Legal
Privacy
Last updated 16 September 2026
This explains what BindasX stores, why it stores it, and what it deliberately does not. It covers two different people: the creator who makes a page, and the visitor who reads one.
If you make a page
We store what you give us, because the product cannot work without it:
- Your email address and name, from signup.
- Everything you put on your page — your work, services, prices, bio, contact details.
- Reviews your clients submit, and your replies to them.
- Images you upload.
Your password is never stored. What is stored is an Argon2id hash of it, which cannot be reversed back into your password — not by us, not by anyone who obtained a copy of the database.
Signing in creates a session that lasts 30 days. The session identifier in your browser is a random value; the database holds only a SHA-256 hash of it. You can end sessions individually, or all at once, from your settings.
If you visit someone's page
Page owners get analytics, and the analytics are built so that they tell the creator what is working without telling anyone who you are.
What is recorded when you view a page or tap a contact button:
- Which page, and what kind of event — a view, a WhatsApp tap, a service tap.
- The host you came from, such as “instagram.com”. Not the full URL, and not your history.
- Campaign tags, if the link that brought you carried them.
- A coarse device class — phone, tablet or desktop. Three buckets, because a full browser string is close to a fingerprint.
What is not recorded: your IP address, your name, a cookie that follows you between pages, or anything that identifies you as a person. There is no Google Analytics, no advertising pixel, and no third-party script of any kind on a public page.
Individual events are deleted automatically after a retention window; only anonymous daily totals are kept beyond it.
If you leave a review
A review link is single-use. We store the name you give, your rating, your words, and any image you attach — all of which appear publicly if the creator approves them. Your email address is not requested and not stored.
The creator can approve, hide or reply to your review. They cannot edit its words. There is no function anywhere in the product that lets them do so.
Who else sees your data
Nobody, with two exceptions. The servers are operated directly rather than through a hosted backend, so there is no analytics vendor, no customer-data platform and no marketing tool holding a copy.
- Email is sent through our own mail server so that you can verify an address or reset a password.
- If and when paid plans are enabled, card details are handled entirely by the payment provider. They never reach our servers, and we never store them.
Your choices
You can edit or delete anything on your page at any time. You can switch your page off entirely, which makes it unreachable without deleting what you have written.
To have your account and everything in it permanently deleted, write to us and it will be done. If you would like a copy of your data first, ask for that too.
Cookies
Two, both necessary, neither used for tracking: one holds your session so you stay signed in, and one carries a token that protects forms against cross-site request forgery. Public pages set no cookies at all.
Who operates this service
To be completed by the operator. Add the legal entity or proprietor name, registered address and a contact email here before taking payments. Left blank rather than guessed, because it is the one thing this page cannot state accurately on its own.
Changes
If this changes in a way that affects what is collected, the date at the top changes and the change is described here. The terms are a separate page.
Questions about any of this? Get in touch.