Bonfium is operated by MB "Baltic uperiai", a private limited company registered in Lithuania.
We are the controller of the personal data described below. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; privacy questions go to the address above.
We collect only what the service needs to work. Each item below has a legal basis under Article 6 GDPR.
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Name and email address | To create your account, sign you in, and show the other side of a trade who they are dealing with | Performance of a contract (Art. 6(1)(b)) | While your account is open, then 12 months |
| Quick Trade name, email, private-link hash, confirmation and access timestamps | To create passwordless access limited to one trade, confirm control of the email address, notify both parties, prevent duplicate acceptance and recover access | Performance of a contract (Art. 6(1)(b)); legitimate interest in access security and fraud prevention (Art. 6(1)(f)) | Participation record with the trade; private-link hashes are erased when they expire. Raw links are never stored |
| Password | To secure your account. Stored only as a one-way hash – we cannot read it, and neither could anyone who obtained our database | Performance of a contract | While your account is open |
| Two-factor authentication secret and backup codes | To protect your account and the money in it. Encrypted at rest; backup codes are hashed | Legitimate interest in account security (Art. 6(1)(f)) | While two-factor is enabled |
| Trade records: item description, price, category, counterparty, status, timestamps | To run the trade, hold funds, resolve disputes, and produce accounting records | Performance of a contract; legal obligation for accounting (Art. 6(1)(c)) | 10 years from the trade, as Lithuanian accounting law requires |
| Identity verification result (verified / rejected, and the date) | To confirm both sides of a trade are real people, and to meet anti-money-laundering duties | Legal obligation; performance of a contract | 5 years after the account closes, as AML law requires |
| Courier tracking number and delivery scans | To know when a parcel arrived, so funds release at the right moment | Performance of a contract | With the trade record |
| Dispute evidence you submit (text, photos, video) | To decide the dispute. Both sides see the same file – there are no secret submissions | Performance of a contract | 3 years after the dispute closes |
| Failed login attempts | To slow down attackers guessing passwords | Legitimate interest in security | 15 minutes |
| Page views (page, referring site, date) | To understand which pages people use. No cookies, no cross-site tracking, no advertising | Legitimate interest in improving the service | 13 months, aggregated |
| Administrative access log | To record which administrator viewed or changed personal data, and when – so that access is accountable | Legal obligation (Art. 5(2) accountability) | 12 months |
We use two cookies, both strictly necessary, so no consent banner is required:
We share data only with processors who help run the service, each under a written data processing agreement, and only what each one needs:
| Processor | What they handle | Where |
|---|---|---|
| Hostinger | Hosting and database | EU |
| AfterShip | Parcel tracking numbers and delivery scans | Outside the EU, under Standard Contractual Clauses |
| iDenfy | Identity verification. They see your document; we do not | Lithuania (EU) |
| Payment institution | Holding and moving funds. Named here once appointed | EU |
We also disclose data where the law requires it – for example to tax authorities under the EU platform reporting rules (DAC7), or to law enforcement acting on a valid legal basis.
When you open or accept an account trade, your counterparty sees your name, whether your identity is verified, your number of completed trades, and your trader rank. In Quick Trade, the counterparty sees the name you entered, that your email was confirmed, and that your identity was not verified. They do not see your email address, your address, private access link, or any other trade.
Under the GDPR you can ask us to:
Write to bonfium@gmail.com. We answer within one month, as Article 12 requires. There is no charge.
If you think we have handled your data badly, please tell us first – we would rather fix it. You also have the right to complain to the Lithuanian supervisory authority:
Traffic is encrypted with TLS. Passwords are hashed, two-factor secrets are encrypted at rest, and sign-in attempts are rate limited. Administrative access to personal data is logged. If a breach ever put your rights at risk, we will notify the supervisory authority within 72 hours and tell you directly where the law requires it.
Some parts of a trade run automatically – for example, funds release after the inspection window closes, or a trade cancels and refunds if a parcel is never sent. These follow the published deadlines on our trade rules page. Disputes are decided by a person, not an algorithm.
Bonfium is not for anyone under 18. Account users failing identity verification on age are closed. Quick Trade users must declare that they are 18 or older, and verification may still be required before payment or payout.
If we change this policy in a way that matters, we will email registered users before it takes effect. The date at the top always shows the current version.
This policy describes the service as built. Some features referenced here – payments and automated identity verification – are not yet live; this policy will be updated with the named providers before they are switched on.