Privacy Policy
Last updated: 2026-07-25
Who we are
Bineyetna is a building-management app. Building administrators and staff use it to run their building; residents and apartment owners use it to see their dues and payments. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the choices and rights you have.
Bineyetna is operated by Mobistack Digital FZ-LLC, based in the United Arab Emirates. For any privacy question, you can contact us at [email protected].
Who uses Bineyetna
- Administrators and staff sign up with their own email address.
- Residents are invited by their building's administrator and sign in with a username tied to their building (for example, sami@yourbuilding). Residents are not required to give a real email inbox, and we do not send them email.
Some information is entered by an administrator about people who don't use the app themselves, for example an apartment's owner, or a person who holds building cash. We process it on the building's behalf; see “Data we collect” below.
Data we collect and why
We collect only what the app needs to run your building. By category:
- Account and identity
- Your name; an email address (a real inbox for administrators, or a building username for residents and staff); an optional phone number; and your preferred language. Your password is stored only as a secure salted hash. We never store or see it in plain text. Used to create and secure your account, show who's who in the building, and (for administrators) send password-reset and account emails.
- Sign-in and security data
- When you sign in, and while you use Bineyetna, we automatically record your IP address, device/browser type, which app you used (web or mobile) and when you were last active, and keep short-lived counters of sign-in attempts. Used to keep your account secure, to see that the service is being used, and to defend against brute-force attempts and abuse.
- Building, apartment, and role data
- Your building's name, address, time zone, and currency; its apartments and sections; who lives in or is assigned to each apartment and their move-in and move-out dates; and staff roles and permissions. An administrator may also record an apartment owner's name and phone number as the contact for that apartment's dues. Used to run the building by assigning dues, showing who is responsible, and managing access.
- Financial records
- Payments (amount; the method you tell us, such as cash, bank transfer, Whish, OMT, or other; the payer; a note; and the date); charges, bills, and payment plans; expenses and building deliveries (amount, category, date); building-fund cash movements; and meter readings and consumption. Used to keep the building's books, bill residents fairly, and track the shared building fund.
- Photos you attach
- Photos an administrator chooses to attach, such as receipts, meter-reading photos, and delivery slips. They are kept in private storage reachable only through short-lived signed links. On mobile, the app asks for camera and photo-library access so you can capture or attach these photos; you can decline. If you choose to auto-scan a receipt, that image is sent to our AI provider to read the amount and date so we can pre-fill the expense form. You always confirm the result.
- Push-notification token
- If you allow notifications, we store a device token so we can send you app notifications. A billing notification names the charge and the amount added to your bill, and nothing else. You can turn notifications off anytime in your device settings.
- Diagnostics and crash data
- If the app crashes or hits an error, we collect a diagnostic report to find and fix the problem. That report contains error details, device and operating-system type, and app state. Our diagnostics are configured not to attach personal identifiers, and we do not record your screen.
- Activity and audit log
- For changes to non-financial records, we keep a log of who made the change, what changed, and when. Used for accountability and to resolve disputes within a building.
Important: Bineyetna does not collect your payment-card or bank-account numbers and does not process payments. “Whish” and “OMT” are simply labels for how a payment was made. We record that a resident paid, not the payment itself.
We do not collect special-category data such as date of birth, government-ID or passport numbers, or precise location (GPS).
Why we're allowed to use your data
Where data-protection law such as the GDPR applies, we rely on these legal bases:
- To provide the service to you and your building (performance of a contract).
- For security, abuse prevention, diagnostics, and keeping accurate building books (our legitimate interests).
- To keep financial records where the law requires it (legal obligation).
- For device push notifications and camera or photo access, which you can allow or decline (consent).
How long we keep your data
- Login and profile data: kept while your account is active, and removed when you delete your account. Your name and phone number are the exception where they appear on the building's payment records, which are kept (see the financial records below).
- Sign-in sessions and cookies: deleted when you sign out, or after at most 90 days of inactivity.
- Activity times (which app you used and when): 90 days, then deleted.
- Push-notification tokens: kept until your device re-registers or your account is deleted.
- Diagnostic and crash data: kept for our provider's limited retention window, then deleted.
- Financial records (payments, expenses, deliveries, fund movements, bills, and meter readings) and the audit log are append-only and retained for the integrity of the building's books. They are not edited or deleted, and corrections are made by adding new entries. This holds even after you delete your account. This is required so a building's accounts stay accurate and auditable.
Your rights and choices
Access and correction
You can view and update your profile in the app, or ask your building administrator to correct information held about you.
Deleting your account
You can delete your account by emailing us at [email protected]; building owners and admins can also delete their account from Account settings on the web. Deleting your account removes your login, sign-in sessions, and push tokens, so you can no longer sign in. Your name, phone number, and payment history stay in the building's records, which the building is required to keep for its accounts (see below).
Please note: the payment records and audit log that form your building's permanent books are kept even after you delete your account, including your name and phone number as they appear on them. We are legally required to retain these accounting records, and a building's accounts must stay accurate and auditable, so these records are not anonymized or removed.
Depending on where you live, you may also have the right to object to or restrict certain processing, to receive a copy of your data, or to complain to your local data-protection authority. Contact us at [email protected] to exercise any of these.
You can turn push notifications, camera access, and photo access on or off at any time in your device settings.
How we protect your data
Passwords are stored only as secure salted hashes. Data is encrypted in transit using HTTPS. Photos are kept in private storage reached only through short-lived signed links. Access to building data is limited by role, and sign-in is rate-limited to defend against brute-force attempts.
Children
Bineyetna is a tool for building administration and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will remove it.
International data transfers
Your data may be processed in countries other than your own by the providers listed above (for example, our database and diagnostics in the European Union, and email, push, and AI providers elsewhere). Where required, we rely on appropriate safeguards for these transfers.
Changes to this policy
We may update this policy from time to time. We will update the “Last updated” date above and, for significant changes, notify you in the app or by email.
Contact us
If you have any question about this policy or your data, contact Mobistack Digital FZ-LLC at [email protected].