Privacy Notice

Last updated 3 June 2026

Who we are

Bouncer ("we", "the service") provides cash-on-delivery (COD) fraud-risk scoring to online merchants selling in Romania. For the order data a merchant connects, the merchant is the data controller and we act as their data processor. For the cross-merchant risk network described below, we act as an independent controller.

What data we process

  • Order details: order value, items, date/time, payment method.
  • Customer contact and delivery data: name, phone, email, shipping address, city, postcode, and IP address — used to score delivery- refusal risk.
  • Delivery outcomes (delivered / refused) used to calibrate the model.

We do not process Romanian national ID numbers (CNP), payment-card data, or any special-category data. Phone numbers and emails are stored as keyed (HMAC-SHA256) pseudonyms for matching; they are pseudonymous, not anonymous.

Why we process it (lawful basis)

Our lawful basis is legitimate interest (GDPR Art 6(1)(f)): preventing payment-default and delivery-refusal fraud on COD orders, which Recital 47 expressly recognises. You can object at any time (see "Your rights").

The cross-merchant risk network

To detect repeat offenders who move between stores, a customer's pseudonymised phone/email is checked against an aggregated network of refusal statistics contributed by other merchants using the service. Only keyed hashes and counts are shared — never names, raw numbers, addresses, or which specific merchant a customer ordered from.

Automated decisions & your right to object

A merchant may choose to automatically cancel orders that score in the critical risk tier. Where this is enabled it is a solely-automated decision (GDPR Art 22). You have the right to object, to obtain human review, and to contest the decision. On request we flag the customer so their orders are reviewed by a person and never auto-cancelled.

How long we keep it

Customer details on order records are erased after the merchant's retention window (18 months by default), leaving only an anonymous risk score. Inactive customer profiles are deleted on the same schedule.

Who we share it with (sub-processors)

  • Supabase — database hosting (EU region).
  • Vercel — application hosting (EU region, Frankfurt).
  • Anthropic — model calibration (receives only aggregated, non-identifying statistics).
  • Twilio — WhatsApp order confirmations, where enabled.

Where your data is stored (international transfers)

Customer order data is stored and processed within the European Union. Our database (Supabase) and application servers (Vercel, Frankfurt) run in EU regions. Where a sub-processor is established outside the EU (Anthropic, Twilio), transfers are covered by the European Commission's Standard Contractual Clauses (GDPR Art 46), and those sub-processors receive only the minimum data needed — Anthropic receives aggregated, non-identifying statistics only.

Your rights

You may request access, rectification, erasure, restriction, objection, or portability of your data, and you may lodge a complaint with the Romanian supervisory authority (ANSPDCP, dataprotection.ro). Requests are handled through the merchant you ordered from; we support them as processor. Contact: ianis@bouncer.ro.


For merchants: disclosure to add to your checkout

You are the controller of your customers' data. Before importing or scoring orders, add the following to your own store privacy policy:

We use a third-party fraud-prevention service (Bouncer) to assess the risk of delivery refusal on cash-on-delivery orders. For this purpose your name, contact details, delivery address, order details and IP address are shared with the service and checked against an aggregated, pseudonymised cross-merchant risk network. Processing is based on our legitimate interest in preventing fraud. High-risk orders may be cancelled or reviewed automatically; you have the right to object and to request human review. See [your privacy contact] to exercise your rights.