Page
Privacy Policy
Privacy Policy for Waterbucket, a B2B catalog advertising platform operated by Better Cheaper Now LTD D/B/A Waterbucket.
Effective date: August 31, 2026
This Privacy Policy describes how Better Cheaper Now LTD D/B/A Waterbucket (“Waterbucket,” “we,” “us”) handles information in connection with the Waterbucket platform, our websites, and related services (collectively, the “Service”).
Waterbucket is an enterprise business-to-business service. It is not offered to, marketed to, or intended for consumers, households, or individuals acting in a personal capacity, and it is not intended for anyone under 18.
1. Nature and scope of this policy
This policy is an informational disclosure provided to meet applicable transparency requirements. It is not a contract, is not incorporated into any agreement unless that agreement expressly says so, creates no rights in any third party, and does not expand our obligations beyond those imposed by applicable law or by an agreement we have signed. Our commitments are set out only in our Terms and Conditions, an executed order form or master agreement, and, where one exists, an executed Data Processing Addendum (“DPA”). Where this policy and any of those documents differ, those documents control.
Descriptions of our practices here are general and describe how we ordinarily operate. They are not warranties, service levels, or representations about any particular instance of processing, and our practices may vary by product, feature, tier, region, customer agreement, and over time. This policy may be supplemented by a notice provided at the point of collection.
Nothing in this policy is a representation that we are certified under, or that our processing meets the requirements of, any standard, framework, or certification unless we state so in writing in a signed agreement.
References to applicable law include that law as amended and any successor, replacement, or comparable law that comes into effect.
2. Our role, and the difference between our data and customer data
The Service ingests, stores, analyzes, transforms, and transmits data supplied by our business customers or retrieved at their direction, including product catalog feeds, imagery, brand assets, configuration, connected account identifiers and credentials, derived and generated outputs, and campaign metrics (“Customer Data”).
As to Customer Data, our customer is the controller, business, or equivalent responsible party, and we act solely as a processor or service provider on that customer’s instructions. We do not determine the purposes or means of processing Customer Data, we do not independently evaluate its content, lawfulness, provenance, licensing, ownership, or accuracy, and we make no representation to any individual whose information it may contain. Our handling of Customer Data is governed by the applicable customer agreement and, where one exists, a DPA, not by this policy.
This policy’s direct-collection disclosures apply to information we handle as a controller, principally information about our website visitors, prospects, and the personnel of our customers and vendors.
If you believe your personal information appears within a customer’s Waterbucket account, direct your request to that customer. Where we can reasonably identify the customer, we may forward the request to them, and we may decline to respond to you directly. Acting on a customer’s instruction, or forwarding a request, does not make us the responsible party.
3. Information we handle
We handle the following categories, to the extent applicable to a given interaction.
Identifiers and contact information. Name, business email, phone, employer, job title, account username, authentication data, and similar identifiers.
Commercial and transactional information. Plan, subscription and credit balances, usage and consumption records, invoices, payment status, purchase and billing history, and payment method metadata. We do not receive or store full payment card numbers.
Internet and network activity. IP address, device and browser characteristics, operating system, referring and exit pages, pages and features accessed, API calls, session and interaction data, timestamps, application and security logs, error and diagnostic data, and cookie and similar identifiers.
Approximate location. Coarse region inferred from IP address.
Professional information. Role, company, industry, and similar business context.
Communications. Correspondence with our sales, support, security, and billing functions, including attachments and metadata, and information provided in forms, demos, and meetings.
Configuration and connection data. Connected platform account identifiers, catalog identifiers, access and refresh tokens, feed locations, and settings.
Inferences and derived data. Aggregated, de-identified, statistical, and derived signals generated from the foregoing and from operation of the Service.
We do not intentionally collect government identifiers, financial account numbers, precise geolocation, biometric identifiers, health information, or other categories designated as sensitive under applicable law, and we ask that they not be submitted to us. Information submitted to us contrary to this paragraph is submitted at the submitter’s own risk, and we may delete it.
Sources. We obtain information directly from you, automatically through operation of the Service and our websites, from our customers and their personnel, from our service providers, from platforms and services you or our customers connect, and from publicly available and commercial business sources.
