Who we are and scope
Bido is an agentic-commerce platform operated by Bido, Inc., a Delaware C Corporation (file number 10712575), headquartered at 2 Marina Blvd, Bldg B, Suite 300 N., San Francisco, CA 94123, USA (hereinafter "Bido", "we", "our").
This Policy covers the following products and surfaces:
- Conversational shopping assistant — intent-based recommendation of coupons, deals and products on WhatsApp, Instagram, SMS and iMessage;
- AI agent platform integrations — our tools exposed via the Model Context Protocol (MCP) inside assistants such as Claude (Anthropic), ChatGPT (OpenAI) and similar;
- Universal checkout (Bido Checkout) — completing purchases directly on the merchant's website, on your behalf and with your confirmation;
- Website — usebido.com and subdomains.
Bido operates exclusively in the United States. This Policy complies with applicable U.S. privacy laws — including state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA), where they apply to you. Cookies and similar technologies are detailed in the Cookie Policy. The conditions for using the service are in the Terms of Use.
Processing roles
For most processing described here, Bido acts as controller: it decides the purpose and means of processing the data of people who talk to us and who buy through our checkout.
In two scenarios the role changes:
- AI agent platforms (Claude, ChatGPT, etc.) — the conversation you hold inside the assistant is processed by the assistant's platform as an independent controller, under its own privacy policy. Bido only receives what the platform sends to our MCP tools (see §5);
- API integrators — when a third-party platform uses the Bido Checkout API to execute purchases for its users, Bido acts as a processor of the buyer data sent by the integrator, which remains the controller vis-à-vis the end user.
Merchants where the purchase is completed are always independent controllers of the order data they receive (see §6.4).
Privacy contact
For any privacy or data-protection matter:
- Owner: Bido Privacy Team
- E-mail: bellujrb@usebido.com
- Postal address: Bido, Inc. — 2 Marina Blvd, Bldg B, Suite 300 N., San Francisco, CA 94123, USA
All data-subject requests (§12 of this policy) should be sent to that e-mail.
Data we collect
4.1. Conversation and per-channel identification
When you interact with Bido on a messaging channel or agent platform, we process:
| Data | Source | Purpose |
|---|---|---|
| Channel identifier — E.164 phone number (WhatsApp, SMS, iMessage), account ID (Instagram) or integration/thread ID (Claude, ChatGPT) | Channel platform (Meta, carrier, Apple, agent host) | Identify your session; route responses; link channels to your single Bido account |
| Profile name (when the channel provides it) | Channel platform payload | Personalize the greeting inside the current session |
| Text messages and button/widget interactions | Channel webhook or MCP tool call | Understand your purchase intent and respond with relevant offers and actions |
| Bido account credentials (e-mail, hashed password) — when you create an account | You, in the login/sign-up flow | Universal account across channels; authentication for checkout tools |
4.2. Universal checkout — buyer data
When you ask Bido (or an agent that uses Bido) to complete a purchase, we process the data needed to place the order with the merchant:
| Data | Purpose |
|---|---|
| Full name, e-mail and contact phone | Order identification at the merchant; status notifications |
| Shipping address | Shipping/tax calculation and delivery of the order by the merchant |
| Order items, amounts and status (product URL, quantity, landed cost) | Execution, tracking and proof of the purchase |
| Payment card — in tokenized form only. Card data is collected and encrypted directly into the Basis Theory vault (PCI DSS Level 1 certified); Bido receives and stores only the token identifier | Paying for the purchase at the merchant's own checkout, with your card |
| Credentials of operational accounts at merchants (when the merchant requires sign-up) — created with your real name and address and a system e-mail managed by Bido, with the password kept in an encrypted vault | Completing purchases at merchants without guest checkout, keeping you as the order's owner |
The full card number (PAN) and CVC never pass through Bido's servers, logs or AI models. The AI agent never has access to the payment instrument — payment filling is a deterministic code step, out of the model's reach.
4.3. Data we do NOT collect
Explicitly, we do not keep:
- Conversation history beyond the session window (see retention in §10);
- Contacts, address book, or friend list;
- Photos, videos or audio;
- Precise geolocation or biometric data;
- Full card number, CVC or bank account data (see §4.2);
- Sensitive data (health, religion, sexual orientation, political opinion) — if sent by mistake, it is neither used nor retained beyond the session.
