for event access and check-in

c. Vendor Marketplace Data

  • Vendor Profile: Business name, service types, availability, hourly/day rates, packages, and location
  • Portfolio Content: Gallery images, video embeds, and descriptions uploaded to showcase services
  • Enquiries & Leads: Messages from organisers, event details, response times, and conversion metrics
  • Quotes: Pricing proposals, line items, terms, validity dates, and acceptance/rejection status
  • Vendor Bookings: Confirmed jobs, event dates, special requests, and completion status
  • Earnings Data: Revenue, platform commissions, payout history, and Stripe Connect account details
  • Reviews & Ratings: Customer reviews, star ratings, and review responses
  • Subscription Data: Subscription tier, billing cycle, and feature entitlements

d. Virtual Event & Communication Data

  • Stream Video Data: Video and audio content from Stream.io virtual events
  • Real-time Communication: WebSocket messages, chat data, and presence information
  • Email Communications: Nodemailer-sent notifications and marketing communications
  • SMS Messages: Twilio-sent SMS notifications and verification codes
  • Push Notifications: Real-time notifications and alerts

e. AI Analytics & Forecasting Data

  • Vendor Analytics: Performance metrics, completion rates, ratings, and response times
  • Revenue Forecasting: Historical booking data, seasonal patterns, and predictive analytics
  • Market Insights: Demand trends, pricing analysis, and competitive benchmarking
  • AI Usage Tracking: OpenAI API usage, token consumption, and cost analytics
  • Business Recommendations: AI-generated insights and optimization suggestions

f. Payment and Financial Information

  • Stripe Express Dashboard: If you connect your Stripe account, we facilitate secure access to your Stripe Express Dashboard for managing payouts. BashBop does not store your Stripe login credentials or sensitive payment data; all payment processing is handled directly by Stripe.
  • Fee Calculations: Service fees, payment processing fees, and currency conversion data
  • Transaction Records: Payment history, booking confirmations, and financial audit trails
  • Currency Data: XE.com API currency conversion rates and multi-currency support

g. Technical Information

  • Device Data: Browser type, operating system, device information, and IP addresses
  • Usage Analytics: Platform usage patterns, performance metrics, and feature utilization
  • Session Data: Redis-cached session information and authentication tokens
  • File Storage: AWS S3 stored images, documents, and user-generated content
  • Database Records: PostgreSQL stored user data, events, bookings, and platform interactions

2. How We Use Your Information

Virtual Events

Stream.io SDK integration for seamless virtual experiences and real-time communication

Event Management

Comprehensive event creation, guest management, and RSVP handling

Vendor Marketplace

Job posting system, vendor applications, and service booking management

Access Control

QR code scanning for event access, check-in, and security verification

Location Services

Google Maps integration for venue information and location-based services

AI Analytics

OpenAI-powered revenue forecasting, market insights, and business recommendations

Payment Processing

Stripe integration for secure payments, fee calculations, and payout management

Communication

Email notifications, SMS alerts, and real-time WebSocket messaging

4. Artificial Intelligence (AI) Disclosure

AI-Powered Features

BashBop uses artificial intelligence technologies provided by OpenAI to enhance your experience. We are committed to transparency about how AI is used on our platform.

How We Use AI:

  • Smart Vendor Recommendations: AI analyzes your event requirements to suggest the best-matched vendors
  • Revenue Forecasting: Vendors receive AI-powered predictions based on historical booking patterns
  • Market Insights: AI generates business intelligence reports including demand trends and pricing analysis
  • Content Generation: AI assists with quote descriptions, event summaries, and communication templates
  • Search Enhancement: Natural language processing improves search relevance and discovery

Data Processed by AI:

  • Event details (type, date, location, guest count, budget)
  • Vendor profiles (services, pricing, availability, performance metrics)
  • Booking history and patterns (anonymized and aggregated)
  • User preferences and search queries

Third-Party AI Provider:

We use OpenAI's API services (GPT models) to power our AI features. Data sent to OpenAI:

  • Is processed in accordance with OpenAI's Privacy Policy and Terms of Use
  • Is not used by OpenAI to train their models (we use their API with data usage opt-out)
  • Is transmitted securely using encryption
  • May be temporarily stored by OpenAI for up to 30 days for abuse monitoring

Data Processing Agreement (DPA)

BashBop Ltd has executed a Data Processing Agreement (DPA) with OpenAI in accordance with GDPR Article 28 requirements. This agreement ensures that OpenAI processes your personal data only on our documented instructions, maintains appropriate security measures, assists with data subject rights requests, and complies with all applicable data protection laws including UK GDPR and EU GDPR. OpenAI acts as a Data Processor on our behalf when processing your data through their API services.

