1. The short version
This summary is not a substitute for the detail below, but it is accurate.
- There are no accounts. You never give us a name, email address or password to use the app.
- Your saved address lives on your device. The service also temporarily caches the schedule it fetches and, if you enable change notifications, stores a push token linked to that schedule.
- We use it only to provide Binminder. Your address details go to our data service, which asks your council or waste provider for collection dates.
- No advertising or profiling. The app has no advertising or third-party analytics SDKs. The service uses limited aggregate operational metrics, described below.
- You can remove your local data. Delete properties or reset the app; uninstalling also removes the app's local storage.
2. Who we are
Binminder ("we", "us") is built and run by Dean Longstaff, an individual developer trading as Binminder. Binminder is not a company, it is one person, working alone, and there is no registered entity or company number behind it.
That person is the "controller" of the personal data described in this policy, which means they decide why and how it is handled.
For anything about privacy or your data, email [email protected]. We have not appointed a Data Protection Officer, as we are not required to. We do not publish a postal address, as it would be a private home address. If you need one in writing for a formal data protection request, or to contact a regulator, email us and we will provide it.
3. What we collect, and why
Here is the data the app and service use to provide and protect Binminder.
Data stored only on your device
The following never leaves your phone except as described under "Data sent to our service" below. It is held in the app's local storage:
- The properties you add: the name you give each one ("Home", "Mum's house"), the address you selected, its postcode, the council or waste provider matched to it, and the reference details that provider needs to identify your property (for example a UPRN in the UK, or the fields that provider's own form asks for).
- Your reminder preferences: whether reminders are on, and at what times.
- A cached copy of your most recent collection schedule, so the app still shows something useful when it cannot reach the internet.
- Whether you have completed the introduction screens.
Legal basis: performance of our contract with you (UK/EU GDPR Art. 6(1)(b)), the app cannot show your bin days without it.
Data sent to our data service
| What | Why | Legal basis |
|---|---|---|
| What you type into address search (UK only), typically a postcode or street name | To find matching addresses so you can pick yours | Contract, Art. 6(1)(b) |
| Your selected provider and its property reference (e.g. UPRN), sent each time the schedule refreshes | To ask that provider when your bins are collected | Contract, Art. 6(1)(b) |
| Your IP address and the basic technical details every web request carries | To apply rate limits, prevent abuse of the service, and keep it running | Legitimate interests, Art. 6(1)(f), keeping the service available |
| Native app verification information | To confirm requests come from a genuine app installation and limit abuse | Legitimate interests, Art. 6(1)(f) |
| Push token and the provider/address references you subscribe to | To refresh your schedule when a provider changes it, if notifications are enabled | Contract, Art. 6(1)(b) |
We do not have user accounts and do not receive your name or email address through the app. The service does, however, hold address-related cache records and, when enabled, a push subscription for the device.
Operational metrics
The service records aggregate request, error, provider and location-funnel metrics to operate and improve reliability. These may include a provider ID, a coarse UK postcode district, country and platform. They do not include a full postcode, UPRN, address, request arguments or push token. The service also keeps a hash of an attestation subject to count anonymous installs and activity; it is not used to identify you.
Subscriptions and payments
If you subscribe, the purchase is made through Apple's App Store or Google Play. We never see your card details. Apple or Google process the payment as the merchant of record and tell us only whether a subscription is active.
We use RevenueCat to check subscription status. RevenueCat assigns your installation an anonymous identifier and receives device and purchase information from the app store in order to do so. It does not receive your address or your collection schedule.
Legal basis: performance of our contract with you, Art. 6(1)(b).
Notifications
Bin day reminders are scheduled on your device by your phone's own operating system. When notifications are enabled, Binminder also uses a silent push notification to tell the app that a provider's dates may have changed. The push contains no address or collection dates; the app fetches those itself. We do not know when a reminder fires.
If you contact us
When you email us or use the form on this website, we receive your email address, whatever you write, and anything you choose to include (such as a council name or postcode). We use it only to answer you. Legal basis: legitimate interests, Art. 6(1)(f), responding to the person who contacted us.
4. What we don't do
Stated plainly, because these are the things people usually worry about:
- The mobile app has no advertising, attribution or third-party analytics SDKs. The service does use aggregate operational metrics and may use Sentry for API error diagnostics.
- We do not sell your personal information or use it for behavioural advertising.
