bunk3r

Privacy Policy

Last updated 30 August 2026

Bunk3r is a sales-operations dashboard used by businesses to see their own sales and marketing data in one place. This policy explains what we handle, why, and how to have it removed. It covers the Bunk3r application at app.bunk3r.ai and this website.

Who we are

Bunk3r is operated as a sole proprietorship. For any privacy question, or to exercise any right described here, write to support@bunk3r.ai.

What we handle

Account data. The email address of each person invited to an organisation, their role, and authentication records. Passwords are never visible to us — authentication is handled by our identity provider, and a person sets their own password through a link we cannot read.

Business data from systems you connect. When an organisation connects a source, we read data belonging to that business:

  • CRM (Close): leads and their contact details, opportunities, booked meetings, call and message activity, and the users on the account.
  • Payments (Stripe): charges, invoices, refunds and disputes.
  • Advertising (Meta): spend, impressions, clicks and reach, at account and ad level. Read only. We do not create, modify or pause campaigns, and we do not request permission to do so.
  • Attribution (Hyros): click and lead attribution records.

This means we handle contact details of an organisation’s own leads and customers. Bunk3r is a processor of that data on behalf of the business that connected it; that business decides what is connected and remains its controller.

What we do not do

  • We do not sell data, and we do not share it with advertisers or data brokers.
  • We do not use one organisation’s data to serve another, ever.
  • We do not use your data to train machine-learning models.
  • We do not run advertising or third-party tracking inside the application.

Platform data from Meta

Data obtained through the Meta Marketing API is used only to report on the connected business’s own advertising performance — return on ad spend, cost per lead, and spend beside revenue — inside that business’s own dashboard. It is not combined across customers, not sold, and not transferred to anyone except the infrastructure providers listed below acting on our behalf. If a connection is removed, the associated advertising data is deleted with it.

Where it is kept

Data is stored in a managed PostgreSQL database hosted by Supabase, with background processing on Railway and the application served by Vercel. These providers process data on our behalf under their own agreements. Data is held in the United States.

Source credentials — API keys and access tokens — are encrypted before storage using an envelope scheme, so the database never holds a usable credential on its own. Every decryption is recorded with the reason it happened. Organisations are isolated from one another in a single place in the code, so a request can only ever read the organisation it was authorised for.

How long we keep it

Business data is kept for as long as the organisation’s account is open, because the product’s purpose is historical comparison. When an organisation closes its account, its data is deleted within 30 days. Disconnecting a single source deletes the data from that source without affecting the others.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete personal data about you, to object to processing, or to complain to a supervisory authority. Write to support@bunk3r.ai and we will respond within 30 days.

If you are a lead or customer of a business that uses Bunk3r rather than a Bunk3r user yourself, that business controls your data. We will pass your request to them and assist them in answering it.

See Data deletion for how to have data removed.

Children

Bunk3r is a business tool and is not directed at anyone under 18. We do not knowingly handle data about children.

Changes

If this policy changes materially we will update the date above and notify account owners by email before the change takes effect.