logo

Privacy Policy for the bonuz
Lifestyle / Wallet app and website

Last update: 10 September, 2026

Version 2.0. Supersedes the version dated 19 March, 2024.

This policy explains which personal data the bonuz Lifestyle / Wallet app and bonuz.xyz process, why, who processes it on our behalf, where it is stored, and what you can do about it. It forms part of our Terms of Use.

Contents▼

  1. 1. Who we are
  2. 2. The short version
  3. 3. What we collect, and why
  4. 4. What we do not collect
  5. 5. Service providers and other recipients
  6. 6. Legal bases (GDPR and UAE PDPL)
  7. 7. International transfers
  8. 8. Retention
  9. 9. Your rights
  10. 10. Your choices
  11. 11. Children
  12. 12. Security
  13. 13. Breaches
  14. 14. Changes
  15. 15. About us and contact

1. Who we are

BONUZ TECHNOLOGY DMCC (Jumeirah Lakes Towers, Dubai, United Arab Emirates) is the controller of personal data processed through the bonuz Lifestyle / Wallet app and bonuz.xyz (the “Services”). Contact: hello@bonuz.tech.

This policy covers the Services only. Websites and materials of our affiliate Bonuz Inc. (Saint Lucia), including bonuz.market and anything relating to the BONUZ token, are outside the scope of this policy. BONUZ TECHNOLOGY DMCC has no role in the BONUZ token; the company and the token merely share a name.

2. The short version

  • Your private keys, recovery phrases, and Face ID or fingerprint data never leave your device. We cannot see them, and we cannot recover them.
  • We collect what the app needs to work: account details (email, handle, profile), your public wallet addresses, app usage and crash data, and, with your permission, your location for nearby content and the camera for the lens (processed on the device, never recorded or uploaded).
  • We use vetted service providers and name every one of them below.
  • Our backend runs in the EU (Frankfurt). Some providers process data in the US, under appropriate safeguards, as described in section 7.
  • You can turn usage analytics off in Settings (app version 4.2.0 and later), delete your account in-app, and exercise the rights in section 9.
  • The Services are for adults 18+.

3. What we collect, and why

Account and profile. Email address (from your login method), name, bonuz handle, profile photo, bio, social links, connections, bookmarks, favourite places. Purpose: creating and operating your account and profile. Basis: contract.

Wallet addresses. The public addresses of wallets you create or import (EVM, Solana, Bitcoin, BTX, smart accounts). Addresses are public, pseudonymous blockchain identifiers. Purpose: wallet features, showing balances and activity, powering handle resolution. Basis: contract. Note: anything recorded on a public blockchain (transactions, published handle records) is public and permanent by design; we cannot alter or delete it (see section 9).

Usage and device data. App events (screens, feature usage), device model, OS, app version, language, session identifiers, IP-derived approximate region. Purpose: product analytics, debugging, abuse prevention. Basis: legitimate interests, and consent where your local law requires it (see section 10). Analytics events are keyed to your wallet address and handle so usage relates to one profile.

Crash and performance data. Crash traces and performance metrics via Sentry, filtered before sending. Basis: legitimate interests.

Install attribution. Which campaign or link brought you to the app (AppsFlyer; on Android this can involve the Google Advertising ID). Purpose: measuring marketing. Basis: legitimate interests, and consent where your local law requires it. You can switch it off together with analytics in Settings (section 10); the app works fully without it.

Location (only with your permission). Precise device location while using the app, for nearby places, events, quests, check-ins, and location-based drops (G-Drop claims record where a drop was collected). Basis: consent via the OS permission; you can revoke it in system settings and the related features degrade gracefully.

Camera and motion (only with your permission). The camera and motion sensors power QR scanning, profile photos, and the AR lens. Lens frames are processed on your device in real time and are not recorded, stored, or uploaded. Photos you take for your profile are uploaded only when you choose them. Basis: consent via the OS permission.

Messages and community content. Chat messages, community posts, and comments you submit are stored to deliver them to recipients. Basis: contract.

Points, rewards, referrals. Point balances and history, missions, leaderboard standings (your handle and score are visible to other users), referral relationships (who invited whom), loyalty punches and vouchers. Basis: contract.

Purchases. For premium handles, Stripe processes your card; we receive confirmation, the price, and a payment reference, never your card number. For crypto buy and sell, Mercuryo is an independent controller running its own KYC; we pass your wallet address to pre-fill your order and receive transaction status. Basis: contract; legal obligation (records).

Notifications. Push tokens for notifications you can control per category in Settings; Apple Wallet pass registrations if you add a pass.

Support and partnership contacts. What you send us at support, and details submitted in partner forms. Basis: legitimate interests, or taking steps toward a contract.

4. What we do not collect

  • Private keys, recovery phrases, or wallet passwords. They are generated and stored on your device (or derived via Web3Auth’s distributed infrastructure for social-login wallets) and never transmitted to us.
  • Biometric data. Face ID and fingerprint matching happens inside your device’s secure hardware; we only receive a yes-or-no unlock result.
  • Microphone audio (the app does not request microphone access), contacts, or background location.

