1. Introduction
1.1Bridgemont Technologies LLC sells software, licence keys and other digital products — the types listed in clause 12.1 of the Acceptable Use Policy — to Buyers in its own name, as the seller on every sale. It buys licences for those products from independent Suppliers at a fixed wholesale price per product. Suppliers use the Supplier Dashboard to load their licence keys and files into Bridgemont and to see what Bridgemont has bought and their statements.
1.2Doing that means handling Personal Data — about the people who buy from Bridgemont, the Suppliers Bridgemont buys from and the individuals who act for them, and the people who visit Bridgemont’s websites, contact support, or apply for a job.
1.3This Policy explains what is collected, why, on what legal basis, who it is shared with, where it goes, how long it is kept, and what you can require of Bridgemont. It is written to be read. Where a passage is legally precise at the cost of being plain, the precision is deliberate.
1.4Bridgemont does not sell Personal Data, and does not share it for third-party advertising.
2. Scope
2.1This Policy applies to Personal Data Bridgemont processes as Controller — that is, where Bridgemont decides why and how the data is processed. Because every sale made through the Bridgemont Sites is made by Bridgemont, that includes all Personal Data about Buyers Processed in connection with a sale.
2.2It applies to Buyers, Suppliers and the individuals who act for them, Website Visitors, Job Applicants, support contacts, and the individual representatives of business partners.
2.3Bridgemont does not share Customer Data with Suppliers. A Supplier learns only that a licence key was sold, and never receives your email or other details. Clause 4 explains the roles.
2.4It does not cover a Supplier’s own website or other channels outside the Bridgemont Sites. If you typed your email or other details on a Supplier’s website, that website’s privacy policy covers it. If a Digital Product checks its licence key with its Supplier’s licence server when you activate it, the Supplier handles that activation record only for Bridgemont, as clause 4.4 describes. Anything else the Digital Product sends to its Supplier’s own servers when you use it is covered by the Supplier’s privacy notice. Buying a Digital Product from Bridgemont never requires you to give your details to a Supplier, and any question about a purchase, or about how your data is used in connection with it, goes to Bridgemont.
2.5Bridgemont’s use of cookies is described in clause 45.
3. Definitions
- Account
- an account created on the Bridgemont Sites or the Supplier Dashboard, including a Supplier account, a Buyer account, a guest record generated at Checkout, and any administrative credential issued by Bridgemont.
- Applicable Law
- any law, regulation, rule, sanctions measure, export control, payment card network rule, or binding order of a competent authority applying to Bridgemont, to a User, or to a transaction.
- Bridgemont
- Bridgemont Technologies LLC, a limited liability company organised under the laws of Wyoming, United States (state entity number 2026-002090864), with its principal place of business at 1309 Coffeen Avenue, Suite 20769, Sheridan, WY 82801, United States, and the seller on every sale made through the Bridgemont Sites. “we”, “us”, and “our” refer to Bridgemont.
- Bridgemont Sites
- the websites operated by Bridgemont for buyers: bridgemont.io, and the Product Pages and Checkout at checkout.bridgemont.io through which Bridgemont sells Digital Products to Buyers, including order confirmation and delivery.
- Buyer
- any natural or legal person who buys, or attempts to buy, a Digital Product from Bridgemont through the Bridgemont Sites.
- Buyer Terms
- the Bridgemont Terms of Sale (also called the Buyer Terms), governing each sale of a Digital Product by Bridgemont to a Buyer.
- Checkout
- the order and payment step on a Product Page, operated by Bridgemont, through which a Buyer places an Order with Bridgemont and pays Bridgemont by card.
- Controller
- the person who determines the purposes and means of Processing, as defined in the GDPR.
- Customer Data
- Personal Data about a Buyer or prospective Buyer Processed in connection with a sale by Bridgemont, including identity and contact data, order and delivery records, and licence and activation records. Buyers are Bridgemont’s customers, and Bridgemont is the Controller of Customer Data.
- Data Subject
- the identified or identifiable natural person to whom Personal Data relates.
- Digital Product
- a digital product of a type listed in clause 12.1 of the Acceptable Use Policy — such as an app or utility, a licence key or activation code, a game mod or overlay (a game mod is sold only where the game’s publisher allows it), a plugin, a template, theme or UI kit, an e-book or guide, or a downloadable course — that Bridgemont buys from a Supplier and sells to Buyers through the Bridgemont Sites, delivered by electronic means. Bridgemont does not sell physical goods.
- EEA
- the European Economic Area, comprising the member states of the European Union together with Iceland, Liechtenstein, and Norway.
- GDPR
- Regulation (EU) 2016/679 (the General Data Protection Regulation), together with the national laws implementing and supplementing it, and, for people in the United Kingdom, the UK GDPR.
- Job Applicant
- a person who applies for a role with Bridgemont or is considered for one, whether or not they applied.
- Order
- a Buyer's request to purchase one or more Digital Products from Bridgemont, submitted through Checkout.
- Personal Data
- any information relating to an identified or identifiable natural person, as defined in the GDPR.
- Policy
- this Privacy Policy, as amended from time to time in accordance with clause 40.
- Processing
- any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, restriction, erasure, and destruction. “Process”, “Processes”, and “Processed” are construed accordingly.
- Processor
- the person who Processes Personal Data for a Controller and on that Controller's instructions, as defined in the GDPR.
- Product Page
- Bridgemont’s page for a Digital Product, hosted by Bridgemont at checkout.bridgemont.io, on which Bridgemont offers the Digital Product for sale in its own name. A Buyer usually reaches a Product Page from a Buy button on the Supplier’s own website, shown next to the words “Sold and delivered by Bridgemont Technologies LLC”, and the sale is always made by Bridgemont. Every Digital Product Bridgemont sells, and its Supplier, is listed at bridgemont.io/approved-developers.
