PRIVACY POLICY

Last updated September 20, 2026

This privacy policy for Bump, Inc. ("Bump," "we," "us," or "our") explains what personal data we collect, why, how long we keep it, who we share it with, and the rights you have over it when you use the Bump mobile application, our websites, and related services (together, the "Services").

Bump is a peer-to-peer network: people who have an internet connection share it with people nearby who do not, and are rewarded for doing so. Running that network means we handle some data that most apps do not — records of who connected through whom, and identifiers that stop the same person collecting a sign-up bonus twice. This policy is written to be specific about those.

Questions or concerns? Our data protection officer is reachable at privacy@bumpapp.xyz (see section 15). If you do not agree with our practices, please do not use the Services.

SUMMARY OF KEY POINTS

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW THE BUMP NETWORK HANDLES YOUR TRAFFIC
  3. HOW DO WE PROCESS YOUR INFORMATION?
  4. WHAT LEGAL BASES DO WE RELY ON?
  5. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  6. INTERNATIONAL TRANSFERS
  7. HOW LONG DO WE KEEP YOUR INFORMATION?
  8. WHAT WE KEEP AFTER YOU DELETE YOUR ACCOUNT
  9. HOW DO WE KEEP YOUR INFORMATION SAFE?
  10. WHAT ARE YOUR PRIVACY RIGHTS?
  11. CHILDREN
  12. CONTROLS FOR DO-NOT-TRACK FEATURES
  13. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
  14. DO WE MAKE UPDATES TO THIS POLICY?
  15. HOW CAN YOU CONTACT US? (DATA PROTECTION OFFICER)
  16. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

1. WHAT INFORMATION DO WE COLLECT?

Information you give us

Sensitive information. We process approximate location data as described below. We do not collect health, biometric, racial, religious, political or other special-category data.

Information collected automatically

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes.

2. HOW THE BUMP NETWORK HANDLES YOUR TRAFFIC

In Short: Traffic you send through another user's connection is encrypted on your phone and exits from a Bump server. The sharer cannot read it, and we do not log where it goes.

When you connect to a hotspot shared by another Bump user (over Wi-Fi Direct or Bluetooth), the app opens an encrypted VPN tunnel from your phone to a VPN server operated by Bump. The sharer's phone only relays that encrypted tunnel; it cannot see the content or destinations of your traffic, and your traffic does not appear to come from the sharer's IP address — it exits to the internet from our server. Likewise, when you share your connection, the traffic of the people using it passes through your phone encrypted, and is never sent to the internet from your own address.

On our VPN servers we keep the connection records described in section 1 (which device, which server, when, how much data, exit IP) for 12 months, because Brazilian law requires providers of internet connection to keep connection records for at least one year and to be able to answer a court order with them. We do not keep records of the applications, websites or services you access through the tunnel. Under Marco Civil Art. 16 we would only ever do so with your prior, separate consent, and we have no plans to ask for it.

Every access to those records by our staff is itself logged (who looked, at whose records, and why), and records are disclosed only in response to a valid legal order or as required by law.

3. HOW DO WE PROCESS YOUR INFORMATION?

4. WHAT LEGAL BASES DO WE RELY ON?

If you are in Brazil, this section applies to you (Lei Geral de Proteção de Dados Pessoais, Lei 13.709/2018, "LGPD").

If you are in Colombia, this section applies to you (Ley 1581 de 2012, Decreto 1377 de 2013). This policy is our política de tratamiento de datos personales, and the notice shown in the app at sign-up is our aviso de privacidad. Bump, Inc. is the responsable del tratamiento. We process your data on the basis of your prior, express and informed authorisation, recorded when you accept this policy in the app, and — for access and connection records, accounting, and the retention of hashed anti-fraud identifiers — on the exceptions in Art. 10 of Ley 1581 (legal duty, and data required for the contract). Purposes are those in section 3. The consent record includes the date, the version of this policy you accepted, and the language it was shown in.

If you are in the EU or UK, we rely on the equivalent GDPR bases: contract (Art. 6(1)(b)), legal obligation (6(1)(c)), legitimate interests (6(1)(f)) and consent (6(1)(a)). Bump is not currently offered in the EU or UK.

5. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: With the service providers below, who process data on our instructions; with other users only to the extent the network requires; and with authorities when the law requires it. We do not sell personal data.

Provider What they do for us Data involved
Google (Firebase, Google Cloud, Play Integrity, Crashlytics, Analytics)Sign-in, database, servers, VPN hosting, app integrity, crash reports, website analyticsEverything we store; see section 6 for location
StripeCard payments for creditsAmount, email, payment card (held by Stripe only)
YativoPIX payments and payouts (Brazil), PSE payments and Bre-B payouts (Colombia)Name, CPF / Cédula, PIX key or bank details, amount
ReloadlyMobile-data reward top-upsPhone number, carrier, bundle
TwilioChecks whether a phone number is a real mobile linePhone number
ShakeIn-app bug reportingWhat you attach to a report, device details, user ID
DatadogServer logs and performance monitoringLogs that may include user ID and IP address

Other users. Your username, avatar and leaderboard statistics are visible to other signed-in users. When you share or use a connection, the other side's device learns your device's Bump ID for the duration of the session; usernames are shown to each other. Your phone number, email, tax ID and payout details are never shown to other users.

Legal requests and business transfers. We disclose data when a court order or applicable law requires it, and may transfer it as part of a merger, acquisition or sale of assets, in which case this policy continues to apply.

6. INTERNATIONAL TRANSFERS

Bump, Inc. is a United States company and our systems run on Google Cloud in the United States. Your data is therefore transferred out of Brazil or Colombia to the United States when you use the Services.

7. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: For as long as your account exists, unless a shorter or longer period is listed here. The periods below are the ones our systems enforce.

Data Retention Why
Account profile, username, avatar, country, balancesLife of the account; anonymised on deletion (section 8)Contract
Phone number and device identifier (raw)Life of the account; deleted with itContract, fraud prevention
Identity of a deleted account (email, name, Google account ID, deletion date), sealedFor 12 months after deletion, then purged automaticallyAnswering court orders against connection records (Marco Civil Art. 13; section 8)
Sign-in access records (time, IP, device)12 months, then deleted automaticallyMarco Civil Art. 15 (minimum 6 months)
VPN connection records (device, server, exit IP, window)12 months, then deleted automaticallyMarco Civil Art. 13 (minimum 12 months)
Log of staff access to the records aboveIndefiniteDecreto 8.771/2016 Art. 13 audit duty
Session totals (bytes, peer, duration), credits and reward-point ledger, payoutsIndefiniteAccounting, payout audit, tax
Live session state (who is connected right now)Deleted at disconnectOperation
Hotspot and demand locations (per user), per-second session location samplesLife of the account; deleted with itCoverage rewards, history
Aggregated coverage map (no user identifiers)24 hours per cellOperation
Chat messages in transit (encrypted) and delivery receipts7 daysDelivery to offline devices
Chat device registrations after you sign out90 daysAbuse tracing
Reward points and bonus credits (the balances themselves)Expire 90 days after being earned or granted; purchased credits do not expireProgramme rules (see Terms)
Bug reports, feedback, abuse reportsLife of the accountSupport, safety
Consent record (policy version, date, language, IP)Life of the accountProof of consent (LGPD Art. 8 §2, Ley 1581 Art. 9)
Database backups7 daysDisaster recovery
Hashed anti-fraud identifiersIndefinite, including after deletionSection 8

8. WHAT WE KEEP AFTER YOU DELETE YOUR ACCOUNT

You can delete your account at any time from Settings. Deletion removes your Google sign-in from Bump, deletes your phone number and raw device identifier, deletes the per-second location samples from your sessions, and anonymises your profile: your email, name and Google account identifier are removed and your username is replaced with a placeholder, so nothing in the app identifies you any more. The following are kept:

Everything else about you is deleted. If you ask us to erase your data (section 10), our reply will list exactly which of the items above we are keeping and why.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

Data is encrypted in transit and at rest on Google Cloud. Phone numbers, device identifiers, tax IDs and payout details are stored in restricted locations that other users can never read, and that our own systems access only through server-side code. Access to connection records by staff is logged. Chat messages are end-to-end encrypted with keys that never leave your device. Anti-fraud identifiers are stored only as one-way hashes. No system is perfectly secure; if we discover a breach that is likely to cause you harm we will notify the ANPD or the SIC and you within the periods required by law.

