Privacy Policy

Last updated: 2026-07-25

Who we are

Bineyetna is a building-management app. Building administrators and staff use it to run their building; residents and unit owners use it to see their dues and payments. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the choices and rights you have.

Bineyetna is operated by Mobistack Digital FZ-LLC, based in the United Arab Emirates. For any privacy question, you can contact us at [email protected].

Who uses Bineyetna

  • Administrators and staff sign up with their own email address.
  • Residents are invited by their building's administrator and sign in with a username tied to their building (for example, apt9@yourbuilding). Residents are not required to give a real email inbox, and we do not send them email.

Some information is entered by an administrator about people who don't use the app themselves — for example a unit's owner, or a person who holds building cash. We process it on the building's behalf; see “Data we collect” below.

Data we collect and why

We collect only what the app needs to run your building. By category:

Account and identity
Your name; an email address (a real inbox for administrators, or a building username for residents and staff); an optional phone number; and your preferred language. Your password is stored only as a secure salted hash — we never store or see it in plain text. Used to create and secure your account, show who's who in the building, and (for administrators) send password-reset and account emails.
Sign-in and security data
When you sign in we automatically record your IP address and device/browser type, and keep short-lived counters of sign-in attempts. Used to keep your account secure and to defend against brute-force attempts and abuse.
Building, unit, and role data
Your building's name, address, time zone, and currency; its units and sections; who lives in or is assigned to each unit and their move-in and move-out dates; and staff roles and permissions. An administrator may also record a unit owner's name and phone number as the contact for that unit's dues. Used to run the building — assign dues, show who is responsible, and manage access.
Financial records
Payments (amount, the method you tell us — cash, bank transfer, Whish, OMT, or other — the payer, a note, and the date); charges, bills, and installment plans; expenses and building deliveries (amount, vendor, category, date); building-fund cash movements; and meter readings and consumption. Used to keep the building's books, bill residents fairly, and track the shared building fund.
Photos you attach
Photos an administrator chooses to attach — receipts, meter-reading photos, and delivery slips. They are kept in private storage reachable only through short-lived signed links. On mobile, the app asks for camera and photo-library access so you can capture or attach these photos; you can decline. If you choose to auto-scan a receipt, that image is sent to our AI provider to read the amount, date, and vendor so we can pre-fill the expense form — you always confirm the result.
Push-notification token
If you allow notifications, we store a device token so we can send you app notifications. A billing notification names the charge and the amount added to your bill — nothing else; you can turn notifications off anytime in your device settings.
Diagnostics and crash data
If the app crashes or hits an error, we collect a diagnostic report — error details, device and operating-system type, and app state — to find and fix the problem. Our diagnostics are configured not to attach personal identifiers, and we do not record your screen.
Activity and audit log
For changes to non-financial records, we keep a log of who made the change, what changed, and when. Used for accountability and to resolve disputes within a building.

Important: Bineyetna does not collect your payment-card or bank-account numbers and does not process payments. “Whish” and “OMT” are simply labels for how a payment was made — we record that a resident paid, not the payment itself.

We do not collect special-category data such as date of birth, government-ID or passport numbers, or precise location (GPS).

Cookies

We use only first-party cookies that the app needs to work. We do not use advertising or tracking cookies.

  • Sign-in cookies keep you logged in and secure your session. They are essential — the app can't work without them.
  • A language-preference cookie remembers whether you're viewing the app in Arabic, French, or English. It is set even before you sign in, so the site shows in your language.

Why we're allowed to use your data

Where data-protection law such as the GDPR applies, we rely on these legal bases:

  • To provide the service to you and your building (performance of a contract).
  • For security, abuse prevention, diagnostics, and keeping accurate building books (our legitimate interests).
  • To keep financial records where the law requires it (legal obligation).
  • For device push notifications and camera or photo access, which you can allow or decline (consent).