Your Rights Regarding AI Processing:

  • Opt-Out: You can disable AI-powered features in your account settings
  • Human Review: You can request human review of any AI-generated recommendation or decision
  • Data Access: You can request a copy of data used in AI processing
  • Explanation: You can request an explanation of how AI recommendations were generated

Important: AI-generated content and recommendations are provided for informational purposes only. Final decisions regarding bookings, pricing, and vendor selection remain with you.

5. How We Share Your Information

We may share your information with:

  • Event Organisers & Vendors: When you register for events or book services, relevant information is shared with organisers and vendors
  • Service Providers: Third-party vendors who help us operate our platform:
    • Stripe for payment processing and Express Dashboard access
    • Stream.io for virtual events and real-time communication
    • Google for maps, OAuth authentication, and location services
    • OpenAI for AI analytics and business recommendations
    • Twilio for SMS notifications and communication
    • AWS S3 for secure file storage and image processing
    • XE.com for currency conversion services
  • Legal Authorities: When required by law or to protect our rights and safety
  • Business Transfers: In connection with mergers, acquisitions, or sale of assets (with notice to you)

We never sell your personal information to third parties for marketing purposes.

6. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations and financial regulations
  • Resolve disputes and enforce our agreements
  • Maintain audit trails for compliance purposes

Specific retention periods:

  • Account Information: Until account deletion, then up to 30 days for backup systems
  • Event Data: 7 years for events with financial transactions, 3 years for free events
  • Payment Data: As required by financial regulations (typically 7 years)
  • AI Analytics Data: 3 years for analytics and forecasting purposes
  • Vendor Booking Data: 5 years for business analytics and dispute resolution
  • Marketing Data: Until you unsubscribe or 3 years of inactivity
  • Audit Logs: 7 years for compliance and security monitoring

7. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

Universal Rights

  • Access: Request copies of your personal information
  • Rectification: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service

GDPR Rights (UK/EU)

  • Restriction: Request limitation of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Automated Decision-Making: Opt-out of automated profiling and AI analytics

CCPA Rights (California)

  • Know: Right to know what personal information is collected
  • Opt-Out: Right to opt-out of sale of personal information
  • Non-Discrimination: Right not to be discriminated against for exercising privacy rights

To exercise these rights, contact us at [email protected] or through your account settings.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

Essential Cookies

  • JWT authentication and session management
  • CSRF protection and security validation
  • Load balancing and performance optimization
  • Redis session caching for improved performance

Functional Cookies

  • Remember your preferences and settings
  • Language and timezone settings
  • Accessibility features and user interface preferences
  • Two-factor authentication settings

Analytics Cookies

  • Understand how you use our platform
  • Improve our services and user experience
  • Measure the effectiveness of our features
  • Track AI usage and cost analytics

You can control cookies through your browser settings, though some features may not work properly if essential cookies are disabled.

9. International Data Transfers

Your personal information may be transferred and processed in countries other than your own. We ensure appropriate safeguards are in place:

  • Adequacy Decisions: Transfers to countries deemed adequate by relevant authorities
  • Standard Contractual Clauses: EU-approved contracts for international transfers
  • Binding Corporate Rules: Internal rules for multinational companies
  • Certification Schemes: Privacy frameworks like Privacy Shield successors

Our third-party service providers (Stripe, Stream.io, Google, OpenAI, etc.) maintain their own data protection standards and certifications.

10. Data Security

We implement comprehensive security measures to protect your personal information and continually update our practices to meet evolving security challenges:

Technical Safeguards

  • End-to-end encryption for data in transit (TLS 1.3)
  • AES-256 encryption for data at rest in PostgreSQL and Redis
  • JWT-based multi-factor authentication for account access
  • Enhanced CSRF protection with dual-validation strategy
  • Regular security audits and penetration testing
  • Real-time threat monitoring and intrusion detection
  • Automated vulnerability scanning and patching
  • Helmet security headers and request compression

Organizational Safeguards

  • Role-based access control and principle of least privilege
  • Regular mandatory employee training on data protection
  • Comprehensive incident response and breach notification procedures
  • Quarterly compliance assessments and security reviews
  • Vendor security assessment program for third-party services
  • Dedicated security team monitoring for emerging threats
  • Audit logging for all financial transactions and sensitive operations

Industry Standards

  • SOC 2 Type II compliance
  • ISO 27001 information security management
  • PCI DSS for payment processing through Stripe
  • GDPR, CCPA, and NDPR compliance
  • Financial audit trail requirements

11. Children's Privacy

Our platform is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

For events that may include minors, event organisers are responsible for obtaining appropriate parental consent and ensuring compliance with applicable child protection laws.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will:

  • Post the updated policy on our website
  • Update the "Last Updated" date
  • Notify you via email for material changes
  • Provide notice through our platform

Your continued use of our platform after changes take effect constitutes acceptance of the updated policy.

