Privacy policy

Last updated: 23 September 2026.

1. Who is responsible for your information

Bongo is run by Northern Peak Ventures Inc., a company incorporated under the Canada Business Corporations Act. This policy says what personal information Bongo collects, why, who sees it, and what you can do about it. It is written to meet Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).

Questions, requests and complaints: hello@bongomp.com, or by post at #1317-1500 W Georgia St, Vancouver, BC V6G 2Z6, Canada.

2. Nobody has an account

Buyers never sign in and never have an account or a password. An order is reached by the link in its receipt, and only by that link. The people who run an organization sign in to their own dashboard with an emailed link or code; that is the only sign-in on Bongo, and it is theirs, not yours.

3. What we collect when you buy from a storefront

When you order. Your first name, your last name, your email address, and your student number, or the fact that you ticked "Not a student". With them, what you ordered: the product, the colour, the size and the quantity, the price and tax at the time, the reference code, and when the order was placed.

Your card. You type your card into a form that belongs to Stripe, our payment processor, and the details go to Stripe, never to Bongo. Bongo keeps Stripe's reference for the payment and the amount Stripe charged, and nothing about the card itself: not the number, not the brand, not the last four digits.

Two cookies. Bongo sets one cookie for your cart on an organization's storefront, which holds what you have put in it, and one for a checkout you are in the middle of, so a second try after a declined card picks up the same order. Both are set for the one address you are on and are never shared with another site. There are no advertising cookies, no third-party analytics and no tracking across other websites.

Automatically. Standard server logs, which carry your network address, your browser and the pages you asked for, kept for security and troubleshooting. To slow abuse, Bongo counts checkout attempts against a hash of your network address and of your email address for a short while; the counter is not a record of who you are.

4. Why we collect it

  • To take your payment and hold the goods for you while it goes through
  • To send you your receipt, with the reference code and the pickup details, and to email you about that order: a change to the pickup details, a reminder to collect, or a refund
  • To give the organization what it needs to hand you the right thing and to answer a refund request
  • To keep the records Canadian tax law requires
  • To detect and prevent fraud

Bongo does not sell your personal information and does not use it for marketing. Bongo emails you about your own order and about nothing else.

5. If you ask to be told when a size is back

A sold-out size offers to email you if more arrive. If you ask, Bongo stores your email address against that one size. When the organization restocks it you get one email, and only one, with a link that stops any further email about that size. Asking for several sizes means one email per size. If the size sells out again after that email and you ask again, you get one more email the next time it is back, and the link in the earlier email keeps working until that next email replaces it.

The organization sees how many people asked for each size, never their addresses. The addresses are never given to the organization, never exported and never used for anything else. Unsubscribing keeps the record that you unsubscribed, so the same address is not emailed again.

Asking is counted against a hash of your network address and of your email address for a short while, to slow abuse; the counter is not a record of who you are. The link in the email is made when the email is sent, works once, and Bongo keeps only a hash of it, so the link cannot be rebuilt from what is stored. A reply to the email goes to the organization's contact address where it has one, and to Bongo otherwise. If you unsubscribe and later ask again about the same size, nothing is stored and nothing is sent.

6. What the organization sees

The organization you bought from can see, for each of its own orders, the fields in this table and nothing else about you. Its owner can see every field; the members it adds to work the pickup table see the pickup list, which is built from the same fields. Bongo's own staff can see the same, to run the service and to pay the organization, and, when it pays the organization, staff read a statement of what each thing it sold has taken in, which names no buyer.

WhatWhy the organization sees it
Your first nameTo find your order at the pickup table
Your last nameTo find your order at the pickup table
Your email addressTo reach you about your order, and to fix a typo before a receipt goes astray
Your student numberA backup check of who you are at the table, never a gate
Whether you said you are not a studentSo the table knows there is no number to ask for
The colour and size you choseTo hand you the right thing
The state of your orderPaid, collected, refund requested, refunded, disputed, charged back, so the table knows what is owed
The reason you gave when asking for a refundThe organization decides on the refund, so it reads your reason
The name of somebody who collected for youWritten down at the table when a friend collects on your behalf
Whether your bank is disputing the payment, the day it began, and the reason category the bank gaveThe money for the order is held back while the bank decides, and the organization answers for the sale, so it is told what is happening and why

Beside each order the organization sees its reference code and what was ordered, which are facts about the order rather than about you. It never sees your card or anything about it, never an order you placed with another organization, and never the name behind a payment that did not go through: an order that was never paid is on no list the organization can see.

