Privacy Policy
Bumpr ApS, CVR no. 46460960, Denmark
Effective date: 23 July 2026
1. Who we are
Bumpr ApS (CVR no. 46460960, Denmark) is the data controller for personal data processed through the Bumpr website and app (the “Platform”). Contact: teis@thingmark.dk. This policy explains what data we collect, why, who we share it with, and your rights under the EU General Data Protection Regulation (GDPR).
2. The data we collect
- Account data: name, email address, phone number, password (stored hashed), and profile settings.
- Booking data: villa, dates, number of guests, price paid, booking history, and communications about your stay (including bump notifications).
- Payment data: payments are processed by our payment provider. We receive confirmation of payment and the last digits of your card; we do not store full card numbers.
- Technical data: device type, app version, IP address, and log data generated when you use the Platform.
- Usage data: how you interact with the Platform, collected through analytics tools (see section 8).
3. Why we process it (legal bases)
- To provide the service — creating your account, processing bookings and payments, sending booking confirmations and bump notifications (contract, GDPR art. 6(1)(b)).
- To meet legal obligations — bookkeeping, accounting and tax rules (legal obligation, art. 6(1)(c)).
- To run and improve the Platform — security, debugging, analytics and product improvement (legitimate interests, art. 6(1)(f)).
- To send marketing — only with your consent, which you can withdraw at any time (consent, art. 6(1)(a)).
4. Who we share data with
We share personal data only where needed to run the service:
- Villa owners and managers: the owner of the villa you book receives your name, party size and stay dates so they can host you.
- Payment processing: Airwallex processes payments and refunds.
- Hosting and infrastructure: Supabase (database and backend), Vercel (web hosting) and GitHub (code and deployment infrastructure).
- Communications: email and push notification providers that deliver booking confirmations, bump notices and other service messages.
- Analytics: product and web analytics providers (see section 8).
- Authorities: where required by law, e.g. tax or law enforcement requests.
These providers act as data processors on our behalf under data processing agreements, except where they are independent controllers (e.g. villa owners, payment networks, authorities). We do not sell personal data.
5. International transfers
Villa owners are located in Indonesia, so booking details necessary for your stay are transferred there in order to perform your contract (GDPR art. 49(1)(b)). Some of our service providers process data in the United States or other countries outside the EEA; where they do, transfers are protected by the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
6. How long we keep data
- Account data: for as long as your account is active, and up to 12 months after deletion for fraud prevention and dispute handling.
- Booking and payment records: 5 years after the end of the financial year, as required by the Danish Bookkeeping Act.
- Technical logs: up to 12 months.
- Marketing consents and related data: until you withdraw consent.
7. Your rights
Under the GDPR you have the right to access, rectify and erase your data; to restrict or object to processing; to data portability; and to withdraw consent at any time (without affecting processing before withdrawal). To exercise any right, email teis@thingmark.dk. We respond within one month. You can also complain to the Danish Data Protection Agency (Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk) or your local supervisory authority.
8. Cookies and analytics
The website uses cookies and similar technologies. Strictly necessary cookies are used to make the site work. Analytics and marketing cookies are only set with your consent, which you can give or withdraw through the cookie banner. The app uses analytics tools to understand how the product is used; where consent is required, we ask for it in the app.
9. Security
We protect personal data with technical and organisational measures including encryption in transit, access controls, and row-level security on our database. No system is perfectly secure; if a breach affects your rights, we will notify you and the supervisory authority as required by law.
10. Children
The Platform is not directed at children. You must be 18 or older to create an account, and we do not knowingly collect data from anyone under 18.
11. Changes to this policy
We may update this policy as the service evolves. Material changes will be notified through the Platform or by email. The current version is always available on our website.
12. Contact
Bumpr ApS · CVR 46460960 · Denmark · teis@thingmark.dk