← Back to Bounder

Privacy Policy

Last updated: March 9, 2026

1. Overview

Bounder ("we," "us," or "our") operates a software-as-a-service platform that lets users upload PDF documents and publish them as interactive, shareable flipbooks. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

By using Bounder, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

2. Information We Collect

Account Information

When you create an account, we collect your email address, full name, and password. You may optionally provide a display name and profile avatar. This information is stored in our database and managed through Supabase Auth.

Content You Upload

When you upload a PDF, we process it into multi-resolution WebP page images (thumbnail, standard, and high resolution). We also extract text content and table-of-contents data from the PDF for search and navigation. The original PDF file and all generated images are stored in secure cloud storage.

Flipbook Analytics

When someone views one of your flipbooks, we collect analytics data including: pages viewed, session duration, device type (mobile, tablet, or desktop), browser name, operating system, HTTP referrer, and country. Country is derived from the viewer's IP address using the MaxMind GeoLite2 database — an in-memory lookup that produces only a 2-letter country code. We do not store precise location data, GPS coordinates, or full IP addresses in analytics records. An anonymous visitor ID (a random UUID) is stored in the viewer's browser localStorage to distinguish unique visitors.

Lead Capture Data

Flipbook owners may enable lead capture forms on their flipbooks. When a viewer submits a lead form, we collect their email address and optionally their name and company. We also record the submitter's IP address and user agent for fraud prevention. This data is collected on behalf of the flipbook owner, who is the data controller for lead capture data (see Section 11).

Payment Information

Payment processing is handled entirely by Stripe. Bounder never receives, processes, or stores payment card numbers, bank account numbers, or other sensitive financial data. Stripe is PCI DSS Level 1 certified.

Automatically Collected Information

When you use the Service, we automatically collect your IP address (used for rate limiting and country derivation, then discarded from request context), user agent string, and HTTP referrer. We use this information for security, abuse prevention, and service improvement.

3. How We Use Your Information

We do not sell your personal information. We do not use your content or data for advertising purposes.

4. Cookies & Local Storage

We use cookies and browser storage strictly for functionality — we do not use third-party advertising or tracking cookies.

NameTypePurposeDuration
sb-*-auth-tokenCookie (httpOnly)Authentication session managed by SupabaseSession
bounder_active_businessCookieRemembers your active business context in the dashboardSession
bounder_active_team_idCookieRemembers your active team filter in the dashboardSession
flipbook_access_{slug}Cookie (httpOnly)Remembers that a viewer has entered the correct password for a protected flipbook24 hours
bounder_vidlocalStorageAnonymous visitor ID (UUID) for flipbook analyticsPersistent
bounder_pending_uploadlocalStorageTemporary flag to resume a pending upload after signupTemporary

5. Third-Party Service Providers

We share data with the following third-party providers solely to operate the Service. Each provider has been evaluated for security and compliance.

6. Data Retention

7. Data Security

We implement technical and organizational measures to protect your data:

For a detailed overview of our security controls, visit our Security page.

8. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:

Legal Basis

We process personal data under the following legal bases:

9. Your Rights Under CCPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

To exercise any of these rights, contact us at haddadcole40@gmail.com. We will respond to verifiable requests within 45 days.

10. International Data Transfers

Bounder's infrastructure is hosted in the United States. If you access the Service from outside the United States, your data may be transferred to, stored, and processed in the US. By using the Service, you acknowledge this transfer. We rely on appropriate safeguards for cross-border data transfers, including the use of service providers who maintain SOC 2 compliance and implement industry-standard security measures.

11. Data Processing on Behalf of Customers

When a Bounder customer enables lead capture on their flipbooks or views analytics about their flipbook viewers, Bounder acts as a data processor. The flipbook owner is the data controller for lead capture data and viewer analytics associated with their flipbooks.

Bounder processes this data only as necessary to provide the Service to the customer. Flipbook owners are responsible for ensuring they have a lawful basis for collecting data from their viewers and for informing their viewers about data collection practices.

12. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. For material changes, we will notify you by email or through a prominent notice in the Service before the change becomes effective. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

haddadcole40@gmail.com

For security-related inquiries, please visit our Security page.