Skip to main content

Privacy Policy

Last Updated: October 5, 2026

Bakebug Inc. ("we", "us", or "Bakebug") values your privacy. This Privacy Policy explains what information we collect, how we use it, your rights, and how we protect your data. Bakebug Inc. is based in Ontario, Canada and currently supports users in Canada, the United States, the United Kingdom, Ireland, and Australia.

Bakebug serves two distinct types of people: Store Owners, who register an account and operate a store on the platform, and Customers, who browse and place orders as guests without creating a Bakebug account. The information we collect and how we communicate with each group differs, and this policy reflects those differences.

Store Owners may use storefronts for different lawful types of goods and services. The categories of personal information described here apply regardless of what a store sells. Store Owners choose the information they include in product listings and collect through customer orders, subject to their own legal obligations.

1. Information We Collect

From Store Owners (registered account holders):

  • Account Information: Name, email address, and authentication credentials when registering via third-party login (Google or Facebook).
  • Store Information: Business name, description, fulfillment options, payment preferences, and other details provided when setting up a store.
  • Business Mailing Address: If a Store Owner sends marketing emails to customers, they must provide a business mailing address (which may be a post office box or other business mailing address where permitted by applicable law). We include this address, together with an unsubscribe link, in the Store Owner's marketing emails, as required by applicable anti-spam and electronic marketing laws. Depending on the Store Owner's choice, we also show it to people who open the links in their marketing texts, or to everyone in their store footer and Contact page, to identify them as the sender of marketing texts.
  • Business Phone Number: A Store Owner may provide a business phone number so customers can reach them, and chooses whether it is shown to everyone on their store, only to people who open the links in their marketing texts, or not at all. Where shown, it also identifies them as the sender of marketing texts.
  • Billing Information: Subscription plan details and billing history. Sensitive payment card data is processed directly by Stripe and is never stored on Bakebug's servers.
  • Referrals: When a Store Owner shares a referral link, we record referral attribution, reward eligibility, and related subscription payment events. Store Owners can see their own referral and reward status, not the referred merchant's private payment details.
  • Usage Data: How Store Owners interact with the platform, including pages visited and features used.
  • Technical Data: IP address, browser type, device information, operating system, timezone, and locale preferences.

From Customers (guest checkout — no Bakebug account created):

  • Contact Information: Email address and, where provided, phone number collected at checkout for order fulfillment and communication purposes.
  • Order Information: Items ordered, fulfillment preferences, and any notes provided at checkout.
  • Communication Preferences: Opt-in status for transactional and marketing email and SMS communications, as collected at checkout or through a store's subscription form.
  • Technical Data: IP address, browser type, device information, and locale, collected automatically when browsing a storefront.
  • Product alerts and unfinished checkouts: When you request a back-in-stock alert, we record the product, email address, request time, and consent wording. If you agree to a checkout reminder, we temporarily keep your cart contents and contact details, but no payment card details.
  • Page views: We record when you open a secure order or quote link so the Store Owner can see the last view time.
  • Storefront and shared-link activity: We count storefront visits and visits to named shared links only when you allow optional analytics. We count redirects through presale and event short URLs separately from confirmed storefront views, without using analytics browser storage. If you allow optional analytics, we may associate a direct storefront order with the tracked link you most recently opened in the same browser tab. The order keeps the link identifier alongside its regular order information, which the Store Owner can access. The separate view and click counters do not keep your name, contact details, IP address, or device fingerprint.

Customer data held by Store Owners:

Store Owners collect and manage customer information (names, contact details, order history, communication preferences) in the normal course of operating their stores. Bakebug stores this data on behalf of Store Owners to enable the platform to function. Store Owners are responsible for ensuring they have the appropriate legal basis to collect and use their customers' data.

2. How We Use Information

We use collected information to operate, provide, maintain, and improve the Services:

  • Creating and managing Store Owner accounts and enabling them to operate their online stores.
  • Processing and facilitating customer transactions (in coordination with payment processors).
  • Sending Store Owners transactional platform emails (subscription confirmations, billing receipts, security alerts, and service announcements).
  • Sending customers transactional emails and, where opted in, transactional SMS messages related to their orders (confirmations, status updates, payment reminders).
  • Sending customers promotional emails or SMS messages from Store Owners, only where the customer has explicitly opted in.
  • Detecting and preventing fraud, improving security, and meeting legal obligations.
  • Localizing the user experience (language, timezone, currency defaults) using geolocation and browser settings.
  • Analyzing usage patterns to improve the Services (subject to analytics consent).
  • Managing Store Owner platform subscriptions and processing related billing through Stripe.
  • Sending requested back-in-stock alerts and, with the applicable marketing consent, one unfinished-checkout reminder. Showing Store Owners when an order or quote page was last opened.
  • With optional analytics consent, providing Store Owners aggregate storefront and named-link views. We separately count redirects through presale and event short URLs without writing analytics cookies or web storage for the click. A redirect click does not confirm that the storefront page loaded. These counts do not store visitor names, contact details, full IP addresses, or referrers for link analytics. When optional analytics is allowed, a short-lived receipt can associate a direct storefront order with the last eligible tracked link opened in the same browser tab, for up to seven days. Store Owners can access their order records, including an associated link identifier, and see aggregate order counts, conversion rates, and order value for each link. Order value may include unpaid or partially paid orders and is not collected revenue. A link may be reused in email, SMS, or social posts; its assigned UTM source does not verify where a visitor found it, and we do not infer an individual blast's results from a reused URL.

3. Email Communications

Store Owner transactional email: By registering a Bakebug account, Store Owners consent to receive transactional platform emails including subscription confirmations, billing receipts, password resets, and security alerts. These are essential to the account and cannot be opted out of.

Customer transactional email: When a customer places an order, they will automatically receive order-related emails (confirmations, status updates, payment reminders). These are necessary for order fulfillment and cannot be opted out of.

Customer marketing email: We will only send promotional emails to customers who have explicitly opted in during checkout, through a store's subscription form, or by affirmatively confirming a subscription request (for example, by clicking a confirmation link sent to their email address). Marketing messages include special offers, new products, promotions, and other non-essential communications. Every marketing email includes the sending Store Owner's name and business mailing address, a link to their store's Contact page, and an unsubscribe link, as required by applicable law.

Opt-out: Customers may opt out of marketing emails at any time by clicking the unsubscribe link in any marketing email or contacting support@bakebug.com.

Store Owners do not receive SMS messages from Bakebug. All Bakebug-to-Store-Owner communications are via email only.

4. SMS Communications

SMS messaging on Bakebug is used exclusively to communicate with customers. Store Owners do not receive SMS messages from Bakebug. The only phone number Bakebug collects from a Store Owner is an optional business phone number shown on their store.

Bakebug operates an SMS messaging platform on behalf of Store Owners. All SMS messages are delivered via Telnyx, our third-party SMS carrier and A2P 10DLC registered messaging provider. Bakebug owns and manages all SMS sending numbers — Store Owners do not purchase or manage their own numbers.

Transactional SMS (customers only): If a customer provides their phone number at checkout and opts in to SMS notifications, they may receive transactional text messages related to their order, including order confirmations, status updates (ready for pickup, fulfilled, canceled), quote notifications, and payment reminders. These messages are sent from a dedicated Bakebug platform number.

Marketing SMS (customers only): If a customer explicitly opts in to marketing SMS from a Store Owner (for example, by ticking an optional box at checkout or on a store sign-up form), they may receive promotional text messages from that Store Owner, including special offers, new products, and store announcements. We record when the customer opted in and which version of the consent wording they agreed to.

Who sent a marketing text: Each marketing text includes the store name and a link to the Store Owner's store. Pages opened through that link show the Store Owner's business name and contact details, including a mailing address where the Store Owner has chosen to show it; the link includes a short marker so we can show these details only to people arriving from a text. Pages opened this way are marked so search engines do not index them. For up to 61 days after a Store Owner's last marketing text, we keep a copy of the business name, mailing address, public contact email, and phone number that identified them, and a record of the links used in their texts, including any custom domain. If the store is renamed, closed, or deleted, or its custom domain is disconnected, during that time, those links show the copy or forward to the store instead, so recipients can still identify and contact the sender, as Canada's Anti-Spam Legislation requires. This copy is kept even if the Store Owner deletes their account, and is deleted when the period ends.

Opt-out: Customers may reply STOP to a marketing text to stop marketing texts from all Bakebug stores, or to a transactional text to stop order and quote texts. To receive help or support information, customers may reply HELP to any message. Opt-outs are processed automatically and customer preferences are updated immediately. Customers may also opt out by contacting support@bakebug.com.

Automated alerts: A requested back-in-stock alert sends at most one message when the item can be ordered again. A consented unfinished checkout may receive one reminder, by email, after about three hours. Both use marketing channels and their unsubscribe rules.