- Special Category Data
- Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data processed to uniquely identify a person, data concerning health, and data concerning a person's sex life or sexual orientation, as described in Article 9 of the GDPR.
- Standard Contractual Clauses
- the standard data protection clauses adopted by the European Commission under Article 46 of the GDPR for transfers of Personal Data to third countries, and the UK equivalents.
- Supervisory Authority
- an independent public authority in an EEA state or in the United Kingdom responsible for monitoring the application of the GDPR.
- Supplier
- a company, or a sole trader aged 18 or over, that makes a Digital Product or holds the rights to sell it, and sells licences for it to Bridgemont at a fixed wholesale price for resale under the Supplier Agreement. A Supplier is Bridgemont’s vendor: it does not sell to the Buyer, does not take the Buyer’s payment, and has no contract with the Buyer. Bridgemont’s public pages call a Supplier a developer.
- Supplier Agreement
- the agreement between a Supplier and Bridgemont governing the supply of Digital Products to Bridgemont, the wholesale price Bridgemont pays for them, refunds, chargebacks, and adjustments.
- Supplier Dashboard
- the website at dashboard.bridgemont.io where invited Suppliers sign in to load licence keys and files into Bridgemont and see their statements and payments.
- User
- any person who uses the Bridgemont Sites or the Supplier Dashboard in any capacity, including a Buyer, a Supplier, and a person administering an Account.
- Website Visitor
- a person who visits a Bridgemont website or a Product Page without placing an Order or signing in.
3.1In this Policy, the capitalised terms below have the meanings given. Terms defined in the singular include the plural and vice versa, and a reference to a clause is a reference to a clause of this Policy unless stated otherwise.
3.2Terms also defined in the Supplier Agreement, the Buyer Terms, or the Acceptable Use Policy carry the same meaning here. Where a definition below is drawn more widely, it governs the construction of this Policy.
4. Data Controller
4.1Bridgemont is the Controller for the Personal Data described in this Policy. Bridgemont can be reached about any privacy matter at [email protected], or by post at 1309 Coffeen Avenue, Suite 20769, Sheridan, WY 82801, United States.
4.2Bridgemont acts as Controller in respect of: Buyers and every sale Bridgemont makes to them, including Orders, payment, delivery, refunds, chargebacks, and support; Supplier Accounts and the individuals who administer them, including the verification of Suppliers and payment for the licences Bridgemont buys from them; fraud prevention and the security of the Bridgemont Sites and the Supplier Dashboard; identity verification, sanctions screening and financial-crime prevention; accounting, tax, and regulatory records; Website Visitors; Job Applicants; support correspondence; and business partner contacts.
4.3Bridgemont is the Controller of Customer Data. As the seller, Bridgemont determines why and how a Buyer’s data is Processed in order to sell to that Buyer, take payment, screen the transaction for fraud, deliver the Digital Product, meet its tax and accounting obligations, and handle refunds, complaints, and chargebacks.
4.4A Supplier is not a Controller of Customer Data. A Buyer’s contract is with Bridgemont, and the Buyer is Bridgemont’s customer, not the Supplier’s. Bridgemont does not share a Buyer’s email or other details with the Supplier. The Supplier learns only that a licence key was sold. It does not contact the Buyer — Bridgemont answers all Buyer support. The one exception is narrow: where a Digital Product checks its licence key with the Supplier’s licence server when you activate it, the Supplier keeps the activation record for that key (for example a device or installation identifier) only to run the licence, as Bridgemont’s Processor under clause 18 of the Supplier Agreement, and may not use it for anything else, including contacting you.
4.5Bridgemont does not act as a Processor for Suppliers. The Supplier Dashboard is provided for supplying Digital Products to Bridgemont and seeing statements and payments, not for a Supplier to store or manage Personal Data for its own purposes.
4.6The same person’s data can be Processed for more than one purpose. When you buy a Digital Product, Bridgemont Processes your data to complete and support the sale, and separately to operate and secure the Bridgemont Sites and to meet its legal obligations. Bridgemont is the Controller for each of those purposes; the purpose determines the legal basis and the retention period, not the person.
4.7A Supplier must never contact a Buyer about a purchase made from Bridgemont. If a Supplier contacts you about a purchase you made from Bridgemont, tell Bridgemont at [email protected].
4.8Bridgemont and a Supplier are not joint Controllers except where Applicable Law characterises a specific Processing operation that way. Where it does, the essence of the arrangement will be made available to affected Data Subjects.
5. Categories of Personal Data
5.1Identity and contact data: name, email address, telephone number, billing address, country of residence, and preferred language.
5.2Business data: trading name, legal name, legal form, registered address, company registration number, EIN or other tax identification number, tax forms such as a W-9 or W-8BEN-E, website, business category, and details of directors and beneficial owners where verification requires them.
5.3Account and authentication data: username, hashed credentials, multi-factor authentication status, session records, sign-in history, password reset events, and permission assignments.
5.4Transaction data: Orders, amounts, currency, Digital Products purchased, licence key and activation records, delivery and download records, invoices, refunds, chargebacks, the wholesale price Bridgemont pays Suppliers and the related monthly purchase statements, and the payment-related information described in clause 9.
5.5Technical and usage data: IP address, browser and device information, device identifiers, operating system, referring page, pages viewed, features used, diagnostic and error logs, and the cookies described in clause 45.
5.6Risk, communications, and other data: the fraud-prevention signals described in clause 24, identity verification material described in clause 12, support correspondence, marketing preferences, survey and feedback responses, and material submitted by a Job Applicant.