Our architecture follows the data minimization principle: each component receives only what is strictly necessary for its function.
AI agent platforms (MCP)
When you use Bido inside an AI assistant (Claude, ChatGPT or similar), there are two distinct processing activities:
- Your conversation with the assistant happens on the assistant's platform, under its own terms and privacy policy (Anthropic, OpenAI, etc.). Bido does not receive your conversation history with the assistant;
- Calls to Bido's tools — when the assistant invokes one of our tools (search for a deal, start a checkout), we receive only the parameters of that call (e.g., the product query, the product URL) and the integration identifier needed to recognize your Bido account.
Your Bido account login and password are entered in a secure component of ours, rendered inside the assistant: the password never passes through the AI model or the assistant's platform in clear text, and the session token is never exposed to the model.
Payment data entered in widgets inside the assistant is tokenized directly against the Basis Theory vault (see §4.2) — it does not pass through the model, the assistant's platform, or Bido's servers.
How we use your data
6.1. Purposes
We process personal data exclusively to:
- Execute the requested service — understand your message, return relevant offers and, when you ask and confirm, complete the purchase at the merchant;
- Execute payment securely — card tokenization and 3DS confirmations with your bank;
- Security and integrity — detect abuse, fraud, prompt-injection attempts and spam;
- Comply with legal obligations — tax, accounting and consumer-protection duties related to executed orders;
- Continuous improvement — analyze aggregate, anonymized patterns to improve recommendations and checkout success rate.
6.2. Legal bases
| Purpose | Legal basis |
|---|---|
| Answer queries and execute requested purchases | Contract performance |
| Payment processing and anti-fraud | Contract performance and legitimate interest |
| Platform security | Legitimate interest |
| Keeping order records and invoices | Compliance with legal obligation |
| Storing a tokenized card for future purchases | Consent — revocable at any time |
6.3. Agentic purchases and automated decisions
Bido's agent only executes a purchase upon your instruction and after your explicit confirmation of the total cost (item + shipping + taxes). No payment is triggered by an autonomous decision of the agent. You may request human review of any automated decision that affects you through the channel in §12.
6.4. What the merchant receives
To place your order, the merchant receives: your name, shipping address, the order items and, when the merchant requires sign-up, a system e-mail managed by Bido (so your personal e-mail is not exposed). The merchant processes this data as an independent controller, under its own privacy policy. The merchant remains the seller (Merchant of Record) and processes the payment on its own provider.
We do not use your data for targeted advertising outside the conversation, for selling data to third parties, for credit profiling or any psychographic analysis.
Sharing with third parties (processors)
To run the service, we rely on sub-processors. Each one receives only the data strictly necessary for its function:
| Processor | Role | Shared data | Location |
|---|---|---|---|
| Meta Platforms Ireland Ltd. | WhatsApp Business Cloud API and Instagram Messaging | Messages and channel identifier (needed to carry the conversation) | EU + global servers |
| SMS carriers / gateways and Apple (iMessage) | Message transport on the respective channels | Messages and phone number | Per channel |
| Anthropic PBC | Natural language processing (LLM Claude) — intent classification and response generation | Current message text + short session history. No phone number or payment data | United States |
| Pinecone Systems Inc. | Semantic vector search for recommendation | Query text (no PII) | United States |
| Supabase Inc. | Application database | Accounts, channel identities, offer catalog, orders and card tokens (token IDs only — never PAN) | United States |
| Basis Theory Inc. | Card vault and payment proxy (PCI DSS Level 1) | Card data (collected directly by the vault; Bido never sees it) | United States |
| Browserbase Inc. | Browser sessions for executing checkout on the merchant's website | Data typed into the merchant's checkout during the session (address, items); session replay for audit | United States |
| Temporal Technologies (Temporal Cloud) | Checkout workflow orchestration | Order state and internal references (no payment instrument) | United States |
| Resend Inc. | System e-mail inbox for operational merchant accounts | Transactional e-mails from the merchant (confirmations, verification codes) | United States |
| Amazon Web Services (AWS) | Application server hosting | Application logs (temporary) | United States |
All processors have Data Processing Agreements requiring confidentiality, security, and compliance with applicable privacy laws.
We do not sell, rent, or share your data with advertisers. Advertisers and partners receive only aggregate performance statistics (impressions, clicks, attributed conversions) with no individual identifier.