7. When you pay for a name on a list

The list itself. An organization that makes a list gives Bongo the names on it, a tell-apart where two names are alike, a size where it already knows one, and an email address where it has one. Bongo did not ask you for any of that: it came from the organization, which is responsible for having your agreement to put your name on a list that the people it shares the link with can see. The list shows the names still to pay to anyone holding the link and the passcode, as the organization wrote them or, if it chose that, as initials with the tell-apart; tapping a name shows it in full on the payment page, so the person paying can confirm it is theirs. Beside a name it never shows an email address, a size, an amount, or whether somebody is in the middle of paying for it. A name comes off the list the moment it is paid for. The organization can hide a name from the list at any time, and if you write to hello@bongomp.com we will have yours hidden.

When you pay. Your email address, and the size you chose where the list has sizes. With them, what you paid for: the item, the name on the list you paid into, the price and tax at the time, the reference code, and when the order was placed. Bongo asks you for nothing else: the name on the order is the name you tapped.

Your card. You type your card into a form that belongs to Stripe, our payment processor, and the details go to Stripe, never to Bongo. Bongo keeps Stripe's reference for the payment and the amount Stripe charged, and nothing about the card itself: not the number, not the brand, not the last four digits.

Why. Bongo uses what it holds about you:

  • To take your payment and hold the name for you while it goes through
  • To send you your receipt, and to email you about that payment if it is moved to another name or refunded
  • To give the organization what it needs to order and hand out the right thing
  • To remind a name the organization gave an address for, before the due date
  • To keep the records Canadian tax law requires
  • To detect and prevent fraud

Bongo does not sell your personal information and does not use it for marketing.

Two cookies. Bongo sets one cookie when you type the passcode, so the list opens without it for the next 30 days in that browser; a changed passcode ends it early. It sets a second when you tap a name, which remembers the name you are paying for: for 10 minutes from the tap, then 15 minutes from the moment you tap pay, and it is cleared when the payment settles. Both are set for the one address you are on and are never shared with another site. There are no advertising cookies, no third-party analytics and no tracking across other websites.

Automatically. Standard server logs, which carry your network address, your browser and the pages you asked for, kept for security and troubleshooting. To slow guessing, Bongo records each passcode try against a hash of your network address, per list, and keeps those records; they are a count of tries, not a record of who you are, and the organization never sees them. Name taps, payment attempts and, where the organization allows it, adding a name are counted the same way for a short while, against a hash of your network address and, for a payment, of your email address.

Reminders. Where the organization put an email address beside your name and set a due date, Bongo emails that address a reminder 3 days before the due date and again on the due date, in the morning, Vancouver time, and never after the date has passed. Each reminder names the organization, the item and the amount, never the passcode, and carries a link that stops any further reminder for that name. A list with no due date sends none, and a name that has been paid for gets none. On the due date the organization is emailed how many names are still to pay and which; it can already see both on its list. The reminder goes to a person who has bought nothing, which is why it goes only to an address the organization gave for a name it expects to pay, is about that one list, and carries the link that stops it.

Adding your own name. An organization can let people add their own name to its list. Where it has, a name you add is on the list like any other, with the tell-apart you give. Adding a name is counted against a hash of your network address for a short while, to slow abuse.

Handing out. Once the organization has placed its order, it ticks your name on its list when it hands you your item, and Bongo keeps the time your name was ticked. The organization can undo a tick until it marks the whole list handed out, and the ticks are fixed after that. Bongo releases what the list took in to the organization only once every name on it is ticked.

How long the list is kept. The list, with every name on it, is kept with the organization's payment records for as long as they are kept, because it is the record of who paid for what. A name the organization removes from its list stays in its records, marked removed, and is in the file the organization downloads. There is no control that deletes a list. If you want your name out of a list that is no longer taking payments, or out of an organization's records, write to hello@bongomp.com and we will remove it, subject to what must be kept by law.

8. What the organization sees about its list

The organization that made the list can see, for each name on it, the fields in this table and nothing else about the person. Its owner sees every field; the members it adds to its dashboard see none of the list. Bongo's own staff can see the same, to run the service and to pay the organization, and, when it pays the organization, staff read a statement of what each thing it sold has taken in, which names no buyer. Only Bongo's staff can mark a name as in without a payment through Bongo, with a reason the organization can read.

WhatWhy the organization sees it
The name as it wrote it on the listIt wrote the list, and the name is how it knows who you are
The tell-apart beside a nameTo tell two people of the same name apart
The email address it put beside your nameIt gave the address, and it is where Bongo's reminders go
The email address you typed when you paidTo reach you about your payment, and to fix a typo before a receipt goes astray; shown on a paid name alone
The sizeTo order the right thing for you
The state of the nameUnpaid, paid, waived or removed, so it knows who is in
The reason a name was waivedOnly Bongo's staff can waive a name, and they write down why
A note the organization wrote about a nameIts own working note, which it wrote
The reference code of your paymentTo find your payment when you write about it
When you paidTo know when a name was paid for
When you were handed your itemIt ticks your name when it hands you the item, so it knows who is still waiting for theirs
Whether your bank is disputing the payment, the day it began, and the reason category the bank gaveThe money for the name is held back while the bank decides, and a dispute about a list is held against the organization that wrote it, so it is told what is happening and why

Beside the list the organization sees how many names are paid for, waived and still to pay, how many items it has handed out once its order is placed, and what the list has taken in before tax, which are facts about the list rather than about you. It never sees your card or anything about it, never a payment on another organization's list, never who is in the middle of paying for a name, and never the address behind a payment that did not go through: an order that was never paid is on no list the organization can see. It can download its list as a file carrying the name, the tell-apart, both email addresses, the size, the state, the day a name was paid for and the reference code, for every name, the removed ones included, and Bongo records every download.

9. What we collect when you take a ticket on a countdown

When you take a ticket. Your first name, your last name, your email address, and your student number, or the fact that you ticked "Not a student". With them, what you reserved: the item, the size, the price and tax at the time, the reference code, and when the ticket was taken.

Your card, and the one thing Bongo keeps about it. You type your card into a form that belongs to Stripe, our payment processor, and the details go to Stripe, never to Bongo. A countdown charges nothing on the day you take a ticket, so Stripe saves the card for the single charge that may come weeks later, and Bongo keeps Stripe's reference to the saved card, which is what lets that charge be made when the countdown ends. Bongo keeps nothing about the card itself: not the number, not the brand, not the last four digits. The organization never sees any of it either, and neither the saved card nor its reference is used for anything but the one charge this countdown is for.

When the card is charged. At the moment the countdown ends, and only if the organization's minimum is in by then; where the organization set no minimum, the countdown goes ahead whatever the number and the sentence you are shown says so. The email you get when you take the ticket names the amount and the exact date and time, weeks in advance, and it is the notice: nothing is sent between the end of the countdown and the charge, because there is no gap between them. If the card does not go through you get one email with a link to a page where you can fix the card, which is either confirming the card you already saved or typing another; anything you type goes to Stripe the same way, and you have 24 hours from that first failure to use it.

When the saved card is let go. Bongo asks Stripe to let go of a ticket's saved card as soon as it is certain no charge will ever be made on it: a countdown that ended under its minimum, a countdown the organization stopped, a ticket you cancelled, and a ticket cancelled because the card was never fixed in time. After that it cannot be charged again, and what is left with Bongo is the record that the ticket existed and that nothing was taken. A card that was charged stays saved at Stripe, because a payment dispute can arrive months after the charge, and a refund when a countdown is withdrawn, and both are made against that same card. A card saved in the moment the countdown ended, whose ticket was refused because the countdown had closed, is let go at once. A card Stripe saves when no ticket is then taken with it at all, because the page lost its connection at that moment or was closed before the ticket was taken, stays saved at Stripe with nothing at Bongo pointing to it, and it can never be charged, because Bongo only ever charges a card for a ticket. The same is true of a card saved on the page that fixes a card when that page is closed before the card is used. When you fix a card by typing another, the card you type becomes your ticket's saved card and the one it replaces is let go at once, and a card you type there that your ticket does not take, because the ticket was paid, cancelled or out of time first, is let go too.

When you cancel. Asking to cancel sends a link to the email address on your ticket. To recognise the link when you use it, Bongo stores a hash of it, with when it was sent, when it stops working and whether it was used; the copy of the email Bongo keeps in order to send it carries the link itself, which stops working a short while after it is sent or as soon as it is used. A cancelled ticket stays on record as cancelled with nothing taken, and its saved card is let go as above.

Why. Bongo uses what it holds about you:

  • To save your card and to charge it once, when the countdown ends and the minimum is met
  • To send you your confirmation with the amount and the date, a reminder while the countdown is still open and a message when a countdown with a minimum reaches it, your receipt when the card is charged, a message if the card does not go through or the item is not going ahead, the email saying your item is ready and the last day to collect, a reminder 2 days before that day if you have not collected, and a note if a refund you asked for lapsed because the organization did not decide in time
  • To send you the link that confirms a cancellation you asked for, and a note once the ticket is cancelled
  • To give the organization what it needs to have the right thing made and to hand you yours
  • To keep the records Canadian tax law requires
  • To detect and prevent fraud

Bongo does not sell your personal information and does not use it for marketing. Bongo emails you about the countdowns you took a ticket on and about nothing else.

Cookies. A countdown page sets no cookie of its own: nothing is held for you in advance, there is nothing to unlock, and your ticket is reached by the link in its confirmation. Stripe's own card form sets what it needs to show the field and to spot fraud. There are no advertising cookies, no third-party analytics and no tracking across other websites.

Automatically. Standard server logs, which carry your network address, your browser and the pages you asked for, kept for security and troubleshooting. To slow abuse, Bongo counts ticket attempts against a hash of your network address and of your email address, and requests to cancel against the ticket and a hash of your network address, for a short while; the counter is not a record of who you are.

10. What the organization sees about its countdown

While the countdown is running the organization sees how many tickets are in and what they come to, and no names at all. Once a card has been charged the organization can see, for that ticket, the fields in this table and nothing else about you. Its owner can see every field; the members it adds to work the pickup table see what that table shows them, which is built from these fields apart from the reason you gave when asking for a refund, which only the owner reads. Bongo's own staff can see the same, to run the service and to pay the organization, and, when it pays the organization, staff read a statement of what each thing it sold has taken in, which names no buyer.

WhatWhy the organization sees it
Your first nameTo find your ticket when the items are handed out
Your last nameTo find your ticket when the items are handed out
Your email addressTo reach you about your ticket, and to fix a typo before a receipt goes astray
Your student numberA backup check of who you are at the table, never a gate
Whether you said you are not a studentSo the table knows there is no number to ask for
The size you choseTo have the right size made for you
The state of your ticketCharged, collected, not collected, refund requested, refunded, disputed, charged back, so the table knows what is owed
The reason you gave when asking for a refundThe organization decides on the refund, so it reads your reason
The name of somebody who collected for youWritten down at the table when a friend collects on your behalf
Whether your bank is disputing the payment, the day it began, and the reason category the bank gaveThe money for the ticket is held back while the bank decides, and the organization answers for the sale, so it is told what is happening and why

Beside each ticket the organization sees its reference code and what was reserved, which are facts about the ticket rather than about you. It never sees your card or anything about it, never a ticket you took on another organization's countdown, and never the name behind a card that was never charged: a ticket that was cancelled, and a ticket whose card never went through, are never named to it. The organization can download what it sees as a file carrying these fields, the dispute column among them, the reference code and the day the card was charged, and Bongo records every download.

11. Who else we share it with

Bongo uses these service providers, and only to run Bongo:

ProviderWhat they doWhat they see
StripeProcesses the paymentYour name, your email address, your card, the amount, and the product code that shows on your statement
RenderHosts the site and its databaseEverything Bongo stores about your order
ResendSends Bongo's emailYour name, your email address and the contents of each email sent to you
CloudflareStores the photos organizations put on what they sellNothing about you

Bongo also discloses personal information where the law requires it.

12. Where your information is stored, and what that means

Your personal information is stored and processed outside Canada, mostly in the United States. The site and its database run with Render in Oregon, payments are processed by Stripe, and email is sent through Resend.

This means your information is subject to the laws of the countries where those providers operate, and may be accessible to the courts, law enforcement and national security authorities there. Canadian privacy law requires us to tell you this, and you should know it before you give us your details.

13. How long we keep it

Order records, which is your name, your email address, what you ordered and the payment records, are kept for as long as Canadian tax and business record law requires, generally six years from the end of the tax year they belong to.

The record of every change to an organization's stock, of every movement of money and of every change an organization makes to an order is written once and never edited; the record of a payment attempt is written before the payment is asked for and records its outcome once, and is never deleted.

An address you gave to be told about a restock is kept, marked as unsubscribed once you unsubscribe, so the same address is not emailed again about that size. Ask us to remove it and we will, subject to what must be kept by law.

Server logs are kept for a shorter period and then deleted. Where personal information is no longer needed and there is no law requiring it to be kept, it is deleted or anonymised.

14. Your rights

Under PIPEDA and BC PIPA you can:

  • Ask what Bongo holds about you and get a copy
  • Correct anything inaccurate, including a mistyped email address on an order, through the organization or through us
  • Withdraw consent and ask for your information to be deleted, subject to what must be kept by law
  • Complain to us and, if you are not satisfied, to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia

Email hello@bongomp.com and you will have an answer within 30 days.

15. Keeping it secure

The application connects to its database with an account that cannot delete the stock ledger, the money ledger, the record of payment attempts or the audit trail, and cannot edit any of them except to record a payment attempt's outcome, once. Card details never reach Bongo. All traffic to Bongo is encrypted. Access to production data is limited to the smallest number of people needed to run the service.

No system is perfectly secure. If a breach affects you and creates a real risk of significant harm, Bongo will notify you and the Privacy Commissioner as the law requires.

16. Changes

This policy may change. The current version is always at this address, with the date it last changed at the top.

17. Contact

Northern Peak Ventures Inc., #1317-1500 W Georgia St, Vancouver, BC V6G 2Z6, Canada. Email hello@bongomp.com: it is a monitored inbox and the fastest way to reach a person.