Privacy Policy
1. Who we are
Binders is operated by ICTOM ("we", "us", "our"), a company incorporated under Moroccan law. Binders provides a social media management platform (Binders SaaS, app.bindmee.com) for creators, brands, and agencies to schedule and publish posts, manage comments and inbox messages, and view analytics across Facebook, Instagram, LinkedIn, YouTube, and TikTok.
ICTOM is the data controller for personal data processed through both services. For all privacy matters, contact us at gdpr@ictom.ma.
2. Data we collect
Account and identity data
- Name, email address, and password (hashed with bcrypt)
- Profile photo (if provided)
- Account type (individual creator, agency, admin)
- Subscription plan and billing status
Social network connection data
When you connect a social account (Instagram, Facebook, LinkedIn, YouTube, TikTok), we store:
- OAuth access tokens and refresh tokens for that platform
- Platform-specific account identifiers (page IDs, channel IDs)
- Display name and profile picture as returned by the platform's API
- Post publications history, comment threads, and engagement metrics retrieved via the platform API
Content data
- Drafts, published posts, captions, hashtags, and media files (images and videos) you create or upload
- Scheduled publication dates and platform targets
- AI-generated suggestions you request (captions, hashtags, translations)
Usage and technical data
- IP address, browser type, and operating system
- Pages visited, features used, timestamps of actions
- Server-side logs and error traces (retained for operational purposes)
Billing data
Subscription payment card details are collected and processed exclusively by Stripe. We never store raw card numbers, CVVs, or full PAN data on our servers. We receive confirmation of payment status and a Stripe payment intent ID.
3. How and why we use your data
| Purpose | Data used |
|---|---|
| Create and maintain your account | Name, email, password |
| Authenticate and secure sessions | Email, JWT tokens, IP address |
| Publish and schedule posts to social networks | OAuth tokens, content data, publication targets |
| Sync and display comments and engagement metrics | OAuth tokens, platform account IDs |
| Provide AI content suggestions | Post drafts (processed by our AI service; not used to train third-party models without consent) |
| Process subscription payments | Email, plan selection (card data handled by Stripe) |
| Send transactional emails | Email address, relevant account details |
| Detect and prevent fraud and abuse | IP address, usage patterns, login history |
| Comply with legal obligations (GDPR, CNDP) | Account data, request records |
| Monitor service health and investigate errors | Technical logs, error traces |
| Improve and develop the service | Aggregated, anonymised usage statistics |
We do not sell your personal data to third parties. We do not use your personal data to build advertising profiles or run behavioural advertising campaigns.
4. Legal bases (GDPR / CNDP)
Where the EU General Data Protection Regulation (GDPR) or Morocco's Law 09-08 (administered by the CNDP) applies, we rely on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Account creation and authentication | Performance of contract (Art. 6(1)(b) GDPR) |
| Publishing and scheduling posts | Performance of contract |
| Syncing social engagement data | Performance of contract |
| Payment processing and subscription management | Performance of contract |
| Sending transactional emails | Performance of contract |
| Fraud detection and abuse prevention | Legitimate interests (Art. 6(1)(f) GDPR) — essential for platform security |
| Service monitoring and error logging | Legitimate interests — necessary to maintain service reliability |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Sending optional product updates or newsletters | Consent (Art. 6(1)(a) GDPR) — you may withdraw at any time |
5. Sharing and disclosure
We share your personal data only with:
| Recipient | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Subscription payment processing | USA (SCCs) |
| Resend, Inc. | Transactional email delivery | USA (SCCs) |
| Google Cloud Platform | Cloud infrastructure, database hosting, media storage (GCS) | USA (us-central1) |
| Meta Platforms | Instagram and Facebook API — posting on your behalf when you authorise the connection | USA |
| LinkedIn Corporation | LinkedIn API — posting on your behalf when you authorise the connection | USA |
| Google LLC (YouTube) | YouTube Data API — publishing and analytics when you authorise the connection | USA |
| TikTok | TikTok API — posting when you authorise the connection (subject to audit approval) | USA / Singapore |
| Legal and regulatory authorities | When required by a court order, regulatory request, or applicable law | Morocco / EU / other |
All third-party service providers are bound by data processing agreements that restrict their use of your data to the purposes listed above.
