Privacy policy
Version: 11 September 2026.
This policy covers Bondry Web accounts, purchases, contact and support, and licensing, update and download services. Bondry, based in Brazil, is the controller for these activities. Contact privacy@bondry.org, use a support ticket or the contact form. Email and the form are available without an account.
Your self-hosted community is a separate environment. Its operator decides how member data is used and must provide its own privacy information. A software purchase does not appoint us to host or routinely process that database. Information you choose to send for support is covered here.
1. Information and sources
- Account: name, email, account identifier, language, verification status, password hash and security events. Two-factor secrets and recovery codes, when enabled, are stored encrypted. Account passwords are not stored in readable form.
- Purchases: order and item details, amounts, currency, tax information when applicable, payment references, status and refund or dispute information. Stripe receives checkout information and returns transaction information. Our application does not collect or store full card numbers or card security codes.
- Licensing and downloads: serial, product, domains, activation history, tokens and identifiers, update entitlement, version, download records and technical installation information. Depending on the client version, host information may include hostname, PHP version, operating system and installation fingerprint.
- Marketplace claims: a submitted Envato purchase code and purchase information returned by Envato, including buyer identifier, item, purchase date and support expiry.
- Contact and support: name, email, subject, messages, attachments, linked order or license, correspondence and case management information. Send redacted examples instead of full community databases or credentials.
- Service and security records: IP address, user agent, session identifiers, request path, date, response status, sign-in history and sensitive account actions, originating from your browser, installation, our infrastructure and security controls.
Required account, payment and license information enables the relevant account, purchase or authorization. Without it, we may be unable to provide that feature. Optional support details should be limited to what the request needs.
2. Purposes and legal grounds
Where a legal basis is required, we process information to perform a contract or take steps you request before purchase: account access, delivery, license verification, downloads, support and transactional messages. We meet legal obligations concerning accounting, tax, lawful authority requests and consumer remedies.
Where legally available, legitimate interests support service security, fraud and unauthorized-use prevention, incident investigation and establishing or defending claims. We consider necessity and impact on individuals. Managing a relationship with the organization you represent may also rely on these interests.
If an optional activity requires consent, we request it separately and allow withdrawal. Accepting terms or this policy is not consent to all processing. Withdrawal does not invalidate earlier lawful processing or prevent processing with another applicable ground.
3. License checks and automated controls
Your installation contacts our API for activation, deactivation, validation, updates and Designer library access. It sends license credentials and technical information; routine endpoints do not request member lists, posts or the community database. A domain, hostname or diagnostic message can nevertheless identify a person.
Rules check signatures, domains, revocation, payment status and update expiry. They can deny activation or downloads, restrict requests or revoke entitlements following refund or dispute events. We do not use them to profile community members for advertising. Contact us for an explanation, correction and human review of an incorrect or significantly affecting result, and to present your position.
4. Recipients
Authorized personnel and providers access information as needed for hosting, storage, transactional email, maintenance, security and support. Backup providers may hold copies of the same categories under restricted access. Access permissions are limited according to the sensitivity of the information and the purpose of the service.
Stripe processes payments under its Privacy policy and applicable contractual roles. Envato receives codes you ask us to verify and processes marketplace data under its Privacy policy. Hosting, email and backup providers operate under arrangements appropriate to their roles. Ask our privacy contact for further recipient information.
Necessary disclosures may be made to professional advisers, competent authorities or parties to a business transfer, with a lawful basis, confidentiality and appropriate limits. We do not sell personal information or share it for cross-context behavioral advertising. Bondry Web does not run third-party advertising or analytics scripts.
5. International processing
Providers may process data outside your country. Transfers requiring safeguards must use a lawful mechanism, such as an applicable adequacy decision or approved contractual clauses, with additional protections where required. Depending on the transfer, relevant rules can include the GDPR, UK data protection rules and Brazil's LGPD and ANPD transfer regulation. Using the website is not consent to an otherwise unlawful transfer.
Contact us for relevant locations, recipients and a copy or explanation of applicable safeguards, subject to protection of confidential information. We do not assert that every destination has an adequacy decision or any particular provider is certified.
6. Retention and account closure
Account and license records remain as needed to administer your account and continuing license rights. Orders, tax records and evidence may remain after closure for legal duties, disputes or applicable limitation periods. Contact messages, tickets, attachments and security records are retained as needed for their purpose, follow-up and legitimate legal or security needs; duration depends on the record and issue.
Application API request logs are scheduled for deletion after 30 days. This does not describe hosting access logs, audit records or evidence preserved for an incident or legal obligation. Expired sessions and temporary verification records are cleared through operational cleanup. Backup copies follow rotation schedules and may remain until overwritten; restored data must respect recorded deletion restrictions.
Requesting closure or erasure does not automatically forfeit a paid license simply for exercising privacy rights. We will explain any minimum records needed to maintain it and any service consequences before acting on your instructions. Legally required records or evidence necessary for legitimate claims may remain with restricted use. We do not delete content on your server.
7. Your rights
Applicable law may entitle you to confirmation and access, correction, erasure, restriction, portability, sharing information, objection to legitimate-interest processing, withdrawal of consent and review of automated decisions. Conditions and lawful exceptions apply; we will explain refusals or limitations and ways to challenge them.
Write to our privacy address or use the contact form. We may require proportionate identity verification or proof of a representative's authority. Do not send identity documents unless specifically requested through an appropriate channel. Requests are normally free and handled within applicable legal deadlines; we will explain any lawful extension or exception.
You may complain to your competent authority, including ANPD in Brazil, an EEA supervisory authority or the UK ICO where applicable. Applicable US state laws may also provide rights to know, correct, delete, obtain a copy, appeal and opt out of sale, sharing, targeted advertising or certain profiling. We do not conduct those advertising activities and do not discriminate for exercising protected rights.
8. Cookies and preferences
We use cookies for authentication and request security, and to remember theme and language. Language preference lasts up to one year; other durations depend on the cookie and session settings. This website has no advertising or audience-tracking cookies. Hosted payment or marketplace pages may use cookies under their own policies.
You can clear or block cookies in your browser. Blocking necessary cookies may prevent sign-in, checkout or forms; clearing preference cookies resets choices. We do not interpret Do Not Track as permission to track, and there is no sale or advertising sharing here for an opt-out signal to disable. Future nonessential tracking requiring consent must be disclosed and obtain it before activation.
9. Security, children and changes
Controls include access restrictions, password hashing, encrypted authentication secrets, request verification and security logging. No service is completely secure. Report suspected unauthorized access promptly. Where a breach requires notification, affected people and authorities will be notified as the law requires.
Our purchasing and account services are intended for people with legal capacity to contract, not directed at children. Contact us about a child's data provided without legally required authorization. Independent community operators set their own age rules and notices.
The date above identifies this version. Material changes will receive appropriate notice before new processing where required, and fresh consent where necessary. A policy change alone does not authorize incompatible use of previously collected data.