Privacy Policy
Last updated: 29 May 2026
Boombiz ("we", "us") is operated by Digital Orca Limited. This policy explains what data we collect when you use Boombiz at getboombiz.com, how we use it, and the choices you have. We never sell your data.
Data we collect
To run your Boombiz store we collect:
- Account details — your name, email address, phone number (optional), and password hash.
- Business profile — business name, address, logo, and the products, customers and orders you create.
- Usage and device data — IP address, browser/user-agent, and basic activity logs used for security, rate-limiting, and abuse prevention.
Sign in with Google — Google user data
Boombiz uses Google OAuth (Sign in with Google) to let you create an account and sign in. We request only Google’s default sign-in scopes: openid, email, and profile.
Google user data we access: your Google account’s email address, name, profile picture URL, locale, and a stable Google account identifier (the OpenID sub claim).
How we use that data:
- To verify your identity and create your Boombiz user account, or sign you back in to an existing account.
- To match a Google sign-in to your existing email/password Boombiz account when the verified email matches, so you have one account rather than two.
- To display your name and profile picture inside your Boombiz dashboard.
- To send essential service emails (account, billing, security) to your Google email address.
How we store it: Your Google email, name and Google account identifier are stored in our Boombiz account systems for as long as your account exists. We may also store the short-lived OAuth access token and refresh token Google issues so that future sign-ins work; we do not currently use these tokens to call any other Google APIs.
How we share it: We do not sell, rent, or share Google user data with any third party for advertising, marketing, or any purpose unrelated to operating Boombiz. We do not transfer Google user data to AI/ML models for training. We share data with infrastructure providers only as strictly needed to operate the service, under their own contractual confidentiality and security terms.
Limited Use compliance: Boombiz’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access: You can disconnect Boombiz from your Google account at any time at myaccount.google.com/permissions, or delete your Boombiz account from the dashboard to remove the stored Google profile data.
Customer data
Customer information you collect through your store (your shoppers’ names, contact details, orders) belongs to you. You are the data controller for that information and are responsible for handling it lawfully (e.g. NDPR compliant).
Payments
Card and bank payments are processed by Paystack and Flutterwave. We never see or store full card details.
Data retention & deletion
We retain your account and business data for as long as your account is active. You can request deletion of your account and associated Google profile data by emailing [email protected]; we will action verified requests within 30 days, subject to legal retention obligations.
Contact
Privacy questions: [email protected]
Digital Orca Limited — operator of Boombiz.