Privacy Policy
Effective date: 21 June 2026 · Last updated: 9 July 2026
This Privacy Policy explains how Hakkens Trading ("BluePing", "we", "us", "our") collects, uses, shares, and protects personal data in connection with the BluePing service (the "Service"), which connects a Slack workspace to one or more Bol.com selling accounts and posts order notifications in Slack. This statement explains how we handle personal data so you can understand and exercise your rights. It is provided for transparency under Articles 13 and 14 GDPR; it is not itself a contract or a consent form. The terms that apply to your use of the Service are set out separately, and where we rely on consent for a specific purpose, we ask for it separately (see Section 3).
1. Who we are and our role
The controller for the personal data described in this policy is Hakkens Trading, Lovensbroek 3, 5541HG Reusel, Netherlands. You can reach us at info@blueping.app. We are not required to appoint a data protection officer under Article 37 GDPR; please direct all privacy inquiries to the contact above. Because we are established in the EEA (Netherlands), an EU representative under Article 27 is not required.
BluePing is a business-to-business tool, and we are the controller for the personal data we process to provide the Service under the General Data Protection Regulation (GDPR). This includes the identity data of the authorized users who sign in to and administer the Service (for example, Slack identity data), the Bol.com API credentials you provide (which we store and use on your behalf to authenticate with Bol.com), and our own business records. The order data we store is a limited product/order summary that contains no end-customer names, addresses, contact details, or payment information (see Section 2), and therefore does not identify your customers.
2. What data we collect
- Identity and sign-in data. When you sign in with Slack, we receive your Slack user ID, your Slack team ID (workspace ID) and name, your display name, and (where your Slack profile shows it) your email address. Your display name and email address are stored only in your encrypted sign-in cookie (
BluePing.Auth) on your device, for the duration of your session; we do not store them in our database. We do store, on the server side, the Slack ID of the user who installs the bot, together with the workspace ID and name. - Slack installation data. When you install the BluePing bot, we store the workspace ID and name, the Slack ID of the installing user, and a Slack bot token used to list channels and post messages. The bot token is stored encrypted.
- Bol.com API credentials. The Bol.com Retailer API client ID and client secret you provide are stored encrypted (encryption at rest) and used solely to authenticate with Bol.com on your behalf.
- Order data. For each order we detect, we store the Bol.com order number, the order date, the order status, and a limited line-item summary: product title, EAN, SKU/offer reference, quantity, fulfilment method (FBR/FBB), and the ship-by or delivery deadline. We do not collect or store end-customer names, addresses, email addresses, or payment information. We receive this order data from the Bol.com Retailer API, not directly from end customers.
- Operational and technical data. Timestamps of connection tests and syncs, the most recent error message per account, and server logs used for security and troubleshooting. We ensure that we do not log credentials, tokens, or the contents of authentication and token-exchange requests; other diagnostic logs may contain API error responses (which may include workspace metadata such as channel names) and request metadata. Our hosting provider and reverse proxy may separately log network-level connection metadata, such as IP addresses.
- Support communications. Information you provide when you contact us.
- Website analytics. Our marketing site (blueping.app) uses Simple Analytics, a cookieless, privacy-friendly analytics provider, to measure aggregated visits and clicks on the sign-up button. It sets no cookies and does not track you across other websites; anonymized, aggregated visit telemetry is collected (such as page URL, referrer, browser type, screen size, and language), and the Do Not Track browser setting is respected.
- Product analytics. Where enabled, the application (app.blueping.app) sends a small set of product-usage events (for example, bot installation, checkout started, subscription changed, notification sent, and usage-limit notices) to PostHog (EU region). These events are linked to your Slack workspace and contain only your workspace name and subscription tier; they contain no end-customer data.
- Billing data. If you subscribe to a paid plan, our payment provider Lemon Squeezy (acting as Merchant of Record) handles your payment. We pass your email address to the Lemon Squeezy checkout to pre-fill the payment form, and we store the Lemon Squeezy customer and subscription IDs, your subscription status, and the renewal/end dates. We do not receive or store your card details.
