How we handle your data.
What we collect, why we collect it, and the rights you have over your information on BashBop.
On this page
- 1.Information we collect
- 2.How we use your information
- 3.Legal basis for processing
- 4.AI disclosure
- 5.How we share your information
- 6.Data retention
- 7.Your privacy rights
- 8.Cookies & tracking
- 9.International transfers
- 10.Data security
- 11.Children’s privacy
- 12.Changes to this policy
- 13.Contact
- 14.Event audience lists
Introduction
At BashBop, we are committed to protecting your privacy while providing a comprehensive event management and vendor marketplace platform. This Privacy Policy explains how we collect, use, and protect your information across our various features including event management, vendor bookings, AI-powered analytics, payment processing, and real-time communication services.
1. Information We Collect
a. Account Information
- Authentication Data: JWT tokens, Google OAuth information, and session data
- Profile Information: Name, email, profile picture, preferences, and role-based access control data
- Two-Factor Authentication: QR codes and 2FA setup information for enhanced security
- Social Connections: Information from connected Google accounts
b. Event & Booking Information
- Event Details: Event names, descriptions, locations, schedules, and capacity information
- Guest Data: RSVP responses, attendance records, and guest preferences
- Vendor Bookings: Service requests, vendor applications, job postings, and booking confirmations
- Location Data: Venue information from Google Maps integration and geolocation data (with permission)
- QR Codes: Information stored in QR codes for event access and check-in
c. Vendor Marketplace Data
- Vendor Profile: Business name, service types, availability, hourly/day rates, packages, and location
- Portfolio Content: Gallery images, video embeds, and descriptions uploaded to showcase services
- Enquiries & Leads: Messages from organisers, event details, response times, and conversion metrics
- Quotes: Pricing proposals, line items, terms, validity dates, and acceptance/rejection status
- Vendor Bookings: Confirmed jobs, event dates, special requests, and completion status
- Earnings Data: Revenue, platform commissions, payout history, and Stripe Connect account details
- Reviews & Ratings: Customer reviews, star ratings, and review responses
- Subscription Data: Subscription tier, billing cycle, and feature entitlements
d. Virtual Event & Communication Data
- Stream Video Data: Video and audio content from Stream.io virtual events
- Real-time Communication: WebSocket messages, chat data, and presence information
- Email Communications: Nodemailer-sent notifications and marketing communications
- SMS Messages: Twilio-sent SMS notifications and verification codes
- Push Notifications: Real-time notifications and alerts
e. AI Analytics & Forecasting Data
- Vendor Analytics: Performance metrics, completion rates, ratings, and response times
- Revenue Forecasting: Historical booking data, seasonal patterns, and predictive analytics
- Market Insights: Demand trends, pricing analysis, and competitive benchmarking
- AI Usage Tracking: OpenAI API usage, token consumption, and cost analytics
- Business Recommendations: AI-generated insights and optimization suggestions
f. Payment and Financial Information
- Stripe Express Dashboard: If you connect your Stripe account, we facilitate secure access to your Stripe Express Dashboard for managing payouts. BashBop does not store your Stripe login credentials or sensitive payment data; all payment processing is handled directly by Stripe.
- Fee Calculations: Service fees, payment processing fees, and currency conversion data
- Transaction Records: Payment history, booking confirmations, and financial audit trails
- Currency Data: XE.com API currency conversion rates and multi-currency support
g. Technical Information
- Device Data: Browser type, operating system, device information, and IP addresses
- Usage Analytics: Platform usage patterns, performance metrics, and feature utilization
- Session Data: Redis-cached session information and authentication tokens
- File Storage: AWS S3 stored images, documents, and user-generated content
- Database Records: PostgreSQL stored user data, events, bookings, and platform interactions
2. How We Use Your Information
Virtual Events
Stream.io SDK integration for seamless virtual experiences and real-time communication
Event Management
Comprehensive event creation, guest management, and RSVP handling
Vendor Marketplace
Job posting system, vendor applications, and service booking management
Access Control
QR code scanning for event access, check-in, and security verification
Location Services
Google Maps integration for venue information and location-based services
AI Analytics
OpenAI-powered revenue forecasting, market insights, and business recommendations
Payment Processing
Stripe integration for secure payments, fee calculations, and payout management
Communication
Email notifications, SMS alerts, and real-time WebSocket messaging
3. Legal Basis for Processing
We process your personal information based on the following legal grounds:
- Contract Performance: To provide our event management and vendor marketplace services
- Legitimate Interest: To improve our services, prevent fraud, ensure platform security, and provide AI-powered analytics
- Consent: For marketing communications, AI analytics, and certain optional features (withdrawable at any time)
- Legal Obligation: To comply with financial regulations, audit requirements, and applicable laws
4. Artificial Intelligence (AI) Disclosure
AI-Powered Features
BashBop uses artificial intelligence technologies provided by OpenAI to enhance your experience. We are committed to transparency about how AI is used on our platform.