Message frequency & rates: Message frequency may vary. Msg & data rates may apply. Reply STOP to opt out, HELP for help. SMS is only supported in North American Numbering Plan (NANP) countries and is not available in the United Kingdom, Ireland, or Australia.

SMS location and send times: We schedule marketing texts using the time zone or zones associated with the area code of the recipient's phone number and, if a Store Owner or customer has recorded one, the customer's time zone. We may store that time zone, country, state or province, who supplied it, and when. Marketing texts are sent only on weekdays between 10:00 AM and 5:00 PM in every one of those time zones, and not on federal holidays or certain state legal holidays. We limit texts to any one number to three in a rolling 24-hour period. We use these limited location details only to time SMS delivery and for support; we do not require a street address or precise device location.

Telnyx as processor: Telnyx acts as a data processor for SMS delivery on our behalf. Customer phone numbers and message content are transmitted to Telnyx solely for the purpose of sending and receiving messages. For details, see Telnyx's Privacy Policy.

5. Phone Number Collection

Customer phone numbers are collected optionally at checkout, for order fulfillment, contact by the Store Owner, and SMS notifications where the customer has opted in. From Store Owners, Bakebug collects only an optional business phone number, which is shown on their store and never used to send them texts.

Customer phone numbers are shared with the relevant Store Owner for order fulfillment purposes and with Telnyx solely for SMS delivery. Phone numbers are never used to send unsolicited messages and are never sold to third parties.

6. Children's Privacy & Minors

Bakebug is not intended for children under 13 years of age (or the local age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect personal information from children under 13. Store Owners must be at least 18 years old to register an account independently, or have the involvement and consent of a parent or legal guardian if under 18.

If we learn that we have collected personal data from a child under 13 without proper parental consent, we will take steps to delete that information as quickly as possible. Contact us at support@bakebug.com if you believe we may have collected information from a child.

7. Cookies, Local Storage & Tracking

We use required browser storage for authentication, security, and core platform functionality. With your optional analytics preference, we also use Google Analytics, session markers for storefront and link views, and a first-party shared-link receipt to measure orders associated with tracked links. We do not use advertising or marketing cookies for this reporting.

Browser storage technologies are used as follows:

  • Essential (Required): Authentication tokens, session identifiers, and security mechanisms necessary to log in and use the platform securely. Cannot be disabled.
  • Functional (Required): Shopping cart contents, checkout session data and session-specific navigation state, stored in localStorage and sessionStorage. These are required for core platform features such as checkout to work correctly. Cannot be disabled.
  • Short-URL redirect counts: Presale and event short URLs count redirect requests on the server without writing analytics cookies or web storage for the click, or retaining a visitor identifier in the count. This count can continue when optional analytics is declined. A click does not confirm a storefront visit and repeat requests or automated traffic may be included.
  • Analytics (Optional): If you allow analytics, Google Analytics 4 collects usage data, such as pages visited and features used and browser-generated identifiers, to help us improve the Services. This data is pseudonymous and not necessarily anonymous. Google Signals and advertising personalization are disabled. We also count storefront and tracked-link views using sessionStorage markers to limit repeat counting in a browser-tab session. Separately, a signed first-party receipt containing the link identifier, store identifier, and issue time is kept in sessionStorage in the current browser tab after an eligible tracked-link visit. It can associate a direct storefront order with that link for up to seven days, provided the tab session continues and analytics remains allowed. It is not a device fingerprint and is not shared with Google Analytics for this purpose. Google Analytics is not loaded, and this order attribution receipt is not issued, when optional analytics is declined. You can change your preference through Cookie Settings; declining or withdrawing it stops new storefront and tracked-link view counts, removes analytics session markers and receipts, and prevents later checkout attribution. Historical view counts include visits recorded before this consent change.

Browser-storage values can be cleared through your browser settings. Aggregate counts and an order's associated link identifier are held by Bakebug, as described above and in Data Retention below.

8. Country Detection & Localization

To improve user experience, we may attempt to detect your country or locale using:

  • IP-based geolocation: We use third-party services (such as country.is API) to estimate your country based on your IP address.
  • Browser locale information: We read your browser's language and region settings.
  • Timezone inference: We use your device's timezone settings to provide appropriate defaults.

This detection is for convenience and localization only (timezone, currency, phone number format, language preferences). Users and Store Owners remain solely responsible for ensuring compliance with all applicable local laws and requirements, regardless of detected location.

