Bonlive ("we", "us", "our") operates a concierge delivery service accessible via www.bonlive.ch and the Bonlive mobile app. This Privacy Policy explains what personal data we collect, why we collect it, and your rights under the Swiss Federal Act on Data Protection (nFADP) and the EU General Data Protection Regulation (GDPR).
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email address, phone number | Create and manage your account, send order updates via SMS |
| Order data | Delivery address, shopping list, order status | Fulfil your concierge and delivery requests |
| Payment data | Card type, last 4 digits, transaction ID | Process payments via Stripe (we never store full card numbers) |
| Location data | Delivery address entered by you | Route your order to a nearby concierge |
| Camera / video | Live POV stream from concierge's device | Show you a live view of your order being fulfilled (concierge app only) |
| Usage data | Pages visited, feature interactions, crash reports | Improve the app and diagnose bugs |
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase (EU) | Database and authentication | Account & order data |
| Stripe (US/EU) | Payment processing | Payment card data (PCI-DSS compliant) |
| Twilio (US) | SMS order notifications | Phone number, order status |
| LiveKit (US) | Live video streaming | Video stream (retained 24h on our servers, then deleted) |
| Mapbox (US) | Address autocomplete | Address text entered by you |
| Vercel (US) | Web hosting | IP address, request logs |
Transfers to non-EU/EEA countries are made to providers that offer Standard Contractual Clauses (SCCs) or operate under an adequacy decision. We are in the process of executing Data Processing Agreements (DPAs) with each provider listed above.
Under nFADP and GDPR you have the right to:
Our website uses strictly necessary cookies for authentication sessions. We do not use advertising or tracking cookies. Analytics are limited to aggregated, anonymised usage statistics.
Bonlive is not directed at children under 16 years of age. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notice. The "Last updated" date at the top of this page always reflects the most recent revision.