This policy explains what personal data we process when you use bambam (the “Service”), why, on what legal basis, and what rights you have. We built bambam to be privacy-first: public bio pages and links are measured without cookies and without storing IP addresses, and we serve fonts and scripts from our own server wherever possible. Last updated: June 2026.
Peer Dicken Media
Kirchentoft 4, 24983 Handewitt, Germany
Email: moin@pd.media
We have not appointed a Data Protection Officer, as we are not legally required to. For any privacy question, write to the address above.
To use the editor you create an account. We process: your email address, your name/display name, an encrypted-at-rest (hashed) password, and — if you enable them — two-factor authentication secrets and passkeys (WebAuthn credentials). We also store account settings such as your plan status and timestamps for consent and onboarding.
Purpose: creating and securing your account, providing the Service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR); for security features, our legitimate interest in protecting accounts (Art. 6(1)(f) GDPR).
In the editor you create short links, bio pages and QR contact cards (vCards), including the text, images, links and contact details you add. We host and display this content to provide the Service (Art. 6(1)(b) GDPR).
Please note: a QR contact card may itself contain personal data (e.g. a name, phone number, email address). If you publish data about other people, you are responsible for having the right to do so. You keep all rights to your content; you grant us only the limited right to host, process and display it to run the Service.
Views and clicks on public pages (bio pages, short links, QR cards) are measured purely statistically. No personal data is stored and no cookies are set:
Legal basis: our legitimate interest in anonymous statistics (Art. 6(1)(f) GDPR). Because no information is read from or stored on your device and no cookies are set, no consent under § 25 TDDDG is required — and no cookie banner.
Public pages set no cookies. In the logged-in area (account/editor) we use a single, technically necessary session cookie to keep you signed in and to secure forms against cross-site request forgery. Legal basis: strictly necessary storage (§ 25(2) TDDDG) and our legitimate interest in a secure, functioning login (Art. 6(1)(f) GDPR). A cookie banner is therefore not required.
When a short link is opened, the click is counted anonymously as described in section 5 and you are immediately redirected to the target URL. Password-protected links ask for the password each time and do not set a cookie.
Paid plans are sold and processed by Paddle.com Market Ltd (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom) as the Merchant of Record — i.e. Paddle is the seller of record and your contracting party for the purchase, and handles payment processing, invoicing, VAT/sales tax and refunds.
When you buy or manage a plan, the data required for the transaction is provided directly to Paddle, and we also exchange identifiers and your email address with Paddle’s API to create and manage your customer and subscription record (e.g. on checkout, cancellation, withdrawal or refund). We receive from Paddle only the data needed to give you access (a customer and subscription identifier, plan, status, billing dates and amounts), which we store to manage your subscription. We never see or store your full card details. Paddle acts as an independent controller/seller for the payment under its own privacy policy. This may involve a transfer to countries outside the EU/EEA, safeguarded by Standard Contractual Clauses and/or an adequacy mechanism. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and, for invoice retention, legal obligation (Art. 6(1)(c) GDPR; retention is handled by Paddle as seller of record).
When you start a paid plan, we record that and when you agreed to the Terms and to the immediate start of the service (waiving the right of withdrawal), together with the plan and the price identifier. We do not store your IP address for this. Legal basis: our legitimate interest in being able to evidence a validly concluded contract and consent (Art. 6(1)(f) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR). See also our Right of withdrawal.
We send service emails (e.g. email verification, password reset, welcome and order confirmation, withdrawal and cancellation confirmations, abuse-report notices). These are sent from our own mail server on the hosting described in section 11 (Hetzner, Germany); we do not use a separate external email-delivery service. We process your email address and the message content for this purpose (Art. 6(1)(b) GDPR). We do not send marketing newsletters without your separate consent.
The application and database are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers in Germany. Hetzner acts exclusively as our processor under a data processing agreement (Art. 28 GDPR).
When a public bio page loads, no third-party content is fetched — fonts, scripts and icons are served from our own server (no Google Fonts CDN or similar). Embedded media (e.g. Spotify, YouTube, an OpenStreetMap map) loads only after the visitor actively clicks the placeholder (“click-to-load”). Only then is a connection to that provider established, only then may that provider receive the visitor’s IP address, and that provider’s own privacy terms apply.