6. Data We Collect Directly
6.1Bridgemont collects Personal Data you provide when you create an Account, ask to join Bridgemont’s developer waiting list or are invited to supply Bridgemont, submit a Digital Product or its description, place an Order, or, as a Supplier, provide the details Bridgemont needs to pay you, including your wallet address and the signed message that proves you own the wallet.
6.2Bridgemont collects what you supply during identity or business verification, as described in clause 12.
6.3Bridgemont collects the content of messages you send — support requests, refund requests and complaints, reports made under the Acceptable Use Policy, sales enquiries, and correspondence about this Policy.
6.4Bridgemont collects material you submit when applying for a role, including your curriculum vitae, covering letter, work history, references where you provide them, and your right to work in the relevant jurisdiction.
6.5Where a field is optional, it is marked as such. Where a field is mandatory and you do not complete it, Bridgemont may be unable to open the Account, accept the Order, pay a Supplier, or provide the feature concerned.
7. Data Collected Automatically
7.1When you use the Bridgemont Sites or the Supplier Dashboard, Bridgemont automatically records technical information: IP address, approximate location derived from it, browser type and version, device type, operating system, screen characteristics, language, referring page, and the pages and features you use.
7.2Bridgemont records service logs — requests made, pages and addresses called, response codes, latency, errors, and security events such as failed sign-in attempts, credential resets, and permission changes.
7.3Bridgemont records signals used to assess the risk of a transaction, described in clause 24.
7.4The cookies Bridgemont uses are described in clause 45.
8. Data Received From Third Parties
8.1Bridgemont receives Personal Data from identity and business verification providers, including the outcome of a check and the information necessary to record that the check was performed.
8.2Bridgemont receives Personal Data from the licensed acquirer that processes card payments for Bridgemont, and from payment card networks, in connection with authorisation, refunds, chargebacks, and dispute handling.
8.3Bridgemont receives Personal Data from fraud-prevention and risk providers, including reputation signals associated with an email address, device, or payment instrument.
8.4Bridgemont receives Personal Data from public registers; from a Supplier that names you as an administrator or contact; from a person who reports you under the Acceptable Use Policy; from a person who submits a notice or counter-notice under the Intellectual Property Policy; and from a competent authority in connection with a lawful request.
9. Payment Information
9.1Buyers pay Bridgemont by card only (Visa or Mastercard). The Buyer enters the card details on Bridgemont’s Checkout. They are sent over an encrypted connection to Bridgemont’s payment system and passed to the licensed acquirer that processes card payments for Bridgemont, for authorisation. Card processing and acquiring are performed for Bridgemont by that acquirer; Bridgemont does not perform regulated payment services itself, and does not accept payments for Suppliers or anyone else.
9.2Bridgemont does not keep the full card number or security code after the payment has been authorised. What Bridgemont holds is limited payment-related information necessary to sell to the Buyer and handle the transaction: a payment reference, the card scheme, the first six and last four digits of the card number, a one-way fingerprint of the card number used to detect fraud and repeat abuse, the cardholder name, the billing address and country, the authorisation result, and the amount, currency, and status of the transaction.
9.3To pay a Supplier for the licences Bridgemont buys, Bridgemont holds the Supplier’s payment details: the address of the wallet to which Bridgemont pays the Supplier in USDC, the signed message from that wallet that proves the Supplier owns it, and the result of the sanctions screening of that wallet. Bridgemont pays only to a wallet that has passed both checks. It also keeps the monthly purchase statements and the records needed to show what Bridgemont paid and when.
9.4Bridgemont Processes payment-related information to take the Buyer’s payment, to process refunds and chargebacks, to prevent and detect fraud, to deliver Digital Products, to pay Suppliers, to operate and secure the Bridgemont Sites, and to comply with its legal obligations, including tax, accounting and sanctions requirements.
9.5Nothing in this clause makes Bridgemont a bank or a provider of payment services to a Supplier or anyone else, or alters the position set out in the Supplier Agreement.
10. Supplier Information
10.1Where you supply Digital Products to Bridgemont, Bridgemont Processes Personal Data about you, and about the individuals who administer your Account, as Controller, for the purpose of buying from you, paying you, providing the Supplier Dashboard to you, and meeting Bridgemont's own obligations.
10.2That data includes your identity and contact details, your business data, your Account and authentication data, the Digital Products and descriptions you submit, the wholesale prices in your purchase agreement, the records of licences Bridgemont has bought and your monthly purchase statements, your wallet address and the proof that you own it, your payment records, your refund and chargeback history, your risk profile, and your support correspondence.
10.3Bridgemont uses this data to decide whether to invite you from the developer waiting list; to verify your identity and, for a company, its registration and beneficial owners, before any of your Digital Products goes on sale; to screen you and your wallet against sanctions lists, including again before each payment to you; to offer and sell your Digital Products; to prepare your monthly purchase statement and pay you as clause 10.7 describes; to hold the reserve and make the deductions the Supplier Agreement provides for; to assess and manage risk; to provide support; to enforce the Acceptable Use Policy; and to meet accounting, tax, sanctions, and other legal obligations.
10.4Bridgemont may Process aggregated and de-identified information derived from Supplier activity to measure how the Bridgemont Sites and the Supplier Dashboard perform, to improve fraud detection, and to produce statistics. Where that information ceases to relate to an identifiable person it is no longer Personal Data.
10.5The Buyers who purchase your Digital Products are Bridgemont’s customers, and their data is Customer Data controlled by Bridgemont. Bridgemont does not share it with you: you learn only that a licence key was sold.
