Privacy Policy

Last updated on

Your privacy matters to us. This Privacy Policy explains how Blooms ("we", "us", "our") collects, uses, stores, and shares your personal information when you use our website (blooms.my), products, and services (the "Services").

Key commitments:

  • We do not sell your personal data.
  • We do not use your data to train AI models.
  • You can request deletion of your data at any time.
  • Our primary infrastructure is hosted in the EU (Germany).

1. Scope and User Roles

This policy applies to:

  • Creators — users who register an account and build pages on Blooms.
  • Visitors — people who view a Creator's published page or public profile.
  • Businesses — organizations using Blooms on behalf of their teams.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address (required for login and communication)
  • Name (first name, last name — optional)
  • Profile picture (optional)
  • OAuth data — if you sign in with Google, we receive your Google account ID, email, and profile picture.

2.2 Profile and Content Data

When you use the Services, you may provide:

  • Public profile data — display name, username, bio, location, social links, profile type (Creator/Business/Personal)
  • Business information — business category, work type, starting price (if applicable)
  • Links — titles, URLs, descriptions, style settings, tracking identifiers
  • Websites and pages — page content, layout, design settings, SEO metadata
  • Media files — images and assets you upload
  • Bookmarks — saved URLs and collections

2.3 AI Assistant Data (Bloomie)

When you use Bloomie, our AI assistant, we collect and process:

  • Conversations — your messages and AI responses are stored in our database
  • Tool usage — inputs and outputs of tools invoked during conversations (e.g., content generation, web search, Instagram data retrieval)
  • Creator memory — your preferred name, niche, tone of voice, goals, platforms, and content preferences (used to personalize AI responses)
  • Conversation summaries — AI-generated summaries, topics, and key decisions
  • Message embeddings — used for contextual retrieval to improve AI responses
  • Credit usage — monthly AI credit balance, quota, and usage history

We may use anonymized and aggregated conversation data to produce usage statistics, improve our AI features, and train or fine-tune AI models. Any data used for these purposes is stripped of personally identifiable information. You can delete your conversations at any time from your dashboard.

2.4 Instagram and Social Integration Data

If you connect your Instagram account, we access and store:

  • Account information — Instagram user ID, username, profile data
  • Conversations — direct message threads and message content
  • Media — posts, images, videos, captions, like and comment counts
  • Comments — comment text, commenter usernames
  • Analytics — follower counts, reach, engagement metrics (cached and refreshed periodically)
  • OAuth credentials — access and refresh tokens (encrypted)

You can disconnect your Instagram account at any time, which stops further data syncing.

2.5 Payment Information

We use Stripe to process payments. We store:

  • Stripe Customer ID — links your Blooms account to your Stripe record
  • Subscription details — plan name, status, billing period dates, trial dates
  • Plan tier — Free, Starter, Pro, or Agency

We do not store your credit card number, CVV, or full payment details. This data is handled entirely by Stripe in compliance with PCI DSS.

2.6 Automatically Collected Data

When you visit blooms.my or any page built on Blooms, we automatically collect:

  • Visitor hash — a privacy-preserving anonymous identifier. We do not store raw IP addresses in our analytics system.
  • Device information — browser type, operating system, device type
  • Geolocation — country, region, and city (derived from Cloudflare headers, not GPS)
  • Page activity — pages viewed, referrer URLs, session duration, bounce status
  • UTM parameters — campaign source, medium, and name (if present in URL)

2.7 Session and Authentication Data

  • Session token — stored as an HTTP-only cookie (7-day expiry)
  • IP address and user agent — recorded per session for security purposes
  • Email verification tokens — temporary, single-use tokens that expire after use

2.8 Moderation Data

If content is reported or flagged:

  • Report details — content type, reason, flagged text
  • Reporter identity — user ID of the person who submitted the report
  • Review records — admin reviewer ID, review notes, decision

2.9 Admin Audit Data

For platform integrity, we log administrative actions:

  • Event type — e.g., user bans, credit adjustments, impersonation
  • Actor and target — which admin performed the action and on whom
  • IP address and geolocation — of the admin at the time of action
  • Auto-expiry — audit logs are automatically deleted after 30 days

