Privacy Policy 

Last Updated: 1 Dec 2025
Effective Date: 1 Dec 2025

This Privacy Policy explains how Bunker Pass LLC (“the Company”, “we”, “us”, “our”), a United States–based organization, collects, processes, stores, transfers, and protects personal data when individuals (“you”, “your”, “Member”) use our website, mobile applications, membership services, emergency notification systems, and other related technologies (“the Service”). Although Bunker Pass LLC is incorporated in the United States, we serve individuals globally, including residents of the European Union (“EU”) and European Economic Area (“EEA”). Accordingly, we comply with applicable U.S. privacy laws and all obligations under the EU General Data Protection Regulation (“GDPR”).

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.


1. Data Controller Information

For all Members, the data controller is:

Bunker Pass LLC
1209 MOUNTAIN RD PL NE, STE R ALBUQUERQUE, NM 87110 USA
Email: privacy@bunkerpass.net
Website: https://bunkerpass.net

For EU/EEA residents, Bunker Pass acts as the Data Controller under GDPR Article 4(7). If required, we will appoint an EU Representative under GDPR Article 27.


2. Categories of Personal Data We Collect

We collect various categories of personal data depending on your interaction with our Service.

2.1 Identity Information

This includes your full name, date of birth, nationality, residential address, identification documents (passport, national ID, or driver’s license), emergency contacts, and dependent information for family memberships.

2.2 Contact Information

This includes email addresses, phone numbers, communication preferences, and any contact data required to reach you during Activation Events.

2.3 Payment and Membership Information

We collect billing information, membership tier details, payment confirmations, Crisis Reserve contributions (if applicable), currency selections, and transaction history. We do not store full credit card numbers. Payment may be facilitated by our partner company Stripe, which may apply different data protection standards.

2.4 Device and Technical Information

We automatically collect IP addresses, device identifiers, browser and operating system data, access logs, authentication events, and approximate geolocation derived from IP addresses.

2.5 Location Information

We may process location data for Facility assignment, emergency routing, or activation-related logistics. Continuous location tracking does not occur without explicit consent.

2.6 Emergency Activation Data

This includes Facility assignment records, arrival and departure logs, Operator reports, and safety-related observations during Activation Events.

2.7 Sensitive Data (When Voluntarily Provided)

We do not request sensitive data unless necessary for safety or operational purposes. If you voluntarily provide medical, accessibility, biometric, or other special-category data, you consent to its processing according to GDPR Article 9(2)(a).


3. Purposes and Legal Bases for Processing

3.1 Contractual Necessity

We process data to create and manage your account, verify identity, issue and authenticate Access Credentials, assign you to Facilities, communicate during emergencies, manage payments, and fulfill contractual obligations associated with your membership.

3.2 Legitimate Interests

We process data to maintain Facility security, prevent unauthorized access, detect fraud, conduct system maintenance, monitor safety compliance, and analyze platform usage.

3.3 Legal Obligations

We process data to satisfy U.S. and EU accounting requirements, comply with tax laws, fulfill regulatory reporting duties, and respond to lawful government requests.

3.4 Vital Interests

During emergencies, we may process and share personal data to protect life or physical safety.

3.5 Consent

We rely on your consent for certain features such as optional location services, biometric authentication, marketing communication, and processing of sensitive data. You may withdraw consent at any time.


4. How We Share Personal Data

We do not sell personal data. We share it only when necessary to deliver the Service.

4.1 Facility Operators

Operators receive only the information necessary to verify your membership and manage your entry and safety, including your name, credential identifier, membership tier, number of dependents, arrival details, and safety-relevant data. Operators never receive your complete profile unless required for emergency protection.

4.2 Service Providers

We use trusted third parties for hosting, payment processing, identity verification, communication services, security monitoring, analytics, and infrastructure maintenance. All providers operate under GDPR-compliant Data Processing Agreements and strict confidentiality requirements.

4.3 Public Authorities

We may disclose information when required by U.S. or international law, court orders, subpoenas, regulatory obligations, or valid emergency safety requests.

4.4 Emergency Services

In life-threatening situations, we may share limited data with first responders, medical services, or crisis-management agencies to protect your safety.

4.5 Business Transfers

If we undergo a merger, acquisition, restructuring, or asset sale, your personal data may be transferred to a successor entity under appropriate safeguards.


5. International Data Transfers (Including Transfers to Jurisdictions Lacking Adequate Protection)

As a U.S.-based company operating a global network of emergency shelters, your personal data may be transferred to and processed in multiple countries, including jurisdictions that do not provide an adequate level of data protection under GDPR Article 45. Some Facilities and Operators are located in regions without strong data protection laws, and certain data transfers are essential to providing access to those Facilities.

