Privacy Policy
Clear information about your data, your choices, and our hospitality workspace.
Updated October 7, 2026. This notice describes the current website and Pinheads pilot. Commercial customer agreements are being prepared. Contact Bondidos Support for questions about the operating company or your data.
Scope & Responsibility
This notice covers the Bondidos Studio public website and explains the intended relationship with its products. A company using a product determines what employee, menu, guest, and event information it enters. Product-specific agreements and privacy notices must identify the responsible legal entity and its role before customer activation.
Information You Provide
A workspace or demo request contains your name, email address, company, product interest, display range, and any message you submit. The hosted website stores those details in private server storage and sends the request to Bondidos Support through Resend. It also sends you a receipt confirmation. Submitting does not create a paid account or collect card information; these messages are transactional, not a marketing subscription. Please avoid sensitive personal information in the message field.
Your browser can store your cookie choice and, only when you allow preferences, your chosen appearance. The server temporarily counts requests by network address to limit repeated submissions. Server diagnostic logs may contain technical errors. This public website does not install analytics or advertising trackers.
Product Workspace Information
Product workspaces may contain brand assets, menus, employee identities and permissions, room designs, schedules, authorized event-integration data, and player identifiers or check-in information. Provide only information needed for your operation and confirm you have permission to upload content. A company administrator controls authorized workspace access.
Connected Sign Studio services use Cloudflare for access protection and Render for hosting. Authorized Tripleseat connections retrieve event and location data. Bondidos accounts store names, email addresses, password hashes, workspace memberships, and permissions. Admin roles require an authenticator app. Authenticator secrets are encrypted, recovery codes are hashed, and active login sessions are stored for account security. Never upload passwords or recovery codes as workspace content.
Why Information Is Used
Workspace and demo requests are used to assess and respond to your setup needs. Product information supports the features your company requests, account access, authorized integrations, display delivery, troubleshooting, and service security. This website does not sell personal information, use advertising audiences, or reuse workspace requests for AI training.
Sharing & Integrations
Do not connect a provider unless your company authorizes the access. The current service uses Render for hosting and private storage, Cloudflare for DNS, network protection, internal access protection and support-email forwarding, and Resend for transactional email. Authorized Sign Studio connections use Tripleseat for event and location data. These providers receive the information needed for the relevant function. Information may also be provided when legally required or when necessary to address abuse. Commercial customer agreements and any applicable international-transfer terms must be finalized before onboarding additional companies.
Security & Data Minimization
The hosted website limits request size and repeated submissions, rejects cross-origin account changes, and restricts direct access to saved records. Login cookies use HTTPS, HttpOnly and SameSite protections. Admin roles require MFA, and sessions are revoked after a password reset. The current Pinheads pilot uses a private backup before this release. Additional customer onboarding requires company isolation, documented incident handling and operational backup and retention procedures. No system can promise absolute security; this draft does not claim an independent security certification.
Retention & Deletion
Submitted requests and workspace records currently remain in private server storage until the operator removes them; automatic record-retention expiry is not implemented. Transactional email jobs may retry after a provider failure. Accepted email-job payloads are cleared; failed jobs and provider delivery records may remain for troubleshooting. Browser consent choices expire after 180 days. Appearance preferences remain until you remove them, withdraw preference consent, or clear browser data. Before commercial customer onboarding, a documented retention schedule must cover workspace records, audit history, integration data, and backups.
Your Choices & Requests
You can reject optional preference storage and change your choice through Cookie Settings. You can request information about, correction of, or deletion of your submitted request using the contact below. We may ask you to verify your identity and authority over a company workspace. Applicable rights and exceptions depend on your location and the role of the company operating the workspace; the website does not automate those requests.
Do not submit information about children. This business website is intended for adults acting for their organizations.
Changes & Contact
Material changes should be reflected in a dated notice and, when required, a new choice or separate notification. A policy change does not retroactively authorize a new use of information.
For privacy questions, data requests, or agreement questions, contact [email protected]. Do not send passwords, payment-card details, or sensitive guest information by email.
