Data Processing Addendum
Last updated: July 31, 2026
This Data Processing Addendum ("DPA") describes how Lovebug's Jump House (the "Business") handles personal information collected through this website on behalf of, and in the course of serving, its guests. It supplements our Privacy Policy and Terms & Conditions. Where a written agreement between the Business and a corporate customer, partner, or vendor requires a formal data-processing agreement, this DPA sets out the baseline terms.
Roles of the parties
For personal information submitted by guests, the Business acts as the controller (it decides why and how the information is used). The software platform that operates this website, and the service providers listed below, act as processors that handle personal information only on the Business's documented instructions.
Categories of data and data subjects
- Data subjects: guests, members, event contacts, and any child whose parent or guardian chooses to provide their details.
- Personal information: names, email addresses, phone numbers, selected pass or membership, visit and attendance records, waiver acceptances (including typed signature, version, timestamp, IP address, and browser), booking details, and marketing preferences. Payment card numbers are entered directly with the payment processor and are never received or stored by the Business.
Purpose and duration of processing
Personal information is processed to register guests; manage passes, memberships, visits, waivers, purchases, and bookings; communicate with guests; operate and secure the website; keep business records; and, where a guest opts in, send marketing. Processing continues for as long as needed to provide these services and to meet legal, accounting, and recordkeeping obligations, after which information is deleted or anonymized.
Sub-processors
The Business engages service providers to help operate the website. Each receives only the information needed to perform its function on the Business's behalf and is bound by confidentiality and data-protection obligations. These operational disclosures do not authorize a provider to use personal information for its own marketing. In particular, mobile phone numbers, text-message opt-ins, and messaging consent data are not shared, sold, rented, or provided to third parties or affiliates for marketing or promotional purposes. Typical sub-processors include:
- Hosting and infrastructure — running the application and its database.
- Payment processing — Stripe, for card payments; card data is handled entirely by the processor.
- Email delivery — the transactional and marketing email provider configured for the Business.
- Text messaging — Twilio, where SMS is enabled, solely to transmit messages on the Business's behalf.
- Scheduling and calendar sync — where the Business enables calendar integration.
- Error monitoring — where enabled, to detect and diagnose faults.
Security measures
The platform applies reasonable technical and organizational safeguards, including encrypted transport (HTTPS), hashed administrator credentials, role-based staff access, an append-only audit trail of sensitive actions, rate-limited sign-in, CSRF protection on forms, and access controls on uploaded documents. No online system can be guaranteed completely secure.
Data subject requests
Guests may request access to, correction of, or deletion of their personal information, and may withdraw marketing consent at any time. The Business honours verified deletion requests by removing the guest's record and associated visits, waivers, payments, and marketing data, subject to information that must be retained by law. Requests can be made using the contact details below.
International transfers
Where personal information is processed or stored in a country other than the guest's own, the Business and its sub-processors rely on appropriate safeguards permitted by applicable law for any such transfer.
Data breach notification
If the Business becomes aware of a personal-data breach affecting guest information, it will assess the incident without undue delay and notify affected individuals and any competent authority where required by applicable law.
Contact
Questions about this DPA, or requests concerning personal information, can be sent to hello@lovebugsjumphouse.com or mailed to 123 Bounce Blvd.