MobiBubble
Data Processing Addendum
Last updated: 4 July 2026.
Scope
This Data Processing Addendum applies when a MobiBubble order form, pilot agreement, or written customer agreement incorporates it by reference. If a signed agreement conflicts with this page, the signed agreement controls.
Roles
For customer booking data processed through a business's MobiBubble booking flow, the business is normally the controller and MobiBubble is the processor. MobiBubble remains an independent controller for platform account administration, security, support, future billing where enabled, product operations, and direct communications with businesses.
Processing details
| Subject matter | Online booking, customer account, admin, support, notification, and operational workflows for mobile car wash businesses. |
|---|---|
| Duration | For the customer agreement term, plus the retention period needed for deletion, export, legal, accounting, dispute, backup, and security purposes. |
| Data subjects | Business owners, business staff, platform admins, support users, and end customers who use a MobiBubble-powered booking flow. |
| Data categories | Identity details, email, phone, address, postcode, vehicle and booking details, booking notes, service selections, pricing snapshots, account/session metadata, support notes, and audit events. |
| Special category data | Not intentionally collected. Businesses must not ask customers to enter special category data unless a separate agreement and lawful basis covers it. |
MobiBubble commitments
- Process customer booking personal data only on documented instructions from the business, unless law requires otherwise.
- Use confidentiality controls for people who can access personal data.
- Apply appropriate security measures for the product stage, including HTTPS, access control, token rotation, hashed refresh-token storage, tenant scoping, and audited support access.
- Use subprocessors under data processing terms and keep a public subprocessor list.
- Help businesses respond to data subject access, correction, deletion, restriction, objection, and portability requests.
- Notify affected businesses without undue delay after becoming aware of a personal data breach affecting their customer booking data.
- Delete or return customer booking data at the end of service where technically possible, unless retention is required for legal, accounting, security, backup, or dispute reasons.
Business commitments
- Give lawful instructions and have a lawful basis for processing customer booking data.
- Keep customer-facing service details, prices, cancellation rules, privacy information, and contact details accurate.
- Use customer data only for legitimate purposes connected with providing and managing the requested service.
- Do not upload unnecessary sensitive information or unlawful content into the platform.
Subprocessors and transfers
MobiBubble uses the subprocessors listed on the subprocessor page. Core booking data is targeted for UK or EEA hosting. Firebase Authentication processes authentication data in the United States, and international transfers are handled through provider data processing terms and recognised transfer mechanisms where applicable.
Contact
For DPA questions, email support@mobibubble.uk.
