Privacy Policy
Last updated 17 August 2026
This policy explains what Bazaang does with data. It covers two different relationships, and the difference matters legally:
- Your data. When you sign up, we are the data controller — we decide what is collected and why.
- Data you put into Bazaang. Your groups, campaigns and results are yours. We are a processor, acting on your instructions.
Bazaang is operated by 123 Konsulent (NIF ESY6488390N), Calle Pintor Sobejano 70B, 30710 Los Alcázares, Spain. Contact us at contact@bazaang.com.
What we collect about you
| What | Why | Legal basis |
|---|---|---|
| Email address | Signing in, and sending you posting reminders | Performance of a contract |
| Business name and website | Labelling your account and building your tracked links | Performance of a contract |
| Billing details | Taking payment and issuing invoices | Contract, and legal obligation for tax records |
| Server logs | Keeping the service working and secure | Legitimate interest |
We do not use tracking cookies, advertising pixels or analytics that follow you around. There is no cookie banner because there is nothing to consent to beyond the cookie that keeps you signed in.
Card details
We never see or store your card. Payments are handled by Stripe, who are PCI-DSS certified. We store only Stripe’s customer reference and your current plan.
Data you put into Bazaang
Your group names and links, campaigns, pictures, captions and results are stored so the service can function. We do not sell it, mine it, use it to train anything, or share it with other customers.
When staff can see it
By default, nobody at Bazaang can read your content at all — the restriction is enforced by the system, not by policy. What we can always see is your plan, how much of it you are using, your subscription status and counts such as how many groups and posts you have. That is what billing and fault-finding need, and it is our legitimate interest as the operator.
To see your actual groups, campaigns, captions or pictures we need your permission. You give it in Settings, for 24 hours or 3 days, and you can end it at any moment. It expires by itself. Nothing about the request pressures you: if you would rather describe the problem than show it, that is a perfectly good answer.
Every time we open your account it is recorded — what was looked at and when — and that record appears in your own settings, not just in ours. If we ever look without a valid permission, the system refuses; there is no override.
How click tracking works
This is the part people ask about, so it is worth being precise. When someone clicks one of your Bazaang links, we increase a counter against that promo in that group and forward them to your website. That is all.
We do not set a cookie on them, and we do not store their IP address, device fingerprint, location or any identifier. The count is a number, not a list of people.
To keep those numbers honest we filter out automated crawlers, ignore repeat clicks from the same visitor within a minute, and cap how many clicks a single link can register per minute. The repeat check works on a salted hash held in memory for sixty seconds and written nowhere; the salt is discarded when the process ends, so it cannot be matched back to anyone or correlated over time.
Because nothing about the visitor is retained, a click cannot be traced back to an individual — which is why no consent banner is needed on your side either.
Who else processes data
| Processor | Purpose | Where |
|---|---|---|
| Supabase | Database, sign-in, picture storage | EU (Frankfurt) |
| Vercel | Hosting the application | EU and US |
| Stripe | Payments and invoicing | EU and US |
| Resend | Sign-in links and reminder emails | EU and US |
Where a processor operates outside the EEA, transfers are covered by the European Commission’s Standard Contractual Clauses.
How long we keep it
- Your account and its contents — while your account exists, and deleted when you delete it.
- Invoices and payment records — retained as Spanish tax law requires, currently four years. This is a legal obligation and survives account deletion.
- Server logs — a short rolling period, typically 30 days.
Deleting your account
Settings → Delete account removes everything: your businesses, groups, campaigns, uploaded pictures and click history. Any subscription is cancelled at the same time. It is immediate and cannot be undone, and we cannot recover it for you afterwards. Invoices are retained for tax as described above.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, have it erased, restrict or object to processing, or receive it in a portable format. Email contact@bazaang.com and we will respond within one month.
If you believe we have handled your data badly, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos.
Security
Data is encrypted in transit and at rest. Access is restricted per account at the database level, so one customer’s data cannot be read by another. If a breach occurs that puts your rights at risk, we will tell you and the supervisory authority within 72 hours.
Children
Bazaang is for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy materially we will email you before it takes effect. The date at the top always reflects the current version.
123 Konsulent
NIF ESY6488390N
Calle Pintor Sobejano 70B
30710 Los Alcázares
Spain
contact@bazaang.com