To make building your page convenient, when you add certain blocks our server fetches information from the relevant third party using the URL or address you entered:
These requests go out from our server, so your page visitors’ IP addresses are not exposed to these providers. However, the content you entered (the link or address) is transmitted to the respective provider and processed under its own terms. Legal basis: performance of the contract / our legitimate interest in providing these editor features (Art. 6(1)(b)/(f) GDPR). If you’d rather not share a particular link or address, simply don’t add that block.
Inside the logged-in editor and dashboard, all scripts, styles, fonts and icons are served from our own server. We use no third-party content delivery network, and no third party receives your IP address there. (The convenience lookups described in section 13 still run on our server when you add an embed, event or map block.)
If someone reports a link or page through our reporting form, we store the report (the reported address, the reason, an optional message and an optional reporter email) to review and act on it. Legal basis: our legitimate interest in keeping the platform safe and compliance with legal obligations regarding illegal content (Art. 6(1)(f) and (c) GDPR).
If you join the waitlist or receive an invitation, we process your name and email address to manage early access (Art. 6(1)(b)/(f) GDPR). You can ask us to remove you at any time.
A QR contact card can offer a “Share your contact back” option. If you choose to use it, you enter your name and one contact detail (an email address or a phone number) and tick a consent box. We then store that entry and send it to the holder of that card so they can get in touch with you.
Likewise, a bio page can offer a “lead magnet” (you enter your email address to receive a file or link). If you choose to use it, you enter your email and tick a consent box; we store that email so the owner of the bio page can follow up and so the download can be released to you.
Who is responsible: the card holder / bio page owner is the controller for the contact you share — they decide to collect it and how to use it to reach you. bambam acts only as the technical provider (processor) that stores the entry and forwards it to that person on their behalf (Art. 28 GDPR). For our own spam protection we additionally limit how often the form can be submitted.
What we store: only the name and the single contact detail (contact exchange) or the email address (lead magnet) you typed, plus the time you gave consent. We do not store your IP address and set no cookie. Your entry is not sold, not added to any newsletter, and not used for anything beyond delivering it to that creator.
Legal basis: your consent (Art. 6(1)(a) GDPR) for sharing the data with the creator; the creator’s legitimate interest in following up (Art. 6(1)(f) GDPR); and our legitimate interest in preventing abuse of the form (Art. 6(1)(f) GDPR). You can withdraw consent and ask for deletion at any time. The creator can delete individual entries or all of them in their dashboard; you may also contact them directly, or write to moin@pd.media and we will pass the request on.
You can deactivate your account at any time (your public links, pages and cards go offline; nothing is deleted; you can reactivate it whenever you like), or delete it permanently in the settings. On deletion we remove your account and the content tied to it; if you have an active paid plan, the subscription is canceled and the account is removed at the end of the paid period. Note that invoices and transaction records are retained by Paddle as seller of record to meet tax and accounting obligations, independently of your account. Residual copies may persist briefly in encrypted backups before being overwritten.
Categories of recipients of personal data are: our hosting provider (Hetzner, EU, processor); Paddle (payments, seller of record); the holder of a QR card you choose to share your contact with (section 17); and, for the convenience lookups in section 13, the respective content providers (e.g. the embed provider you chose, or OpenStreetMap/Nominatim). Our hosting, mail and geo lookup stay within the EU. Transfers to third countries may occur via Paddle and the section-13 providers; these are safeguarded by Standard Contractual Clauses and/or an applicable adequacy decision.
Under Art. 15–22 GDPR you have the right of access, rectification, erasure, restriction, objection and data portability, and the right to withdraw consent with future effect. For our anonymous reach measurement there is generally no data attributable to you. To exercise a right, contact moin@pd.media.
You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
We do not use automated decision-making producing legal effects concerning you (Art. 22 GDPR). Our reputation/safety checks on submitted target URLs operate on the link, not on you as a person.
We may update this policy to reflect new features or legal requirements. We will publish the current version here and, for material changes, notify you by email or in the app. Questions: moin@pd.media.