10.6Bridgemont publishes an Approved developers page at bridgemont.io/approved-developers, so that Buyers can check that a Buy button is genuine. It shows each Supplier’s legal or trade name, country, approved websites and the products Bridgemont sells for it, and the date it was approved. It shows business details only, never Buyer data. Where a Supplier trades under an individual’s name, that name appears on the page.
10.7Bridgemont pays you against a monthly purchase statement: licences bought × wholesale price. Each statement is paid 30 days after the end of each month, paid in USDC, only to a wallet you have proved you own (a signed message from that wallet) and that passes sanctions screening. 10% of each statement is held as a reserve for 120 days. That is why Bridgemont holds your wallet address, the signed message that proves you own the wallet, and the result of the wallet’s sanctions screening.
11. Buyer Information
11.1Where you buy from Bridgemont, Bridgemont Processes Personal Data about you as Controller, as the seller, for the purpose of the contract between you and Bridgemont under the Buyer Terms.
11.2That data includes your identity and contact details, your Account or guest record, your Order and delivery records, your licence key and activation records, the payment-related information described in clause 9, your refund and chargeback history, the risk signals described in clause 24, and your support correspondence with Bridgemont.
11.3We do not share your email or other details with the Supplier (the developer of the Digital Product you bought). The Supplier learns only that a licence key was sold. If you typed your email on a Supplier’s own website, that website’s privacy policy covers it.
11.4Bridgemont does not disclose your payment card details to a Supplier. A Supplier does not take your payment and has no need of them.
11.5You never need to contact the Supplier about your Order. Delivery, refunds, and complaints are handled by Bridgemont at [email protected], and questions about your Personal Data by Bridgemont at [email protected].
12. Identity Verification Information
12.1Before any of a Supplier’s Digital Products goes on sale, Bridgemont verifies the Supplier’s identity and, for a company, its registration and beneficial owners, and screens it against sanctions lists. Before each payment, Bridgemont repeats the sanctions screening for the Supplier and for the wallet it is paid to. Bridgemont may also verify a Buyer where a transaction, an Account, or a legal obligation requires it.
12.2Verification may involve collecting an identity document, a photograph or liveness capture, proof of address, business registration documents, ownership and control information, and, for a Supplier, a message signed from its wallet.
12.3Where a photograph or liveness capture is Processed by automated means to confirm that you are who you say you are, that Processing involves biometric data, which is Special Category Data. Bridgemont does this only with your explicit consent, under Article 9(2)(a) of the GDPR, which Bridgemont asks for separately before the check starts. If you do not want a biometric check, you can choose a check without biometrics instead — a short video call with a member of Bridgemont’s team, with your identity document — and choosing it does not count against you. You may withdraw your consent at any time before the check is complete.
12.4Verification material is Processed only for verification, for the prevention and detection of fraud and other financial crime, and for the retention period in clause 27. It is not used for marketing, and is not disclosed to a Supplier or a Buyer. Biometric data from a liveness check is deleted as soon as the check is complete; the record that the check was done, and its result, are kept under clause 27.4.
13. Device Information
13.1Bridgemont records information about the device you use: device type, operating system and version, browser and version, screen and rendering characteristics, language and time zone, and a device identifier derived from those characteristics.
13.2Device information is used to keep the Bridgemont Sites and the Supplier Dashboard secure, to recognise a returning session, to detect account takeover and coordinated abuse, to reproduce a defect you report, and to render the interface correctly.
13.3Device information used for fraud prevention is described in clause 24, and the cookies Bridgemont uses in clause 45.
14. Usage Information
14.1Bridgemont records how the Bridgemont Sites and the Supplier Dashboard are used: pages and screens viewed, features opened, actions taken, search terms entered, request volumes, errors encountered, and performance timings.
14.2Usage information is used to operate and secure those websites, to diagnose faults, to measure whether features work, to plan capacity, to enforce rate limits and the Acceptable Use Policy, and to decide what to build.
14.3Bridgemont aggregates usage information wherever aggregation serves the purpose as well as identifiable data would.
15. Cookies and similar technologies
15.1Bridgemont uses only strictly necessary cookies, and no advertising or analytics cookies. Clause 45 describes them.
16. Analytics
16.1Bridgemont measures how the Bridgemont Sites and the Supplier Dashboard are used, in order to understand which features are used, where users encounter difficulty, and how the service performs in the field.
16.2Analytics is configured to minimise Personal Data. Bridgemont does not use analytics to build advertising profiles, does not combine analytics data with Customer Data, and does not sell or share it for third-party advertising.
16.3Bridgemont does not use analytics cookies or similar technologies, as clause 45 explains. It measures use from its own service logs, using aggregated or de-identified information wherever that serves the purpose.
17. Communications
17.1Bridgemont sends service communications that are necessary to sell and deliver to you and to run its websites: Order confirmations, delivery notifications and licence key or download details, receipts and invoices, refund and chargeback updates, security alerts, verification requests, statements to Suppliers, and notices of changes to the Bridgemont legal documents.
17.2Service communications are not marketing and cannot be opted out of while you hold an Account or an active Order, because they are how Bridgemont discharges its obligations to you.
17.3Bridgemont sends marketing communications only in accordance with clause 37.
17.4Bridgemont records that a communication was sent, and may record whether it was delivered and opened, in order to establish that a required notice reached you and to diagnose delivery failures.
18. Customer Support
18.1When you contact Bridgemont, the message, the contact details you use, and Bridgemont's response are recorded so the matter can be handled, so a later contact has context, and so Bridgemont can evidence what was said.
18.2Support staff may access the Account information necessary to resolve your matter, under the access controls described in clause 28. Access is logged.
