bindro.

bindro · version 2026-08-12

Privacy Policy

Draft prepared [2026-08-12] — pending review by counsel; [bracketed items] are for counsel to complete.

This policy explains what personal data bindro.io collects, why we collect it, who we share it with, and what you can do about it. We have tried to write it so you can read the whole thing in one sitting. If anything here is unclear, email us at privacy@bindro.io and we will give you a straight answer.

Who we are

bindro.io is a self-serve ticketing and registration platform operated by [ENTITY NAME], a [STATE OF FORMATION] entity ("bindro", "we", "us"). Hosts use bindro to run events and sell or give away tickets. Buyers use bindro to register and pay. Visitors browse event pages.

bindro appears under twenty different vertical brand presentations — for example, brands tailored to fitness, workshops, or community events. These are presentations of one service. Whichever brand you see, there is one platform, one legal relationship, and this one privacy policy.

At launch, host onboarding is available in the United States only, and all transactions are in US dollars.

The short version

  • We collect your phone number and email to sign you in and to send you booking messages. Nothing else rides on those channels — no marketing.
  • Card numbers never touch our systems. Stripe collects them directly.
  • Some events ask registration questions that touch on health or relate to minors. That data gets extra protection: encrypted at rest, kept out of our AI features, and kept out of our operational logs.
  • We do not sell your personal data. We do not share it for advertising. There is no ad tech on our pages, and the only cookie we set is the one that keeps you signed in.
  • You can ask for access, correction, deletion, or a copy of your data at privacy@bindro.io.

What we collect and why

Account data

When you create an account, we collect your phone number and email address. We use your phone number to send one-time sign-in codes — that is how sign-in works on bindro. Hosts can optionally sign in to the host console with Google instead. We use your email for account and booking communications. We also collect your name.

Booking and registration data

When you register for an event, we collect the names of the people attending and your answers to the registration questions the host has set up for that event. Some hosts also require a waiver, in which case we collect your e-signature on it.

In some verticals, registration questions can ask about health-related matters (for example, medical conditions relevant to a physical activity) or collect information about minors. We treat both classes of data with extra care:

  • It is encrypted at rest.
  • It is excluded from our AI features. Our AI assistant never sees health-class or minor-class data.
  • It is excluded from our operational logs.

Payment data

We record payment outcomes — whether a charge succeeded, failed, or was refunded, and for how much. We never collect or store card numbers. bindro is the merchant of record for card payments, and charges are processed by Stripe on bindro's account — but card details are collected by Stripe directly, in Stripe's own iframe and pages. That data goes to Stripe and does not pass through bindro's systems.

For hosts: to receive payouts, you complete Stripe Connect Express onboarding. Your identity documents and bank details are collected by Stripe, not by bindro, and the Stripe Connected Account Agreement applies to that relationship. Your bank details exist only at Stripe.

At the door

When you attend an event, we record check-in and attendance. Hosts use this to run their events, and it forms part of the record of what happened at an event.

Our legal bases

Where laws such as the GDPR or UK GDPR apply, we rely on the following legal bases:

  • Contract. Most of what we do — accounts, bookings, payments, payouts, refunds, check-in — is processing we need to perform to provide the service you or your host signed up for.
  • Legitimate interest. Keeping the platform secure, preventing fraud, maintaining our audit log, and defending against disputes.
  • Consent. For the sensitive classes of data described above — health-class registration answers and minor-class data — we rely on consent, collected when you answer those questions or complete a guardian consent flow.

Who controls what: bindro and your host

Privacy law distinguishes between the party who decides why data is collected (the "controller" or "business") and the party who processes it on their behalf. On bindro, that split works like this:

  • bindro is the controller for platform account data — your phone number, email, name, sign-in activity, and payment outcomes.
  • The host is the controller for attendee registration data collected on the host's behalf — the answers to that event's registration questions, waivers, and attendance for that event. bindro processes that data for the host, under processing terms carried in our host agreement.

What this means in practice: if you send us a rights request about a specific booking, and the host is the controller of that data, we may forward your request to the host, because the decision is legally theirs. But for the data bindro controls, we honour your request directly — no forwarding, no runaround.

Subprocessors and service providers

We use a short list of service providers. Each one receives only the data needed for its purpose:

ProviderPurposeData involved
StripeCard payment processing, Connect payouts to hosts, host identity verificationCard details (collected by Stripe directly — never by us), host identity and bank details, transaction data
TextbeltSMS deliveryPhone number, message content (sign-in codes and booking messages)
TwilioSMS delivery (secondary)Phone number, message content (sign-in codes and booking messages)
Amazon Web Services (SES)Email deliveryEmail address, message content
GoogleOptional console sign-inGoogle account identity, if you choose to sign in with Google
OVHHosting — a dedicated server in an OVH datacenter, serving US trafficPlatform data as described in this policy

One other party receives personal data: the host of an event you register for, who receives that event's registration data — that is the service working as described in the controller section above. Beyond your hosts and the providers in this table, we do not share personal data with anyone unless the law requires us to. We never sell personal data, and we never share it for advertising.