4. Purposes
We may use information for any purpose compatible with the context in which it was obtained, including to:
- provide, operate, host, maintain, secure, support, and administer the Service
- authenticate users, provision access, and enforce permissions and entitlements
- meter usage, calculate charges, invoice, collect payment, and manage accounts
- perform the processing our customers direct, including ingestion, analysis, enrichment, transformation, generation, and delivery to connected platforms
- monitor, investigate, detect, and prevent fraud, abuse, misuse, security incidents, and violations of our agreements or policies
- develop, test, evaluate, tune, benchmark, and improve the Service and our systems, models, taxonomies, and methods, and conduct internal research
- create and use aggregated, de-identified, statistical, and derived data for any lawful business purpose
- communicate with you about the Service, including service, security, billing, transactional, and administrative messages
- market our products and services to business contacts, subject to applicable law
- perform analytics, business planning, reporting, audits, and corporate transactions
- establish, exercise, and defend legal claims, and comply with law, legal process, and regulatory obligations
Automated processing and machine learning. The Service applies automated, statistical, computer vision, and machine learning techniques, including systems operated by us and by third parties on our behalf. We may use information, and data derived from it, for the development, evaluation, tuning, and improvement of those systems and of the Service. Our use of Customer Data for these purposes is governed by the applicable customer agreement and any DPA, which control over this policy.
Legal bases (where the EU or UK GDPR applies to processing for which we are the controller). Performance of a contract, our legitimate interests in operating, securing, improving, and marketing our business, compliance with legal obligations, and, where required, consent. Where we act as a processor, our customer determines the legal basis.
5. Disclosure of information
We may disclose information in the following circumstances.
Service providers and subprocessors. To vendors and subprocessors that perform functions on our behalf, including cloud hosting, compute and storage, content delivery, queueing and orchestration, artificial intelligence, machine learning and inference services, payment processing, email and communications, customer support, analytics, logging, error and performance monitoring, security, and professional services. We select, add, remove, and replace these providers at our discretion. We do not maintain a public subprocessor list. A customer under an executed DPA may request current subprocessor information in writing, and notice of changes is provided only to the extent that DPA requires it.
Connected platforms. To advertising, commerce, and other third-party platforms that a customer connects or directs us to interact with, as configured by that customer. Those platforms handle data under their own terms and policies. We do not control them and are not responsible for their acts, omissions, decisions, retention, or security.
Within a customer account. To other authorized users and administrators of the same account, and to any agency, reseller, or partner through which the account was established.
Corporate transactions. In connection with, or during negotiations for, a financing, merger, acquisition, reorganization, insolvency, or sale of all or part of our business or assets.
Legal and protective disclosures. Where we determine in good faith that disclosure is required by law, regulation, subpoena, warrant, court order, or other legal or governmental process, or is appropriate to enforce our agreements, to investigate suspected fraud, abuse, or a security incident, or to protect the rights, property, safety, or interests of us, our customers, or others. We are not obligated to challenge, delay, or give advance notice of such disclosure except where a signed agreement or applicable law requires it.
Affiliates and professional advisors. To our affiliates, insurers, auditors, accountants, and legal counsel, subject to confidentiality obligations.
At your direction. Where you or our customer instruct or authorize disclosure.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under applicable US state privacy laws.
6. Retention
We retain information for as long as we determine necessary for the purposes described in this policy. The applicable period depends on factors including the nature and sensitivity of the information, the status and duration of the relevant account, our operational, backup, archival, and security requirements, applicable statutes of limitation, and legal, tax, accounting, audit, regulatory, and litigation hold obligations.
Retention and deletion of Customer Data following termination are governed by the applicable customer agreement and any DPA. Data may persist in backups, archives, and logs after removal from active systems and will age out in the ordinary course of those systems’ cycles. Aggregated, de-identified, and derived data may be retained indefinitely, and we will not attempt to re-identify it. We may retain information as necessary to enforce our agreements, resolve disputes, and comply with law, notwithstanding any deletion request.
