B
Bonzino
FeaturesHow it worksPricing
Sign in Start free trial
← Back

Privacy Policy

Last updated: July 2026

1. Introduction

Bonzino ("we", "our", "us") is operated by Baseplate Technologies Ltd (company number 17333932, registered in England and Wales), registered office at 66 Paul Street, London, EC2A 4NA, United Kingdom. We operate the bonzino.com website and the Bonzino affiliate marketing platform at app.bonzino.com.

This Privacy Policy explains how we collect, use, share, and protect personal data when you use our services as a merchant or affiliate. It also describes our role as a data processor on behalf of merchants who install our tracking script on their own websites.

Our supervisory authority is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. ICO registration number: [ICO_REGISTRATION_NUMBER — to be completed by operator].

2. Lawful basis for processing

The table below summarises each processing activity, the personal data involved, and the lawful basis under UK GDPR Art. 6.

Processing activityData categoriesLawful basis
Account creation and managementName, email address, business name, website URLContract (Art. 6(1)(b))
Commission calculation and payoutsClick records, transaction amounts, payout detailsContract (Art. 6(1)(b))
Fraud preventionIP address hash, click patterns, device signalsLegitimate interests (Art. 6(1)(f))
Transactional email (receipts, notifications)Email addressContract (Art. 6(1)(b))
Platform analytics (PostHog) User ID, tenant ID, page interactions (memory-only, no persistent cookie) Legitimate interests (Art. 6(1)(f))
Legal compliance and dispute resolutionAccount records, transaction logsLegal obligation (Art. 6(1)(c))

3. Our role as a data processor

When a merchant installs the Bonzino tracking script (track.js) on their website, Bonzino acts as a data processor on that merchant's behalf. The merchant is the data controller for their own website visitors.

In this role, we process the following categories of personal data belonging to the merchant's website visitors:

  • A randomly generated click identifier (UUID), stored in a first-party cookie on the merchant's domain
  • IP address (hashed, used for fraud prevention and de-duplication only — the raw IP is not stored)
  • Email address, where provided by Stripe via webhook when a sale completes (used solely for attribution and payout calculation)

Merchants are responsible for disclosing this processing to their website visitors and for obtaining any consent required under applicable law (including PECR in the UK). The contractual basis for this processor relationship is set out in Section 6 of our Terms of Service.

4. Cookies

We use cookies in two distinct contexts.

4.1 Affiliate attribution cookies (merchant websites)

Merchants who install track.js on their websites set a first-party attribution cookie on their own domain. This cookie is not set by Bonzino on bonzino.com — it is set on the merchant's own domain by the merchant's own embedded script.

  • Cookie name:_us_<publishable_key>_id, where <publishable_key> is the merchant's unique Bonzino key (e.g. _us_pk_abc123…_id). The key scopes the cookie to that merchant so that multiple merchants' programmes on the same device never interfere with each other.
  • Purpose: stores a randomly generated click UUID to attribute an affiliate referral to a later purchase by the same visitor.
  • TTL: up to 90 days (the exact duration is configurable by the merchant; the default is 60 days).
  • Domain: the merchant's own website domain — not bonzino.com.
  • Contents: a randomly generated UUID only. No name, email, IP address, or browsing history is stored in the cookie itself.

4.2 Authentication and session cookies (app.bonzino.com)

When you use the Bonzino dashboard or affiliate portal at app.bonzino.com, we set cookies that are strictly necessary for authentication and to maintain your session. These cookies are set by Supabase (our authentication provider) and by Bonzino's own session logic.

  • Supabase auth cookies: store your encrypted session token. Strictly necessary to keep you logged in.
  • active_tenant_id: remembers which merchant account is active when you have access to multiple programmes. httpOnly, 30-day expiry.

4.3 Attribution cookie on app.bonzino.com

track.js is also installed on app.bonzino.com so that Bonzino's own affiliate programme operates through the same standard code path as any merchant. Visiting app.bonzino.com/auth/signup, app.bonzino.com/login, or app.bonzino.com/programme-ended via an affiliate referral link will set a cookie named _us_<platform_key>_id on app.bonzino.com. This cookie has a 90-day TTL and is used solely to attribute a Bonzino subscription sale to the affiliate who referred the merchant. A notice is displayed on these pages.

This cookie is set under our legitimate interests in operating our own affiliate programme.

5. Sub-processors

We share personal data with the following sub-processors in order to deliver the Bonzino platform. Each operates under its own DPA or privacy policy linked below.

Sub-processorPurposeData location
StripePayment processing, webhook eventsUSA (SCCs in place)
ResendTransactional email deliveryUSA (SCCs in place)
SupabaseDatabase hosting, authenticationEU (eu-west-2)
VercelApplication hosting and edge networkGlobal CDN; processing in USA (SCCs in place)
PostHogProduct analytics (memory-only, no persistent cookie)EU (EU Cloud)
Sentry Error monitoring (PII-scrubbed — no request bodies, cookies, or auth headers are sent) USA (SCCs in place)

6. Data retention

We retain different categories of data for different periods:

  • Active account data — retained for as long as your account is active.
  • Post-closure retention — when a merchant or affiliate account is closed, data is retained for 90 days to allow recovery or dispute resolution, then scheduled for deletion.
  • Hard purge — automated hard-deletion of data following the retention period is planned for Phase 5 of our roadmap (issue #417). Until that tooling is live, deletion requests are handled manually within 30 days of a request to privacy@bonzino.com.
  • Attribution click data — click records are retained for as long as the associated merchant account is active, to support commission auditing and dispute resolution.
  • Transaction records — retained indefinitely as financial records subject to legal obligation.

7. Your rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access (Subject Access Request)
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Rights related to automated decision-making and profiling

To exercise any of these rights, send a request to privacy@bonzino.com. We will respond within 30 days as required by UK GDPR Art. 12. Automated erasure tooling is planned for Phase 5; until then, requests are fulfilled manually.

You also have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint.

8. Governing law

This Privacy Policy is governed by the laws of England and Wales. Our supervisory authority is the Information Commissioner's Office (ICO), United Kingdom.

9. Contact

For privacy-related enquiries, contact us at privacy@bonzino.com.

B
Bonzino

Turn your customers into your best sales channel.

Product

  • Features
  • How it works
  • Pricing

Legal

  • Privacy Policy
  • Terms of Service

Get started

  • Start free trial
  • Sign in

© 2026 Bonzino. A product of Baseplate Technologies Ltd.