This Policy explains what information the WootBB website and customer app process, why it is used, product sharing and first-party promotion attribution, the retention and sharing boundaries, and how you can request access, correction, or deletion of eligible data.
Account and contact data: name, email, and contact details needed for checkout, delivery, support, returns, and disputes.
Transaction data: carts, orders, shipping, invoices, refunds, selected payment method, and payment-provider status; WootBB does not store full card numbers.
Shopping, BB, and sharing interactions: searches, product views, wishlist activity, cart actions, checkout starts, BB chats, recommendation interactions, and the creation and attribution-eligible opening of product-share links.
Security and compliance data: consent records, device/IP security signals, support requests, dispute evidence, fraud-prevention, and audit records.
2. Purposes
Provide local products, carts, orders, delivery, payment status, support, and after-sales services.
Within applicable consent and settings, improve search, recommendations, BB shopping, and cross-surface record consistency.
Generate verifiable first-party product-share links and measure aggregate attribution-eligible opens and subsequent cart additions, checkout starts, and order creation.
Prevent fraud, bot previews, duplicate counting, account abuse, and transaction risk, and meet tax, accounting, compliance, dispute, and regulatory duties.
3. Market, region, and device information
WootBB may use your selected market, language, currency, shipping country or region, coarse IP region, and device-security signals to match deliverable products, payment methods, and applicable rules. Precise device location requires an active permission request; you can decline and choose a market and address manually.
Market matching, coarse region, and device security are separately recorded required permissions. They are not treated as accepted merely because a page is opened, an account is used, or products are browsed.
4. Product sharing, first-party attribution, and cookies
When you create or open a WootBB first-party product-share link, WootBB processes the target product, seller, market, language, currency, share channel, link expiry, and opening time to return the correct product and measure sharing performance. A link expires 90 days after creation. A custom campaign identifier is stored only for a signed-in seller authorized for the target product's seller; links created anonymously or by ordinary customers do not store one.
Creating a link may set a first-party visitor cookie. An attribution-eligible open uses or sets that visitor cookie and sets a first-party attribution cookie. The visitor cookie contains a signed random seed and expiry for up to 90 days. The attribution cookie contains signed internal share-link and touch IDs plus an expiry for up to 30 days, never beyond the link's expiry. Both are HttpOnly, SameSite=Lax, Path=/, and Secure in production deployments.
Recognized link-preview bots and known creator self-visits still redirect to the product but do not create a touch or attribution cookie and do not set a new visitor cookie; an existing visitor cookie is not actively cleared. Clearing cookies or switching browsers or devices can prevent a creator self-visit from being recognized, so unknown self-visits may remain in aggregate results. Detection also cannot exclude every automated request, so unidentified automated opens may remain in aggregate results.
For share-token and visitor or creator subject identifiers, the database stores only a SHA-256 digest of the share token and HMAC-SHA-256 hashes of visitor and creator subjects, not the plaintext share token. Network addresses, User-Agent values, and request headers are processed transiently for bot detection, abuse controls, and rate limiting, but are not persisted in the share-attribution tables in raw form. Closely repeated opens are deduplicated, creation and access are rate-limited, and each touch has a cumulative open-count cap.
After registration or sign-in, an unexpired anonymous touch may be associated with the account. Cart additions, checkout starts, and order creation are recorded only after the server uses the signed attribution cookie to revalidate the actual product, market, cart, or order. A record may include account, product, cart or order associations, quantity, currency, and the associated item value, and uses the last valid touch for attribution.
Seller reports default to the previous 30 days and support a 1-to-90-day range. They expose only the seller's link count, aggregate opens, cart, checkout, placed orders and placed-order item value, plus product, channel, or authorized-campaign dimensions; they do not expose visitor identity. That value is recorded when an order is created and may still be pending payment; it is not paid value, GMV, net revenue, or commission. Product sharing currently provides no cashback, referral reward, or promotion commission, and WootBB does not sell share-visitor identities.
5. Sharing, processors, and international processing
Necessary information is shared with payment, logistics, storage, email, tax, and professional service providers only to provide services, complete payment and delivery, prevent fraud, handle support or disputes, or meet legal duties.
Information may be processed outside your location. WootBB uses applicable contractual, security, and minimization controls and does not sell passwords, verification codes, or full payment credentials.
6. Retention, security, and your choices
A share link is valid for 90 days after creation. WootBB's scheduled internal bounded-cleanup job selects links only after both the 90-day creation cutoff and link expiry, then deletes their associated touches and conversion detail; each run processes a limited batch rather than an unbounded job.
You can clear WootBB cookies or site data in browser or device settings to remove the visitor and attribution cookies held on that device. This does not retroactively delete recorded sharing detail or aggregate results. There is currently no separate product-share attribution opt-out switch; creating another link or opening another attribution-eligible link can set the applicable cookie again.
For eligible data associated with an account, submit an access, correction, or deletion-review request through the signed-in Support Center. This creates a trackable support ticket and verifies account or order context; it does not promise immediate deletion. A sharing record that exists only as a non-directly-identifying hash and is not account-linked cannot be located automatically through an account ticket.
Records needed for transactions, tax, settlement, disputes, fraud prevention, audits, or other necessary duties may be retained for the necessary period.
Never include passwords, verification codes, card numbers, bank credentials, or full payment tokens in a privacy request.
7. Versions and contact
Policy updates create a new version, effective date, and content hash; historical consent keeps its original version evidence. From this version, newly submitted customer or seller sign-in/registration consent and customer checkout consent reference Privacy Policy v2 through an explicit control that is not preselected.
The current implementation does not interrupt an existing signed-in session solely because this version was published. When a user later submits an affected sign-in, registration, or checkout flow, the server requires the then-current consent version.
Contact and support
Submit a privacy or data request through the signed-in Support Center, or contact support with a question. WootBB verifies identity through account or order context.