Privacy Policy
Last updated on
Your privacy matters to us. This Privacy Policy explains how Blooms ("we", "us", "our") collects, uses, stores, and shares your personal information when you use our website (blooms.my), products, and services (the "Services").
Key commitments:
- We do not sell your personal data.
- We do not use your data to train AI models.
- You can request deletion of your data at any time.
- Our primary infrastructure is hosted in the EU (Germany).
1. Scope and User Roles
This policy applies to:
- Creators — users who register an account and build pages on Blooms.
- Visitors — people who view a Creator's published page or public profile.
- Businesses — organizations using Blooms on behalf of their teams.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (required for login and communication)
- Name (first name, last name — optional)
- Profile picture (optional)
- OAuth data — if you sign in with Google, we receive your Google account ID, email, and profile picture.
2.2 Profile and Content Data
When you use the Services, you may provide:
- Public profile data — display name, username, bio, location, social links, profile type (Creator/Business/Personal)
- Business information — business category, work type, starting price (if applicable)
- Links — titles, URLs, descriptions, style settings, tracking identifiers
- Websites and pages — page content, layout, design settings, SEO metadata
- Media files — images and assets you upload
- Bookmarks — saved URLs and collections
2.3 AI Assistant Data (Bloomie)
When you use Bloomie, our AI assistant, we collect and process:
- Conversations — your messages and AI responses are stored in our database
- Tool usage — inputs and outputs of tools invoked during conversations (e.g., content generation, web search, Instagram data retrieval)
- Creator memory — your preferred name, niche, tone of voice, goals, platforms, and content preferences (used to personalize AI responses)
- Conversation summaries — AI-generated summaries, topics, and key decisions
- Message embeddings — used for contextual retrieval to improve AI responses
- Credit usage — monthly AI credit balance, quota, and usage history
We may use anonymized and aggregated conversation data to produce usage statistics, improve our AI features, and train or fine-tune AI models. Any data used for these purposes is stripped of personally identifiable information. You can delete your conversations at any time from your dashboard.
2.4 Instagram and Social Integration Data
If you connect your Instagram account, we access and store:
- Account information — Instagram user ID, username, profile data
- Conversations — direct message threads and message content
- Media — posts, images, videos, captions, like and comment counts
- Comments — comment text, commenter usernames
- Analytics — follower counts, reach, engagement metrics (cached and refreshed periodically)
- OAuth credentials — access and refresh tokens (encrypted)
You can disconnect your Instagram account at any time, which stops further data syncing.
2.5 Payment Information
We use Stripe to process payments. We store:
- Stripe Customer ID — links your Blooms account to your Stripe record
- Subscription details — plan name, status, billing period dates, trial dates
- Plan tier — Free, Starter, Pro, or Agency
We do not store your credit card number, CVV, or full payment details. This data is handled entirely by Stripe in compliance with PCI DSS.
2.6 Automatically Collected Data
When you visit blooms.my or any page built on Blooms, we automatically collect:
- Visitor hash — a privacy-preserving anonymous identifier. We do not store raw IP addresses in our analytics system.
