Binder

Privacy Policy

Last updated 26 July 2026

Binder is a business tool that stores premises service records. This policy explains what we hold, why, who else touches it, and how to get it back or get rid of it.

1. What we collect from you

  • Your email address. It is your identity here. We sign you in by sending a code to it. Optionally your name.
  • Your business and locations. Business name, location names and addresses, timezone, the equipment you list, the intervals you set, and your vendors' names and contact details.
  • What you confirm and change. Which document you confirmed, which date you set, and when. This is an audit trail; it is the point of the product and it is retained for as long as your account exists.
  • Technical records. IP address and browser user-agent attached to each sign-in session, so a suspicious login can be investigated. Standard request logs.

We do not use tracking cookies, advertising pixels, or third-party analytics. The only cookies we set are the one that keeps you signed in and a short-lived one during sign-in. There is nothing to consent to because there is nothing tracking you.

2. What we receive from your vendors

Each of your locations has an email address. When your hood cleaner, extinguisher company, or grease hauler sends a report there, we receive and store:

  • the attached documents;
  • the full original message, including headers, sender address, and subject line . Kept because it is the provenance of the document, and provenance is what makes a record defensible;
  • text we extract from the document in order to read dates off it.

Those documents are authored by third parties and may name individual technicians. We process them on your instruction, as your records. If a vendor contacts us about something they sent to your address, we will point them to you, because the record belongs to you and not to us.

Mail arriving from a sender your account has not seen before is held for your review instead of being filed automatically.

3. What we never see

Card details. Payment is handled entirely by Stripe on Stripe's own pages. Card numbers never reach our servers, and there is no code in our application capable of accepting one. We store only a Stripe customer identifier and the subscription's status.

Passwords. There are none. We never store a password because we never ask for one.

4. Why we hold it

To run the service you asked for: to store and organise your records, to tell you what your record says is due, to let you show those records to someone, to bill you, and to keep the service secure. We do not use your documents for any other purpose.

We do not sell personal information. We do not share it for advertising. We will not use the contents of your documents to build or sell a separate product without asking you first, separately and explicitly.

5. Who processes it besides us

A short list, on purpose:

  • Cloudflare. Hosting, database, file storage, and inbound email routing. Your documents live in Cloudflare R2 storage.
  • Stripe. Payment processing and card data, for paid accounts.
  • Postmark. Sending our transactional email, such as sign-in codes and reminders.

We may also disclose information if we are legally required to. If we receive a demand for a customer's records, we will tell that customer unless we are prohibited from doing so.

6. Where it is held

On Cloudflare's network, with data at rest in the United States. If you are outside the US, using Binder means your information is processed there.

7. How long we keep it

  • Documents: until you delete them, or until 30 days after your account is closed.
  • Sign-in codes: minutes. They expire in ten and are purged.
  • Sessions: up to 30 days, then they expire. Signing out revokes immediately.
  • Audit trail: for the life of the account. It exists precisely so that it cannot be selectively erased.

8. Your choices

  • Export. Download everything, any time, including after cancelling.
  • Delete. Delete a document and the stored file is deleted, not flagged. Close your account and we delete your documents.
  • Correct. Every date and detail is editable by you.
  • Ask. Email us and we will tell you exactly what we hold about you.

Depending on where you live you may have additional rights over your personal information, including access, correction, deletion, and portability. Ask and we will honour them; we are not going to make you cite a statute.

9. Security

The measures that matter most here are structural rather than promises: there are no passwords to steal; sign-in codes and session tokens are stored only as hashes, so a copy of our database cannot be used to sign in as anyone; every query is scoped to your account by the server, not by anything the browser sends; and payment card data never touches our systems.

No service is immune. If we discover a breach affecting your information we will tell you what happened, what was affected, and what we did about it.

10. Children

Binder is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 16.

11. Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.

12. Contact

support@compliancebinder.com