We do not use advertising cookies, and we do not sell your data or track you across unrelated third-party websites for advertising. The analytics described above are limited to measuring our own site and product usage.
3. How we use data, and our legal bases
- To provide the Service: authenticating with Bol.com, checking your accounts for new orders and status changes, deduplicating orders, posting order notifications, and responding to slash commands. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To secure, maintain, debug, and improve the Service and to prevent fraud and abuse. Legal basis: our legitimate interests (Art. 6(1)(f)) in keeping the Service reliable, secure, and free of abuse. We limit this processing to what is necessary, for example by not including credentials and no request content from authentication/token endpoints in our logs (see Section 2) and by isolating and scoping all data per workspace (see Section 7). You may object to this processing at any time (see Section 8), and a summary of our legitimate-interests balancing test is available on request.
- To comply with legal obligations (Art. 6(1)(c)).
- With your consent where we ask for it for an optional purpose (Art. 6(1)(a)); you can withdraw your consent at any time.
We do not use your data for automated decision-making that produces legal effects or similarly significant effects.
4. How we share data
We do not sell your personal data, and we do not share it for advertising. We share data only with the following categories of recipients, under contract and on a need-to-know basis:
- Slack (Slack Technologies, LLC / Salesforce): our identity provider for sign-in and the destination for the order notifications you configure.
- Bol.com: we send your API credentials to Bol.com to authenticate, and receive your order data from Bol.com, on your behalf.
- Cloudflare: our edge network, CDN, and reverse proxy/tunnel sit in front of the Service; Cloudflare processes connection metadata, including visitor IP addresses, and terminates TLS.
- Amazon Web Services (AWS): AWS Key Management Service (KMS), in the eu-west-2 region (London, United Kingdom), which envelope-encrypts our encryption keyring. Where offsite backups are enabled, encrypted database and keyring backups may also be stored in AWS S3 (eu-west-2). AWS does not host the live application or database.
- Sentry: application error monitoring used to capture and diagnose technical errors; diagnostic events may contain request metadata.
- OVH: our VPS hosting provider (in the European Union), which runs the server and the PostgreSQL database on which the Service's data is stored.
- Lemon Squeezy: our payment provider and Merchant of Record for paid plans. When you subscribe, we pass your email to the checkout and receive subscription and customer IDs, status, and renewal dates via webhook. Lemon Squeezy is the seller of record and handles payment, invoicing, and taxes under its own terms and privacy policy.
- PostHog: product analytics provider (EU region) that, where enabled, receives aggregated, per-workspace-linked usage events (such as installations, checkouts, subscription changes, and sent notifications) with your workspace name and subscription tier, and no end-customer data.
- Simple Analytics: cookieless, EU-hosted website analytics for our marketing site (blueping.app), which receives anonymized, aggregated visit telemetry as described in Section 2.
- Professional advisers and authorities: where required by law, legal process, or to protect rights and safety.
- In a business transaction: for example, a merger or acquisition, subject to this policy.
An up-to-date list of our sub-processors is available on request.
5. International data transfers
We host the Service, the application, and its associated PostgreSQL database on an OVH VPS in the European Union. Our website analytics (Simple Analytics) and product analytics (PostHog, EU region) are hosted in the EU, so these involve no transfer outside the EEA. However, some of our other recipients process personal data outside the European Economic Area (EEA): Slack/Salesforce, Cloudflare, Sentry, and Lemon Squeezy are established in the United States, and our AWS KMS key material and any encrypted offsite backups are processed in the United Kingdom (eu-west-2, London). Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, a European Commission adequacy decision for the country concerned, or the EU–US Data Privacy Framework where the recipient is certified. A copy of the relevant safeguard is available on request.
