GDPR & Data Protection
Last updated: 19 September 2026
If you are in the European Economic Area or the United Kingdom, the GDPR (or UK GDPR) gives you specific rights over your personal data. This page explains how Bring Back meets those duties. It complements our Privacy Policy.
1. Our role
For our own website, business accounts and billing, Bring Back is the controller. For customer data collected by a restaurant, café or gym using our platform, that business is the controller and Bring Back is its processor, acting only on the business's documented instructions.
2. Lawful bases we rely on
- Contract (providing the service you signed up for)
- Legal obligation (tax, accounting)
- Legitimate interests (security, fraud prevention, service improvement)
- Consent (marketing messages, where you opt in)
3. Your rights
- Access your data and get a copy
- Have inaccurate data corrected
- Have your data erased ("right to be forgotten")
- Restrict or object to processing, including direct marketing
- Data portability in a common machine-readable format
- Withdraw consent at any time
- Not be subject to solely automated decisions with legal effect. We do not make such decisions.
Email hello@bringback.com to exercise a right. We reply within one month. If your data was collected by one of our business customers, we may pass your request to them.
4. International transfers
Our systems and providers may be located outside the EEA/UK, including in India and the USA. We protect transfers using the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful mechanism, plus supplementary safeguards where needed.
5. Sub-processors
We use vetted sub-processors for hosting and database (Supabase, Vercel), payments (such as Cashfree, Razorpay, Stripe) and email delivery (Resend). Each is bound by a data processing agreement. Business customers can request the current list and a Data Processing Agreement (DPA) at hello@bringback.com.
6. Security and breaches
We apply encryption, access control and tenant isolation. If a personal data breach is likely to put people at risk, we notify the relevant supervisory authority within 72 hours of becoming aware and notify affected controllers and individuals without undue delay.
7. Complaints
Contact us first at hello@bringback.com and we will try to put things right. You also have the right to complain to your local supervisory authority, such as your national data protection authority in the EU or the ICO in the UK.
8. EU/UK representative
For GDPR matters you can reach us at hello@bringback.com. See also our Privacy Policy and Cookie Policy.