International data transfers
Bido is headquartered and operates in the United States, and your data is processed in the U.S. by the processors in §7. When a processor needs to process data outside the U.S. (e.g., global messaging infrastructure), we require:
- Standard Contractual Clauses with each processor;
- Verification that the organization provides adequate data-protection safeguards;
- Periodic compliance audits.
Security
We adopt technical and administrative measures aligned with industry best practices:
- Encryption in transit: TLS 1.3 on all HTTP communication;
- Encryption at rest: databases encrypted on the provider side;
- End-to-end card tokenization (Basis Theory, PCI DSS Level 1) — the PAN never exists in Bido's infrastructure; tokens are excluded from logs and metrics;
- AI / payment separation — the AI model never accesses the payment instrument; the payment step is deterministic code;
- Encrypted credential vault for operational merchant accounts;
- HMAC-SHA256 validating received webhooks to prevent spoofing;
- Least-privilege principle — access tokens scoped narrowly;
- Input sanitization — protection against prompt injection attempting to exfiltrate data;
- Audit trails — checkout session replay for execution verification;
- Continuous dependency auditing and periodic credential rotation.
No system is 100% immune. In case of a material security incident, we notify affected individuals and the competent authorities as required by applicable U.S. state data-breach notification laws. A detailed explanation of how we protect your card is at usebido.com.
Data retention
| Data | Retention period | Reason |
|---|---|---|
| Conversation state (session) | 30 minutes after the last message | Operational need |
| Full message history | Not retained beyond the session | Data minimization |
| Executed orders (items, amounts, shipping address, status) | 5 years after the purchase | Applicable tax and consumer-protection obligations |
| Card token (vault ID) | Until you remove the card or close the account | Consent — revocable at any time |
| Operational merchant accounts (vaulted credentials) | While needed for orders, returns and support; deleted upon request | Contract performance |
| Technical access logs (IP, timestamp) | 90 days | Security and fraud prevention |
| Encrypted backups | 30 days after deletion | Disaster recovery |
After the applicable period, data is permanently deleted or irreversibly anonymized.
Minors
Bido is not directed at anyone under 18 — executing purchases requires full legal capacity. The channels used (WhatsApp, Instagram, etc.) already impose their own minimum age under the respective platforms' terms.
If we identify an account or interaction from a minor, we delete the data and end the interaction. We do not conduct targeted advertising to minors.
Your rights as a data subject
Under applicable privacy laws (including the CCPA/CPRA, where applicable), you may at any time:
- Confirm that we process your data;
- Access the data we hold about you;
- Correct incomplete, inaccurate or outdated data;
- Anonymize, block or erase unnecessary, excessive or non-compliant data;
- Port your data to another provider upon express request;
- Delete data processed based on consent (e.g., remove a saved card);
- Be informed about public or private entities with which we share data;
- Be informed about the possibility of withholding consent and its consequences;
- Withdraw consent at any time;
- Request review of decisions made exclusively based on automated processing.
To exercise any right, e-mail bellujrb@usebido.com with:
- Full name;
- Identifier used with Bido — phone (e.g., +14155550123), account e-mail or agent channel;
- The right you wish to exercise.
We acknowledge receipt within 5 business days and reply within 45 calendar days, per the deadlines of applicable privacy laws.
Cookies and similar technologies
Messaging channels (WhatsApp, Instagram, SMS, iMessage) and AI assistants do not use cookies of ours. On the website, we use only what is strictly necessary.
The full breakdown — categories, purposes and how to control them — is in the Cookie Policy.
Changes to this Policy
We may update this Policy from time to time. The current version is always published at:
https://usebido.com/privacidade
Material changes will be communicated via:
- A message inside the channel on your next interaction;
- A prominent notice on the website.
Continued use of Bido after a change implies awareness of the new version.
Governing law and venue
This Policy is governed by the laws of the State of Delaware, United States, without regard to its conflict-of-laws rules. Any controversy will be resolved by the competent state or federal courts located in Delaware, USA.
Residents of certain U.S. states (such as California, Colorado and Virginia) may have additional rights under their state privacy laws — to exercise them, use the channel in §12.
Complaint to the authority
In addition to the internal channels in §12, you may file a complaint directly with the competent U.S. authorities:
- Federal Trade Commission (FTC): https://reportfraud.ftc.gov
- Your state's Attorney General — for example, in California: https://oag.ca.gov/contact/consumer-complaint-against-business-or-company

