Bump Buy 360 Privacy Policy
Last updated: 9 July 2026
1. Introduction
This Privacy Policy explains how Fitflick Ltd trading as Bump Buy 360 collects, uses, stores, shares and protects personal information when you use Bump Buy 360.
It also explains your rights under applicable data-protection law.
- Data controller: Fitflick Ltd
- Trading name: Bump Buy 360
- Company number: 17031125
- Registered office: 14 Whitehurst Road, Cheadle, Staffordshire, ST10 1FU
- Privacy contact: bumpbuy360@outlook.com
For the personal information described in this Privacy Policy, Fitflick Ltd is generally the controller, meaning we determine why and how that information is processed.
This notice is designed to provide the categories of information expected under UK GDPR transparency requirements, including purposes, lawful bases, recipients, transfers, retention and individual rights.
2. Scope
This Privacy Policy applies to personal information processed through:
- the Bump Buy 360 mobile application
- associated Bump Buy 360 websites
- user accounts
- onboarding
- personalised shopping lists
- hospital-bag features
- profile settings
- product discovery
- scans and tests discovery
- courses and classes discovery
- offers and discount features
- affiliate links
- customer support
- analytics
- security
- communications; and
related Bump Buy 360 services.
It does not govern a third party’s independent processing once you interact directly with that third party.
3. Personal Information We May Collect
The exact information depends on how you use the App.
3.1 Account and identity information
We may collect:
- display name
- email address
- user ID
- account identifier
- authentication status
- profile image
- account creation date
- login information
- authentication-provider information; and
related account metadata.
We do not intend to store your plain-text password. Authentication credentials may be handled through authentication infrastructure such as Firebase Authentication or third-party sign-in providers.
3.2 Pregnancy and personalisation information
Depending on the features you use, we may collect:
- expected due date
- calculated pregnancy week
- days until due date
- whether this is your first baby
- whether you already have children
- expected number of babies
- singleton, twins, triplets or other multiple-pregnancy information
- intended feeding plan
- intended sleeping arrangements
- budget preference
- car ownership or access information
- pregnancy-related preferences
- onboarding responses
- planning preferences; and
other information you voluntarily provide for personalisation.
Important: some pregnancy-related information may reveal or strongly imply information concerning health and may therefore constitute special-category personal data.
The ICO explains that special-category data requires both an Article 6 lawful basis and a separate Article 9 condition.
3.3 Shopping-list information
We may collect:
- items included in your personalised list
- items marked purchased
- items marked complete
- list progress
- preferred products
- item interactions
- timestamps
- categories
- planning stages; and
other shopping-list activity.
3.4 Hospital-bag information
We may collect:
- hospital-bag items
- items marked packed
- completion status
- packing progress
- timestamps; and
related interactions.
3.5 Product, offer and affiliate interaction information
We may collect:
- products viewed
- links clicked
- retailer links clicked
- offers viewed
- discount codes viewed
- affiliate links clicked
- referral identifiers
- campaign identifiers
- click timestamps
- source information
- conversion information where made available to us
- transaction attribution information
- commission status; and
aggregated commercial-performance information.
We may not receive full details of everything you purchase from a third-party retailer. The information available depends on the affiliate network, retailer and tracking arrangement.
3.6 Course, scan and service interactions
We may collect information about:
- courses viewed
- classes viewed
- scan services viewed
- test services viewed
- provider links clicked
- searches
- categories
- interaction timestamps; and
referral or affiliate attribution.
Depending on context, interaction with pregnancy-related services may itself reveal sensitive inferences. We therefore aim to treat such data carefully.
3.7 Device and technical information
We may collect:
- device type
- operating system
- app version
- browser type where applicable
- device identifiers
- IP address
- language
- time zone
- approximate region derived from technical information
- network information
- session information
- crash information
- diagnostic information
- performance data
- security logs; and
technical event information.
3.8 Usage and analytics information
Where permitted and, where legally required, with appropriate consent, we may collect:
- screens viewed
- buttons clicked
- feature usage
- session duration
- app opens
- navigation paths
- engagement events
- conversion events
- acquisition source
- campaign source
- performance information
- crash events; and
aggregated usage statistics.
