Privacy Policy

Last updated: 9 July 2026

This policy explains how Fitflick Ltd trading as Bump Buy 360 collects, uses, stores, shares and protects personal information.

Bump Buy 360 Privacy Policy

Last updated: 9 July 2026

1. Introduction

This Privacy Policy explains how Fitflick Ltd trading as Bump Buy 360 collects, uses, stores, shares and protects personal information when you use Bump Buy 360.

It also explains your rights under applicable data-protection law.

For the personal information described in this Privacy Policy, Fitflick Ltd is generally the controller, meaning we determine why and how that information is processed.

This notice is designed to provide the categories of information expected under UK GDPR transparency requirements, including purposes, lawful bases, recipients, transfers, retention and individual rights.

2. Scope

This Privacy Policy applies to personal information processed through:

related Bump Buy 360 services.

It does not govern a third party’s independent processing once you interact directly with that third party.

3. Personal Information We May Collect

The exact information depends on how you use the App.

3.1 Account and identity information

We may collect:

related account metadata.

We do not intend to store your plain-text password. Authentication credentials may be handled through authentication infrastructure such as Firebase Authentication or third-party sign-in providers.

3.2 Pregnancy and personalisation information

Depending on the features you use, we may collect:

other information you voluntarily provide for personalisation.

Important: some pregnancy-related information may reveal or strongly imply information concerning health and may therefore constitute special-category personal data.

The ICO explains that special-category data requires both an Article 6 lawful basis and a separate Article 9 condition.

3.3 Shopping-list information

We may collect:

other shopping-list activity.

3.4 Hospital-bag information

We may collect:

related interactions.

3.5 Product, offer and affiliate interaction information

We may collect:

aggregated commercial-performance information.

We may not receive full details of everything you purchase from a third-party retailer. The information available depends on the affiliate network, retailer and tracking arrangement.

3.6 Course, scan and service interactions

We may collect information about:

referral or affiliate attribution.

Depending on context, interaction with pregnancy-related services may itself reveal sensitive inferences. We therefore aim to treat such data carefully.

3.7 Device and technical information

We may collect:

technical event information.

3.8 Usage and analytics information

Where permitted and, where legally required, with appropriate consent, we may collect:

aggregated usage statistics.

3.9 Customer-support communications

If you contact us, we may collect:

information reasonably necessary to respond.

3.10 Marketing preferences

If we offer marketing communications, we may collect:

engagement information where legally permitted.

3.11 Information from third parties

We may receive information from:

technical service providers.

The exact information depends on the relationship and your interaction.

4. Information We Do Not Intend To Collect

Unless a specific feature expressly requires it, we do not intentionally request:

precise continuous GPS location.

Please do not submit unnecessary sensitive information through free-text support channels.

If our service changes, this Privacy Policy should be updated before materially different processing begins.

5. How We Use Personal Information And Our Lawful Bases

UK GDPR requires us to identify an appropriate lawful basis. The basis depends on the processing activity.

5.1 Creating and managing your account

Purposes:

account security.

Lawful basis: performance of a contract or steps taken at your request before entering into a contract.

Where necessary for fraud prevention or security, we may also rely on legitimate interests.

5.2 Providing core App functionality

Purposes:

provide requested functionality.

Lawful basis: performance of a contract.

5.3 Personalising your shopping list

Purposes:

tailor other planning features.

Article 6 lawful basis: generally performance of a contract for ordinary personalisation data; where consent is the appropriate basis, consent.

Where special-category health data is processed: our intended Article 9 condition is explicit consent under Article 9(2)(a).

Because pregnancy-related information may constitute special-category data, we recommend a separate, explicit in-app consent mechanism before such data is used for personalisation. ICO guidance recognises explicit consent as a possible Article 9 condition where appropriately obtained.

5.4 Due-date and pregnancy-stage functionality

Purposes:

organise shopping suggestions.

Article 6 lawful basis: performance of a contract and/or consent depending on implementation.

Article 9 condition where the data constitutes health data: explicit consent.

5.5 Hospital-bag functionality

Purposes:

calculate progress.

Lawful basis: performance of a contract.

Where information reveals health-related circumstances beyond ordinary organisational data, an appropriate Article 9 condition will also be required; where applicable, we intend to rely on explicit consent.

5.6 Affiliate links and commercial attribution

Purposes:

measure commercial performance.

Lawful basis: legitimate interests where appropriate.

Our legitimate interests include operating and monetising the App, understanding referral performance and preventing fraud.

Where tracking involves storage or access technologies on your device, separate PECR consent requirements may apply. We will seek consent where required.

5.7 Analytics and product improvement

Purposes:

understand engagement.

Lawful basis: legitimate interests where processing can lawfully occur without consent and privacy impacts are appropriately balanced; otherwise consent.

PECR: where analytics involves non-essential storage or access technologies, we will seek consent where required.

The ICO’s current guidance makes clear that PECR can apply to technologies used in mobile apps, not merely traditional browser cookies.