18.3Do not send Bridgemont Special Category Data or payment card numbers through a support channel. Where you do so unprompted, Bridgemont removes the material from the record once the matter is resolved unless retention is legally required.
19. Purposes of Processing
19.1To sell and deliver Digital Products and run the Bridgemont Sites and the Supplier Dashboard: creating and administering Accounts, operating Product Pages and Checkout, taking payment, delivering Digital Products, processing refunds, handling chargebacks, and paying Suppliers for the licences Bridgemont buys from them.
19.2To secure the Bridgemont Sites and the Supplier Dashboard and prevent harm: authentication, access control, monitoring, incident detection and response, rate limiting, and the fraud prevention described in clause 24.
19.3To comply with the law and prevent financial crime: identity verification, sanctions screening, accounting, sales tax and, where it applies, VAT record-keeping, responding to lawful requests, and the enforcement obligations described in the Acceptable Use Policy.
19.4To support and communicate: answering enquiries, handling refund requests, complaints, and reports, sending service communications, and sending marketing where clause 37 permits.
19.5To improve and develop: diagnosing faults, measuring feature usage, planning capacity, and designing new functionality, using aggregated or de-identified information wherever that serves the purpose.
19.6To operate the business: accounting, recovering amounts due under the Supplier Agreement, insurance, professional advice, corporate transactions as described in clause 39, and the establishment, exercise, or defence of legal claims.
20. Legal Bases for Processing
20.1Performance of a contract, under Article 6(1)(b) of the GDPR, for: administering your Account; buying licences from Suppliers and paying for them; selling Digital Products to Buyers, taking payment, and delivering Orders; processing refunds; and providing support in connection with a transaction. Without this Processing Bridgemont cannot perform the Supplier Agreement or the Buyer Terms.
20.2Compliance with a legal obligation, under Article 6(1)(c), for: sanctions screening; accounting, invoicing, sales tax and, where it applies, VAT records; responding to a binding order; and the retention periods Applicable Law imposes.
20.3Legitimate interests, under Article 6(1)(f), for: verifying the identity, registration and beneficial owners of the Suppliers Bridgemont buys from, and the wallets it pays them to, and meeting the requirements Bridgemont’s payment partners set for knowing who it buys from; publishing the Approved developers page so that Buyers can check that a Buy button is genuine; preventing and detecting fraud, payment abuse, and chargeback abuse; securing the Bridgemont Sites and the Supplier Dashboard and investigating misuse; enforcing the Acceptable Use Policy; measuring and improving the service; producing aggregated statistics; direct marketing to existing business customers in the narrow circumstances described in clause 37; and establishing, exercising, or defending legal claims.
20.4Where Bridgemont relies on legitimate interests it has assessed those interests against your interests, rights, and freedoms, and Processes only what the purpose requires. You may object as described in clause 35, and may ask Bridgemont for a summary of the assessment.
20.5Consent, under Article 6(1)(a), for: marketing communications where clause 37 requires consent; any analytics or other non-essential cookies, which Bridgemont does not use today and would add only with your consent (clause 45); and any other Processing described as consent-based at the point it is collected. Consent may be withdrawn at any time, without affecting Processing carried out before withdrawal.
20.6Explicit consent, under Article 9(2)(a), where identity verification involves biometric data, as described in clause 12. You may refuse or withdraw it and use the check without biometrics instead.
20.7Vital interests, under Article 6(1)(d), where Processing is necessary to protect the life or physical safety of a person — for example where a communication received through the Bridgemont Sites discloses a credible risk of serious harm and disclosure to an emergency service is necessary.
20.8Where more than one basis is available, Bridgemont relies on the one stated above and does not switch basis to defeat a right you have exercised.
21. Sharing Personal Data
21.1Bridgemont does not share your email or other details with the Supplier of a Digital Product you buy. The Supplier learns only that a licence key was sold, and keeps an activation record only as clause 4.4 describes.
21.2Bridgemont shares Personal Data between the parties to an intellectual property claim. Under the Intellectual Property Policy a notice of infringement carries the notifier's contact details, and a counter-notice carries the contact details of the person who submits it and is passed to the original complainant. Anyone using either process should understand that their details will reach the other side, because a claim cannot be answered anonymously.
21.3Bridgemont shares Personal Data with the categories of recipient described in clauses 22 to 25 — service providers, payment partners, fraud-prevention providers, and competent authorities.
21.4Bridgemont shares Personal Data with its professional advisers, auditors, and insurers where necessary and subject to confidentiality, and in connection with a corporate transaction as described in clause 39.
21.5Bridgemont does not sell Personal Data, does not share it for third-party advertising, and does not disclose it to a Supplier, a Buyer, or any other User beyond what this Policy describes.
21.6Where a court order or a lawful request from a law enforcement authority prohibits Bridgemont from telling you that a disclosure has been made, Bridgemont will not tell you while the prohibition lasts.
22. Service Providers
22.1Bridgemont engages providers to run parts of its operation: cloud hosting and infrastructure, content delivery, email and messaging delivery, customer support tooling, error monitoring and observability, analytics, backup and disaster recovery, and business administration.
22.2A provider Processing Personal Data for Bridgemont does so as Processor, under a written contract meeting Article 28 of the GDPR, only on Bridgemont's instructions, subject to confidentiality and security obligations, and with no right to use the data for its own purposes.
22.3Bridgemont gives Suppliers no Customer Data. The only Processing a Supplier does for Bridgemont is keeping the licence activation record described in clause 4.4, as Bridgemont’s Processor under clause 18 of the Supplier Agreement.
22.4Bridgemont assesses a provider before engaging it and remains responsible for its performance.
