Privacy notice
How BunStack handles personal data
Version 2026-09-13. Applies during the pilot.
BunStack is a platform for running an online shop. This notice covers two things: the data BunStack holds about you as a merchant, where BunStack decides how it is used, and the data in your shop — products, orders, customers — which BunStack processes on your behalf and on your instructions.
01Who is responsible
BunStack is the controller for the data about your account. Reach us at support@bunstack.co.
For the data in your shop you are the controller and BunStack is your processor. The pilot terms set out what that means.
02What BunStack stores about you
When you create an account BunStack stores your e-mail address and a hash of your password — the password itself is never stored — the company details you enter under Settings, the shops you set up with their domains, and the team members you invite.
As you work in the admin BunStack keeps an audit log of what was changed, by whom and when, and a record of the notifications sent to you. Mail you send to support@bunstack.co stays in that mailbox.
The basis for this is the pilot agreement with you (article 6.1 b GDPR) and BunStack's legitimate interest in keeping the platform secure and every change traceable (article 6.1 f).
03The data in your shop
Products, orders, customers, reviews and the other records in your shop belong to you. BunStack stores and processes them only to run your shop, as your processor under the pilot terms. Your customers exercise their rights through you; the customer page in the admin exports or erases one customer's record on request.
Providers you connect yourself — Kustom for checkout, Sendify for shipping — receive the order data they need under your own agreement with them. BunStack passes it on because you connected them.
04Where the data is kept
The database, sign-in and file storage run in Supabase's project in AWS Stockholm (eu-north-1). Supabase's edge functions, which handle checkout and outgoing mail, run close to the caller and keep nothing themselves; what they store goes to the Stockholm project.
bunstack.co, the shops and the designer are hosted by Vercel. Their server code runs in Stockholm (arn1). Static files — pages, scripts, images, fonts — and the layer that routes a request to the right shop are served from Vercel's global network, as for every site on Vercel. bunstack.co, the shops and the designer serve their fonts themselves, not from Google.
Supabase and Vercel are US companies. Both work under data processing agreements that include the EU standard contractual clauses; their support staff and operational logs can involve people and systems outside the EU.
05Who else processes the data
BunStack uses these providers and no others. It sells no data and runs no advertising or analytics trackers on bunstack.co.
- Supabase, Inc. — database, sign-in and the mail sign-in sends (address confirmation, password reset), file storage and edge functions. Project in Stockholm (eu-north-1).
- Vercel, Inc. — hosting for bunstack.co, the shops and the designer. Server code in Stockholm (arn1); static files on a global network.
- Resend, Inc. — delivers the other mail the platform sends: the welcome mail, order confirmations, notifications. Resend receives the recipient's address and the message and keeps a sending log. Resend is a US company; the transfer rests on the EU standard contractual clauses in its data processing agreement.
- Sentry (Functional Software, Inc.) — error reports from the admin, the designer and the shops. In the admin and the designer this includes session replays with all text masked before it leaves the browser; in a shop, session replay and performance data are added only after the visitor accepts statistics cookies, and until then Sentry receives error reports only. Used only when error reporting is switched on. Sentry is a US company; the transfer rests on the EU standard contractual clauses in its data processing agreement.
06How long it is kept
Your account data stays while the account exists and is deleted when the pilot ends and you have exported what you need. Audit log entries are deleted automatically after your plan's retention window.
Shop data stays as long as the shop does. When a customer asks to be erased, the customer page removes the personal data from the customer record and their orders and keeps the order lines bookkeeping law requires.
Supabase takes a daily backup of the database and keeps them for about a week; a deleted record can remain in those backups until they expire. Files you upload, such as product images, are not part of that backup.
07Cookies on bunstack.co
bunstack.co sets no tracking cookies. Signing in stores a session cookie so you stay signed in across bunstack.co and the designer; the sign-up wizard keeps what you have typed in your browser's session storage until the account is created. The shops have their own cookie banner and cookie policy, set by each merchant.
08Your rights
You can ask to see, correct, export or delete the data BunStack holds about you, and object to processing that rests on legitimate interest. Write to support@bunstack.co; BunStack answers within a month. You can also complain to the Swedish Authority for Privacy Protection (IMY) or to the supervisory authority in your own country.
09Changes
When this notice changes, the version date at the top changes and account holders are told by mail before the change applies.
Questions
Write to support@bunstack.co.