Privacy Policy

Last Updated: August 5th, 2025

Bonsai Technologies Inc. (“Bonsai,” “we,” “our,” and/or “us”) values the privacy of individuals who use our website and related services (collectively, our “Services”). This privacy policy (the “Privacy Policy”) explains how we collect, use, and disclose information from individuals who interact with our Services. It applies to our website visitors, individuals who interact with our services as or on behalf of our “Users” (as defined in our Terms of Service), prospective job applicants and individuals who receive our marketing materials. Please read this Privacy Policy carefully so that you understand your rights in relation to your Personal Information, and how we will collect, use and process your Personal Information. By using our Services, you agree to the collection, use, disclosure, and procedures this Privacy Policy describes. Beyond the Privacy Policy, your use of our Services is also subject to our Terms of Service.

In this Privacy Policy, “Personal Information” means any information relating to an identified or identifiable individual.

If you are a resident of California, please also review our California Resident Privacy Notice for more information about the types of personal information we collect and disclose, as well as how to exercise your rights under California law(s).

This Privacy Policy does not apply to the extent we process information in the role of a processor or service provider on behalf of our Users (for example, on behalf of our Users who use our CRMs or finance management tools). In that context, our processing of your personal information is subject to our agreements with our Users. Our Users are the data controllers, and their privacy policies will apply to the processing of your personal information. We are not responsible for the privacy or data security practices of our Users, which may differ from those explained in this Privacy Policy. 

Personal Information We Collect

We may collect a variety of Personal Information from or about you or your devices from various sources, as described below. In some cases, we need to collect your Personal Information to be able to provide you with our Services. In these cases, if you choose not to provide the requested Information, you may not be able to use our Services. Where required by applicable law, we will tell you if and why you have to provide us your Personal Information, as well as what the consequences if you choose not to.

A. Personal Information You Provide to Us.

Registration Information. When you sign up for an account, we ask you to provide contact information such as name, email address, and phone number. If you sign up using a Google or Apple account, we will also receive information from those services such as your name and email address.

Account Information. We may also collect information you provide when using our Services , included but not limited to, project names, task names, timesheets, agreements, invoices, attachments, expenses and payment records. 

Communications. If you contact us directly, we may receive additional information about you, included but not limited to, your name, email address, phone number, the contents of a message or attachments that you may send to us, and other information you choose to provide. When you communicate with us online, third party vendors receive and store these communications on our behalf. 

Careers. If you decide that you wish to apply for a job with us, you may submit your contact information and your resume online. We will collect the information you choose to provide on your resume, such as your education and employment experience. You may also apply through a third-party service, such as LinkedIn. If you do so, we will collect the information you make available to us through that service.

B. Personal Information We Collect When You Use Our Website. 

Location Information. When you use our website, we infer your general, non-precise location information by using your IP address.

Device Information. We receive information about the device and software you use to access our Services, including IP address, device type, device identifiers, web browser type and version, operating system version, phone carrier and manufacturer, application installations, mobile advertising identifiers, and push notification tokens. 

Usage Information. We automatically receive information about your interactions with our website, like the pages or other content you view and click, referrer information (the website you visited before coming to our Services), the dates and times of your visits, heatmaps, clickstream data, and scroll behavior.

 

Information from Cookies and Other Technologies. We and our third-party partners collect information about your activities on our website using, for example, cookies, pixel tags, SDKs, or other tracking and analytics technologies (collectively, “Cookies”). Our third-party partners, such as analytics, advertising, and security partners, may also use these technologies to collect information about your online activities over time and across different Services. We may use both session Cookies and persistent Cookies. A session Cookie disappears after you close your browser. A persistent Cookie remains after you close your browser and may be used by your browser on subsequent visits to our Services.

You can find more information about the types of cookies used on our website in our Cookie Policy.

C. Personal Information We Receive from Third Parties.

Third-Party Services. If you use the Google Calendar integration feature on our website, we may be able to view your calendars and events. If you connect your bank account to our Services using Plaid, we may receive information about your account transactions for use in our bookkeeping and related features.

