Legal
Privacy policy
How Bright Binnie collects, uses and protects your personal information.
Who is responsible for your information
Bright Binnie is the trading name used for this product by Adam Warburton, an individual sole trader and the data controller for the personal information described here. The postal contact address is 21 Borth Avenue, Stockport, SK2 6AJ, United Kingdom.
Privacy and data-rights questions can be sent to bins@brightbinnie.com or through our support form.
What this policy covers
This policy covers the Bright Binnie website, iPhone app, customer support and the online service used by a physical Binnie. It does not cover a third party’s own website or service, such as Stripe’s hosted checkout; that provider’s privacy information also applies when you use it.
Information we collect
- Orders and delivery — name, email address, phone number, delivery address, the address where Binnie is intended to live, the email chosen for app setup, items and quantities, optional printed house numbers, discount code, payment totals, currency, order status and Stripe checkout reference. The intended address and setup email may be different for a gift. Stripe processes the card details; we do not receive or store the full card number or security code.
- App account and home — email address and sign-in record, household label and address, postcode, council, collection schedule, timezone, reminder times, reminder recipients, saved reminder light-colour preferences, referral-code usage and the paid-order match used to prefill or confirm the setup home. The password is handled by Supabase Auth and is not readable by us.
- Binnie and service information — device code and internal identifier, claim status, firmware version, last check-in time and security credentials held as one-way hashes. If an owner separately releases a locally erased unit for return, we keep a minimal event containing the device, old household/account identifiers, request identifier and time; it contains no setup key or Wi-Fi details. These details let the app show whether Binnie is connected, let the service return the correct reminder and saved light colour, and prevent an ownership handover from being lost or repeated.
- Support and reviews — the name, email address and message you submit, plus a rating if you leave a review. Approved review text, rating and name may appear publicly; an optional review email address is not published. For abuse prevention, the sending IP address is immediately converted into a purpose-specific one-way hash used to limit repeated submissions. Support and reviews use separate hash namespaces, and we do not store the raw IP in the support ledger. A random submission identifier makes a network retry safe without creating duplicate messages.
- Checkout abuse prevention — before creating a Stripe Checkout session, the service converts a namespaced client/IP key into a one-way SHA-256 hash and counts recent attempts. The application does not store the raw IP in this counter. Inactive counter rows are scheduled for deletion within about three hours.
- App launch updates — an email address if you ask to hear when the app launches.
- Routine technical information — hosting and infrastructure providers may process request, device, browser, diagnostic and security-log information when they deliver the website or online service.
Please do not put card details, passwords, Wi-Fi details, private setup codes or sensitive personal information in a support message or review.
Camera, Bluetooth and Wi-Fi setup
The iPhone app uses the camera only to scan the private setup QR supplied with a Binnie. It does not take or upload a photo or video. The app uses Bluetooth to find and configure that Binnie.
Your Wi-Fi network name and password travel from the iPhone directly to Binnie over an encrypted Bluetooth setup connection. Binnie stores them locally so it can reconnect, but they are never sent to or stored on Bright Binnie servers. The private setup code is sent securely to our setup service to prove possession of the device; only a one-way digest is kept in the database.
Where information comes from
Most information comes directly from you, your app or your Binnie. We receive the final delivery address and other paid-order details from Stripe. If Binnie is a gift, the buyer may provide the intended home and setup email on the recipient’s behalf. We obtain council names and collection details from postcodes.io and the relevant council’s public lookup service or published schedule. The enabled providers, credits and reuse terms are listed on our data sources and licences page.
Why we use it and our lawful bases
- Contract — to take and fulfil an order, provide the app and Binnie service, retrieve the correct collection schedule and give customer support.
- Legal obligation — to keep records required for tax, accounting, consumer-protection or other legal duties.
- Legitimate interests — to secure and operate the service, prevent form abuse, diagnose faults, monitor whether devices can reach the service and respond to enquiries. Those interests are balanced against your rights and expectations.
- Consent — where you ask for an optional email, such as an app launch update or reminder. You can withdraw that request by contacting us.
We do not sell personal information, use it for third-party advertising, or make solely automated decisions about you that have legal or similarly significant effects.
Who receives it
- Stripe — hosted checkout and payment processing. The Checkout Session carries an opaque internal reference so we can reconcile the order after payment. We do not put a separate Binnie-home address or recipient setup email in Stripe metadata; those details remain in our service-only order system. Stripe still receives the delivery details you enter on its checkout page.