3.9 Customer-support communications
If you contact us, we may collect:
- name
- email address
- message content
- attachments
- complaint information
- support history; and
information reasonably necessary to respond.
3.10 Marketing preferences
If we offer marketing communications, we may collect:
- consent status
- opt-in date
- opt-out date
- communication preferences
- suppression status; and
engagement information where legally permitted.
3.11 Information from third parties
We may receive information from:
- authentication providers
- affiliate networks
- Awin
- retailers
- analytics providers
- app stores
- referral partners
- advertising or attribution partners where lawfully used
- fraud-prevention providers; and
technical service providers.
The exact information depends on the relationship and your interaction.
4. Information We Do Not Intend To Collect
Unless a specific feature expressly requires it, we do not intentionally request:
- medical records
- NHS numbers
- detailed clinical notes
- scan images
- genetic test results
- bank-card details directly into our own database
- passport information
- national-insurance numbers; or
precise continuous GPS location.
Please do not submit unnecessary sensitive information through free-text support channels.
If our service changes, this Privacy Policy should be updated before materially different processing begins.
5. How We Use Personal Information And Our Lawful Bases
UK GDPR requires us to identify an appropriate lawful basis. The basis depends on the processing activity.
5.1 Creating and managing your account
Purposes:
- registration
- authentication
- login
- account management
- profile functionality
account security.
Lawful basis: performance of a contract or steps taken at your request before entering into a contract.
Where necessary for fraud prevention or security, we may also rely on legitimate interests.
5.2 Providing core App functionality
Purposes:
- save lists
- display progress
- synchronise data
- maintain preferences
provide requested functionality.
Lawful basis: performance of a contract.
5.3 Personalising your shopping list
Purposes:
- tailor items
- tailor timing
- tailor multiple-birth items
- tailor feeding-related items
- tailor sleeping-arrangement items
- tailor budget-related items
tailor other planning features.
Article 6 lawful basis: generally performance of a contract for ordinary personalisation data; where consent is the appropriate basis, consent.
Where special-category health data is processed: our intended Article 9 condition is explicit consent under Article 9(2)(a).
Because pregnancy-related information may constitute special-category data, we recommend a separate, explicit in-app consent mechanism before such data is used for personalisation. ICO guidance recognises explicit consent as a possible Article 9 condition where appropriately obtained.
5.4 Due-date and pregnancy-stage functionality
Purposes:
- calculate estimated pregnancy stage
- display countdowns
- tailor chronological planning
organise shopping suggestions.
Article 6 lawful basis: performance of a contract and/or consent depending on implementation.
Article 9 condition where the data constitutes health data: explicit consent.
5.5 Hospital-bag functionality
Purposes:
- create or display lists
- record packed status
calculate progress.
Lawful basis: performance of a contract.
Where information reveals health-related circumstances beyond ordinary organisational data, an appropriate Article 9 condition will also be required; where applicable, we intend to rely on explicit consent.
5.6 Affiliate links and commercial attribution
Purposes:
- track referrals
- attribute qualifying transactions
- calculate commission
- prevent affiliate fraud
measure commercial performance.
Lawful basis: legitimate interests where appropriate.
Our legitimate interests include operating and monetising the App, understanding referral performance and preventing fraud.
Where tracking involves storage or access technologies on your device, separate PECR consent requirements may apply. We will seek consent where required.
5.7 Analytics and product improvement
Purposes:
- understand feature usage
- improve design
- identify bugs
- measure performance
understand engagement.
Lawful basis: legitimate interests where processing can lawfully occur without consent and privacy impacts are appropriately balanced; otherwise consent.
PECR: where analytics involves non-essential storage or access technologies, we will seek consent where required.
The ICO’s current guidance makes clear that PECR can apply to technologies used in mobile apps, not merely traditional browser cookies.
5.8 Crash diagnostics and security
Purposes:
- detect crashes
- diagnose errors
- protect accounts
- prevent abuse
maintain security.
Lawful basis: legitimate interests, and where necessary compliance with legal obligations.
Where a particular device technology requires consent under PECR, we will obtain it unless an exemption applies.
5.9 Customer support
Purposes:
- answer enquiries
- resolve problems
- investigate complaints
maintain records.
Lawful basis: performance of a contract, legitimate interests, and where relevant compliance with legal obligations.