6. How long we keep data
- Slack OAuth state tokens: short-lived and automatically deleted (within approximately one hour).
- Order history ("seen orders"): by default automatically deleted once older than 90 days (configurable). We keep this limited order summary to prevent duplicate notifications and to display the order overviews. You can request deletion at any time.
- Credentials and tokens: kept for the duration of the connection. Deleting a Bol.com account on the settings page removes its stored credentials. When you remove (uninstall) the BluePing app in Slack, we automatically delete your entire workspace record and all data linked to it, including the connected Bol.com accounts and their credentials, the order history, and your notification settings. Merely revoking the Slack bot token without uninstalling the app reversibly pauses processing and does not delete any data.
- Server logs (which may contain request metadata): retained for up to 90 days for security and troubleshooting, then deleted or anonymized. Where logs are retained by our hosting, edge, or logging provider, the retention period follows their configured period, which we limit to the minimum needed for these purposes.
- We delete or anonymize personal data when it is no longer needed for the purposes above or upon a valid erasure request, subject to any statutory retention obligations.
7. How we protect data
- Credentials and tokens are stored encrypted (encryption at rest) with authenticated encryption (AES-256 with HMAC-SHA256), and in our production environment the encryption keyring itself is envelope-encrypted with a cloud key-management service (AWS KMS), so that read access to the key store alone is insufficient to decrypt stored secrets.
- Data in transit is protected with TLS/HTTPS.
- Each customer's data is isolated and scoped to their Slack workspace: one workspace cannot access another's accounts, orders, or credentials.
- We apply least-privilege access controls and a secure-by-default configuration.
- No method of transmission or storage is completely secure, so we cannot guarantee absolute security. In the event of a personal data breach, we will notify the competent supervisory authority and, where required, the affected individuals as required by law (under the GDPR, without undue delay and, where feasible, within 72 hours).
8. Your rights
As a data subject, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected and incomplete data completed;
- have your data erased ("right to be forgotten");
- restrict our processing of your data in certain circumstances (Art. 18);
- object, on grounds relating to your particular situation, to processing we carry out based on our legitimate interests (Art. 21); if you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment, exercise, or defense of a legal claim;
- receive your data in a portable format;
- withdraw your consent where processing is based on consent; and
- lodge a complaint with a supervisory authority; in the Netherlands this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
To exercise a right, contact us at info@blueping.app. We respond to rights requests free of charge and without undue delay, and in any case within one month of receipt. We may extend this period by up to two months where a request is complex or where we receive a large number of requests, and we will let you know within one month if this is necessary. We may ask you to verify your identity before we act on a request. We will not disadvantage you for exercising your rights.
9. Cookies
BluePing uses strictly necessary cookies only; no analytics, advertising, or cross-site tracking cookies are used:
BluePing.Auth: keeps you signed in for up to 7 days, extended on use (HttpOnly, Secure, SameSite=Lax).BluePing.SignInState: a short-lived cookie (about 10 minutes) that protects the sign-in flow against cross-site request forgery (HttpOnly, Secure, SameSite=Lax).- A framework anti-forgery cookie (default name
.AspNetCore.Antiforgery.*) and a one-time-message cookie (.AspNetCore.Mvc.CookieTempDataProvider), set by the application for security (cross-site request forgery protection) and to display one-time status messages. These are session-bound, HttpOnly, and strictly necessary.
These cookies are set by the application at app.blueping.app; the marketing site at blueping.app sets no cookies of its own, though it does use cookieless analytics (Simple Analytics) as described in Sections 2 and 4. Because all these cookies are strictly necessary, no consent banner is required, but we list them here for transparency.
10. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with data, please contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here and adjust the "last updated" date, and will provide additional notice of material changes where required.
12. Contact
Hakkens Trading, Lovensbroek 3, 5541HG Reusel, Netherlands.
Privacy inquiries: info@blueping.app. We are not required to appoint a data protection officer or an EU representative.