Privacy Policy

Last updated: April 3, 2026

At bioflyr, we take your privacy seriously. This policy explains what data we collect, why we collect it, and how we keep it safe.

1. Who We Are

bioflyr ("we", "our", "us") operates the website bioflyr.com and the related services that let creators and small sellers publish an online store as a bio link. Our registered contact e-mail is privacy@bioflyr.com.

2. Information We Collect

a) Information you give us directly

  • Account dataname, e-mail address, and password when you register.
  • Store datastore name, slug, logo, product titles, prices, and images you upload.
  • Contact informationWhatsApp number or phone number you add to your store.
  • Payment dataPayPal e-mail address. We never store full card numbers; payments are processed by PayPal.
  • Messagesany support requests you send us.

b) Information collected automatically

  • Usage datapages viewed, time spent, actions taken inside the dashboard.
  • Store visit countshow many times your store page is visited (no personal data of the visitor is stored).
  • Device & browser infoIP address, browser type, operating system, referrer URL, and language preference.
  • Cookies & local storage session tokens, theme preference, and language preference. See our Cookie Policy for details.

c) Images uploaded to Cloudinary

Product and store logo images are uploaded to and hosted by Cloudinary, Inc. Their privacy policy applies to image storage.

3. How We Use Your Information

  • Provide, operate, and improve the bioflyr service.
  • Authenticate your identity and protect your account.
  • Render your public store page to visitors.
  • Send you transactional e-mails (password reset, account notifications). We do not send marketing e-mails without your explicit consent.
  • Analyse aggregate usage to improve features (data is anonymised before analysis).
  • Comply with legal obligations and enforce our Terms of Service.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases:

  • Contractprocessing necessary to provide the service you signed up for.
  • Legitimate interestsanalytics and fraud prevention, where our interests are not overridden by your rights.
  • Consentwhere we explicitly request it (e.g. marketing communications).
  • Legal obligationwhen required by law.

5. Sharing Your Data

We do not sell your personal data. We share it only with:

  • Vercelhosting and serverless functions (EU and US regions).
  • Cloudinaryimage storage and delivery.
  • PayPalpayment processing when you enable PayPal on your store.
  • Upstash / Redisrate-limiting and session caching.
  • Legal authoritieswhen required by applicable law or valid legal process.

All third-party processors are contractually bound to handle your data securely and only for the purposes we specify.

6. Data Retention

We keep your personal data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required by law to retain it longer (e.g. financial records for 5 years).

Anonymised, aggregated analytics data may be retained indefinitely.

7. Your Rights

Depending on your location you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time (where processing is based on consent).

To exercise any of these rights, e-mail us at privacy@bioflyr.com. We will respond within 30 days.

8. International Transfers

bioflyr is operated from Morocco. Your data may be transferred to and processed in the United States and the European Union by our infrastructure providers. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA.

9. Security

We use industry-standard measures including HTTPS/TLS encryption in transit, bcrypt password hashing, JWT session tokens, and regular dependency audits. No system is 100% secure; in the event of a data breach we will notify affected users within 72 hours as required by applicable law.

10. Children's Privacy

bioflyr is not directed to children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top and, for material changes, notify you by e-mail or a prominent banner on the site. Continued use of bioflyr after the effective date constitutes acceptance of the updated policy.

12. Contact

Questions or concerns about this policy? Contact us: