Privacy Policy
1. Summary
BOOM (“BOOM”, “we”, “us”) is a service that helps a group of people send messages from their own phones at the same moment. Guests never create an account. We collect the smallest amount of information needed to run a Boom, we do not sell personal information, and we never read or store the messages you send from your own device. This policy explains what we collect, why, how long we keep it, who we share it with, and the choices you have.
2. Who is responsible for your data
BOOM is operated by Dan B. (“the operator”) as the data controller for the information described here. You can reach us at help@sendaboom.com for any privacy question, access request, or deletion request. If you are contacting us on behalf of someone else, please tell us so in your message.
3. Information we collect
3.1 Information organizers give us
- Email address — used to send a one-time sign-in link (“magic link”) and to send you the private links to Booms you create. We do not store a password.
- Boom details — the title, the first name or nickname of the person the Boom is for, the occasion, and the date, time and time zone you choose.
- Optional notes — anything else you type into a Boom description. Please do not put sensitive information there.
3.2 Information guests give us
- First name or nickname — so the organizer can see who has committed.
- Phone number (optional) — used only to identify duplicate check-ins and, if you ask for it, to send you a reminder about the Boom. We do not use it for marketing.
- ZIP or postal code (optional) — converted to the approximate center of that postal area so the organizer can see a map of roughly where the Boom is going off. We do not collect or derive street-level location, and we do not use your device GPS.
3.3 Information collected automatically
- Server and security logs — IP address, user agent, timestamps, and the pages or endpoints requested. Used to keep the service available and to detect abuse.
- Aggregate product counts — for example how many people opened a Boom link or tapped a button. These counts are not used to build a profile about you.
- Essential storage — we use local storage in your browser to remember an in-progress Boom draft and your sign-in session. We do not use advertising cookies or third-party ad-tracking pixels.
3.4 What we never collect
- The contents of the messages you send — those go through your own phone, not through us.
- Your contacts, photo library, camera roll, or address book.
- Precise GPS location, government identifiers, or payment card numbers.
4. Why we use your information (and our legal bases)
- To provide the service — creating a Boom, showing the countdown in your local time, recording commitments, and building the recap. Legal basis: performance of a contract.
- To send service email — sign-in links, organizer links and event reminders. Legal basis: performance of a contract or your consent where required.
- To keep the service safe — rate limiting, abuse prevention, and debugging. Legal basis: legitimate interests.
- To improve the product — de-identified, aggregate usage counts. Legal basis: legitimate interests.
- To comply with law — responding to lawful requests and enforcing our terms. Legal basis: legal obligation.
5. How we share information
We do not sell personal information and we do not share it for cross-context behavioral advertising. We share it only:
- With the organizer of a Boom you join — your first name, whether you committed, and an approximate area derived from your postal code.
- With service providers (processors) acting on our instructions — hosting and application delivery, managed database and authentication, transactional email delivery, and postal-code-to-coordinates lookup. They may only process data to provide those services to us.
- For legal reasons — when required by applicable law, valid legal process, or to protect the rights, property or safety of users or the public.
- In a business transfer — if the service is acquired or transferred, information may move with it, subject to this policy.
6. International transfers
BOOM is operated from the United States and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses for transfers out of the EEA, UK or Switzerland.
7. How long we keep information
- Boom and guest records — kept while the event is upcoming and for up to 90 days afterwards so the recap works, then deleted or de-identified.
- Organizer accounts — kept while your account is active; deleted within 30 days of a verified deletion request.
- Security logs — typically kept up to 90 days.
- Aggregate counts — retained in de-identified form without time limit.
An organizer can delete a Boom at any time from their control room, which removes the associated guest entries.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your information; to object to or restrict certain processing; to withdraw consent; and to not be discriminated against for exercising these rights. If you are in California, this includes the rights to know, delete, correct, and opt out of sale or sharing (we do neither). If you are in the EEA, UK or Switzerland, you also have the right to complain to your local supervisory authority.
To exercise a right, email help@sendaboom.com from the address you used, or include enough detail about the Boom so we can find your entry. We respond within 30 days (45 days in California where permitted) and may need to verify your request. You may use an authorized agent.
Guests: giving a phone number or postal code is always optional. You can commit to a Boom with just a first name.
9. Security
We use encryption in transit (HTTPS), row-level access rules on our database, unguessable random tokens for Boom links, and passwordless sign-in to reduce credential risk. No system is perfectly secure, so please keep your organizer link private — anyone who has it can view that Boom’s control room. If we learn of a breach affecting your information, we will notify you and any regulator as required by law.
10. Children’s privacy
BOOM is not directed to children under 13 and we do not knowingly collect their personal information. If you believe a child under 13 submitted information, email us and we will delete it promptly. Users between 13 and 18 should only use BOOM with a parent or guardian’s involvement.
11. Do Not Track and automated decisions
We do not respond to browser Do Not Track signals because there is no common standard, and we do not use your information for profiling or automated decisions that have legal effects.
12. Changes to this policy
We may update this policy as the product evolves. We will change the “Last updated” date above and, for material changes, give notice in the product or by email before the change takes effect. Continuing to use BOOM after the effective date means you accept the updated policy.
13. Contact
Privacy questions, access requests and deletion requests: help@sendaboom.com.