Privacy Policy
What personal data Bikabo collects, why, who processes it and what you can ask us to do with it.
This policy describes what Bikabo actually does with personal data, not what it might do. Where something is not in use, it says so rather than listing it speculatively.
1. Who this covers
Bikabo is used by businesses to run client work. That creates two different relationships, and they matter for privacy.
- For account data, such as the details of the person who signs up, we are the controller: we decide why and how it is processed.
- For workspace content, such as the client records, tasks and financial records a business enters, that business is the controller and we are a processor acting on its instructions.
If you are a client or team member of a business using Bikabo and want to know what they hold about you, ask them first. We will help them respond.
2. What we collect
Account data. The name and email address of people with accounts, the business name, the role and access level held in each workspace, and password hashes. We never store passwords in a recoverable form.
Workspace content. Whatever a business records: clients, engagements, tasks, files, messages, compensation agreements, payments and invoices. What this contains is decided by that business, not by us.
Technical and session data. Access and error logs, IP addresses, and the session identifier held in a cookie. These exist to run and secure the service.
Contact submissions. If you use the contact form, the name, email address, business name, reason and message you send.
Audit records. Sensitive actions are recorded with who performed them, what they affected and when. This is a security feature and it is deliberately not editable.
3. Why we process it
- To provide the service and perform our agreement with the business.
- To secure it: rate limiting, session validation and detecting misuse.
- To communicate with you about your account, including notifications you have enabled and messages about the service itself.
- To answer enquiries you send us.
- To meet legal obligations where they apply.
We do not use workspace content to advertise to you, and we do not make automated decisions about people that produce legal or similarly significant effects.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in United States state privacy laws. We have never done either. There is no advertising technology anywhere in this service.
4. Cookies and similar storage
This marketing site sets one cookie, and only when you use the contact form: a session cookie carrying the token that protects the form against cross-site request forgery. It is strictly necessary and expires when your browser session ends.
No analytics, advertising or tracking scripts are loaded on this site. If that changes, this policy and the Cookie Policy will be updated before the change takes effect, and non-essential scripts will not run without consent where consent is required.
The application on its own subdomain sets a session cookie once you sign in. It is strictly necessary, marked HTTP-only, and marked secure when served over HTTPS.
5. Who processes data for us
We use a small number of providers to run the service. Each processes data on our behalf, under agreements requiring them to protect it and to use it only for what we ask.
- Email delivery. Brevo (Sendinblue) sends transactional email: invitations, password resets, notifications you have enabled, and invoices you choose to send to your clients through Bikabo. It receives the recipient address and the message content.
- Hosting. Our hosting provider stores the application, its database and uploaded files, and provides the infrastructure the service runs on.
We do not currently use an analytics provider, a customer support platform, an error monitoring service, or a payment provider for our own subscription billing. If any of those is introduced, this list will be updated first.
6. Where data is processed
Our agreement with you is governed by the laws of the State of Delaware, United States. Our hosting and email providers operate internationally, so personal data may be processed in the United States and in other countries where those providers operate.
If you are outside the United States, using Bikabo may mean your data is transferred to and processed in the United States, where privacy laws differ from those in your country. Where personal data is transferred internationally we rely on the safeguards our providers put in place, including standard contractual clauses where they apply.
If you need the specific location of processing for a compliance assessment, ask us and we will tell you what we know.
7. How long we keep it
Workspace content is kept for as long as the workspace exists, because it is the record the business relies on. Records in Bikabo are generally deactivated or archived rather than deleted, so that history stays intact: removing a team member ends their access and preserves the record of their work, and financial corrections are new linked entries rather than edits.
Account data is kept while the account exists and for a reasonable period after closure so we can deal with questions and meet legal obligations.
Technical logs and security records are kept for a limited period appropriate to their purpose. Contact form submissions are kept for as long as needed to deal with your enquiry and any follow-up.
After termination we will make data available for a reasonable period on request so it can be retrieved, after which it may be deleted.
8. How we protect it
The measures in place are described in more detail on our security page. In summary:
- Every workspace’s data is scoped to that workspace, and every query that reads it filters on that scope.
- Authorisation is checked on the server on every request, against both the person and the specific record.
- Sessions are revalidated against the database on every request rather than trusted for their lifetime, so removing access takes effect immediately.
- Passwords are stored as hashes. Sign-in attempts are rate limited.
- Sensitive access details recorded against work are encrypted at rest, masked by default, revealed only by someone holding that permission, and every reveal is recorded.
- Uploaded files are stored outside the paths the web server will serve, and are returned only after an authorisation check.
- Forms that change data carry a token checked on submission.
No system is perfectly secure. We do not claim certification against a security standard, and our security page says plainly which claims we do not make.
9. Your rights
Residents of United States states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia and others as they take effect, generally have the following rights over personal information we hold as a controller:
- To know what personal information we collect, the sources it comes from, why we collect it and who we disclose it to.
- To access a copy of it, in a portable form where technically feasible.
- To have inaccurate information corrected.
- To have it deleted, subject to the limitation described below.
- To opt out of the sale or sharing of personal information, and of targeted advertising. We do none of these, so there is nothing to opt out of.
- Not to be discriminated against for exercising any of these rights. We do not offer different service or pricing on that basis.
To exercise any of them, contact us using the details at the end of this page. We will respond within the period the applicable law requires, and may need to verify your identity first. You may use an authorised agent where the law allows it. If we decline a request you may appeal by replying to our response, and we will review it.
If you are in the European Economic Area, the United Kingdom or another region with equivalent rights, you may also have the right to object to or restrict processing and to complain to your local supervisory authority.
If your data is in a workspace belonging to a business that uses Bikabo, that business decides what it holds and why, and we act as its service provider. Direct your request to them; we will support them in responding.
One limitation, stated openly rather than buried: some records are append-only by design, including financial entries and the audit trail. Where deletion is requested and a record cannot be edited away without destroying the integrity of what it belongs to, we will work with you on the appropriate remedy, which may be restriction of processing rather than erasure. United States state privacy laws recognise exceptions of this kind, including for completing a transaction and for internal uses reasonably aligned with your expectations.
10. Children
Bikabo is a business tool, is not directed at children, and is not intended for anyone under 18. We do not knowingly collect personal information from children under 13, consistent with the Children’s Online Privacy Protection Act. If you believe a child has provided us with personal information, contact us and we will delete it.
11. Changes to this policy
We will update this policy when what we do changes, in particular when we add or change a provider. The version and last updated date at the top of this page will change, and where a change is material we will give notice.
Contact
Questions about this document can be sent to support@bikabo.com, or through the contact form.