← Bingoo Connect

Privacy Policy

Last updated: July 11, 2026

1. Introduction

Bingoo Connect ("we," "our," or "us") operates the Bingoo Connect platform at bingooconnect.com, including our website, mobile applications, NFC-enabled digital business card services, appointment booking, lead management, document wallet, and shop.

This Privacy Policy explains how we collect, use, share, and protect your personal information. By using Bingoo Connect, you agree to the practices described here.

This is a product/compliance draft, not legal advice. A lawyer should review it before final adoption.

2. Information We Collect

2.1 Account & Profile Data

  • Full name, email address, and password (hashed — never stored in plain text)
  • Phone number and WhatsApp number
  • Profile photo and cover photo
  • Job title, company name, and bio
  • Website URL, social media links (Instagram, Facebook, TikTok, LinkedIn, YouTube)
  • Physical or business location (if you choose to display it)
  • Payment links (Zelle, Cash App, Wave, Orange Money, custom)
  • Language and theme preferences (light/dark mode)

2.2 Public Profile Data

  • Any information you choose to display on your public profile page
  • This includes your name, photo, job title, contact details, social links, services, portfolio items, business hours, and appointment booking options
  • Public profile data is visible to anyone who visits your profile link or taps your NFC device
  • You control what appears — you can hide specific fields at any time

2.3 NFC Device Data

  • Device codes linked to your account
  • Device type (card, metal card, keychain, bracelet, stand, badge, sticker, tag)
  • Activation status (available, assigned, active, lost, disabled, replaced)
  • Assignment date and linked profile
  • Device designs and custom configurations

2.4 QR Scan & Analytics Data

  • Profile views, link clicks, and button interactions (WhatsApp, phone, email, social, payment)
  • QR code scans and NFC tap events
  • Visitor device type and approximate country/region (based on IP, not GPS)
  • Timestamps of all interactions
  • No personally identifying information about visitors is collected unless they submit a form

2.5 Leads, Appointments & Booking Data

  • Lead form submissions: name, phone, email, preferred contact method, message
  • Appointment bookings: visitor name, email, phone, date, time slot, service requested, notes
  • Appointment status (pending, confirmed, completed, cancelled, no-show)
  • Lead status, follow-up dates, CRM timeline entries, and relationship type
  • This data is visible only to you (the profile owner) and authorized admins

2.6 Shop & Order Data

  • Shop orders: product purchased, quantity, price, shipping address
  • Order status and tracking information
  • Transaction metadata (Stripe receipt ID — not card numbers)
  • Cart contents (stored in your browser until checkout)

2.7 Stripe Billing Data

  • Subscription plan and billing status (active, trial, past due, canceled)
  • Stripe customer ID and subscription ID
  • Payment history and billing period dates
  • All payment processing is handled securely by Stripe. We do not store raw card numbers, CVVs, or full bank account numbers

2.8 Document Wallet Data

  • Documents you upload to your private Document Wallet (files, file names, file types, file sizes)
  • Document categories (see 2.9 for the full list)
  • Front and back side images for ID-type documents
  • Expiration dates and personal notes you add
  • Visibility setting: private by default, or shared if you explicitly enable it
  • Documents are PRIVATE BY DEFAULT. Only you (the owner) and authorized admins can access private documents

2.9 Sensitive Document Types

Specific document types you may store in the Document Wallet include:

  • Government ID cards (front and back)
  • Passports
  • Social Security cards
  • Work authorization documents
  • Visas
  • Professional certifications and licenses
  • Business documents and contracts
  • Tax documents
  • Insurance cards
  • Medical records
  • Education records and diplomas
  • Pet records and vaccination cards
  • Asset proof documents (receipts, ownership records)
  • Resumes and photos

These documents are private by default. They are never shown on your public profile. They are only accessible to you and authorized admins. Shared document links are intentional, revocable, and can be set to expire.