- We do not build profiles or make automated decisions about you.
- We do not track your location. The app does not request location permission; the address you enter is the address you chose to type in.
- We do not read your contacts, photos, calendar or other apps' data.
5. Who we share it with
We share personal data only with the following, and only for these reasons:
| Who | What they get | Why |
|---|---|---|
| Your council or waste provider | The property reference their own system needs | To look up your collection dates. They are independent controllers of the data in their own systems. |
| Apple App Attest and Google Play Integrity | App and device verification information | To verify native app requests |
| RevenueCat, Apple, Google | Subscription and purchase data, never your address | To process payment and confirm your subscription is active |
| Expo, Apple and Google push services | Push token and a notification request containing no address or dates | To deliver silent schedule-change notifications |
| Fly.io | Data processed by the data service, including its stored cache records | To run the data service. A third-party infrastructure provider acting as our processor under contract, with no right to use the data for its own purposes. |
We may also disclose data where the law requires it, or to establish or defend legal claims. We require our processors to protect your data to the same standard set out in this policy.
6. International transfers
Some of the parties above are based outside the UK and EEA. RevenueCat, Apple and Google are US-headquartered, the councils and providers you connect to are in whichever country you selected, and our data service runs on third-party hosting infrastructure. You can ask us where the service is currently hosted at any time.
Where personal data leaves the UK or EEA, we rely on the UK and EU adequacy regulations where they apply, and otherwise on Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement, as appropriate), together with the safeguards those require. You can ask us for details of the safeguards applying to any particular transfer.
7. How long we keep it
- On your device: until you remove the property, reset the app, or uninstall it. We do not control this data and cannot retrieve it.
- Collection-date responses: normally refreshed after six hours locally or 12 hours in production. A last-known-good response may remain longer while a provider is unavailable, then is replaced or discarded.
- Push subscriptions: removed when you disable notifications or unregister the device, and pruned after prolonged inactivity.
- Operational metrics and technical logs: kept for service operation, security and troubleshooting under the retention settings of the relevant monitoring or hosting provider.
- Subscription records: retained by Apple, Google and RevenueCat under their own policies. We do not receive your card details.
8. Your rights
If you are in the UK or the EEA, you have the right to access your data, to have it corrected or erased, to restrict or object to how we use it, to data portability, and to withdraw consent where we rely on it. You can exercise any of these by emailing [email protected]. We will respond within one month.
A practical note. Because we have no user account, we may need additional information to identify a particular device, address record or support message. Where we genuinely cannot identify you, Art. 11 of the UK/EU GDPR applies and we may not be able to act without additional information.
You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority in the country where you live or work.
California residents. We do not sell or share personal information and do not use it for cross-context behavioural advertising. You have rights to know, delete, correct and to non-discrimination; the same contact address applies.
9. Deleting your data
The fastest routes, in order of thoroughness:
- Delete a single property in the app's Settings to remove that address and its schedule.
- Reset the app from Settings to erase every property, schedule and preference it holds.
- Uninstall the app to remove everything it stored on your device.
There is no account to delete, because there is no account. To cancel a subscription, use the Subscriptions section of your App Store or Google Play account; deleting the app does not cancel billing. Removing a property or resetting the app also removes its push subscription from the service when the device can connect; cached service records and aggregate metrics are not necessarily deleted immediately.
10. Children's privacy
Binminder is a household utility intended for adults responsible for a property. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
Requests to our service use HTTPS, native app verification where supported, and rate limiting. Data on your device is protected by the device's own storage protections and passcode or biometric lock. No system is perfectly secure.
12. This website
This site sets no cookies and runs no analytics. It stores a single value in your browser's local storage, your light or dark theme choice, so the site looks the same when you come back. That is set only when you use the theme toggle, is not used to identify or track you, and is cleared when you clear your browsing data.
Our hosting provider (Fly.io) may process your IP address to serve the page and protect against attacks, as any web host does.
The site loads its typeface from Google Fonts, which may receive your IP address and browser request as part of serving the font.
13. Changes to this policy
If we change this policy we will update the date at the top of the page. If the change is significant, new categories of data, a new purpose, or a new recipient, we will say so in the app before it takes effect.
14. Contact us
Privacy questions, data rights requests and everything else: [email protected]
Binminder is run by Dean Longstaff. A real person reads these and replies.