How We Use the Personal Information We Collect

We use the Personal Information we collect:

  • To provide, maintain, improve, and enhance our Services;
  • To personalize your experience on our website such as by providing tailored content and recommendations; 
  • To understand and analyze how you use our website and develop new products, Services, features, and functionality;
  • To communicate with you, provide you with updates and other information relating to our Services, provide information that you request, respond to comments and questions, and otherwise provide customer support;
  • For marketing and advertising purposes, such as developing and providing promotional and advertising materials that may be relevant, valuable or otherwise of interest to you;
  • To generate anonymized or aggregate data containing only de-identified, non-personal information that we may use for any lawful purposes such as to publish reports;
  • To send you text messages for account authentication purposes and push notifications for any purpose related to our Services; 
  • To find and prevent fraud and abuse, and respond to trust and safety issues that may arise; 
  • For compliance purposes, including enforcing our Terms of Service or other legal rights, or as may be required by applicable laws and regulations or requested by any judicial process or governmental agency; and
  • For other purposes for which we provide specific notice at the time the Personal Information is collected.

Legal Bases for Processing European Personal Information

To the extent required by applicable law, if you are located in the European Economic Area (“EEA”), Switzerland or the United Kingdom (“UK”) (together “Europe”), we only process your Personal Information when we have a valid “legal basis,” including as set forth below.

  • Consent. You have consented to the use of your Personal Information. For example, we may process your Personal Information to send you marketing communications where you have consented to such use.
  • Contractual Necessity. We need your Personal Information to provide you with our Services. For example, we may need to process your Personal Information to respond to your inquiries or requests.
  • Compliance with a Legal Obligation. We have a legal obligation to use your Personal Information. For example, we may process your Personal Information to comply with tax, labor and accounting obligations.
  • Legitimate Interests. We or a third party have a legitimate interest in using your Personal Information. Specifically, we have a legitimate interest in using your Personal Information for Service development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our Services. We only rely on our or a third party’s legitimate interests to process your Personal Information when these interests are not overridden by your rights and interests.

How We Disclose the Personal Information We Collect

We may share your Personal Information with third parties in the following circumstances:

Affiliates. We may disclose any Personal Information we receive to our current or future affiliates for any of the purposes described in this Privacy Policy. 

Vendors and Service Providers. We work with third party service providers to operate our Services. For example, this includes services like SendGrid and Customer.io for sending emails to users, Intercom for providing live chat support, Stripe and Chartmogul for managing subscription payments and Stripe for identity document verification. These third parties may have access to or process your Personal Information as part of providing those services to us. 

Analytics Partners. We use analytics services such as Google Analytics and Mixpanel to collect and process certain analytics data. You can learn more about Google’s practices by visiting https://www.google.com/policies/privacy/partners/. You can opt out by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.

 

Advertising Partners. We work with third-party advertising partners to collect and process your information in order to show you ads that we think may interest you. Some of our advertising partners are members of the Network Advertising Initiative (https://optout.networkadvertising.org) or the Digital Advertising Alliance (https://optout.aboutads.info) and serve ads through cookie-based technologies. Please visit their opt-out pages to learn about how you may opt out of receiving certain web-based personalized ads from member companies. These opt-outs will apply only to our third-party advertising partners that are members of these organizations. These opt-outs will not apply when our partners serve ads through non-cookie-based technologies. You can access any settings offered by your mobile operating system to limit ad tracking, or you can install the AppChoices mobile app to learn more about how you may opt out of personalized ads in mobile apps. 

As Required by Law and Similar Disclosures. We may access, preserve, and disclose your Personal Information if we believe doing so is required or appropriate to: (a) comply with law enforcement requests and legal process, such as a court order or subpoena; (b) respond to your requests; or (c) protect your, our, or others’ rights, property, or safety. For the avoidance of doubt, the disclosure of your Personal Information may occur if you post any objectionable content on or through the Services.