23. Payment Partners
23.1Taking a Buyer’s card payment requires Bridgemont to exchange information with the licensed acquirer that performs card processing and acquiring for Bridgemont, and with payment card networks. Paying a Supplier requires Bridgemont to share the Supplier’s wallet address, and the amount of each payment, with any provider Bridgemont uses to make USDC payments or to screen wallets against sanctions lists.
23.2The information exchanged is what the transaction requires: the amount, currency, and reference; the card details passed for authorisation and the card metadata described in clause 9; the merchant and transaction descriptors; the cardholder name and billing address where the scheme requires them; the authorisation result; and the information needed to handle a refund or a chargeback.
23.3A payment partner may Process that information as an independent Controller for its own regulatory, risk, and record-keeping obligations. Where it does, its own privacy notice applies to that Processing.
23.4Payment card networks and the payment institutions that process payments for Bridgemont may require Bridgemont to report activity that breaches scheme rules, including activity connected with a Supplier or its Digital Products, and to provide the information that report requires.
24. Fraud Prevention
24.1Bridgemont scores transactions and Accounts for fraud risk. The signals used include IP address and derived location, device and browser characteristics, the age and reputation of an email address, proxy and anonymisation indicators, payment instrument metadata, order velocity and value patterns, the relationship between an Account and others, and prior dispute and chargeback history.
24.2Bridgemont Processes these signals to protect Buyers from unauthorised transactions, to protect Bridgemont and its Suppliers from fraud and chargeback loss, to protect the payment institutions that process payments for Bridgemont from loss, and to meet obligations under Applicable Law and payment card network rules.
24.3A score may result in additional verification, a declined transaction, a restriction on an Account, or a review by a person. The consequences of an Enforcement Action taken as a result are governed by the Acceptable Use Policy.
24.4Bridgemont retains risk records for the period stated in clause 27 so that repeat abuse can be recognised. A record that an Account or instrument was associated with fraud may be retained after the Account closes.
24.5Where a decision is taken by automated means with legal or similarly significant effect, clause 36 applies.
25. Regulatory Compliance
25.1Bridgemont discloses Personal Data to a competent authority — law enforcement, a regulator, a Supervisory Authority, a tax authority, or a court — where required by a binding order, where necessary to comply with a legal obligation, where necessary to prevent or detect a serious crime, or where necessary to protect the vital interests of a person.
25.2Where Bridgemont suspects fraud or another crime connected with an Order, an Account or a Supplier, it may report it to the police or another competent authority, and may give its payment partners the information their rules require.
25.3Bridgemont answers a request from an authority only under valid legal process, such as a subpoena, court order or warrant, and checks each request before it answers. Where the request concerns a person in the EEA or the UK, Bridgemont also checks that the disclosure is allowed under the GDPR.
25.4Bridgemont will tell you about a disclosure made under this clause where it is lawfully able to do so and where doing so would not prejudice an investigation.
26. International Transfers
26.1Bridgemont is a company in the United States. If you are in the EEA or the UK, the Personal Data you give Bridgemont is therefore handled outside the EEA and the UK.
26.2Some of Bridgemont’s providers, payment institutions, and support functions operate in other countries. Where Bridgemont sends Personal Data about a person in the EEA or the UK to a provider outside those areas, it does so only where a valid transfer mechanism under Chapter V of the GDPR applies.
26.3Where the destination is the subject of an adequacy decision by the European Commission, or of UK adequacy regulations, Bridgemont relies on that decision. Where it is not, Bridgemont relies on Standard Contractual Clauses, or on another mechanism recognised under Chapter V that is appropriate to the transfer.
26.4Where the law or practice of the destination country may undermine the protection a mechanism provides, Bridgemont assesses the transfer and applies supplementary measures where they are required and effective — which may include encryption, pseudonymisation, contractual restrictions on onward disclosure, and transparency about government access requests. Where no effective measure exists, Bridgemont does not make the transfer.
26.5You may ask Bridgemont at [email protected] which mechanism applies to a particular transfer, and Bridgemont will tell you or provide a copy of the relevant clauses with commercially confidential terms redacted.
27. Data Retention
27.1Bridgemont keeps Personal Data only for as long as it is needed for the purpose it was collected for, or for as long as Applicable Law requires, and then deletes it or renders it permanently de-identified.
27.2Account data: for as long as the Account is open, and for up to 12 months after closure, so that a reopened Account can be restored and a late dispute answered.
27.3Transaction, invoicing, accounting and tax records (including sales tax and, where it applies, VAT): for as long as US tax and accounting law, and the tax law of any other country where Bridgemont collects tax, requires. This period is imposed by law and cannot be shortened at your request.
27.4Supplier verification, wallet ownership and sanctions screening records: for as long as Bridgemont buys from the Supplier and for five years after the relationship ends. Biometric data from a liveness check is not kept: it is deleted as soon as the check is complete, as clause 12.4 says.
27.5Fraud and risk records: up to five years, so that repeat abuse can be recognised. Support correspondence: three years. Service and security logs: 90 days, save where a log is preserved for an investigation under clause 24 or the Acceptable Use Policy.
27.6Job Applicant material: for the duration of the recruitment process and for up to six months afterwards, or for up to two years where you consent to being kept on file. Marketing preferences: until you withdraw consent or object, and a suppression record indefinitely so that Bridgemont can honour that withdrawal.
27.7Where Bridgemont is required to preserve material for an investigation, a legal claim, or a lawful order, it retains that material for as long as the requirement lasts, notwithstanding any shorter period above and notwithstanding a request for erasure.
28. Security Measures
28.1Bridgemont applies technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the Processing.
28.2Those measures include: encryption of Personal Data in transit; the limits on stored payment card data described in clause 9; access control on a least-privilege basis; individual credentials and multi-factor authentication for administrative access; and logging of access to Personal Data.