How long we keep data

The full retention schedule is published at /privacy/retention/. The numbers on that page are generated from the same constants our automated deletion sweeps actually run on, so the published schedule cannot drift from what the system does. The summary:

  • Financial and audit records are kept for 7 years. This is required so money disputes — refunds, chargebacks, payout questions — can be resolved long after an event ends.
  • Everything else follows the published schedule at the link above.

When you ask us to delete your data, here is honestly what happens: we "tombstone" your identity. Your name, email, and registration answers are destroyed. But the financial records — that a transaction of a certain amount happened on a certain date — are retained for the 7-year period, because we are required to keep them for money disputes. One boundary, stated plainly: the contact address on an order is part of the sale record — a receipt, a refund, and a chargeback all need it — so it is kept with the financial records for that same period. The audit trail records that an erasure happened; it does not keep a copy of what was erased. We tell you this up front rather than implying that deletion erases every trace.

Your rights

You can ask us to:

  • Access the personal data we hold about you.
  • Correct data that is wrong.
  • Delete your data (see the tombstoning explanation above for exactly what deletion does).
  • Port your data — receive a copy in a usable format.

Send any request to privacy@bindro.io. If your request concerns booking data where a host is the controller, we may forward it to that host, as described above; for the data we control, we act on it directly.

California residents

If you are a California resident, the CCPA/CPRA gives you rights to know, access, correct, and delete your personal information, and the right not to be discriminated against for exercising them. You can exercise these rights through privacy@bindro.io.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. Because we do not sell or share personal information, there is no opt-out to exercise — there is nothing to opt out of. We use no third-party advertising technology.

EU and UK residents

If the GDPR or UK GDPR applies to you, you additionally have the right to restrict or object to certain processing, the right to withdraw consent where processing is based on consent (this does not affect processing that already happened), and the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are set out above.

Cookies

We set one cookie: the session cookie that keeps you signed in. It is essential — the service does not work without it. We set no tracking cookies, no analytics cookies, and no advertising cookies, and no third-party ad tech runs on our pages. Because we only use an essential cookie, you will not see a cookie consent banner on bindro; there is nothing to consent to.

Children and minors

bindro is a platform for hosts and buyers. Where an event involves minors, information about them reaches us through the buyer's registration — typically a parent, a coach, or a team manager — in the youth-facing verticals that ask for it.

For those verticals, the platform requires the guardian's own act, not just a box ticked on the booking form: we email a signing link to the guardian's own email address, and the guardian countersigns with their own typed name. Until that happens, the minor's ticket will not admit them at check-in. Minor-class data receives the extra protections described earlier — encrypted at rest, excluded from AI features, and excluded from operational logs.

Hosts are prohibited from running events targeting minors without using this consent machinery.

SMS

We send two kinds of text messages: one-time sign-in codes, and transactional booking messages about your registrations. That is all. We do not send marketing SMS, ever. By providing your phone number and signing in, you consent to receiving these transactional messages. Message and data rates may apply, depending on your carrier plan.

The AI assistant

bindro includes an AI assistant. It is read-only: the only action it can take is filing a support ticket on your behalf. It cannot modify your data, and it never sees health-class or minor-class registration data.

Security

Our security posture includes:

  • Per-tenant database isolation — every database query runs inside a context scoped to a single host, enforced at the database layer itself, so one host's queries cannot reach another host's data.
  • A tamper-evident audit log — records of significant actions that cannot be silently altered.
  • A written incident-response plan with defined notification deadlines, so if something goes wrong, affected people hear about it on a schedule, not at our convenience.
  • No card data in scope — because card numbers never touch our systems, they cannot be exposed by them.
  • Encryption at rest for health-class and minor-class registration data.

International transfers

bindro is hosted on a dedicated server in an OVH datacenter serving US traffic, and the platform serves the US market. If you access bindro from outside the United States, your data will be processed and stored in the United States. Where laws such as the GDPR require safeguards for such transfers, we rely on the mechanisms available for transfers to the United States; contact privacy@bindro.io for details of the safeguards applicable to you.

Changes to this policy

If we change this policy, we will post the updated version with a new effective date. If a change meaningfully affects how we handle your data, we will notify you before it takes effect, using the contact details on your account. We will not quietly weaken the commitments in this policy.

Governing law

Questions of governing law, venue, and dispute resolution for this policy are addressed in our Terms of Service. [GOVERNING LAW / VENUE — COUNSEL TO INSERT.] [ARBITRATION DECISION — COUNSEL TO CONFIRM.]

Contact

For any privacy question or request: privacy@bindro.io.

[ENTITY NAME], [STATE OF FORMATION]. Postal address: [COUNSEL TO INSERT].


Version 2026-08-12. Related: Terms of Service · Host Agreement · Acceptable Use Policy · Data retention schedule