5.10 Legal and regulatory compliance
Purposes:
- comply with law
- respond to lawful requests
- establish legal claims
- defend legal claims
maintain legally required records.
Lawful basis: legal obligation and/or legitimate interests.
Where special-category data is involved, we will identify an additional valid Article 9 condition before processing.
5.11 Direct marketing
If we send electronic direct marketing:
Lawful basis: consent where required; in limited circumstances another lawful basis may apply under applicable law.
We will comply with applicable UK GDPR and PECR requirements.
The ICO confirms that UK GDPR sits alongside PECR for electronic marketing and similar technologies.
6. Explicit Consent For Pregnancy-Related Data
Because the App may process information concerning pregnancy, we may ask you to provide explicit consent.
A suitable consent request should be separate and clear, for example:
I explicitly consent to Fitflick Ltd trading as Bump Buy 360 processing the pregnancy-related information I provide, including my due date and other pregnancy-related onboarding answers, to personalise my shopping lists, planning timeline, hospital-bag features and relevant App content. I understand that I can withdraw this consent at any time.
Do not hide this solely inside the Terms.
Where we rely on explicit consent:
- consent must be affirmative
- we will record it
- you may withdraw it
- withdrawal does not retrospectively make earlier lawful processing unlawful; and
withdrawal may mean some personalised features can no longer operate.
7. Automated Personalisation And Profiling
The App may automatically use onboarding answers and preferences to:
- include or exclude list items
- order items
- tailor shopping suggestions
- tailor content
- calculate progress
- display pregnancy-stage information
show relevant categories.
For example, an answer concerning:
- feeding intentions
- number of babies
- sleeping arrangements
- car access
- budget preference; or
- first-baby status
may affect the items displayed.
This is a form of automated personalisation and may amount to profiling in some contexts.
We do not currently intend to use this process to make decisions producing legal effects or similarly significant effects about you within the meaning of applicable data-protection law.
If that changes, we will update our disclosures and implement required safeguards.
8. Firebase And Google-Related Infrastructure
The App may use services provided by Google group companies, including services within the Firebase ecosystem.
Depending on configuration, these may include:
- Firebase Authentication
- Cloud Firestore
- Firebase Storage
- Firebase Analytics / Google Analytics
- Firebase Crashlytics
- Firebase Cloud Messaging
- Firebase App Check
- hosting or cloud infrastructure; and
related technical services.
These services may process:
- account identifiers
- email addresses
- database records
- uploaded profile images
- device information
- analytics events
- crash data
- technical logs; and
other information necessary for the configured service.
The exact processing depends on our technical configuration.
Users can review Google’s official Privacy Policy for information about Google’s own privacy practices.
Important implementation point: your published policy should match the Firebase products you actually enable. Do not claim you use only Authentication and Firestore if you later activate Analytics, Crashlytics, Cloud Messaging or advertising features without updating the notice and consent setup.
9. Affiliate Networks, Including Awin
We currently use or may use Awin for affiliate marketing.
We may also add other:
- affiliate networks
- retailer affiliate programmes
- referral partners
- attribution providers; or
commercial partners.
When you interact with affiliate content, information may be processed to:
- identify a referral
- attribute a transaction
- measure a conversion
- calculate commission
- prevent fraud; and
report performance.
Information may include:
- click identifiers
- timestamps
- referral source
- device or browser information
- transaction reference
- order value or category
- commission information; and
pseudonymous identifiers.
The relevant third party may act as an independent controller, joint controller or processor depending on the arrangement.
Where required, we will provide additional information about material partners.
10. Who We May Share Personal Information With
We may share personal information where necessary with categories including:
10.1 Cloud and infrastructure providers
For:
- hosting
- databases
- storage
- authentication
- security
- backups
app infrastructure.
10.2 Analytics and diagnostics providers
For:
- analytics
- crash reporting
- performance
- debugging
service improvement.
10.3 Authentication providers
Where you choose:
- Apple sign-in
- Google sign-in; or
another third-party authentication method.
10.4 Affiliate networks and partners
Including:
- Awin
- retailer programmes
- attribution partners
- referral partners
future affiliate networks.
10.5 Professional advisers
Including:
- lawyers
- accountants
- insurers
- auditors
consultants.