28.3They further include: monitoring; applying security updates; reviewing changes before they go live; backups; a process for handling security incidents; and periodic review of the measures themselves.
28.4Personnel with access to Personal Data are bound by confidentiality, and have access limited to what their role needs, removed promptly when it is no longer required.
28.5If you find a security problem in the Bridgemont Sites, please report it to [email protected]. Security testing against the Bridgemont Sites is governed by clause 24 of the Acceptable Use Policy.
28.6No system is perfectly secure, and Bridgemont does not represent that it is. Where a personal data breach occurs, Bridgemont notifies the people affected and the authorities the law requires — including a Supervisory Authority where the GDPR applies, and the notices US state breach-notification laws require.
29. Your GDPR Rights
29.1Where Bridgemont is the Controller, you hold the rights described in clauses 30 to 36, together with the right to withdraw consent at any time and the right to complain as described in clause 42.
29.2To exercise a right, write to [email protected]. Bridgemont responds within one month of receiving your request, and may extend that by up to two further months where the request is complex or where several requests have been made — in which case Bridgemont tells you within the first month, and why.
29.3Bridgemont may need to verify your identity before acting, and may ask for information sufficient to do so. That information is used only for verification.
29.4Exercising a right is free. Bridgemont may charge a reasonable fee, or decline to act, only where a request is manifestly unfounded or excessive — and if it does, it explains why and tells you how to challenge that decision.
30. Access Requests
30.1You may ask whether Bridgemont Processes Personal Data about you and, if so, obtain a copy of it together with information about the purposes, the categories of data, the recipients, the retention period, the source, and the existence of automated decision-making.
30.2Bridgemont provides the copy in a commonly used electronic form unless you ask otherwise.
30.3Where providing a copy would adversely affect the rights and freedoms of another person — for example by revealing a third party's Personal Data, the substance of a report made about you under the Acceptable Use Policy, or details of a disclosure to an authority that clause 25.4 allows Bridgemont to withhold — Bridgemont provides what it can and explains what has been withheld and why.
31. Rectification
31.1You may require Bridgemont to correct inaccurate Personal Data about you, and to complete data that is incomplete for the purpose it is Processed for.
31.2Much of your data can be corrected directly in your Account. Where it cannot, write to [email protected]. Where Bridgemont has disclosed the data to a recipient, it informs that recipient of the correction unless doing so proves impossible or involves disproportionate effort.
32. Erasure
32.1You may require Bridgemont to erase Personal Data about you where it is no longer necessary for the purpose it was collected for, where you withdraw the consent it rests on and there is no other basis, where you successfully object under clause 35, or where it has been unlawfully Processed.
32.2The right is not absolute. Bridgemont will refuse, and will explain why, where Processing is necessary to comply with a legal obligation — including the retention periods in clause 27 — or for the establishment, exercise, or defence of legal claims.
32.3In practice this means transaction records, accounting records, verification records, and fraud records generally cannot be erased on request until the applicable period expires. Bridgemont can usually erase marketing data, support correspondence outside its retention period, and optional profile information immediately.
32.4Where Bridgemont cannot erase data, it will restrict its Processing under clause 33 where you ask and the conditions are met.
33. Restriction
33.1You may require Bridgemont to restrict Processing where you contest the accuracy of the data, for as long as it takes Bridgemont to verify it; where the Processing is unlawful but you prefer restriction to erasure; where Bridgemont no longer needs the data but you need it for a legal claim; or while an objection under clause 35 is being considered.
33.2Restricted data is stored but not otherwise Processed, except with your consent, for a legal claim, to protect another person's rights, or for reasons of important public interest.
33.3Bridgemont tells you before a restriction is lifted.
34. Portability
34.1Where Bridgemont Processes Personal Data you provided, by automated means, on the basis of your consent or of a contract with you, you may receive it in a structured, commonly used, machine-readable format, and may have it transmitted directly to another controller where technically feasible.
34.2This right covers data you provided and data generated by your activity. It does not extend to inferences Bridgemont has drawn — for example a risk score — or to data Processed on another legal basis.
34.3A Supplier’s contractual access to its product, sales and statement records is governed by the Supplier Agreement, not by this clause, and never includes Customer Data.
35. Objection
35.1Where Bridgemont Processes Personal Data on the basis of legitimate interests, you may object on grounds relating to your particular situation. Bridgemont stops unless it demonstrates compelling legitimate grounds that override your interests, rights, and freedoms, or unless the Processing is for a legal claim.
35.2Where Bridgemont Processes Personal Data for direct marketing, you may object at any time and Bridgemont stops. There is no balancing exercise and no exception.
35.3An objection to fraud prevention or to the security of the Bridgemont Sites will usually be refused, because those interests protect other people from financial loss and Bridgemont from regulatory and scheme obligations. Bridgemont considers each objection on its facts and explains its decision.
35.4Objecting does not prevent Bridgemont from declining to provide the Bridgemont Sites where it cannot operate them safely or lawfully without the Processing objected to.
36. Automated Decision-Making
36.1Bridgemont uses automated processing to score transactions and Accounts for fraud risk, as described in clause 24, and to apply rate limits and abuse controls.
36.2Most automated outputs inform a decision rather than constitute it. Where an automated decision produces legal effects concerning you or similarly significantly affects you — for example an automatic decline of a transaction, or an automatic restriction of an Account — you have the right to obtain human intervention, to express your point of view, and to contest the decision.
36.3To exercise that right, write to [email protected], or use the appeal route in clause 56 of the Acceptable Use Policy where the decision was an Enforcement Action. An appeal is decided by a person who was not responsible for the original decision.
