Binders

Privacy Policy

Effective date: 1 July 2026  ·  Operated by ICTOM

1. Who we are

Binders is operated by ICTOM ("we", "us", "our"), a company incorporated under Moroccan law. Binders provides a social media management platform (Binders SaaS, app.bindmee.com) for creators, brands, and agencies to schedule and publish posts, manage comments and inbox messages, and view analytics across Facebook, Instagram, LinkedIn, YouTube, and TikTok.

ICTOM is the data controller for personal data processed through both services. For all privacy matters, contact us at gdpr@ictom.ma.

2. Data we collect

Account and identity data

  • Name, email address, and password (hashed with bcrypt)
  • Profile photo (if provided)
  • Account type (individual creator, agency, admin)
  • Subscription plan and billing status

Social network connection data

When you connect a social account (Instagram, Facebook, LinkedIn, YouTube, TikTok), we store:

  • OAuth access tokens and refresh tokens for that platform
  • Platform-specific account identifiers (page IDs, channel IDs)
  • Display name and profile picture as returned by the platform's API
  • Post publications history, comment threads, and engagement metrics retrieved via the platform API

Content data

  • Drafts, published posts, captions, hashtags, and media files (images and videos) you create or upload
  • Scheduled publication dates and platform targets
  • AI-generated suggestions you request (captions, hashtags, translations)

Usage and technical data

  • IP address, browser type, and operating system
  • Pages visited, features used, timestamps of actions
  • Server-side logs and error traces (retained for operational purposes)

Billing data

Subscription payment card details are collected and processed exclusively by Stripe. We never store raw card numbers, CVVs, or full PAN data on our servers. We receive confirmation of payment status and a Stripe payment intent ID.

3. How and why we use your data

PurposeData used
Create and maintain your accountName, email, password
Authenticate and secure sessionsEmail, JWT tokens, IP address
Publish and schedule posts to social networksOAuth tokens, content data, publication targets
Sync and display comments and engagement metricsOAuth tokens, platform account IDs
Provide AI content suggestionsPost drafts (processed by our AI service; not used to train third-party models without consent)
Process subscription paymentsEmail, plan selection (card data handled by Stripe)
Send transactional emailsEmail address, relevant account details
Detect and prevent fraud and abuseIP address, usage patterns, login history
Comply with legal obligations (GDPR, CNDP)Account data, request records
Monitor service health and investigate errorsTechnical logs, error traces
Improve and develop the serviceAggregated, anonymised usage statistics

We do not sell your personal data to third parties. We do not use your personal data to build advertising profiles or run behavioural advertising campaigns.

4. Legal bases (GDPR / CNDP)

Where the EU General Data Protection Regulation (GDPR) or Morocco's Law 09-08 (administered by the CNDP) applies, we rely on the following legal bases:

Processing activityLegal basis
Account creation and authenticationPerformance of contract (Art. 6(1)(b) GDPR)
Publishing and scheduling postsPerformance of contract
Syncing social engagement dataPerformance of contract
Payment processing and subscription managementPerformance of contract
Sending transactional emailsPerformance of contract
Fraud detection and abuse preventionLegitimate interests (Art. 6(1)(f) GDPR) — essential for platform security
Service monitoring and error loggingLegitimate interests — necessary to maintain service reliability
Compliance with legal obligationsLegal obligation (Art. 6(1)(c) GDPR)
Sending optional product updates or newslettersConsent (Art. 6(1)(a) GDPR) — you may withdraw at any time

5. Sharing and disclosure

We share your personal data only with:

RecipientPurposeLocation
Stripe, Inc.Subscription payment processingUSA (SCCs)
Resend, Inc.Transactional email deliveryUSA (SCCs)
Google Cloud PlatformCloud infrastructure, database hosting, media storage (GCS)USA (us-central1)
Meta PlatformsInstagram and Facebook API — posting on your behalf when you authorise the connectionUSA
LinkedIn CorporationLinkedIn API — posting on your behalf when you authorise the connectionUSA
Google LLC (YouTube)YouTube Data API — publishing and analytics when you authorise the connectionUSA
TikTokTikTok API — posting when you authorise the connection (subject to audit approval)USA / Singapore
Legal and regulatory authoritiesWhen required by a court order, regulatory request, or applicable lawMorocco / EU / other

All third-party service providers are bound by data processing agreements that restrict their use of your data to the purposes listed above.