10.6 Regulators and authorities
Where required or permitted by law, including:
- courts
- law-enforcement bodies
- regulators
- tax authorities
data-protection authorities.
10.7 Corporate transaction parties
If we consider or complete:
- investment
- financing
- merger
- acquisition
- restructuring
- asset sale
business sale.
We will apply appropriate safeguards where required.
11. We Do Not Sell Personal Information In The Ordinary Sense
We do not intend to sell your personal information as a standalone commodity.
However, affiliate tracking, advertising technology and data-sharing arrangements can have specific legal meanings in some jurisdictions.
If our business model changes to involve processing legally characterised as a “sale” or “sharing” under applicable law, we will update this Privacy Policy and provide required rights.
12. Cookies, Sdks And Similar Technologies
The App and associated websites may use:
- cookies
- SDKs
- local storage
- mobile identifiers
- pixels
- tracking links
- link decoration
- attribution technologies
- tags
- scripts; and
similar technologies.
These may be used for:
- essential operation
- authentication
- security
- preferences
- analytics
- performance
- affiliate attribution
- marketing
advertising, if introduced.
PECR is not limited to traditional browser cookies. Current ICO guidance expressly covers storage/access technologies and mobile-app environments.
Where prior consent is legally required, we will seek it before activating the relevant non-essential technology.
You should implement a real consent-management mechanism if non-essential analytics or tracking SDKs are used. A Privacy Policy alone is not enough.
13. International Data Transfers
Some service providers or partners may process personal information outside the United Kingdom.
This may include processing in:
- the European Economic Area
- the United States
or other countries where providers operate.
Where UK data-protection law requires safeguards for a restricted transfer, we will use an appropriate mechanism, which may include:
- UK adequacy regulations
- the UK International Data Transfer Agreement
- the UK Addendum to the EU Standard Contractual Clauses
- another legally recognised transfer mechanism; and
supplementary measures where appropriate.
We will assess transfer arrangements where required.
ICO transparency guidance expects applicable international-transfer information to be addressed in privacy notices.
14. How Long We Keep Personal Information
We do not keep personal information for longer than reasonably necessary for the relevant purpose, subject to legal, accounting, security and dispute requirements.
Our intended retention framework is:
14.1 Active account data
Retained while your account remains active.
14.2 Deleted or closed accounts
Core personal account data will generally be deleted or anonymised within 90 days after confirmed account deletion, unless:
- legal retention is required
- a dispute exists
- fraud or security concerns justify temporary retention
- backups require a limited additional period; or
another lawful reason applies.
14.3 Pregnancy and personalisation data
Retained while needed to provide requested personalised features.
Following account deletion, generally deleted or anonymised within 90 days, subject to the exceptions above.
We may also provide controls allowing earlier deletion.
14.4 Shopping and hospital-bag data
Retained while the account is active and generally deleted or anonymised within 90 days following confirmed account deletion, subject to lawful exceptions.
14.5 Customer-support records
Generally retained for up to 3 years after the matter is closed, unless a longer or shorter period is justified.
14.6 Complaints and legal disputes
Generally retained for up to 6 years after closure where reasonably necessary for legal claims, subject to the circumstances.
14.7 Financial and tax records
Where records must be retained for legal, tax or accounting reasons, generally retained for 6 years or another period required by applicable law.
14.8 Affiliate and transaction-attribution records
Generally retained for up to 6 years where reasonably necessary for accounting, fraud prevention, contractual reconciliation or legal claims.
Data not required at identifiable level may be aggregated or anonymised earlier.
14.9 Security logs
Generally retained for between 30 days and 12 months, depending on the log’s purpose and security need.
14.10 Analytics data
Retained according to configured provider settings and our operational needs. We aim to select proportionate retention periods.
14.11 Backups
Deleted data may remain in protected backups for a limited period until backup cycles overwrite it. Access is restricted and backup data is not ordinarily restored except for continuity or disaster-recovery purposes.
We will periodically review retention.
15. Data Security
We use appropriate technical and organisational measures designed to protect personal information.
Measures may include:
- authenticated access
- access controls
- encrypted transmission
- cloud security
- role-based access
- logging
- secure development practices
- database rules
- restricted administrative access
- backups
- monitoring; and
incident-response procedures.
However, no internet-connected system is completely secure.