36.4Bridgemont does not use automated decision-making that produces legal or similarly significant effects on the basis of Special Category Data.
36.5Bridgemont does not use Personal Data Processed for fraud prevention to train general-purpose models, and does not sell or license risk signals derived from your activity.
37. Marketing Communications
37.1Bridgemont sends marketing communications — product announcements, feature updates, and commercial offers — only where you have consented, or where Applicable Law permits marketing to an existing customer about similar products and you have not objected.
37.2Every marketing communication identifies Bridgemont as the sender, states that it is a commercial communication, and offers a working, cost-free means of unsubscribing that is honoured promptly.
37.3You may withdraw consent or object at any time, through the unsubscribe link, through your Account settings, or by writing to [email protected]. Withdrawal takes effect promptly and does not affect messages already sent.
37.4Withdrawing marketing consent does not stop the service communications described in clause 17, which are not marketing.
38. Children's Privacy
38.1The Bridgemont Sites are not directed at children. The Supplier Agreement requires a Supplier that is an individual trading as a business to be at least 18 years old, and under the Buyer Terms a Buyer must be at least 18 or the age of majority in their jurisdiction if higher.
38.2Bridgemont does not knowingly collect Personal Data from a child. Where Bridgemont becomes aware that it holds such data, it deletes it promptly and closes any Account concerned.
38.3If you believe a child has provided Personal Data to Bridgemont, write to [email protected] and it will be investigated and, where confirmed, deleted.
39. Business Transfers
39.1Where Bridgemont is involved in a merger, acquisition, financing, reorganisation, or sale of all or part of its business, Personal Data may be disclosed to the counterparty and its advisers as part of that process, and may transfer as part of the assets.
39.2Before completion, disclosure is limited to what the counterparty reasonably requires for diligence, is made under confidentiality obligations, and is minimised or pseudonymised wherever that serves the purpose.
39.3Where Personal Data transfers to a new controller, Bridgemont notifies you and the recipient remains bound by this Policy until it gives you notice of any change, at which point your rights under clause 29 apply against that recipient.
40. Changes to this Policy
40.1Bridgemont may amend this Policy to reflect changes to the Bridgemont Sites, to its business, to Applicable Law, or to its Processing.
40.2Where an amendment materially affects your rights or the way your Personal Data is Processed, Bridgemont gives at least 30 days' notice by email or by prominent notice on the Bridgemont Sites before it takes effect. Amendments that do not materially affect you, including corrections and clarifications, take effect on publication.
40.3Where an amendment introduces Processing that requires your consent, Bridgemont asks for it rather than relying on notice. Continued use of the Bridgemont Sites is not consent to such Processing.
41. Contact Information
41.1Privacy enquiries and requests to exercise a right should be sent to [email protected], or by post to Bridgemont Technologies LLC, 1309 Coffeen Avenue, Suite 20769, Sheridan, WY 82801, United States.
41.2Please say what you are asking for and give enough detail to identify the Personal Data concerned. A vague request slows matters down for both of us.
41.3A person reads every privacy message. Bridgemont acknowledges receipt and tells you who is handling the matter.
42. Complaints
42.1If you are unhappy with how Bridgemont has handled your Personal Data or your request, tell Bridgemont first at [email protected]. Most matters are resolved faster that way, and Bridgemont would rather know.
42.2You can complain to an authority whether or not you raise it with Bridgemont first, and doing so does not prejudice any other remedy.
42.3If you live in the EEA or the UK, you can complain to the data protection authority where you live or work.
42.4If you live elsewhere, including in the United States, you can contact the privacy or consumer protection authority where you live, such as your state attorney general. You also have the right to an effective judicial remedy.
43. Governing Law
43.1This Policy, and any non-contractual obligation arising out of or in connection with it, are governed by the laws of the State of Wyoming, United States, without prejudice to the GDPR and to any mandatory provision of the law of your country of habitual residence.
43.2Subject to the rights of Data Subjects below, the state courts located in Sheridan County, Wyoming, or the United States District Court for the District of Wyoming have jurisdiction over any dispute arising out of or in connection with this Policy. A Data Subject in the EEA or the UK keeps every right the GDPR gives to bring proceedings before the courts of the place where they live.
43.3This clause does not limit your right to complain as described in clause 42, and is to be read consistently with the governing law and jurisdiction provisions of the Supplier Agreement and the Buyer Terms, which prevail in the event of any inconsistency.
44. Effective Date
44.1This Policy takes effect on the effective date stated at the head of this document, and applies from that date to all Processing described in it, including Processing of Personal Data collected before that date.
44.2The last updated date stated at the head of this document records when this Policy was last amended. Bridgemont maintains previous versions and will supply an earlier version on request to [email protected].
44.3This Policy supersedes any previous privacy policy published by Bridgemont.
45. Cookies
45.1Bridgemont’s website, bridgemont.io, sets no advertising or analytics cookies, and no other cookie that is not strictly necessary.
45.2The Checkout at checkout.bridgemont.io uses strictly necessary cookies only: a session cookie that keeps your checkout tied to your browser, and a bot check that protects payments from automated abuse. They are set without asking for your consent because the Checkout cannot work safely without them. They are not used for advertising or to follow you across other websites.
45.3Parts of the card payment step, including the 3-D Secure check, may be provided by the payment processor that handles card payments for Bridgemont. That processor may set its own strictly necessary cookies for fraud prevention and 3-D Secure.
45.4If Bridgemont ever adds analytics or any other cookie that is not strictly necessary, it will ask for your consent first and update this clause before that cookie is used.
45.5You can block or delete cookies in your browser settings. If you block the Checkout’s cookies, you may not be able to complete a purchase.