Where transfers occur to jurisdictions lacking adequate protection, we rely on one or more of the following legal bases:

  1. Standard Contractual Clauses (SCCs) approved by the European Commission, combined with additional safeguards such as encryption, access limitations, and Operator confidentiality agreements.

  2. Your explicit consent under GDPR Article 49(1)(a), particularly when assignment to a Facility in such regions necessitates coordination with Operators.

  3. The necessity of the transfer for the performance of our contract with you under GDPR Article 49(1)(b), especially regarding Facility access during emergencies.

  4. The protection of vital interests under GDPR Article 49(1)(f) when your safety or life may depend on Facility coordination.

  5. Compelling legitimate interests under GDPR Article 49(1)(2nd subparagraph), when no other transfer mechanism is adequate and such interests are not overridden by your rights and freedoms.

Although some Facility jurisdictions lack robust data protection frameworks, we implement technical, organizational, and contractual measures to mitigate these risks. Operators receive only the minimum information required to verify your access and maintain safety. By using the Service, you acknowledge that such international transfers are necessary for Bunker Pass to provide global emergency shelter access and that certain jurisdictions may not offer the same level of data protection as your home country.


6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy unless a longer retention period is required by law. Membership account data is retained for the duration of your membership. Access logs may be stored for 3 to 10 years depending on operational, safety, and regulatory requirements. Operator incident reports may be retained for up to 10 years. Billing data is retained for 7–10 years in compliance with U.S. and EU accounting laws. Deleted accounts are anonymized or purged within 90 days unless retention is legally required.


7. Data Security Measures

We employ strong administrative, technical, and physical safeguards to protect your data, including encryption of data in transit and at rest, multi-factor authentication, strict access controls based on least privilege, hardware security modules, secure data centers, encrypted backups, regular vulnerability assessments, mandatory Operator confidentiality obligations, and continuous security monitoring. Despite these measures, no system can guarantee absolute security.


8. Your Privacy Rights

8.1 Rights of EU/EEA Residents Under GDPR

You have the right to request access to your data, request correction of inaccurate data, request deletion (“right to be forgotten”), restrict processing, object to processing, request data portability, withdraw consent where applicable, and file complaints with your national Data Protection Authority.

8.2 Rights of U.S. Residents

Depending on your state of residence (e.g., California, Virginia, Colorado), you may have rights to access your personal information, delete personal information, correct inaccuracies, opt out of data sharing for targeted advertising, and request information about our data collection practices.

We respond to verified U.S. consumer rights requests as required by applicable state laws.


9. Children’s Privacy

We do not knowingly collect personal data from children under the age of 13 (per U.S. COPPA) or under the age of 16 (per GDPR) without parental or guardian consent. Minors included in family membership plans must have their data submitted by a parent or legal guardian.


10. Cookies and Online Tracking

We use cookies for security, authentication, session management, and analytics. Analytics data is anonymized or pseudonymized when possible. We do not use third-party advertising cookies or behavioral tracking tools. EU/EEA visitors may be shown a cookie consent banner in accordance with GDPR and the ePrivacy Directive.


11. Automated Decision-Making

We may use automated systems for Facility assignment, risk-scoring, authentication, fraud detection, and communication prioritization. Critical decisions involving Facility access always involve human oversight. You may request human review of any automated decision that materially affects your rights.


12. Data Breach Notification

If a personal data breach occurs and it poses a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours (for EU/EEA residents) and notify affected individuals without undue delay as required by GDPR Articles 33 and 34. We follow all applicable U.S. state-level breach notification laws as well.


13. Confidentiality

All Company employees, contractors, and Facility Operators who handle personal data are required to maintain strict confidentiality. They are granted access only to the information necessary to perform their duties, and all personnel undergo security and privacy training. Unauthorized disclosure may result in termination and legal action.


14. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in legal requirements, technological developments, or our operational practices. Material updates will be communicated by email or through platform notifications. Continued use of the Service after amendments constitutes acceptance of the updated Policy.


15. Contact Information

For questions or to exercise privacy rights, contact us at:

Bunker Pass LLC – Privacy Team
Email: privacy@bunkerpass.net
Mailing Address: 1209 MOUNTAIN RD PL NE, STE R ALBUQUERQUE, NM 87110 USA

For EU residents:

EU Representative (GDPR Art. 27)
MAWIPO OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia – legal@mawipo.com

You may also contact your local Data Protection Authority.