Social platform tokens: OAuth access tokens used to post on your behalf are encrypted at rest in our database and are transmitted only to the corresponding social platform API. We do not share tokens with any other third party.

6. International transfers

Our infrastructure is hosted on Google Cloud Platform in the us-central1 region (Iowa, USA). If you are located in the European Economic Area (EEA) or the United Kingdom, your data is transferred to the United States.

We rely on the following safeguards for these transfers:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with GCP, Stripe, and Resend
  • Supplementary technical measures including encryption in transit (TLS 1.2+) and encryption at rest

You may request a copy of the applicable SCCs by emailing gdpr@ictom.ma.

7. Retention periods

Data categoryRetention periodReason
Account data (active users)Duration of account + 30 days after deletion request fulfilledContractual obligation
Social OAuth tokensUntil you disconnect the account or delete your Binders accountNeeded to perform the service
Post content and draftsDuration of account + 30 daysContractual obligation
Billing and invoice records7 yearsMoroccan accounting law; EU VAT rules
GDPR / CNDP request records3 yearsDemonstrating compliance
Server and access logs90 daysSecurity and debugging
Anonymised analyticsIndefinitely (no personal data)Product improvement

After the applicable retention period, data is securely deleted or irreversibly anonymised.

8. Your rights

Depending on your location, you have the following rights regarding your personal data:

  • Right of access — request a copy of all personal data we hold about you
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request deletion of your account and personal data
  • Right to restriction — ask us to pause processing while a dispute is resolved
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — for any processing based on consent, withdraw at any time without affecting prior processing
  • Right not to be subject to automated decision-making — we do not make solely automated decisions with legal or significant effects on you

To exercise any of these rights, submit a request at bindmee.com/data-deletion or email gdpr@ictom.ma. We will respond within 30 days. We may need to verify your identity before processing the request.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with:

  • Morocco: Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP)cndp.ma
  • EU/EEA: the supervisory authority in your country of residence

9. Cookies and tracking

The Binders SaaS application (app.bindmee.com) uses the following cookies and storage mechanisms. For full details, including how to manage or withdraw your consent, see our Cookie Policy.

Cookie / storagePurposeDuration
next-auth.session-tokenKeeps you signed in (encrypted session JWT) — strictly necessary30 days (rolling)
next-auth.csrf-tokenCSRF protection for authentication flows — strictly necessaryBrowser session
cookie_consentRecords your cookie consent choice from the banner — strictly necessary1 year
theme (localStorage)Remembers light/dark mode preference — functional (requires consent)Persistent (local)
rp:open, rp:tab (localStorage)Remembers side panel state — functional (requires consent)Persistent (local)

We do not use third-party advertising cookies, tracking pixels, or cross-site analytics on our platform. The marketing website (bindmee.com) does not use any analytics or tracking scripts.

10. Children

The Binders SaaS platform is intended for users aged 16 or older. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a minor, please contact us at gdpr@ictom.ma and we will delete it promptly.

11. Security

We implement industry-standard security measures including:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for database storage on Google Cloud Platform
  • Password hashing using bcrypt with a high work factor
  • OAuth tokens encrypted at rest and never logged in plaintext
  • Role-based access controls and least-privilege database accounts per service
  • Rate limiting on all public API endpoints
  • Regular dependency vulnerability scanning

No method of transmission over the internet or electronic storage is 100% secure. If you discover a security vulnerability, please report it responsibly to gdpr@ictom.ma.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" at the top of this page and, where required by law, notify you by email or in-app notification before the changes take effect. Your continued use of Binders after the effective date constitutes acceptance of the updated policy.

Prior versions of this policy are available upon request by emailing gdpr@ictom.ma.

13. Contact and complaints

Data Controller: ICTOM
Email: gdpr@ictom.ma
Data Requests: bindmee.com/data-deletion

If you have any questions about this Privacy Policy or how we handle your data, please contact us at the address above. We aim to respond to all enquiries within 5 business days.