Who this policy covers

This policy applies when you visit binddock.com, create a BindDock account, use the dashboard, or connect a supported provider. For privacy questions or requests, email hulktheadventurer@gmail.com.

Information we process

Account and authentication

We process your account email, authentication status, and session information so you can create an account, sign in, and access your protected dashboard. Authentication is provided through Supabase. If you sign in with Google or GitHub, those providers and Supabase also process information needed to authenticate you.

Provider connections

When you choose to connect a provider, we process the authorization response, encrypted access and refresh tokens, token expiry details, and provider account identifiers needed to maintain the connection. For Supabase, BindDock requests read-only access to organization and project information. For Vercel, BindDock stores the encrypted integration access token and configuration identifier and reads the projects permitted by the selected personal account or team. For a GitHub App installation, BindDock reads only metadata for the all or selected repositories granted to that installation, including repository names, owners, visibility, default branches, and update times. GitHub installation tokens are generated when needed and are not stored. For Resend, BindDock stores encrypted access and rotating refresh tokens and reads domain names, identifiers, regions, capabilities, and verification statuses. BindDock does not use the Resend grant to send email or modify domains. This provider information is displayed in your dashboard.

Support

If you contact support, we process your email address, message, and any troubleshooting details you choose to send so we can respond and investigate the issue.

Analytics and performance

We use Vercel Web Analytics and Speed Insights to understand general site usage and performance. These services provide aggregated, anonymous measurements such as routes visited, referrers, broad location and device information, and web performance metrics. They are designed without cookies or cross-site tracking identifiers.

BindDock can also support Google Analytics 4. When a measurement ID is configured, that analytics tag is loaded only after you choose Accept analytics. If you reject analytics, it is not loaded. You can revisit your choice through the site's privacy controls. Advertising and remarketing consent are denied by default.

Why we use the information

  • To provide and secure your account and dashboard.
  • To create and maintain connections you explicitly authorize.
  • To show provider information requested by you.
  • To diagnose errors, prevent abuse, and protect the service.
  • To respond to support requests.
  • To understand and improve site reliability and performance.

Depending on the context and applicable law, these purposes rely on performing our agreement with you, our legitimate interests in operating a secure service, your consent, or compliance with legal obligations.

Sharing and international processing

We use service providers to operate BindDock, including Supabase for authentication and database services and Vercel for hosting, analytics, and performance monitoring. Google is involved only when you choose its sign-in method. GitHub is involved when you choose GitHub sign-in or separately install the BindDock GitHub App. Resend is involved when you connect a Resend workspace. A connected provider processes its own authorization and API requests.

These providers may process information in countries outside your own. Where required, we rely on the safeguards offered by those providers and applicable data-protection mechanisms.

Security and retention

We use access controls, protected sessions, validated authorization state, provider-appropriate OAuth safeguards including PKCE where supported, signed webhook validation, and encrypted storage for persistent provider tokens. Short-lived GitHub installation tokens are not persisted. No internet service can promise absolute security.

We keep personal information only while it is reasonably needed to provide the service, maintain security, resolve disputes, or meet legal obligations. Retention depends on the type of record and why it is held. Disconnecting a provider removes the stored connection and its associated tokens from BindDock. Provider-side records may remain subject to that provider's own policies.

Your choices and rights

Depending on where you live, you may have rights to access, correct, erase, restrict, or receive your personal information, object to certain processing, or withdraw consent. You may also disconnect a provider at any time.

Contact us at hulktheadventurer@gmail.com. We may need to verify your identity before completing a request. If you are in the UK and remain unhappy, you can complain to the Information Commissioner's Office at ico.org.uk.

Changes to this policy

We may update this policy as BindDock changes. The effective date at the top shows the latest published version. Material changes will be presented in a reasonable way before they take effect where required.

For product help rather than a privacy request, visit Support.