Kern Platforms Private Limited ("Kern Platforms", "Bump", "we", "us") operates the Bump platform — guest experiences at partner venues (music requests, ordering, games, events, reservations, pickup and delivery) and the business tools those venues, artists and their staff use. This policy explains what personal data we process, why, and the rights you have over it. It applies to everyone who uses Bump: guests ("patrons"), venue owners and staff, and artists.
1. What we collect
If you are a patron
- Account identity — your name and email from Google or Meta sign-in (used only to verify who you are; we never post to your accounts), and your phone number, collected once, used to keep your credits and history attached to you. Your phone number is stored encrypted; day-to-day systems use a one-way coded form of it.
- Activity at venues — song requests, orders and bills, game participation, reservations, reactions and posts you make, and payments (processed by our payment partner; we never see or store your card or UPI credentials).
- Preferences you set — favourite artists, dietary choices, and similar settings, used to personalise your experience.
- Wallet and credits — balances, top-ups, packs, gifts sent and received.
- Friends and shared occasions — if you accept a friend suggestion, we record the connection and the fact that you were out together. Suggestions are only ever generated from occasions you genuinely shared (a split bill, a shared table, a game played together) — never from contact uploads, location tracking, or browsing. Declining a suggestion is permanent, and removing a friend deletes the connection and its shared-occasion records for both of you.
- Delivery details — if you order pickup or delivery, the address you provide, stored encrypted and deleted a short period after the order completes.
If you are a venue owner, staff member, or artist
- Your name, contact details (phone stored encrypted), role, and sign-in identity.
- Operational records tied to your role — bookings, schedules, sales attribution, onboarding records.
- For staff using attendance: whether you clocked in inside your venue's attendance zone. Precise location coordinates are used only to make that check and are deleted when your shift closes — we keep only the in/out result.
- For artists: profile content you choose to publish (photo, bio, performance details).
2. Why we process it
- To run the services you ask for — playing your song, delivering your order, settling a bill, scheduling a shift, managing a booking.
- To personalise your experience at venues you visit.
- To keep the platform safe — fraud prevention, abuse and content moderation, payment integrity.
- To meet legal obligations — tax invoices and financial records.
We collect data with your consent, given when you create your account and when you use specific features. You can withdraw consent by deleting your account (see Your Rights).
3. Who sees your data
- The venue you're at sees your activity at that venue — your requests, orders and bills there, and your name if you've shared it — the same way any restaurant knows its regulars. Venues do not see your activity at other venues, your friends list, or your wallet history.
- Your friends on Bump see what you deliberately share with them — the connection itself, gifts, and shared-occasion records. Nobody you haven't accepted can see anything.
- Service providers that operate under contract with us: payment processing (Razorpay), music playback (Spotify, under the venue's own account), messaging (WhatsApp via Meta, only where you've provided your number for service messages), sign-in (Google, Meta), music metadata (Last.fm), and our hosting and database infrastructure. Each receives only what its function needs.
- Nobody else. We do not sell, rent, or trade personal data, and we do not share it with advertisers.
4. Your rights
- Access — download everything we hold about you from your Profile ("Download my data"), any time.
- Correction — update your name and preferences in the app; contact us for anything you can't edit yourself.
- Erasure — request account deletion from your Profile ("Delete my account"). We anonymise your identity and personal records, remove you from friends' lists, and delete your connections and shared-occasion records. Financial records (bills, invoices, payment entries) are retained in anonymised form as tax law requires.
- Grievance — write to privacy@bump.rocks. We respond within 7 days. If you are not satisfied, you may escalate to the Data Protection Board of India as provided under the Digital Personal Data Protection Act, 2023.
5. How long we keep it
- Account and preference data: while your account is active, or until you delete it.
- Delivery addresses: deleted shortly after the order completes.
- Service-message records: pruned within 90 days.
- Staff location coordinates: deleted when the shift closes (only the attendance result is kept).
- Sign-in sessions and one-time codes: expire and are purged automatically.
- Financial and tax records: retained for the periods Indian law requires, in anonymised form after account deletion.
6. Security
All traffic is encrypted in transit (HTTPS). Phone numbers and delivery addresses are encrypted at rest. Passwords for your Google or Meta accounts never touch our systems. Payment credentials are handled entirely by our payment processor. Access to production data is restricted and audited. If a breach affecting your personal data ever occurs, we will notify you and the authorities as the law requires.
7. Children
Bump accounts are for adults (18+). We do not knowingly process children's personal data; if you believe a child has created an account, contact us and we will remove it.
8. Changes
When this policy changes materially, we'll update the date above and tell you in the app. Continued use after a change means the updated policy applies.