Privacy Policy
Last updated 2 September 2026
Bento Pages is a website builder at bentopages.com, operated by Jonathan Itzen as a sole proprietor ("we", "us", "our"). Bento Pages is a trading name rather than a separate company, so the person responsible for your data is Jonathan Itzen. This policy explains what we do with personal data, and what you can ask us to do about it.
Who this covers
This policy covers two different groups of people, and the difference between them decides who you need to talk to.
- People with a Bento Pages account. You signed up and you build sites here. We decide how your data is handled, which makes us the controller of it.
- People who visit a site built with Bento Pages. You may never have heard of us. If you fill in a form on one of those sites, the team who built it decides what happens to your answers. They are the controller. We store the answers for them, which makes us their processor.
If you sent a form reply and want it removed, ask the team whose site you sent it to. They can delete it themselves. You can also write to us at [email protected] and we will pass the request on to them.
The terms we process that data under are set out in How we handle the data you collect, which is the data processing agreement between us and the team who runs the site.
What we collect
Account data
Your name, your email address, and your password. The password is stored hashed and we cannot read it. If you turn on two-factor authentication we store the secret and your recovery codes, encrypted. If you register a passkey we store its public key and its identifier. We also record when you verified your email address.
Site content
Everything you put into a site: the text of your pages and posts, images and other files you upload, your team's name and address, its theme, its navigation, and the meta title and description you set. Some of this is published to anyone who visits your site, because that is the point of the service.
Billing data
If you subscribe we store your Stripe customer identifier, your card's brand, its last four digits, and the date your trial ends. We never see or store your full card number. Card details go straight to Stripe through their hosted checkout and billing portal, and never reach our servers.
Form replies
When a visitor submits a lead form on a site built here, we store the answers, the questions they were asked, the page the form was on, the time it arrived, and the visitor's IP address. We keep the IP address to enforce rate limits and to give the team a way to spot abuse. We hold all of it on behalf of the team, not for our own purposes.
Technical data
Our servers keep logs containing IP addresses, request paths, timestamps, browser user agents, and error details. We use them to keep the service running and to investigate faults and abuse.
Cookies
We set a session cookie so you stay signed in, and a token cookie that protects forms against cross-site request forgery. Both are necessary for the service to work, and neither follows you around other websites. We run no advertising or analytics cookies. If that ever changes we will ask for your consent first.
Do Not Track
Some browsers send a "Do Not Track" signal. There is no agreed standard for what a site should do about it, so we do not respond to it differently. We do not track you across other websites either way, so there is nothing for the signal to turn off.
How we use it
- To give you the service: your account, your teams, your sites, and publishing them.
- To send transactional email, meaning address verification, password resets, and team invitations.
- To take payment and manage your subscription.
- To keep the service secure, which covers rate limiting, abuse investigation, and fraud prevention.
- To answer you when you get in touch.
- To meet obligations the law places on us.
We do not sell personal data, and we do not share it for advertising.
Our legal bases
If you are in the UK or the EEA, we rely on the following bases under the GDPR.
- Performance of a contract for your account, your sites, and your subscription.
- Legitimate interests for security, abuse prevention, and keeping the service working. We have weighed these against your rights.
- Legal obligation for tax and accounting records.
- Consent where we ask for it, which you can withdraw at any time.
Who we share it with
We use a small number of processors to run the service.
- Stripe, for payments and subscription billing.
- Resend, for sending transactional email.
- Amazon Web Services, for hosting.
They act on our instructions and may not use your data for their own purposes. We may also disclose data where the law requires it, or where we need to protect our rights, our users, or the public. If the business is ever sold or merged, personal data may transfer with it, and we will tell you before that happens.
Where your data is stored
On servers hosted by Amazon Web Services in the United States. Stripe and Resend process data in their own locations, which may also be outside your country. If you are in the UK or the EEA, that means your data is transferred to the United States, and the transfer relies on standard contractual clauses or on an adequacy decision covering it.
How long we keep it
- Account data for as long as your account is open. Deleting your account deletes it, together with your teams, sites, posts, and uploads.
- Form replies until the team who owns them deletes them or closes their account.
- Billing records for as long as tax and accounting law requires, normally six years.
- Server logs for a short rolling window, after which they are discarded.
Backups may hold deleted data for a short period before they roll over and overwrite it.
Your rights
Depending on where you live, you can ask us to do the following.
- Give you a copy of the personal data we hold about you.
- Correct data that is wrong or incomplete.
- Delete your data.
- Give you your data in a portable format, or send it to someone else.
- Stop or limit a particular use of it.
- Withdraw a consent you gave earlier.
You can change your name, your email address, and your password from your profile settings, and you can delete your account from the same page. Deleting your account happens immediately and cannot be undone.
For anything else, write to [email protected]. We answer within one month. If you are unhappy with our answer you can complain to your data protection regulator. In the UK that is the Information Commissioner's Office.
If you are in California
You can ask what personal information we have collected, ask us to delete it, and ask us to correct it. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.
Security
Passwords are hashed with bcrypt. Traffic runs over HTTPS. We offer two-factor authentication and passkeys, and we require you to verify your email address. Access to production systems is limited to people who need it. We take your data seriously and we will tell affected users and the regulator about a breach where the law requires it.
Children
Bento Pages is not intended for children. You must be at least 16 to create an account, which matches the age requirement in our Terms of Service. We do not knowingly collect personal data from anyone younger, here or through a lead form on a site built here. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We update this policy when what we do changes. The date at the top always reflects the current version. If a change materially affects you, we will email account holders before it takes effect.
Contact
Email [email protected]. That address reaches Jonathan Itzen, who operates Bento Pages and is the controller of the data described here. We do not publish a postal address. If you need one to serve a formal notice or to make a regulatory complaint, ask and we will give you one.