How We Use AI:
- Smart Vendor Recommendations: AI analyzes your event requirements to suggest the best-matched vendors
- Revenue Forecasting: Vendors receive AI-powered predictions based on historical booking patterns
- Market Insights: AI generates business intelligence reports including demand trends and pricing analysis
- Content Generation: AI assists with quote descriptions, event summaries, and communication templates
- Search Enhancement: Natural language processing improves search relevance and discovery
Data Processed by AI:
- Event details (type, date, location, guest count, budget)
- Vendor profiles (services, pricing, availability, performance metrics)
- Booking history and patterns (anonymized and aggregated)
- User preferences and search queries
Third-Party AI Provider:
We use OpenAI's API services (GPT models) to power our AI features. Data sent to OpenAI:
- Is processed in accordance with OpenAI's Privacy Policy and Terms of Use
- Is not used by OpenAI to train their models (we use their API with data usage opt-out)
- Is transmitted securely using encryption
- May be temporarily stored by OpenAI for up to 30 days for abuse monitoring
Data Processing Agreement (DPA)
BashBop Ltd has executed a Data Processing Agreement (DPA) with OpenAI in accordance with GDPR Article 28 requirements. This agreement ensures that OpenAI processes your personal data only on our documented instructions, maintains appropriate security measures, assists with data subject rights requests, and complies with all applicable data protection laws including UK GDPR and EU GDPR. OpenAI acts as a Data Processor on our behalf when processing your data through their API services.
Your Rights Regarding AI Processing:
- Opt-Out: You can disable AI-powered features in your account settings
- Human Review: You can request human review of any AI-generated recommendation or decision
- Data Access: You can request a copy of data used in AI processing
- Explanation: You can request an explanation of how AI recommendations were generated
Important: AI-generated content and recommendations are provided for informational purposes only. Final decisions regarding bookings, pricing, and vendor selection remain with you.
6. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations and financial regulations
- Resolve disputes and enforce our agreements
- Maintain audit trails for compliance purposes
Specific retention periods:
- Account Information: Until account deletion, then up to 30 days for backup systems
- Event Data: 7 years for events with financial transactions, 3 years for free events
- Payment Data: As required by financial regulations (typically 7 years)
- AI Analytics Data: 3 years for analytics and forecasting purposes
- Vendor Booking Data: 5 years for business analytics and dispute resolution
- Marketing Data: Until you unsubscribe or 3 years of inactivity
- Audit Logs: 7 years for compliance and security monitoring
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
Universal Rights
- Access: Request copies of your personal information
- Rectification: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data to another service
GDPR Rights (UK/EU)
- Restriction: Request limitation of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Automated Decision-Making: Opt-out of automated profiling and AI analytics
CCPA Rights (California)
- Know: Right to know what personal information is collected
- Opt-Out: Right to opt-out of sale of personal information
- Non-Discrimination: Right not to be discriminated against for exercising privacy rights
To exercise these rights, contact us at [email protected] or through your account settings.
9. International Data Transfers
Your personal information may be transferred and processed in countries other than your own. We ensure appropriate safeguards are in place:
- Adequacy Decisions: Transfers to countries deemed adequate by relevant authorities
- Standard Contractual Clauses: EU-approved contracts for international transfers
- Binding Corporate Rules: Internal rules for multinational companies
- Certification Schemes: Privacy frameworks like Privacy Shield successors
Our third-party service providers (Stripe, Stream.io, Google, OpenAI, etc.) maintain their own data protection standards and certifications.
10. Data Security
We implement comprehensive security measures to protect your personal information and continually update our practices to meet evolving security challenges:
Technical Safeguards
- End-to-end encryption for data in transit (TLS 1.3)
- AES-256 encryption for data at rest in PostgreSQL and Redis
- JWT-based multi-factor authentication for account access
- Enhanced CSRF protection with dual-validation strategy
- Regular security audits and penetration testing
- Real-time threat monitoring and intrusion detection
- Automated vulnerability scanning and patching
- Helmet security headers and request compression
Organizational Safeguards
- Role-based access control and principle of least privilege
- Regular mandatory employee training on data protection
- Comprehensive incident response and breach notification procedures
- Quarterly compliance assessments and security reviews
- Vendor security assessment program for third-party services
- Dedicated security team monitoring for emerging threats
- Audit logging for all financial transactions and sensitive operations
Industry Standards
- SOC 2 Type II compliance
- ISO 27001 information security management
- PCI DSS for payment processing through Stripe
- GDPR, CCPA, and NDPR compliance
- Financial audit trail requirements
11. Children's Privacy
Our platform is not intended for children under 13 years of age (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
For events that may include minors, event organisers are responsible for obtaining appropriate parental consent and ensuring compliance with applicable child protection laws.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Post the updated policy on our website
- Update the "Last Updated" date
- Notify you via email for material changes
- Provide notice through our platform
Your continued use of our platform after changes take effect constitutes acceptance of the updated policy.