6. International transfers
Our infrastructure is hosted on Google Cloud Platform in the us-central1 region (Iowa, USA). If you are located in the European Economic Area (EEA) or the United Kingdom, your data is transferred to the United States.
We rely on the following safeguards for these transfers:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with GCP, Stripe, and Resend
- Supplementary technical measures including encryption in transit (TLS 1.2+) and encryption at rest
You may request a copy of the applicable SCCs by emailing gdpr@ictom.ma.
7. Retention periods
| Data category | Retention period | Reason |
|---|---|---|
| Account data (active users) | Duration of account + 30 days after deletion request fulfilled | Contractual obligation |
| Social OAuth tokens | Until you disconnect the account or delete your Binders account | Needed to perform the service |
| Post content and drafts | Duration of account + 30 days | Contractual obligation |
| Billing and invoice records | 7 years | Moroccan accounting law; EU VAT rules |
| GDPR / CNDP request records | 3 years | Demonstrating compliance |
| Server and access logs | 90 days | Security and debugging |
| Anonymised analytics | Indefinitely (no personal data) | Product improvement |
After the applicable retention period, data is securely deleted or irreversibly anonymised.
8. Your rights
Depending on your location, you have the following rights regarding your personal data:
- Right of access — request a copy of all personal data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion of your account and personal data
- Right to restriction — ask us to pause processing while a dispute is resolved
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — for any processing based on consent, withdraw at any time without affecting prior processing
- Right not to be subject to automated decision-making — we do not make solely automated decisions with legal or significant effects on you
To exercise any of these rights, submit a request at bindmee.com/data-deletion or email gdpr@ictom.ma. We will respond within 30 days. We may need to verify your identity before processing the request.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with:
- Morocco: Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) — cndp.ma
- EU/EEA: the supervisory authority in your country of residence
9. Cookies and tracking
The Binders SaaS application (app.bindmee.com) uses the following cookies and storage mechanisms. For full details, including how to manage or withdraw your consent, see our Cookie Policy.
| Cookie / storage | Purpose | Duration |
|---|---|---|
next-auth.session-token | Keeps you signed in (encrypted session JWT) — strictly necessary | 30 days (rolling) |
next-auth.csrf-token | CSRF protection for authentication flows — strictly necessary | Browser session |
cookie_consent | Records your cookie consent choice from the banner — strictly necessary | 1 year |
theme (localStorage) | Remembers light/dark mode preference — functional (requires consent) | Persistent (local) |
rp:open, rp:tab (localStorage) | Remembers side panel state — functional (requires consent) | Persistent (local) |
We do not use third-party advertising cookies, tracking pixels, or cross-site analytics on our platform. The marketing website (bindmee.com) does not use any analytics or tracking scripts.
10. Children
The Binders SaaS platform is intended for users aged 16 or older. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a minor, please contact us at gdpr@ictom.ma and we will delete it promptly.
11. Security
We implement industry-standard security measures including:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest for database storage on Google Cloud Platform
- Password hashing using bcrypt with a high work factor
- OAuth tokens encrypted at rest and never logged in plaintext
- Role-based access controls and least-privilege database accounts per service
- Rate limiting on all public API endpoints
- Regular dependency vulnerability scanning
No method of transmission over the internet or electronic storage is 100% secure. If you discover a security vulnerability, please report it responsibly to gdpr@ictom.ma.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" at the top of this page and, where required by law, notify you by email or in-app notification before the changes take effect. Your continued use of Binders after the effective date constitutes acceptance of the updated policy.
Prior versions of this policy are available upon request by emailing gdpr@ictom.ma.
13. Contact and complaints
Data Controller: ICTOM
Email: gdpr@ictom.ma
Data Requests: bindmee.com/data-deletion
If you have any questions about this Privacy Policy or how we handle your data, please contact us at the address above. We aim to respond to all enquiries within 5 business days.