5.8 Crash diagnostics and security

Purposes:

maintain security.

Lawful basis: legitimate interests, and where necessary compliance with legal obligations.

Where a particular device technology requires consent under PECR, we will obtain it unless an exemption applies.

5.9 Customer support

Purposes:

maintain records.

Lawful basis: performance of a contract, legitimate interests, and where relevant compliance with legal obligations.

5.10 Legal and regulatory compliance

Purposes:

maintain legally required records.

Lawful basis: legal obligation and/or legitimate interests.

Where special-category data is involved, we will identify an additional valid Article 9 condition before processing.

5.11 Direct marketing

If we send electronic direct marketing:

Lawful basis: consent where required; in limited circumstances another lawful basis may apply under applicable law.

We will comply with applicable UK GDPR and PECR requirements.

The ICO confirms that UK GDPR sits alongside PECR for electronic marketing and similar technologies.

6. Explicit Consent For Pregnancy-Related Data

Because the App may process information concerning pregnancy, we may ask you to provide explicit consent.

A suitable consent request should be separate and clear, for example:

I explicitly consent to Fitflick Ltd trading as Bump Buy 360 processing the pregnancy-related information I provide, including my due date and other pregnancy-related onboarding answers, to personalise my shopping lists, planning timeline, hospital-bag features and relevant App content. I understand that I can withdraw this consent at any time.

Do not hide this solely inside the Terms.

Where we rely on explicit consent:

withdrawal may mean some personalised features can no longer operate.

7. Automated Personalisation And Profiling

The App may automatically use onboarding answers and preferences to:

show relevant categories.

For example, an answer concerning:

may affect the items displayed.

This is a form of automated personalisation and may amount to profiling in some contexts.

We do not currently intend to use this process to make decisions producing legal effects or similarly significant effects about you within the meaning of applicable data-protection law.

If that changes, we will update our disclosures and implement required safeguards.

8. Firebase And Google-Related Infrastructure

The App may use services provided by Google group companies, including services within the Firebase ecosystem.

Depending on configuration, these may include:

related technical services.

These services may process:

other information necessary for the configured service.

The exact processing depends on our technical configuration.

Users can review Google’s official Privacy Policy for information about Google’s own privacy practices.

Important implementation point: your published policy should match the Firebase products you actually enable. Do not claim you use only Authentication and Firestore if you later activate Analytics, Crashlytics, Cloud Messaging or advertising features without updating the notice and consent setup.

9. Affiliate Networks, Including Awin

We currently use or may use Awin for affiliate marketing.

We may also add other:

commercial partners.

When you interact with affiliate content, information may be processed to:

report performance.

Information may include:

pseudonymous identifiers.

The relevant third party may act as an independent controller, joint controller or processor depending on the arrangement.

Where required, we will provide additional information about material partners.

10. Who We May Share Personal Information With

We may share personal information where necessary with categories including:

10.1 Cloud and infrastructure providers

For:

app infrastructure.

10.2 Analytics and diagnostics providers

For:

service improvement.

10.3 Authentication providers

Where you choose:

another third-party authentication method.

10.4 Affiliate networks and partners

Including:

future affiliate networks.

10.5 Professional advisers

Including:

consultants.

10.6 Regulators and authorities

Where required or permitted by law, including:

data-protection authorities.

10.7 Corporate transaction parties

If we consider or complete:

business sale.

We will apply appropriate safeguards where required.

11. We Do Not Sell Personal Information In The Ordinary Sense

We do not intend to sell your personal information as a standalone commodity.

However, affiliate tracking, advertising technology and data-sharing arrangements can have specific legal meanings in some jurisdictions.

If our business model changes to involve processing legally characterised as a “sale” or “sharing” under applicable law, we will update this Privacy Policy and provide required rights.

12. Cookies, Sdks And Similar Technologies

The App and associated websites may use:

similar technologies.

These may be used for:

advertising, if introduced.

PECR is not limited to traditional browser cookies. Current ICO guidance expressly covers storage/access technologies and mobile-app environments.

Where prior consent is legally required, we will seek it before activating the relevant non-essential technology.

You should implement a real consent-management mechanism if non-essential analytics or tracking SDKs are used. A Privacy Policy alone is not enough.

13. International Data Transfers

Some service providers or partners may process personal information outside the United Kingdom.

This may include processing in:

or other countries where providers operate.

Where UK data-protection law requires safeguards for a restricted transfer, we will use an appropriate mechanism, which may include:

supplementary measures where appropriate.

We will assess transfer arrangements where required.

ICO transparency guidance expects applicable international-transfer information to be addressed in privacy notices.

14. How Long We Keep Personal Information

We do not keep personal information for longer than reasonably necessary for the relevant purpose, subject to legal, accounting, security and dispute requirements.

Our intended retention framework is:

14.1 Active account data

Retained while your account remains active.

14.2 Deleted or closed accounts

Core personal account data will generally be deleted or anonymised within 90 days after confirmed account deletion, unless:

another lawful reason applies.