13. Contact Information
For questions about this Privacy Policy or to exercise your privacy rights, contact us at:
Privacy Officer: [email protected]
General Support: [email protected]
Postal Address: BashBop Ltd, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
Phone: +44 20 3807 6969
Data Protection Authorities
You have the right to lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ico.org.uk)
- EU: Your national data protection authority
- US: State Attorney General or FTC
- Australia: Office of the Australian Information Commissioner (oaic.gov.au)
- Nigeria: Nigeria Data Protection Commission
14. Event Audience Lists
Organisers can upload a list of email contacts to an event (the "Audience List") and send those contacts a branded invite via BashBop.
Controller / processor roles
For data in an Audience List, the organiser is the data controller and BashBop is the data processor. Organisers warrant that they have a lawful basis (consent or legitimate interest) to contact each email on the list.
What we collect
- Email address (required)
- Full name and phone number (optional, if provided by the organiser)
- Delivery state (queued, sent, failed, unsubscribed) and timestamps
Lawful basis
We process contact data on behalf of the organiser on the basis of the contract we have with them (Article 6(1)(b) UK GDPR). Each invite email includes the sender's identity and a one-click unsubscribe link in line with PECR and CAN-SPAM.
Unsubscribe
Every invite email includes a one-click unsubscribe link scoped to the specific event. Clicking it removes the contact from all future sends for that event immediately and is honoured across re-imports. Unsubscribes are retained indefinitely to prevent accidental re-contact.
Retention
Audience List data is retained for the lifetime of the event (so organisers can review sends and unsubscribes) and deleted on organiser request or when the event is permanently deleted. Unsubscribe records are kept beyond event deletion to honour the recipient's choice if the organiser re-uploads the same email to a future event.
Recipient rights
Recipients can request access, correction, or deletion of their data by emailing [email protected]. We will route the request to the relevant organiser (the controller) and confirm completion within the statutory timeframe.
15. Effective Date
This Privacy Policy is effective as of April 19, 2026.
Last updated: April 19, 2026
Your data, your control
Access, update, or delete your personal information any time from your account settings, or contact us to exercise your rights.
Your GDPR Rights
Under the General Data Protection Regulation (GDPR), you have specific rights regarding your personal data. We are committed to ensuring you can exercise these rights easily and transparently.
Right to Access
You have the right to request access to all personal data we hold about you. This includes:
- What data we collect
- Why we collect it
- How we use it
- Who we share it with
- How long we keep it
How to exercise: Use the Data Access Request feature in your settings. We will respond within 30 days.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON). You can also request that we transfer this data to another service provider where technically feasible.
How to exercise: Use the Export Your Data feature in your settings to download your complete data package.
Right to Rectification
You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.
How to exercise: Update your information directly in your account settings or contact us at [email protected]
Right to Erasure (”Right to be Forgotten”)
You have the right to request deletion of your personal data in certain circumstances. Note that we may need to retain some information for legal or legitimate business purposes.
Deletion timeline: We provide a 30-day grace period after you request account deletion, during which you can cancel the request. After this period, your data will be permanently deleted.
How to exercise: Use the Delete Account feature in your settings.
Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
How to exercise: Contact us at [email protected]
Right to Object
You have the right to object to processing of your personal data for direct marketing purposes (including profiling) and processing based on legitimate interests.
How to exercise: Manage your email preferences in your account settings or click "unsubscribe" in any marketing email.
Response Times & Contact
- •Standard requests: We will respond to all GDPR requests within 30 days
- •Complex requests: May require up to 60 days (we will notify you if an extension is needed)
- •Data Protection Officer: For GDPR-related inquiries, email [email protected]
- •Complaints: You have the right to lodge a complaint with your local supervisory authority
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: For marketing communications and optional features
- Contract: To provide our event management services
- Legal Obligation: To comply with tax, accounting, and legal requirements
- Legitimate Interest: To improve our services, prevent fraud, and ensure platform security
We're Here to Help
If you have any questions about our privacy practices or would like to exercise your rights regarding your data, our team is ready to assist you.
Contact Our Privacy Team