10. WHAT ARE YOUR PRIVACY RIGHTS?

Wherever you are, you can ask us to confirm whether we process your data, to access it, correct it, receive a copy in a portable format, delete it, or object to processing based on our legitimate interests, and you can withdraw consent at any time. Send requests to privacy@bumpapp.xyz from the email address on your account, or through the in-app feedback reporter while signed in so we can verify it is you.

Brazil (LGPD)

Under Art. 18 you have the right to: confirmation that we process your data; access; correction of incomplete, inaccurate or outdated data; anonymisation, blocking or deletion of unnecessary or excessive data or data processed in breach of the LGPD; portability to another provider; deletion of data processed on the basis of consent; information about the public and private entities we share data with; information about the possibility of refusing consent and its consequences; and revocation of consent. We answer in simplified form immediately where we can, and with a complete declaration within 15 days (Art. 19). You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

Colombia (Ley 1581)

Under Art. 8 you have the right to know, update and rectify your data; to request proof of the authorisation you gave; to be informed how your data has been used; to file complaints with the Superintendencia de Industria y Comercio (SIC); to revoke your authorisation and request deletion where no legal or contractual duty requires us to keep the data; and to access your data free of charge. Consultas (requests to know what we hold) are answered within 10 business days of receipt, extendable once by 5 business days with notice. Reclamos (correction, deletion, complaints about a breach of this policy) are answered within 15 business days of a complete claim, extendable once by 8 business days with notice; if a claim is incomplete we will ask you to complete it within 5 business days, and it lapses after 2 months without reply. Requests go to privacy@bumpapp.xyz; you may also contact the SIC at sic.gov.co.

Withdrawing consent

You can withdraw consent for location by revoking the permission in Android settings, and for everything else by deleting your account or writing to us. Withdrawal does not affect processing that already happened, nor processing we carry out on another basis (sections 4 and 8).

Account information

You can change your username, avatar and phone number in the app, download a copy of your data by asking us, and delete your account from Settings. Deletion is described in section 8.

11. CHILDREN

The Services are for people aged 18 and over. We do not knowingly collect data from anyone under 18; if you believe we have, write to privacy@bumpapp.xyz and we will delete it.

12. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") setting. No uniform standard for honouring DNT signals has been adopted, so we do not currently respond to them. If a standard we must follow is adopted, we will describe it in a revised version of this policy.

13. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

Bump is not offered in California, but if you are a California resident the California Consumer Privacy Act gives you the right to know what personal information we collect (section 1), to request its deletion, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioural advertising, and have not done so in the preceding twelve months. To exercise these rights email privacy@bumpapp.xyz; we will verify your identity against the account before acting. California Civil Code §1798.83 also lets you request, once a year, the categories of personal information we disclosed to third parties for their direct marketing: none.

14. DO WE MAKE UPDATES TO THIS POLICY?

Yes. The "Last updated" date at the top changes with every revision. When the changes are material, the app will ask you to review and accept the new version the next time you sign in, and we keep a record of which version you accepted. Continued use after a non-material change means you accept it.

15. HOW CAN YOU CONTACT US? (DATA PROTECTION OFFICER)

Our data protection officer — the encarregado pelo tratamento de dados pessoais under LGPD Art. 41 and the contact for the responsable del tratamiento under Ley 1581 — is Jason Ernst, reachable at privacy@bumpapp.xyz. Access, portability, correction, deletion and objection requests sent to that address are acknowledged and answered within the periods in section 10.

Bump, Inc.
500 Boylston St.
Suite 900
Boston, MA 02116
United States

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

Change your username, avatar or phone number in the app. Delete your account from Settings. For anything else — a copy of your data, a correction we cannot make in-app, or a question about what we keep — email privacy@bumpapp.xyz or use the request form here.

This policy is available in Portuguese and Spanish. Where the law of your country requires the policy to be provided in your language, that version governs for you.