You should:
- use a strong password
- protect your device
- avoid sharing credentials
notify us of suspected unauthorised access.
16. Data Breaches
Where a personal-data breach occurs, we will assess it under applicable law.
Where legally required, we will:
- notify the Information Commissioner’s Office; and/or
notify affected individuals.
17. Your Data-Protection Rights
Depending on the circumstances, UK data-protection law may give you rights including:
17.1 Right of access
You may request a copy of personal information we hold about you.
17.2 Right to rectification
You may ask us to correct inaccurate or incomplete information.
17.3 Right to erasure
You may ask us to delete personal information in circumstances provided by law.
This right is not absolute.
17.4 Right to restriction
You may ask us to restrict processing in certain circumstances.
17.5 Right to data portability
Where applicable, you may request certain information in a structured, commonly used and machine-readable format and may have rights concerning transmission to another controller.
17.6 Right to object
You may object to certain processing based on legitimate interests.
17.7 Rights concerning direct marketing
You may object to direct marketing at any time.
17.8 Rights concerning automated decision-making
You may have rights where a solely automated decision produces legal or similarly significant effects.
17.9 Right to withdraw consent
Where processing relies on consent, you may withdraw it at any time.
Withdrawal does not affect the lawfulness of processing before withdrawal.
18. How To Exercise Your Rights
Contact:
- bumpbuy360@outlook.com
Please state clearly what you are requesting.
We may request information reasonably necessary to verify identity.
We generally aim to respond within the time required by applicable law.
We will not normally charge a fee, although the law permits fees or refusal in limited circumstances involving manifestly unfounded or excessive requests.
19. Complaints
We would appreciate the opportunity to address privacy concerns directly.
Contact:
- bumpbuy360@outlook.com
You also have the right to complain to the UK data-protection regulator, the Information Commissioner’s Office.
- Information Commissioner’s Office
Your right to complain to a regulator is not affected by first contacting us.
20. Children
The App is intended for adults aged 18 and over.
We do not knowingly intend to offer user accounts directly to children.
If we learn that a child’s personal information has been collected inappropriately, we will take reasonable steps to investigate and delete it where required.
Information entered by an adult about an expected baby or child is treated as information provided by the adult account holder and will be handled according to applicable law.
21. Third-Party Links
When you follow a link to a third party, that party may independently collect personal information.
Examples include:
- retailers
- scan providers
- course providers
- clinics
- affiliate partners
- app stores
authentication providers.
Their privacy policies apply to their independent processing.
We encourage you to review them.
22. Apple And Google Sign-In
If you choose a third-party sign-in method, the provider may process information under its own terms.
Depending on the method and permissions, we may receive:
- account identifier
- name
- email address
- profile information
authentication token.
We will use the information to provide and secure your account.
23. Marketing Communications
Where available, we may send:
- product updates
- offers
- promotional communications
- newsletters
partner offers.
We will obtain consent where required.
You may opt out using:
- an unsubscribe mechanism
- account settings where available; or
Opting out of marketing does not necessarily stop essential service communications.
24. Special-Category Data And Marketing
We do not intend to use pregnancy or health-related special-category information to target direct marketing unless we have identified a lawful Article 6 basis, a valid Article 9 condition and complied with applicable PECR requirements.
This is important because the ICO specifically notes that using special-category information for direct marketing requires both a lawful basis and a special-category condition.
25. Changes Of Business Ownership
If Fitflick Ltd or Bump Buy 360 is involved in:
- merger
- acquisition
- investment
- restructuring
- sale
- insolvency process
- transfer of assets,
personal information may be disclosed or transferred where lawful.
We will take appropriate steps to protect information and provide notice where required.
26. Changes To This Privacy Policy
We may update this Privacy Policy to reflect:
- legal changes
- regulatory guidance
- new features
- new partners
- new technologies
- new processing activities
business changes.
Material changes may be communicated through:
- the App
- an in-app notice
another appropriate method.
Where new consent is legally required, we will request it.
27. Contact Details
For privacy enquiries or rights requests:
- Fitflick Ltd trading as Bump Buy 360
- Email: bumpbuy360@outlook.com
- Registered office: 14 Whitehurst Road, Cheadle, Staffordshire, ST10 1FU
- Company number: 17031125