7. Security
We maintain administrative, technical, and organizational measures designed to protect information against unauthorized access, use, alteration, disclosure, and loss, appropriate to the nature of the information and the risks involved as we assess them. The specific measures we employ are determined by us, may vary by system and over time, and are not enumerated here.
No method of transmission or storage is secure, and we do not warrant, guarantee, or represent that information will be free from unauthorized access, loss, alteration, or misuse. You are responsible for the security of your own systems, credentials, devices, networks, and personnel, for configuring the Service appropriately, and for the consequences of your own configuration choices and integrations.
Where an incident affecting information occurs, our notification obligations are those imposed by applicable law and by any agreement we have signed, and no others. Nothing in this policy creates a broader obligation to notify, investigate, remediate, indemnify, or compensate.
Security research. Good-faith reports of suspected vulnerabilities may be sent to the address in Section 14. Testing that degrades the Service, accesses data you are not authorized to access, or otherwise exceeds authorization is prohibited and is not authorized by this paragraph. We operate no bug bounty program and make no commitment to respond to, act on, or compensate any report.
8. International processing
We and our service providers operate in the United States and may process information in other jurisdictions. Information may be transferred to, stored in, and accessed from countries whose data protection laws differ from those of your country. Where a transfer mechanism is legally required for transfers from the EEA, the UK, or Switzerland, we rely on approved mechanisms, which may include the European Commission’s Standard Contractual Clauses and the UK Addendum, together with measures we consider appropriate. Terms applicable to a customer relationship are set out in that customer’s DPA.
9. Individual rights
To the extent, and only to the extent, that applicable law grants you a right with respect to personal information for which we are the controller or business, you may request to access, obtain a copy of, correct, delete, or restrict the use of that information, to object to certain processing, to withdraw consent, to appeal a decision on your request, and to be free from unlawful discrimination for exercising a right.
Requests may be submitted to the address in Section 14. We will verify the requester’s identity and authority to a standard we consider appropriate before acting, and we may request additional information for that purpose. We may deny, limit, or charge for a request to the extent permitted by applicable law, including where the request is unverified, manifestly unfounded, excessive, repetitive, or technically infeasible, would adversely affect the rights of others, or where an exemption applies. We respond within the period required by applicable law and may extend that period as the law allows.
Requests concerning information within a customer’s account are handled as described in Section 2.
Because we do not sell or share personal information as those terms are defined by applicable US state privacy laws, opt-out preference signals, including Global Privacy Control, have no sale or share activity on our part to apply to. We do not respond to browser “Do Not Track” signals.
Individuals in the EEA, the UK, or Switzerland may lodge a complaint with a competent supervisory authority. Where we are required by law to designate a local representative, that designation is available on request.
10. Cookies and similar technologies
Our websites and application use cookies, local storage, pixels, tags, and similar technologies that are necessary for operation and security, that remember preferences, and that support analytics and measurement. Where consent is required by applicable law, we obtain it through the mechanism presented in the relevant jurisdiction. These technologies may be controlled through your browser or through any consent tool we present. Blocking technologies necessary for operation will impair or prevent use of the Service. Third parties that provide these technologies handle data under their own policies.
11. Third-party sites and services
The Service and our websites may link to or interoperate with third-party sites, platforms, and services we do not control. We are not responsible for their content, practices, security, or handling of information. Use of them is governed by their own terms and policies.
12. Children
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from them. If we become aware that we have, we will take steps we consider appropriate, which may include deletion.
13. Changes, interpretation, and governing law
We may revise this policy at any time. Revisions are effective when posted with a new effective date, unless a later date is stated. Where notice of a change is required by applicable law or by an agreement we have signed, we will provide notice as required. Continued use of the Service after the effective date constitutes acceptance. We are not obligated to give notice of changes that are not material.
This policy is provided in English, and the English version controls over any translation. Headings are for convenience only. If any provision is held invalid or unenforceable, it will be limited or severed to the minimum extent necessary and the remainder continues in effect. This policy, and any dispute concerning it, is governed by the laws of the State of Ohio, without regard to conflict of laws rules, except where applicable data protection law requires otherwise.
14. Contact
Better Cheaper Now LTD D/B/A Waterbucket
1383 Hempwood Drive
Columbus, Ohio 43229, United States