Who we share data with

We do not sell your personal data. We share it only with the service providers that help us run Bineyetna, with the people in your building who are meant to see it, and where the law requires. Our service providers are:

  • Neon hosts our database, where the app's data is stored (in the European Union — Frankfurt, Germany).
  • Fly.io runs the application servers.
  • Cloudflare R2 stores receipt, meter, and delivery photos privately.
  • Resend sends our account emails (password reset, welcome, and sign-up alerts).
  • Zoho hosts our support email inbox.
  • Expo, Google (Firebase Cloud Messaging), and Apple (Push Notification service) deliver push notifications to your device.
  • Sentry collects crash and error diagnostics (processed in the European Union).
  • Anthropic reads a receipt image when you choose to auto-scan it, and returns the extracted fields.
  • Stripe handles the building's own subscription payment to us, when an administrator subscribes. Stripe collects the card details directly on its own page — we never see or store them. Residents and owners never pay through Stripe; money you pay your building is recorded by your administrator, not collected by us.

Within your building, your data is visible only to the people who should see it. Residents and unit owners see their own unit in full — their charges, payments, and meter readings — plus building-level totals: what the building paid, what it used altogether, summary figures for the shared money, and a dated list of what the building spent. They never see another resident's name, balance, or payments. Staff see only their building, and administrators see only their own organization's buildings. Other buildings and their administrators cannot see your data.

Our own staff may access an account to provide support or maintain the service. Any such access is recorded in an internal log together with the reason for it.

When an administrator records a non-user's contact details (a unit owner, or a person who holds building cash), we process that information on the building's behalf to manage the building's dues and cash.

How long we keep your data

  • Login and profile data: kept while your account is active, and removed when you delete your account — except your name and phone number where they appear on the building's payment records, which are kept (see the financial records below).
  • Sign-in sessions and cookies: deleted when you sign out, or after at most 90 days of inactivity.
  • Push-notification tokens: kept until your device re-registers or your account is deleted.
  • Diagnostic and crash data: kept for our provider's limited retention window, then deleted.
  • Financial records (payments, expenses, deliveries, fund movements, bills, and meter readings) and the audit log are append-only and retained for the integrity of the building's books. They are not edited or deleted — even after you delete your account — and corrections are made by adding new entries. This is required so a building's accounts stay accurate and auditable.

Your rights and choices

Access and correction

You can view and update your profile in the app, or ask your building administrator to correct information held about you.

Deleting your account

You can delete your account by emailing us at [email protected]; building owners and admins can also delete their account from Account settings on the web. Deleting your account removes your login, sign-in sessions, and push tokens, so you can no longer sign in. Your name, phone number, and payment history stay in the building's records, which the building is required to keep for its accounts (see below).

Please note: the payment records and audit log that form your building's permanent books — including your name and phone number as they appear on them — are kept even after you delete your account. We are legally required to retain these accounting records, and a building's accounts must stay accurate and auditable, so these records are not anonymized or removed.

Depending on where you live, you may also have the right to object to or restrict certain processing, to receive a copy of your data, or to complain to your local data-protection authority. Contact us at [email protected] to exercise any of these.

You can turn push notifications, camera access, and photo access on or off at any time in your device settings.

How we protect your data

Passwords are stored only as secure salted hashes. Data is encrypted in transit using HTTPS. Photos are kept in private storage reached only through short-lived signed links. Access to building data is limited by role, and sign-in is rate-limited to defend against brute-force attempts.

Children

Bineyetna is a tool for building administration and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will remove it.

International data transfers

Your data may be processed in countries other than your own by the providers listed above (for example, our database and diagnostics in the European Union, and email, push, and AI providers elsewhere). Where required, we rely on appropriate safeguards for these transfers.

Changes to this policy

We may update this policy from time to time. We will update the “Last updated” date above and, for significant changes, notify you in the app or by email.

Contact us

If you have any question about this policy or your data, contact Mobistack Digital FZ-LLC at [email protected].