- Supabase — account authentication, database and Edge Function infrastructure. The primary production project is currently hosted in the Ireland AWS region (eu-west-1).
- Resend — order, reminder, support and operational emails.
- Vercel — website hosting and delivery.
- postcodes.io — the postcode where Binnie will live, used to identify the relevant council.
- Your local council’s lookup service — the postcode, address or property reference needed to retrieve that household’s bin schedule.
- Professional advisers, authorities or a buyer of the business— only where reasonably necessary and permitted by law.
International processing
Hosting the primary Supabase project in Ireland does not mean that every backup, log, Edge Function or subprocessor stays there. Stripe and other service providers may also process information outside the UK. Stripe publishes a data processing agreement that includes the UK International Data Transfer Addendum for relevant transfers. Where a restricted transfer occurs, we require a lawful UK transfer mechanism, such as an adequacy regulation, the UK Addendum or an International Data Transfer Agreement, as appropriate. You can ask us for information about the relevant safeguards.
Cookies and analytics
Bright Binnie’s current website code does not use advertising cookies or optional audience analytics. Hosting may use strictly necessary security or delivery technology. If optional analytics or similar technology is added, this notice and the consent controls will be updated before it is switched on.
Stripe’s hosted checkout is a separate service and may use its own cookies for payment, fraud prevention and security. Stripe provides information about those cookies on its service.
When we hand you to Stripe, the checkout page temporarily saves the pre-payment form details in this browser tab’s session storage. This lets us restore them if you cancel and return. It never includes card details or a Stripe payment link, is cleared after the successful return, and is normally removed when the tab closes. Any unread copy older than 24 hours is rejected and removed when checkout is next opened from the cancellation page.
How long we keep information
- App account and household information is kept while the account is active and is removed through the in-app deletion flow, subject to the exceptions below.
- Paid-order records, including the intended Binnie home and setup email, are retained for the period needed for fulfilment, tax, accounting, fraud prevention and legal claims, even if the app account is deleted.
- If checkout is not completed, the temporary Binnie-home and setup-email record is removed after seven days. After a completed checkout has been transferred into the paid-order record, that temporary copy is removed after 30 days.
- Transactional email queue content is kept until delivery succeeds. Sent queue records are removed after 30 days; the resulting emails remain subject to the normal mailbox and legal-retention rules. A queued support or review email is linked to its submission and is deleted with that submission, including when matching app-account data is erased.
- Support, review, launch-list and operational records are kept only while they are needed for their stated purpose, abuse prevention or a legal claim.
- A device-release event is retained as a minimal inventory and security audit. If the related app account is deleted, its user and household links are removed; the device, request identifier and release time may remain so a returned unit is not accidentally attached to the former home again.
- Infrastructure providers retain their own security and service logs under their configured retention periods.
- The short-lived checkout and app-launch-list abuse-prevention counters are scheduled to remove an inactive hashed client key within about three hours. Each purpose uses a separate one-way hash namespace; raw IP addresses are not stored in these counters. This is separate from request metadata retained by the hosting providers under their own settings.
Where an exact period is not stated above, we review the record against why it is still needed, applicable record-keeping duties, security needs and whether a dispute or legal claim could arise. We delete or anonymise it when there is no longer a justified reason to keep it.
Deleting an app account
The app includes Delete my account. It removes the login, household and address, reminder recipients, collection schedule, saved reminder light-colour preferences, send history, referral code, matching support or launch-list data, and linked queued copies of those support messages. It detaches Binnie and clears its service token so it can be claimed again. Any earlier device-release audit loses its account and household links when those records are deleted. Device manufacturing records and paid-order records, including their original setup instructions, remain where needed for inventory, fulfilment history, tax, accounting, fraud prevention or legal claims.
Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or receive your information, and to object to some uses. Where processing relies on consent, you can withdraw it. These rights are not all absolute; contact us and we will explain the outcome of your request.
Your right to object: you can object to processing based on our legitimate interests and to any direct marketing at any time. Email bins@brightbinnie.com.
Please contact us first so we can try to resolve a concern. You can also complain to the Information Commissioner’s Office.
Contact
Contact Adam Warburton, trading as Bright Binnie, by emailing bins@brightbinnie.com or using the support form.
Adam WarburtonTrading as Bright Binnie21 Borth AvenueStockportSK2 6AJUnited KingdomLast updated: 19 August 2026.