5. Service providers and other recipients

ProviderWhatWhere
Google Cloud (our backend)Account data, app content, points, messagesEU (Frankfurt)
PostHogProduct analyticsUS
SentryCrash and performance reportsUS / EU
AppsFlyerInstall attributionGlobal (US)
Google Firebase (FCM) / Apple (APNs)Push notification deliveryUS / global
StripeCard payments for premium handles (independent controller for payment data)US / EU
MercuryoCrypto buy and sell, including its own KYC (independent controller)EU
LI.FI and execution venuesSwap routing (receives addresses and transaction parameters)Global
Web3Auth (Torus)Social-login key infrastructure (never holds complete keys)Global
WalletConnectdApp connection relayGlobal
Blockchain networks and RPC providersBroadcast transactions, read balances (public addresses)Global, public

We also disclose data where the law requires it (courts, regulators, competent authorities), to enforce our terms and prevent fraud or abuse, within our corporate group where needed to operate the Services and under appropriate safeguards, and in a merger, acquisition, or reorganisation. We do not sell personal data and do not use it for third-party advertising.

6. Legal bases (GDPR and UAE PDPL)

Performance of our contract with you (the items in section 3 marked contract); your consent (OS permissions, and analytics or attribution where required), which you can withdraw at any time; our legitimate interests (running, securing, and improving the Services, preventing abuse), balanced against your rights; and compliance with legal obligations (records, lawful requests, breach notification).

7. International transfers

Our backend is hosted in the EU. Where a provider processes data outside the EU, the UK, or the UAE (see the table above, notably PostHog, Sentry, AppsFlyer, and Firebase in the US), we rely on adequacy decisions (including the EU-US Data Privacy Framework where the provider is certified) and/or Standard Contractual Clauses, and on the cross-border transfer conditions of the UAE PDPL and its Executive Regulation. Copies of the relevant safeguards are available via hello@bonuz.tech.

8. Retention

DataKept
Account and profileWhile your account exists; deleted on account deletion
Analytics and crash dataOnly as long as needed for the purposes in section 3, then deleted or aggregated; crash reports typically within 90 days
Messages and community contentWhile your account exists
Points, rewards, referralsWhile your account exists
Purchase and transaction recordsAs required by tax and commercial law (typically 5 years or more)
Support correspondence3 years
Blockchain recordsPermanent by design; outside our control

9. Your rights

Depending on where you live (EEA and UK under the GDPR; UAE under the PDPL; several US states), you can ask for: access to your data; correction; deletion (fastest path: delete your account in the app under Settings, Account); restriction of or objection to processing; portability; and withdrawal of consent at any time without affecting prior processing. We respond within one month (EU and UAE) or the period your local law sets. You can complain to your supervisory authority: in the UAE, the UAE Data Office; in the EU, your national data protection authority. We will not discriminate against you for exercising your rights.

The blockchain limitation, honestly: data recorded on public blockchains (transactions from your addresses, handle records you chose to publish) is replicated across networks nobody controls and cannot be erased or rewritten by us. Deleting your bonuz account removes our copy of your profile and app data, but not on-chain history. Think before publishing profile fields on-chain; that feature is opt-in per field for exactly this reason.

10. Your choices

  • Analytics and attribution: the “Share usage analytics” switch in Settings (app version 4.2.0 and later) stops PostHog analytics and AppsFlyer attribution on your device.
  • Permissions: camera, location, photos, notifications, and Face ID are all optional OS permissions you can revoke in system settings.
  • Notifications: per-category controls in Settings.

11. Children

The Services are not directed at, and may not be used by, anyone under 18. We do not knowingly process children’s data; if we learn we hold any, we delete it. Contact hello@bonuz.tech if you believe a minor is using the Services.

12. Security

Keys stay in your device’s secure storage; app data in transit is encrypted (TLS); backend access is role-restricted and logged; crash reports are filtered for sensitive values before sending; and we never ask for your recovery phrase. No system is perfectly secure: protect your device and your recovery phrase.

13. Breaches

If a personal-data breach creates risk to you, we will notify the competent authority (the UAE Data Office; EU data protection authorities where applicable) within the legally required timeframe (72 hours where the GDPR or PDPL so requires) and inform affected users without undue delay.

14. Changes

We will post updates here with a new date and may notify you in the app about material changes. The English version prevails over translations. This version 2.0 supersedes the version dated 19 March 2024 and forms part of our Terms of Use.

15. About us and contact

NameBONUZ TECHNOLOGY DMCC
Licence numberDMCC-826733
Registration numberDMCC191690
AddressALMAS-48-CV44, ALMAS Tower, Plot No: JLT-PH1-A0, Jumeirah Lakes Towers, Dubai, United Arab Emirates
Emailhello@bonuz.tech (general, legal, and privacy inquiries)

Explore bonuz Wallets

Bitcoin Wallet·BTX Wallet·Ethereum Wallet·Solana Wallet·Base Wallet·BNB Chain Wallet·Meme Coin Wallet·DeFi Wallet·Stablecoin Wallet·Self-Custodial Wallet·Crypto for Beginners·Events & Rewards App·Free Biolink·Crypto Wallet for Events·Upgrade your App or Business·Branding & Press Kit·Blog & News

Join our E-Mail list

Stay up to date about new releases of the bonuz Ecosystem.

Built on:

Ethereumbasesmartchainbiconomy
Join our TelegramWhitepaper

Get Started

Business / Brand Sign UpCreators Sign UpDownload bonuz App

Products

For Business CatalogReal-World BusinessesUpgrade Protocolbonuz MarketBusiness Dashboardbonuz ID

About Us

Core ContributorsAdvisorsBrandingContact Us

More

Terms of UsePrivacy PolicyBlog / News
bonuz on X (Twitter)bonuz Telegram communitybonuz HQ Telegram channelbonuz blog on Mediumbonuz on Instagrambonuz on Facebook

© 2026 Bonuz Technology DMCC. All rights reserved.