Privacy policy
Last updated July 17, 2026
Who we are
Bump (bump.build) is operated by Koora Care Pty Ltd, an Australian company. When this policy says "we", it means Koora Care Pty Ltd. For anything privacy related, email support@bump.build.
Bump sells a source-code starter kit. We collect the minimum we need to sell it, deliver it, and run this site. We do not sell personal information, and we do not run advertising networks on this site.
What we collect and why
- GitHub username. Collected at checkout so we can generate your private copy of the kit and invite that account to it. It is stored in our purchase records, mirrored to your Stripe customer record, and appears in the name of the repository we create for you and in the license stamp inside it. We share it with GitHub to make the delivery.
- Email address. Collected by Stripe during checkout. Stripe uses it for your receipt; we use it to send your delivery email through Resend. If you join the waitlist, we store the email you enter, along with the page you signed up from, the referring page, and your browser's user-agent string, so we can tell you when something ships and understand where signups come from.
- Payment details. Processed entirely by Stripe on Stripe-hosted checkout pages. Your card number never touches our servers and we never store it. We keep the purchase records Stripe gives us: a checkout session ID, a Stripe customer ID, the GitHub username, the generated repository name, and a license ID.
- Analytics. We use PostHog to understand how the site is used. It captures page views, clicks, and form interactions, and uses cookies or browser storage to recognize return visits. Analytics load by default when you visit the site. If you are visiting from the EEA, the UK or Switzerland, we ask first and analytics stay off unless you accept. The notice banner tells you this when you first visit; we do not load any advertising tags. If you want your analytics data deleted, email us.
- Server logs. Our hosting (Vercel) and database (Supabase) keep standard server logs, which include IP addresses. We use them for security, rate limiting, and debugging, not for profiling.
- Support and bug reports. If you email support@bump.build, we keep the correspondence and whatever you choose to include in it so we can help you and honor the promises attached to your purchase.
Where your data lives
Our own database is hosted with Supabase in Sydney, Australia. The services we rely on process data in the United States and other regions where they operate:
- Stripe: payments and receipts.
- GitHub: repository generation and the delivery invite.
- Resend: transactional email.
- PostHog (US cloud): analytics.
- Vercel: site hosting and server logs.
Each of these acts as a processor with its own privacy policy and safeguards. We only pass them the data listed above.
How long we keep it
- Purchase records: for as long as needed to honor your license and security-advisory coverage, and at least as long as Australian tax law requires us to keep transaction records.
- Waitlist entries: until you ask to be removed, or we retire the list.
- Analytics and server logs: per the retention settings of PostHog, Vercel, and Supabase; we do not archive them separately.
- Support email: kept while your license is active so we have context if you come back.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email support@bump.build and we will respond within a reasonable time. Note that we may need to keep purchase records we are legally required to retain, and the license stamp in a delivered repository is part of the product you bought.
We handle personal information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles. If you are unhappy with how we handled a complaint, you can contact the Office of the Australian Information Commissioner (OAIC). If you are in the EEA or the UK, you also have the rights the GDPR and UK GDPR give you, including access, rectification, erasure, and the right to complain to your local supervisory authority; where the GDPR applies, we rely on contract (delivering your purchase) and legitimate interests (running and securing the site) as our legal bases.
Changes to this policy
If we change this policy, we will update this page and the date at the top. If a change meaningfully affects how we handle data from past purchases, we will email buyers.