Privacy Policy
Last updated 30 September 2026
OÜ Bindito ("Bindito", "we", "us") explains here how we collect, use and protect your personal data when you use the Bindito app and our website, bindito.com. Some features described here may not be available yet. Their sections apply from the day each feature is available.
1. Who we are
OÜ Bindito, an Estonian company (registry code 17362405) based in Tallinn, is the data controller responsible for your personal data. We comply with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws.
2. What data we collect
- Account and profile: email address and account identifier from your sign-in provider (Apple, Google or Facebook), your name if the provider shares it, date of birth, username, country, sport and team preferences, avatar and bio.
- Cards and activity: photos and details of your cards, reps, follows, comments, messages, reports and blocks.
- Marketplace: listings, offers, orders, shipping details, disputes and ratings. For sellers, the identity, bank and tax details needed for verification and tax reporting, mostly collected by our payment provider.
- Technical data: IP address, device and app information, session identifiers and logs.
- Messages to us: anything you send to us by email.
We don't collect your password, contacts or precise location. The app uses your camera and photo library only when you scan or upload a card, and only with your permission.
3. How we use your data
- Performance of a contract: to provide Bindito, including your account, collection, card recognition, feed, social features, messages, notifications and the marketplace.
- Legal obligation: to verify sellers, report to tax authorities under EU rules (DAC7), keep accounting records and respond to lawful requests.
- Legitimate interest: to confirm users are 18 or older, keep Bindito safe from fraud, abuse and spam, handle reports, and run, secure and improve our services, including card recognition.
- Consent: to send news and updates by email. You can withdraw consent at any time.
We don't use your data for advertising, and we don't make decisions about you based solely on automated processing.
4. What other collectors can see
Bindito is a public community. Every card you save is posted to the feed.
- Public: your username, avatar, bio and favourite team, the cards you save, your followers and who you follow, reps, comments, listings and ratings.
- Never shown: your email address, date of birth, country, how you signed in, reports, blocks and payment details.
In an order, the other party sees only what's needed to complete it, such as a shipping address or tracking number. Messages are private to the people in the conversation. Please keep faces, documents and anything personal out of your card photos.
5. Card recognition
We use automated tools, including AI models from third-party providers, to identify cards from your photos. You review the result before saving.
- Providers process photos only on our instructions and don't use them to train their models.
- They keep photos only for a limited period.
- Photos that aren't football or basketball cards can't be saved and are deleted.
Card recognition identifies cards, not people. We may change providers over time as long as they meet these rules.
6. Sharing data with third parties
We don't sell your data or share it with advertisers. We share personal data only when necessary, with providers who act on our instructions under data protection agreements:
- Hosting and infrastructure: servers, databases, storage and network security.
- Card recognition: AI and automated recognition providers.
- Payment processors: payments, payouts and seller verification.
- Logistics: delivery tracking for marketplace orders.
- Communication: email, app stores and push notification services.
- Professional advisers: such as lawyers and accountants.
We also share data with tax and other authorities when the law requires it, with the other collector in an order, to protect people or Bindito from fraud or harm, and with a buyer or investor if Bindito is sold or merges. You can ask us for the current list of providers.
7. Where we store your data
Your data is stored in the European Union where possible. Some providers may process data outside the European Economic Area, including in the United States. We protect these transfers with the European Commission's Standard Contractual Clauses, the EU-US Data Privacy Framework, or another safeguard the GDPR allows.
8. Data retention
We keep personal data:
- Until you delete it or your account. If you have an open order, deletion completes when the order closes.
- As required by law, such as accounting and tax records, currently up to 7 years.
- Only as long as needed for logs, backups, reports and messages to us.
Unfinished sign-ups, sign-ups from anyone under 18, and photos that can't be saved are deleted promptly.
9. Age
Bindito is for people aged 18 and over. We ask your date of birth when you sign up. If you're under 18, your account and its data are deleted straight away. If you think someone under 18 is using Bindito, please tell us.
10. Your rights under GDPR
You have the right to:
- Access your personal data.
- Correct inaccurate or incomplete data. Most of it you can edit in the app.
- Delete your data, subject to legal requirements. You can delete your account in Settings.
- Restrict processing of your data in certain circumstances.
- Object to processing based on our legitimate interests, and to direct marketing.
- Data portability, meaning you can request your data in a structured format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data protection authority. In Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).
We reply to requests within one month.
11. Cookies
Our website uses privacy-friendly analytics that don't set cookies or identify you. We don't use advertising or tracking cookies on the website or in the app. If we ever use cookies that need your consent, we'll ask first.
12. Security
We protect your data with technical and organisational measures, including encrypted connections and access limited to the people who need it. If a breach puts your data at risk, we'll inform you and the authorities as the GDPR requires.
13. Changes to this policy
We'll update this policy when we change how we use your data, and show the new date at the top. For significant changes, we'll let you know in the app first.
14. How to contact us
For questions or requests about your personal data, or anything else, contact us at hello@bindito.com.
