Chowkidar is free. We will never ask you for money.Help me recover my funds

Privacy Policy

Effective 26 June 2026.

This policy explains what personal data Binari Chowkidar (“we”) processes, why, the lawful basis for it, how long we keep it, and the rights you have — including erasure. We aim to collect as little personal data as possible: looking up an identifier requires no account, and our report model is deliberately low-PII.

1. Who is responsible

Binari Chowkidar is operated by Binari as the data controller for the processing described here. Data-protection requests can be made via the contact channel on the About page.

2. What data we collect

  • Look-up visitors: standard server logs (IP address, user agent, timestamp, and requested URL) generated automatically when you load a page. No account or cookie-based tracking is required to search.
  • Registered reporters: your account identifier, email address, and display name from our identity provider (Keycloak) when you sign in.
  • Submission metadata (server-side only): when you submit, edit, or dispute a report we record the submission timestamp, IP address, user agent, a coarse country hint, theAccept-Language header, and the version of the Terms/Privacy you consented to. This metadata is never published.
  • Report content: the category, description, amounts, country, and identifiers you enter. You are asked not to include personal data about yourself or third parties; free text is stripped and reviewed to reduce the risk of exposing personal data.

3. What we do not collect

We do not ask for or store victim dossiers (such as victim home addresses or job titles), and we do not store personally identifying information in your browser’s local storage. Unsubmitted report drafts are kept only in your session storage and exclude the identifier values you type; they are cleared on submit, navigation, or closing the tab.

4. How and why we use data, and our lawful basis

  • Operating the registry (publishing the PII-stripped projection of reports) — lawful basis: legitimate interests in maintaining a public-interest anti-fraud resource.
  • Account management (letting you sign in and manage your reports) — lawful basis: performance of a contract (these Terms).
  • Abuse prevention and security (rate limiting, captcha, retaining submission metadata) — lawful basis: legitimate interests in protecting the Service from fraud and abuse.
  • Consent — where you explicitly accept a specific Terms/Privacy version at submission, we rely on that record of consent.

5. Sharing

The public projection of reports (with personal data removed) is visible to anyone. We may share data with law-enforcement or regulators where legally required. We use our identity provider and infrastructure providers as processors under appropriate agreements. We do not sell personal data.

6. Retention

  • Published reports are retained while they remain in the public interest, or until you delete them or successfully dispute them.
  • Submission metadata is retained for up to 24 months for abuse prevention, then deleted or anonymised.
  • Server access logs are retained for up to 90 days.
  • Account data is retained until you request account deletion.

7. Your rights

Subject to applicable law (including the UK GDPR / EU GDPR), you have the right to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability.

  • Erasure / deletion: signed-in users can delete individual reports from the account panel, or request full account deletion, which removes your reports and erases the submission metadata associated with your account (subject to legal retention obligations).
  • Disputing a listing about you: if a report unfairly targets you or your business, use the dispute button on the relevant entity page. Disputed reports are flagged while reviewed; allowlisted custodial services are handled separately to prevent mislabelling.
  • Other requests and complaints: contact us via the About page. You also have the right to lodge a complaint with your local data-protection authority.

8. Privacy by design for sensitive identifiers

Email and phone entity pages are never indexed by search engines, and email identifiers are hashed in public URLs, to reduce de-anonymisation and victim-privacy risk.

9. Analytics & cookies

Looking up an identifier needs no analytics cookies. We set one necessary cookie (ck_consent) to remember your choice, and we load Google Analytics 4 plus a first-party pageview beacon only after you accept analytics cookies — declining keeps necessary cookies only. With consent we set an anonymous first-party visitor id (ck_vid) and collect coarse usage signals (page path, referrer, device viewport and screen size, pixel ratio, timezone, and browser language). Separately, for abuse prevention, our server records your IP address, an IP-derived country, and network/ASN with best-effort VPN detection; we never request precise geolocation and never store personal data in your browser. Manage or withdraw consent at any time from our Cookie Policy.

10. Changes

We may update this policy; material changes are reflected by a new effective date. See our Terms of Service for the rules governing use of the Service.

Privacy Policy · Binari Chowkidar