14.3 Pregnancy and personalisation data

Retained while needed to provide requested personalised features.

Following account deletion, generally deleted or anonymised within 90 days, subject to the exceptions above.

We may also provide controls allowing earlier deletion.

14.4 Shopping and hospital-bag data

Retained while the account is active and generally deleted or anonymised within 90 days following confirmed account deletion, subject to lawful exceptions.

14.5 Customer-support records

Generally retained for up to 3 years after the matter is closed, unless a longer or shorter period is justified.

14.6 Complaints and legal disputes

Generally retained for up to 6 years after closure where reasonably necessary for legal claims, subject to the circumstances.

14.7 Financial and tax records

Where records must be retained for legal, tax or accounting reasons, generally retained for 6 years or another period required by applicable law.

14.8 Affiliate and transaction-attribution records

Generally retained for up to 6 years where reasonably necessary for accounting, fraud prevention, contractual reconciliation or legal claims.

Data not required at identifiable level may be aggregated or anonymised earlier.

14.9 Security logs

Generally retained for between 30 days and 12 months, depending on the log’s purpose and security need.

14.10 Analytics data

Retained according to configured provider settings and our operational needs. We aim to select proportionate retention periods.

14.11 Backups

Deleted data may remain in protected backups for a limited period until backup cycles overwrite it. Access is restricted and backup data is not ordinarily restored except for continuity or disaster-recovery purposes.

We will periodically review retention.

15. Data Security

We use appropriate technical and organisational measures designed to protect personal information.

Measures may include:

incident-response procedures.

However, no internet-connected system is completely secure.

You should:

notify us of suspected unauthorised access.

16. Data Breaches

Where a personal-data breach occurs, we will assess it under applicable law.

Where legally required, we will:

notify affected individuals.

17. Your Data-Protection Rights

Depending on the circumstances, UK data-protection law may give you rights including:

17.1 Right of access

You may request a copy of personal information we hold about you.

17.2 Right to rectification

You may ask us to correct inaccurate or incomplete information.

17.3 Right to erasure

You may ask us to delete personal information in circumstances provided by law.

This right is not absolute.

17.4 Right to restriction

You may ask us to restrict processing in certain circumstances.

17.5 Right to data portability

Where applicable, you may request certain information in a structured, commonly used and machine-readable format and may have rights concerning transmission to another controller.

17.6 Right to object

You may object to certain processing based on legitimate interests.

17.7 Rights concerning direct marketing

You may object to direct marketing at any time.

17.8 Rights concerning automated decision-making

You may have rights where a solely automated decision produces legal or similarly significant effects.

17.9 Right to withdraw consent

Where processing relies on consent, you may withdraw it at any time.

Withdrawal does not affect the lawfulness of processing before withdrawal.

18. How To Exercise Your Rights

Contact:

Please state clearly what you are requesting.

We may request information reasonably necessary to verify identity.

We generally aim to respond within the time required by applicable law.

We will not normally charge a fee, although the law permits fees or refusal in limited circumstances involving manifestly unfounded or excessive requests.

19. Complaints

We would appreciate the opportunity to address privacy concerns directly.

Contact:

You also have the right to complain to the UK data-protection regulator, the Information Commissioner’s Office.

Your right to complain to a regulator is not affected by first contacting us.

20. Children

The App is intended for adults aged 18 and over.

We do not knowingly intend to offer user accounts directly to children.

If we learn that a child’s personal information has been collected inappropriately, we will take reasonable steps to investigate and delete it where required.

Information entered by an adult about an expected baby or child is treated as information provided by the adult account holder and will be handled according to applicable law.

21. Third-Party Links

When you follow a link to a third party, that party may independently collect personal information.

Examples include:

authentication providers.

Their privacy policies apply to their independent processing.

We encourage you to review them.

22. Apple And Google Sign-In

If you choose a third-party sign-in method, the provider may process information under its own terms.

Depending on the method and permissions, we may receive:

authentication token.

We will use the information to provide and secure your account.

23. Marketing Communications

Where available, we may send:

partner offers.

We will obtain consent where required.

You may opt out using:

bumpbuy360@outlook.com.

Opting out of marketing does not necessarily stop essential service communications.

24. Special-Category Data And Marketing

We do not intend to use pregnancy or health-related special-category information to target direct marketing unless we have identified a lawful Article 6 basis, a valid Article 9 condition and complied with applicable PECR requirements.

This is important because the ICO specifically notes that using special-category information for direct marketing requires both a lawful basis and a special-category condition.

25. Changes Of Business Ownership

If Fitflick Ltd or Bump Buy 360 is involved in:

personal information may be disclosed or transferred where lawful.

We will take appropriate steps to protect information and provide notice where required.

26. Changes To This Privacy Policy

We may update this Privacy Policy to reflect:

business changes.

Material changes may be communicated through:

another appropriate method.

Where new consent is legally required, we will request it.

27. Contact Details

For privacy enquiries or rights requests: