Data Controller
The data controller for personal data processed through the bakshish.bg platform is:
Deedy Labs (Дийди Лабс ЕООД)
UIC: 205325050
Data we collect
The platform serves two types of users, and different data is collected for each:
Tip givers (paying customers)
IP address, device type, and transaction data (amount, currency, date). Card details are processed directly by Stripe and never pass through or are stored on our servers. We do not store payment card data (PCI Compliant). Optionally: a rating of the visit and a comment.
Tip recipients
Name, email address, notification phone number, and the venue's name and type. For employees: name, job title and, optionally, a photo. We do not collect or store IBANs, identity documents or other KYC information — it is provided directly to Stripe (see the "Identity Verification" section).
Technical data (all users)
IP address, browser type, and access logs — collected automatically for the security and operation of the platform. For signed-in users also: the names of the browser and the operating system (read from the browser's header; the header itself is not stored), the IP address and time of each sign-in and of the last activity in each session, and a hash of the browser's identifier (the BAKSHISH_DEVICE cookie). We show them in Settings → Security (a list of sessions and devices) and use them for the email about a sign-in from a new browser. The IP address is also kept in the counters that limit the number of requests.
Messages from the contact form
Name, email address, optionally phone and company, and the text of the message — only to reply to it.
Purposes and legal basis
| Purpose | Legal basis |
|---|---|
| Processing and confirming payments | Contract performance |
| Managing business accounts and employees | Contract performance |
| Facilitating direct payments to recipients via Stripe Connect | Contract performance |
| Directing recipients to identity verification (KYC) in Stripe and tracking its status | Contract performance |
| Generating income reports | Contract performance |
| Sending transactional email notifications | Contract performance |
| Compliance with tax and financial requirements | Legal obligation |
| Security and fraud prevention | Legitimate interest |
| A list of sessions and devices, signing a device out, and an email about a sign-in from a new browser | Legitimate interest (account security) |
| Replying to messages from the contact form | Legitimate interest / Steps prior to entering into a contract |
| AI analyses in the owner’s dashboard: comment sentiment, suggested amounts, AI assistant | Legitimate interest |
Identity Verification (KYC)
To prevent fraud and meet legal requirements, tip recipients undergo a Know Your Customer (KYC) procedure. It takes place during onboarding, directly with Stripe, not with Bakshish.
- Data collected: Neither Bakshish nor Deedy Labs collects or stores identity documents, IBANs, addresses, company registration numbers or representative details. They are entered directly into Stripe's form. From Stripe we receive only the verification status (for example under review or completed) and whether the account can receive payments.
- Process: During onboarding, the owner is redirected to a page hosted by Stripe and enter their details there. Stripe verifies them and creates the recipient's payment account. The data does not pass through our servers. Stripe acts as an independent data controller for this data.
- Retention: Because we do not store this data, there is no deletion period on our side. Stripe retains it under its own privacy policy and legal obligations.
- Security: Identity data is processed in Stripe's secure environment. Accounts on the platform are protected by a password and, optionally, two-factor authentication (2FA) or a passkey. Communication is encrypted.
Communication and system notifications
We use your email address to send:
- Tip receipt confirmations
- Verification status notifications (approval/rejection)
- Periodic income reports (on request or automatically)
- Notices about a sign-in to your account from a new browser or device
- Important notices about changes to the Terms or account security
These notifications are transactional and a necessary part of the service — they are not unsolicited commercial messages. For delivery, we use an external email service provider to whom we share only the email address and message content.
Data recipients
We do not sell your data. To operate the platform, we share information only with the following trusted partners:
| Partner | Role |
|---|---|
| Stripe Payments Europe, Ltd. | Payment processing and payouts, and KYC verification of recipients carried out directly by Stripe. Stripe is PCI DSS certified and acts as an independent data controller for verification purposes. |
| Google Cloud (Google Ireland Limited) | Hosting infrastructure. Data is stored on servers within the European Economic Area (EEA). |
| Google Gemini API (Google Ireland Limited) | The AI features of the owner’s dashboard: sentiment analysis of guests’ comments, suggested tip amounts from a venue’s recent tips, and the AI assistant’s answers, built from the account’s tip data (amounts, dates, locations, employees’ names and job titles). We share no email addresses, phone numbers or card data. |
| Email service provider | Delivery of transactional notifications. We share only the email address and message content. |
| Public authorities (NRA, CPDP, etc.) | Only when legally required (e.g. tax audit or official order). |
Retention periods
- Transaction data: 5 years under accounting and tax law — even after account closure.
- The guest's IP address and browser type on a tip: deleted 90 days after the tip; the tip itself is kept longer (see above), without them.
- KYC verification data: not stored by us — processed directly by Stripe.
- Session and device data: an active session — until it expires (1 hour without activity) or you sign out; a remembered login — up to 30 days or until you sign the device out; the records of known browsers — 1 year after the last sign-in; the IP address in the request-limiting counters — up to 24 hours.
- Conversations with the AI assistant: 12 months after the last message in the conversation.
- Technical records: processed Stripe events — 90 days; dismissed platform problem notices — 180 days; unused owner invitations — 90 days after they expire; tip page visits (no personal data) — 400 days.
- Other data: for the duration of the active account or until a deletion request (fulfilled within 30 days), unless a legal obligation requires longer retention.
Your rights under GDPR
As a data subject you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Object to processing
- Lodge a complaint with the Personal Data Protection Commission — www.cpdp.bg, Sofia, Blvd. "Prof. Tsvetan Lazarov" № 2
International transfers
Stripe Payments Europe, Ltd. is based in Ireland (EU). Transfers outside the EEA are possible when Stripe or Google use infrastructure in third countries, including when Google processes requests to the Gemini API — in such cases, Standard Contractual Clauses (SCCs) approved by the European Commission and/or the EU-US Data Privacy Framework apply.
Changes
We may update this policy periodically. For significant changes, we will publish the updated version with a new date.
Contact
For questions about personal data or to exercise your rights, contact us at info@bakshish.bg