Merger, Sale, or Other Asset Transfers. We may transfer your Personal Information to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or we sell, liquidate, or transfer all or a portion of our assets. 

Consent. We may also disclose your Personal Information with your permission.

Your Rights and Choices

Marketing Communications. You can unsubscribe from our promotional emails via the link provided in the emails. Even if you opt out of receiving promotional email messages from us, you will continue to receive administrative messages from us.

Your European Privacy Rights. To the extent applicable, if you are located in Europe, you have the additional rights described below:

  • Access and Portability. You may ask us to provide you with a copy of the Personal Information we maintain about you, including a machine-readable copy of the Personal Information that you have provided to us, and request information about its processing.
  • Rectification and Deletion. You may ask us to update and correct inaccuracies in your Personal Information, or to have the information anonymized or deleted, as appropriate.
  • Restriction and Objection. You may ask us to restrict the processing of your Personal Information, or object to such processing.
  • Consent Withdrawal. You may withdraw any consent you previously provided to us regarding the processing of your Personal Information, at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.
  • Complaint. You may lodge a complaint with a supervisory authority, including in your country of residence, place of work, or where an incident took place. We would, however, appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.

You may exercise these rights by contacting us using the contact details as indicated in the “Contact Information” section below. Before fulfilling your request, we may ask you to provide reasonable information to verify your identity. Please note that there are exceptions and limitations to each of these rights, and that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain Personal Information for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so, to the extent permitted by applicable law.

Third Parties

Our Services may contain links to other websites, products, or services that we do not own or operate. We are not responsible for the privacy practices of these third parties. Please be aware that this Privacy Policy does not apply to your activities on these third-party services or any information you disclose to these third parties. We encourage you to read their privacy policies before providing any Personal Information to them.

Retention

To the extent required by applicable law, we take measures to delete your Personal Information or keep it in a form that does not permit identifying you when your Personal Information is no longer necessary for the purposes for which we process it unless we are required by law to keep your Personal Information for a longer period. When determining the specific retention period, we consider various factors, such as the type of service provided to you, the nature and length of our relationship with you, and mandatory retention periods provided by law and the statute of limitations.

Security 

We make reasonable efforts to protect your Personal Information by using physical and electronic safeguards designed to improve the security of the Personal Information we maintain. However, because no electronic transmission or storage of Personal Information can be entirely secure, we can make no guarantees as to the security or privacy of your Personal Information.

Children’s Privacy

We do not knowingly collect, maintain, or use Personal Information from children under 18 years of age, and no part of our Service(s) is directed to children. If you learn that a child has provided us with Personal Information in violation of this Privacy Policy, then you may alert us at support@hellobonsai.com. 

International Transfers

Our Services are hosted in the United States (“U.S.”). If you choose to use the Services from Europe or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that your Personal Information is processed and stored in the U.S. We may also transfer your Personal Information from the U.S. to other countries or regions in connection with its storage and processing, fulfilling your requests, and operating the Services. 

If you are located in Europe, we will comply with applicable European data protection laws when transferring your Personal Information outside Europe. We may transfer your Personal Information to countries which have been found to provide adequate protection by the competent supervisory authorities as appropriate, use contractual protections for the transfer of Personal Information, transfer to recipients who have adopted Binding Corporate Rules, or rely on an appropriate legal derogation, to the extent necessary to comply with applicable European data protection laws. To the extent applicable, if you are located in Europe, you may contact us as specified below for more information about the safeguards we use to transfer Personal information outside of Europe.

Update Your Personal Information 

You can update your account information or close your account through your profile settings. For more information about deactivating or deleting your account, please refer to our Help Center.

Changes to this Privacy Policy

We will post any adjustments to the Privacy Policy on this page, and the revised version will be effective when it is posted. If we materially change the ways in which we use or disclose Personal Information previously collected from you through the Services, we will notify you through the Services, by email, or other communication.

Contact Information

Bonsai is responsible for processing your Personal Information described in this Privacy Policy. If you have any questions, comments, or concerns about our processing activities, please email us at support@hellobonsai.com.

See previous version.