3. How We Use Your Information

We use your information for the following purposes:

PurposeLegal Basis (GDPR)
Providing and operating the ServicesPerformance of contract
Processing payments and managing subscriptionsPerformance of contract
AI assistant (Bloomie) conversations and personalizationPerformance of contract
AI improvement — anonymized analytics and model trainingLegitimate interest
Sending transactional emails (verification, billing, security)Performance of contract
Analytics and service improvementLegitimate interest
Fraud prevention and security monitoringLegitimate interest
Content moderation and policy enforcementLegitimate interest
Marketing emails and product updatesConsent

4. How We Share Your Information

We do not sell your personal data. We share data only with the following categories of service providers ("sub-processors") who process data on our behalf:

ProviderPurposeLocation
Infrastructure providerHosting and analyticsGermany (EU)
Cloudflare, Inc.CDN, DNS, DDoS Protection, Media StorageGlobal
Database providerApplication databaseUSA
Stripe, Inc.Payment ProcessingGlobal
Google LLCAI Assistant (Bloomie), AnalyticsUSA
Microsoft CorporationBehavior AnalyticsUSA
Email service providerTransactional EmailUSA
Meta Platforms, Inc.Instagram Integration (only if you connect your account)USA

We may also disclose your information if required by law, court order, or to protect the rights, safety, or property of Blooms or others.

5. International Data Transfers

Our primary infrastructure is hosted in Germany (EU), which means your core data resides within the European Economic Area.

For sub-processors located in the United States, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914)
  • EU-US Data Privacy Framework where applicable (Stripe, Google, Microsoft)

6. Data Retention

Data TypeRetention Period
Account dataUntil you delete your account
Websites and pagesUntil you delete them or your account
Media filesUntil you delete them or your account
AI conversationsUntil you delete them or your account
Analytics data13 months
Admin audit logs30 days (auto-deleted)
Email verification tokensUntil used or expired
Session data7 days per session
Instagram cached dataRefreshed periodically, deleted on disconnect

When you delete your account, all associated data (websites, links, conversations, media, sessions) is permanently deleted via cascading deletion. This process is irreversible.

7. Your Rights

For all users:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate personal data
  • Erasure — request deletion of your personal data
  • Restriction — request that we limit processing of your data
  • Portability — request your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You can delete your account at any time from Settings in your dashboard. This permanently removes all your data.

For EU/EEA residents (GDPR):

You have the right to lodge a complaint with your local data protection authority. For French residents, this is the CNIL.

For California residents (CCPA):

You have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell your data)
  • Non-discrimination for exercising your rights

8. Cookies and Tracking Technologies

We use cookies and similar technologies. For full details, see our Cookie Policy.

Summary of cookies used:

  • Strictly necessary — authentication session cookies, Cloudflare security cookies
  • Analytics — product analytics, traffic analytics, behavior analytics
  • Functionality — editor auto-save (localStorage), display preferences

9. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit — TLS 1.2+ for all connections
  • Encryption at rest — sensitive credentials are encrypted
  • Hashed analytics — visitor identifiers are anonymized (raw IPs are not stored in analytics)
  • Access control — role-based access for administrative functions
  • Session security — HTTP-only cookies, IP and user agent tracking per session
  • Audit logging — all administrative actions are logged (30-day retention)

10. Data Breach Notification

In the event of a personal data breach, we will:

  1. Notify affected users without undue delay (and within 72 hours where required by GDPR)
  2. Notify the relevant supervisory authority where required
  3. Provide details of the breach and steps taken to mitigate it

11. Children's Privacy

Our Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are in the EU, you must be at least 16 to use the Services without parental consent.

If we learn that we have collected data from a child under the applicable age, we will delete it promptly. If you believe a child has provided us with personal data, contact us at [email protected].

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we may also send you an email notification.

Your continued use of the Services after changes are posted constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: [email protected]

For GDPR-related inquiries, you may also contact your local data protection authority.

Related Policies

Learn about our privacy practices, refund policy, and cancellation terms.