- Device information — browser type, operating system, device type
- Geolocation — country, region, and city (derived from Cloudflare headers, not GPS)
- Page activity — pages viewed, referrer URLs, session duration, bounce status
- UTM parameters — campaign source, medium, and name (if present in URL)
2.7 Session and Authentication Data
- Session token — stored as an HTTP-only cookie (7-day expiry)
- IP address and user agent — recorded per session for security purposes
- Email verification tokens — temporary, single-use tokens that expire after use
2.8 Moderation Data
If content is reported or flagged:
- Report details — content type, reason, flagged text
- Reporter identity — user ID of the person who submitted the report
- Review records — admin reviewer ID, review notes, decision
2.9 Admin Audit Data
For platform integrity, we log administrative actions:
- Event type — e.g., user bans, credit adjustments, impersonation
- Actor and target — which admin performed the action and on whom
- IP address and geolocation — of the admin at the time of action
- Auto-expiry — audit logs are automatically deleted after 30 days
3. How We Use Your Information
We use your information for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing and operating the Services | Performance of contract |
| Processing payments and managing subscriptions | Performance of contract |
| AI assistant (Bloomie) conversations and personalization | Performance of contract |
| AI improvement — anonymized analytics and model training | Legitimate interest |
| Sending transactional emails (verification, billing, security) | Performance of contract |
| Analytics and service improvement | Legitimate interest |
| Fraud prevention and security monitoring | Legitimate interest |
| Content moderation and policy enforcement | Legitimate interest |
| Marketing emails and product updates | Consent |
4. How We Share Your Information
We do not sell your personal data. We share data only with the following categories of service providers ("sub-processors") who process data on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Infrastructure provider | Hosting and analytics | Germany (EU) |
| Cloudflare, Inc. | CDN, DNS, DDoS Protection, Media Storage | Global |
| Database provider | Application database | USA |
| Stripe, Inc. | Payment Processing | Global |
| Google LLC | AI Assistant (Bloomie), Analytics | USA |
| Microsoft Corporation | Behavior Analytics | USA |
| Email service provider | Transactional Email | USA |
| Meta Platforms, Inc. | Instagram Integration (only if you connect your account) | USA |
We may also disclose your information if required by law, court order, or to protect the rights, safety, or property of Blooms or others.
5. International Data Transfers
Our primary infrastructure is hosted in Germany (EU), which means your core data resides within the European Economic Area.
For sub-processors located in the United States, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
- EU-US Data Privacy Framework where applicable (Stripe, Google, Microsoft)
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Websites and pages | Until you delete them or your account |
| Media files | Until you delete them or your account |
| AI conversations | Until you delete them or your account |
| Analytics data | 13 months |
| Admin audit logs | 30 days (auto-deleted) |
| Email verification tokens | Until used or expired |
| Session data | 7 days per session |
| Instagram cached data | Refreshed periodically, deleted on disconnect |
When you delete your account, all associated data (websites, links, conversations, media, sessions) is permanently deleted via cascading deletion. This process is irreversible.
7. Your Rights
For all users:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate personal data
- Erasure — request deletion of your personal data
- Restriction — request that we limit processing of your data
- Portability — request your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You can delete your account at any time from Settings in your dashboard. This permanently removes all your data.
For EU/EEA residents (GDPR):
You have the right to lodge a complaint with your local data protection authority. For French residents, this is the CNIL.
For California residents (CCPA):
You have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell your data)
- Non-discrimination for exercising your rights
8. Cookies and Tracking Technologies
We use cookies and similar technologies. For full details, see our Cookie Policy.
Summary of cookies used:
- Strictly necessary — authentication session cookies, Cloudflare security cookies
- Analytics — product analytics, traffic analytics, behavior analytics
- Functionality — editor auto-save (localStorage), display preferences
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit — TLS 1.2+ for all connections
- Encryption at rest — sensitive credentials are encrypted
- Hashed analytics — visitor identifiers are anonymized (raw IPs are not stored in analytics)
- Access control — role-based access for administrative functions
- Session security — HTTP-only cookies, IP and user agent tracking per session
- Audit logging — all administrative actions are logged (30-day retention)
10. Data Breach Notification
In the event of a personal data breach, we will:
- Notify affected users without undue delay (and within 72 hours where required by GDPR)
- Notify the relevant supervisory authority where required
- Provide details of the breach and steps taken to mitigate it
11. Children's Privacy
Our Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are in the EU, you must be at least 16 to use the Services without parental consent.
If we learn that we have collected data from a child under the applicable age, we will delete it promptly. If you believe a child has provided us with personal data, contact us at [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification.
Your continued use of the Services after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Email: [email protected]
For GDPR-related inquiries, you may also contact your local data protection authority.
Related Policies
Learn about our privacy practices, refund policy, and cancellation terms.