Legal
Privacy policy
Last updated 17 August 2026
This policy explains what Bday Message (https://www.bdaymessage.com) collects and why. The Operator is Web Window OÜ, registry code 17163769, Maakri tn 19/1, Kesklinna linnaosa, 10145 Tallinn, Harju maakond, Estonia. Contact: support@bdaymessage.com.
This site does not use analytics cookies, advertising pixels, or a consent banner. If that changes, this policy changes in the same release.
What we collect
If you only browse the public pages, we store what the host logs by default (IP, user agent, timestamp) to keep the service up. We do not use that log to profile you.
If you sign in, we store your email, a hashed one-time login code until it expires, a signed session cookie, the timezone from your device or location, and the plan you bought.
- Contacts you sync or type: name, identifiers on a network, birthday month and day, optional year, preferred network
- Messages you schedule: the text, once or every year, send time, and a send log (sent, failed, skipped)
- Connected account status: network, display name, and whether the session is alive. Session secrets live on the connector host, encrypted at rest by file permissions and host disk, not in the public app database
- Payment data: Stripe handles cards. We store Stripe customer and checkout ids, plan, paid date, and expiry. We do not store card numbers
Why we collect it
To sign you in, show your calendar, send the messages you scheduled from your linked accounts, email you about missing wishes and failed sends, and record the plan you paid for.
Legal basis (GDPR)
Contract: running the service you signed up for. Legitimate interests: keeping sessions alive, preventing abuse of login codes, and sending operational mail. Payment processing is required to provide paid access.
Processors
Vercel hosts the website. Neon hosts the database. Resend sends email. Stripe processes payments. A connector host we operate (or a vendor we name in this policy if that changes) holds live WhatsApp and Telegram sessions. Each of those companies processes data under their own terms.
Retention
Login codes expire in minutes and are then unused. Session cookies stay until you sign out. Opening the app extends the cookie so browsers that cap cookie age do not drop you. Account data stays until you ask us to delete it, except records we must keep for accounting (paid invoices).
Your rights
If you are in the EEA or UK you can ask for a copy, a correction, deletion, or a restriction. Email support@bdaymessage.com. You can also complain to the Estonian Data Protection Inspectorate.
Transfers
The Operator is in Estonia. Some processors run in the EU or the US. Where a transfer needs a safeguard we use the processor's standard contractual clauses.