9. Third-Party Services & Payment Processing

We use third-party service providers to help us operate and improve the Services, including hosting, email delivery, SMS delivery, analytics, and payment processing. These providers process data on our behalf under appropriate data processing agreements.

For Store Owner payment processing on their storefronts, we integrate with Square. To facilitate transactions and refunds, we store minimal information from Square including:

  • Square merchant IDs and location IDs
  • Access and refresh tokens (encrypted)
  • Token expiration times
  • Location details (name, address, currency, country)
  • Primary location flags

For Bakebug platform subscription billing (Store Owners only), we use Stripe as our payment processor. Stripe collects and processes payment information on our behalf. For details on how Stripe handles payment data, see Stripe's Privacy Policy.

For SMS delivery to customers, we use Telnyx as our messaging carrier. Customer phone numbers and message content are transmitted to Telnyx solely for the purpose of sending and receiving SMS messages. For details, see Telnyx's Privacy Policy.

Sensitive cardholder data (card numbers, CVV codes) is processed directly by our payment processors and is never stored on Bakebug's servers. For details on how Square handles payment data, see Square's Privacy Policy (Square publishes country-specific privacy notices, including one for Australia).

Custom email sending domains: A Store Owner may configure Bakebug to send transactional and marketing emails to their customers from the Store Owner's own verified domain instead of Bakebug's default sending address. This uses the same underlying email infrastructure and processing described in this Privacy Policy — no additional third party is introduced, and the same consent, opt-out, and retention rules described elsewhere in this policy continue to apply regardless of which domain a message is sent from.

10. Sharing of Information

We do not sell personal information. We may share information with:

  • Service Providers: Third parties that assist with hosting, email delivery, SMS delivery (Telnyx), analytics, and payment processing (Stripe for Store Owner subscriptions; Square for storefront payments).
  • Store Owners: When a customer places an order or subscribes to updates from a store, their contact information and communication preferences are shared with that Store Owner to fulfill orders and send communications the customer has consented to receive.
  • Legal Requirements: Authorities when required by law, court order, or to protect rights and safety.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (with notification to affected users).
  • With Your Consent: When you explicitly authorize us to share information.

11. Data Retention

We retain personal data only as long as necessary for the purposes described in this Privacy Policy and as required by applicable law:

  • Store Owner account information is retained while the account is active. For new accounts that never start a plan, deletion is scheduled 75 days after account creation, with a warning around day 68. Explicit closure has a seven-day recovery period; legacy dormant accounts have a separate 75-day retention period.
  • Named shared-link records and aggregate view counts, along with aggregate click counts for presale and event short URLs, are deleted with the Store Owner account. Browser sessionStorage markers and optional attribution receipts are limited to the current browser-tab session. A receipt is accepted for attribution for no more than seven days after its issue time. If an eligible order is placed, its link identifier remains with the order under the order retention policy. Deleting a merchant-created shared link clears its association with existing orders.
  • Back-in-stock requests expire after 90 days and closed requests are deleted after 30 days. Unfinished checkout records close after seven idle days and are deleted 30 days after closure; recovery links expire after seven days.
  • Customer order and contact information is retained as long as necessary for the Store Owner to fulfill orders and manage customer relationships, or as required by law.
  • Transaction records may be retained longer to comply with legal, tax, and accounting requirements.
  • Customer marketing opt-in preferences are retained until the customer opts out or requests deletion.
  • Customer SMS opt-in and opt-out records (including STOP requests) are retained to demonstrate compliance with applicable messaging laws and to honor customer preferences.
  • SMS send logs are retained for operational and compliance purposes.
  • Marketing SMS sender details (a Store Owner's business name, mailing address, public contact email, and phone number) and the links used in their marketing texts are kept for up to 61 days after the Store Owner's last marketing text, including after account deletion, to meet sender-identification requirements.
  • When a customer record is deleted or merged into another, or its store's account is deleted, we keep the record's identifier, unsubscribe token, store, and email address for 61 days so unsubscribe links in emails already sent keep working.
  • When a Store Owner account is deleted, its connected storefront domain and email sending domain are released from our hosting and email providers. A storefront domain linked from marketing texts in the previous 61 days keeps showing the sender details described above until that period ends, and is then released.
  • Short-lived SMS frequency records contain a recipient phone number and submission time to limit repeat messages. They are removed after approximately 25 hours.
  • Marketing banner dismissal records are retained for 7 days in local browser storage.