13. Contact Information

For questions about this Privacy Policy or to exercise your privacy rights, contact us at:

Privacy Officer: [email protected]

General Support: [email protected]

Postal Address: BashBop Ltd, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom

Phone: +44 20 3807 6969

Data Protection Authorities

You have the right to lodge a complaint with your local data protection authority:

  • UK: Information Commissioner's Office (ico.org.uk)
  • EU: Your national data protection authority
  • US: State Attorney General or FTC
  • Australia: Office of the Australian Information Commissioner (oaic.gov.au)
  • Nigeria: Nigeria Data Protection Commission

14. Event Audience Lists

Organisers can upload a list of email contacts to an event (the "Audience List") and send those contacts a branded invite via BashBop.

Controller / processor roles

For data in an Audience List, the organiser is the data controller and BashBop is the data processor. Organisers warrant that they have a lawful basis (consent or legitimate interest) to contact each email on the list.

What we collect

  • Email address (required)
  • Full name and phone number (optional, if provided by the organiser)
  • Delivery state (queued, sent, failed, unsubscribed) and timestamps

Lawful basis

We process contact data on behalf of the organiser on the basis of the contract we have with them (Article 6(1)(b) UK GDPR). Each invite email includes the sender's identity and a one-click unsubscribe link in line with PECR and CAN-SPAM.

Unsubscribe

Every invite email includes a one-click unsubscribe link scoped to the specific event. Clicking it removes the contact from all future sends for that event immediately and is honoured across re-imports. Unsubscribes are retained indefinitely to prevent accidental re-contact.

Retention

Audience List data is retained for the lifetime of the event (so organisers can review sends and unsubscribes) and deleted on organiser request or when the event is permanently deleted. Unsubscribe records are kept beyond event deletion to honour the recipient's choice if the organiser re-uploads the same email to a future event.

Recipient rights

Recipients can request access, correction, or deletion of their data by emailing [email protected]. We will route the request to the relevant organiser (the controller) and confirm completion within the statutory timeframe.

15. Effective Date

This Privacy Policy is effective as of April 19, 2026.

Last updated: April 19, 2026

Your data, your control

Access, update, or delete your personal information any time from your account settings, or contact us to exercise your rights.

Your GDPR Rights

Under the General Data Protection Regulation (GDPR), you have specific rights regarding your personal data. We are committed to ensuring you can exercise these rights easily and transparently.

Right to Access

You have the right to request access to all personal data we hold about you. This includes:

  • What data we collect
  • Why we collect it
  • How we use it
  • Who we share it with
  • How long we keep it

How to exercise: Use the Data Access Request feature in your settings. We will respond within 30 days.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON). You can also request that we transfer this data to another service provider where technically feasible.

How to exercise: Use the Export Your Data feature in your settings to download your complete data package.

Right to Rectification

You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.

How to exercise: Update your information directly in your account settings or contact us at [email protected]

Right to Erasure (”Right to be Forgotten”)

You have the right to request deletion of your personal data in certain circumstances. Note that we may need to retain some information for legal or legitimate business purposes.

Deletion timeline: We provide a 30-day grace period after you request account deletion, during which you can cancel the request. After this period, your data will be permanently deleted.

How to exercise: Use the Delete Account feature in your settings.

Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

How to exercise: Contact us at [email protected]

Right to Object

You have the right to object to processing of your personal data for direct marketing purposes (including profiling) and processing based on legitimate interests.

How to exercise: Manage your email preferences in your account settings or click "unsubscribe" in any marketing email.

Response Times & Contact

  • Standard requests: We will respond to all GDPR requests within 30 days
  • Complex requests: May require up to 60 days (we will notify you if an extension is needed)
  • Data Protection Officer: For GDPR-related inquiries, email [email protected]
  • Complaints: You have the right to lodge a complaint with your local supervisory authority

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: For marketing communications and optional features
  • Contract: To provide our event management services
  • Legal Obligation: To comply with tax, accounting, and legal requirements
  • Legitimate Interest: To improve our services, prevent fraud, and ensure platform security
Questions about privacy?

We're Here to Help

If you have any questions about our privacy practices or would like to exercise your rights regarding your data, our team is ready to assist you.

Contact Our Privacy Team
Loading footer...
Privacy Policy | BashBop