2.10 Asset Recovery & Lost Mode Data

  • When you mark an NFC device as "Lost," we store that status and your recovery preferences
  • When a finder scans a lost device, we collect: their name, phone, email, self-reported location, message, and scan timestamp
  • GPS coordinates may be collected if the finder grants browser permission
  • Your preferred safe contact method is shown to the finder (phone, email, WhatsApp, or none)
  • This data is visible only to you (the device owner) in your dashboard
  • For asset items (pets, luggage, keys, equipment, vehicles), we store asset type, name, photo, and recovery instructions

2.11 Admin Access & Audit Logs

  • Admin is an internal role, not a subscription plan — admins are authorized Bingoo Connect staff
  • Admins can access certain data for support and platform management
  • All admin actions are logged in our audit system: action type, who performed it, target entity, old value, new value, and timestamp
  • Admin access to private documents is logged
  • Admins cannot view raw payment data (Stripe handles that)

2.12 Push Notification Data

  • Browser push notification subscription tokens (VAPID keys)
  • Device label, browser type, and platform/OS
  • Notification preferences and opt-in/opt-out status

2.13 Cookies, Analytics & Device/Browser Data

  • Session cookies to maintain your login
  • Local storage for preferences (language, dark mode, cart contents)
  • Visitor device type and browser (for analytics, not personally identifying)
  • We do not use third-party advertising cookies
  • We do not sell analytics data

3. Public vs Private Visibility Rules

  • Your public profile shows only what you choose to display: name, photo, contact info, social links, services, portfolio, business hours, and booking options
  • Private documents in your Document Wallet are NEVER shown on your public profile
  • Sensitive fields (like SSN, full ID numbers) are hidden by default in any shared view
  • Leads, appointments, and CRM data are visible only to you (the profile owner) and admins
  • Analytics data is visible only to you and admins
  • You control what is public vs private through your profile settings and privacy controls
  • Visitors to your public profile cannot see your document wallet, leads, appointments, or analytics

4. Controlled Sharing (Links, QR, Barcode Document Cards)

  • You can create shared document cards with controlled access
  • Shared links are intentional — you must explicitly enable sharing for each document
  • Shared links are revocable — you can disable sharing at any time
  • Shared links can be set to expire automatically
  • Shared document cards show only the information you choose to include
  • Visitors accessing a shared link do not see your other private documents
  • Shared links do not require a login, but they are unique URLs that are not publicly listed or indexed by search engines (unless you opt in)

5. How We Use Your Information

  • To provide and operate the Bingoo Connect platform
  • To display your public profile to visitors
  • To process subscription and shop payments via Stripe
  • To send notifications about new leads, appointments, and finder reports
  • To enable Lost Mode recovery
  • To provide analytics on your profile performance
  • To improve our platform and develop new features
  • To communicate service updates and security notices
  • To comply with legal obligations

6. How We Share Information

We do not sell your personal data. We may share data with:

  • Stripe — for payment processing and subscription management
  • Base44 — our infrastructure and hosting provider
  • Push notification services — to deliver notifications you opt into
  • Law enforcement — if required by applicable law or to protect safety

Your public profile is visible to anyone with your link or NFC device. Private documents are never shared without your explicit action.

7. Data Retention

  • We retain your data for as long as your account is active
  • If you delete your account: profile and personal data is deleted within 30 days
  • Stripe billing records are retained as required by financial regulations
  • Anonymized/aggregated analytics may be retained indefinitely
  • Admin audit logs are retained for security and compliance purposes
  • Shared document links remain active until you revoke them or they expire

8. Data Deletion

You can request deletion of your personal data at any time. Visit our Data Deletion page to submit a request. We will verify your identity before processing. Deletion is irreversible. Some data may be retained for legal, security, or billing reasons (see section 7).

9. Data Export

You can request a copy of your data in a structured format. Visit our Data Deletion page and select "Data Export" as the request type. We will send your data to the email on file within 14 days.

10. Data Correction

You can update your profile information directly in your dashboard at any time. For data you cannot edit yourself, submit a correction request through our Data Deletion page and select "Data Correction."

12. Security Practices

  • HTTPS encryption for all data transmission
  • Secure API authentication with row-level security on our database
  • Documents stored in private storage with signed URLs for temporary access
  • Passwords are hashed, never stored in plain text
  • Payment data is handled entirely by Stripe (PCI-compliant)
  • Admin access is role-restricted and logged in the audit system
  • No system is 100% secure; we continuously improve our security practices

13. API Access & Future Integrations

  • We may introduce API access for Enterprise/Bulk plans in the future
  • API keys would be scoped, rate-limited, and revocable
  • API users would be subject to these same privacy rules
  • We will update this policy before launching any API or new integration that affects your data

14. International Users

Bingoo Connect is available globally. If you are outside the United States, your data may be processed in the US. By using our service, you consent to this transfer. We comply with applicable data protection laws, including GDPR where it applies.

15. Children's Privacy

Bingoo Connect is not directed to children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us immediately.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice in the app. The "Last updated" date at the top of this page reflects the most recent revision.

17. Contact Us

For privacy questions or data requests:

© 2026 Bingoo Connect. All rights reserved.