Search engines: Pages that belong to a particular customer or Store Owner, such as order, quote, and gift card pages, checkout recovery and unsubscribe pages, and pages showing marketing text sender details, tell search engines not to index or archive them. Public storefront pages may be indexed.

Store Owners may request deletion of their account and personal data by contacting support@bakebug.com. Customers may request deletion of their data by contacting support@bakebug.com. Data removed from our active systems may remain in access-restricted backups for up to 35 days. We use those copies only to recover from data loss and reapply deletion requests if a backup is restored. Certain transaction records may be retained longer where required by law.

12. Security

We employ reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, secure authentication, access controls, and regular security assessments.

No method of internet transmission or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. Store Owners are responsible for maintaining the security of their account credentials.

13. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal data, including:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal retention requirements).
  • Objection: Object to certain processing of your data.
  • Portability: Request transfer of your data in a structured, machine-readable format.
  • Withdrawal of Consent: Customers may withdraw consent for marketing email communications by clicking the unsubscribe link in any marketing email, and may withdraw consent for SMS communications at any time by replying STOP or contacting us.
  • Opt-Out of Sale: We do not sell personal information to third parties.

To exercise these rights or for questions about your personal data, contact support@bakebug.com. We will respond within the timeframe required by applicable law.

14. International Transfers

Personal data may be processed and stored in Canada or in other jurisdictions where our service providers operate. If you access Bakebug from outside Canada, your information may be transferred to, stored, and processed in Canada or other countries where data protection laws may differ from those in your jurisdiction.

Where required by law, we adopt appropriate safeguards for international data transfers, such as standard contractual clauses or other approved mechanisms.

Australia: Bakebug does not currently offer Australian data residency. Personal information about Store Owners and Customers in Australia may be processed or stored outside Australia, including in Canada, where Bakebug is based, in the United States, and in other countries where Bakebug's service providers operate.

15. Jurisdiction-Specific Rights

For California Residents (CCPA): You have specific rights to know what personal information we collect, to request deletion, and to opt out of the sale of personal information (note: we do not sell personal information).

For Canadian Residents (CASL): We comply with Canada's Anti-Spam Legislation. Commercial electronic messages, including email and SMS to customers, are only sent with express or implied consent as defined by CASL, and consent may be withdrawn at any time. Every marketing text message identifies the sending Store Owner by name and includes a working STOP unsubscribe mechanism; given SMS's character-length constraints, required identification and contact information is available through a clearly accessible link provided in the message. Marketing emails identify the sender, include an unsubscribe link that keeps working for at least 60 days after sending, and include the sending Store Owner's business mailing address and a link to their store's Contact page, as required by applicable law.

For EU/UK Residents (GDPR/UK GDPR): You have enhanced rights including the right to data portability, the right to restriction of processing, and the right to lodge a complaint with a supervisory authority.

For UK and Irish Residents (PECR / ePrivacy Regulations): Marketing emails sent to UK and Irish customers identify the sending Store Owner, do not disguise or conceal the sender's identity, and include a valid contact address that can be used to opt out, in addition to the unsubscribe link.

For Australian Residents: You may request access to, or correction of, the personal information we hold about you by contacting support@bakebug.com. If you have a concern about how we have handled your personal information, please contact us first. Depending on the circumstances, you may also have the right to raise a complaint with the Office of the Australian Information Commissioner (oaic.gov.au). Marketing emails sent through Bakebug identify the sending Store Owner and include a working unsubscribe link. Bakebug SMS is not available for Australian stores or numbers. Store Owners in Australia are responsible for their own obligations to their customers, including under the Privacy Act where it applies to them.

For US Residents (TCPA / CAN-SPAM): We design customer SMS messaging practices to comply with applicable telecommunications and messaging laws, including the Telephone Consumer Protection Act (TCPA). Customers may revoke consent for automated SMS messages at any time by replying STOP. Marketing emails sent to US customers comply with the CAN-SPAM Act, including a valid physical postal address for the sending Store Owner and a working unsubscribe mechanism.

16. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The revised policy will be posted on this page with a new "Last Updated" date. Material changes may be communicated via email or prominent notice on the platform.

Continued use of the Services after updates constitutes acceptance of the revised Privacy Policy. We encourage you to review this page periodically.

17. Contact

For privacy questions, concerns, or requests regarding your personal data, contact us at: support@bakebug.com