BJB Digital ← Back to site
Legal

Privacy Policy

Last updated 6 August 2026

01Who we are

BJB Digital (“BJB Digital”, “we”, “us”) operates the website at bjb-digital.com and the digital products published under its name. For the purposes of UK data protection law we are the data controller for personal data described in this policy.

BJB Digital Ltd, a private limited company registered in England and Wales, company number 15711877.
Registered office: 119 Edinburgh Road, St Leonards-on-Sea, England, TN38 8DA.
Contact: hello@bjb-digital.com

Where we build and host a platform on behalf of another business, that business is normally the data controller for its own users’ data and we act as a data processor under a separate written agreement. This policy does not govern those arrangements.

02What this policy covers

This policy covers this website and any BJB Digital application that links to it. Individual applications may publish an in-app privacy notice with additional detail specific to that product; where the two differ, the in-app notice applies to that product.

03Information we collect from this website

This website sets no cookies. It carries no advertising cookies, no tracking pixels and no analytics. Because nothing is stored on or read from your device, no cookie consent banner is required.

  • Technical data. Our hosting provider records standard server logs — IP address, browser type, pages requested and timestamps — to deliver the site and protect it from abuse. These are retained for a short period and then deleted.
  • Fonts. Typefaces are served by Google Fonts. Your browser requests them directly from Google, which receives your IP address as part of that request. See Google’s privacy policy.
  • Correspondence. If you email us we hold your message and contact details so we can reply and keep a record of the exchange.

04Information our applications collect

Our applications are built on Supabase, which provides the database, authentication and file storage behind them. The categories below reflect what our current applications collect. Where an individual product collects anything beyond this, it will say so in its own in-app privacy notice.

CategoryExamplesWhy we collect it
Account dataEmail address, display name, and a securely hashed password. We never store passwords in a readable form.To create your account, sign you in and keep it secure
Profile and activityYour settings, in-app selections, progress and history within the productTo provide the core function of the product and keep your progress between sessions
Technical dataDevice type, operating system version, and app version, recorded with requests to our serversTo keep the product working across devices and diagnose faults
Support correspondenceMessages you send us and our repliesTo answer your query and keep a record of it

We do not run third-party analytics or advertising software inside our applications. We do not build advertising profiles, we do not sell personal data, and we do not share it with data brokers.

If you choose to share crash and usage data with developers through your device settings, Apple or Google may pass us aggregated diagnostic reports. These come from the platform, not from code we have added, and we receive them in a form that does not identify you.

Payments and subscriptions

Our applications do not currently offer paid subscriptions or in-app purchases. When a product does, purchases will be handled by the Apple App Store, Google Play or a regulated payment provider. Those providers process your payment details directly — we never see or store card numbers. We would receive only your subscription status and a transaction reference, so we can give you access to what you have paid for. This policy will be updated before any such feature goes live.

05Our lawful bases

Under UK GDPR we rely on the following:

  • Contract — to provide an account, product or subscription you have asked for.
  • Legitimate interests — to keep our services secure, prevent abuse, fix faults and improve what we build, balanced against your rights.
  • Consent — where we ask for it, such as optional notifications or marketing email. You can withdraw consent at any time.
  • Legal obligation — where we must retain records, for example for tax or accounting.

06Who else handles your data

We keep the number of third parties involved deliberately small. Each one processes data only on our instructions, under a written data processing agreement.

  • Supabase — database, authentication and file storage for our applications. Supabase privacy policy.
  • Our website host — serves bjb-digital.com and keeps short-lived server logs for delivery and security.
  • Apple and Google — where you install our applications through their stores, they operate as independent controllers for the data they collect about your download, device and any purchase. Their own privacy policies govern that.

We may also disclose personal data where the law requires it, or to establish, exercise or defend legal claims. We do not otherwise share it with anyone.

07International transfers

Some providers may process data outside the UK. Where they do, we rely on UK adequacy regulations or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) to protect it.

08How long we keep it

Account data is kept while your account is active and for a reasonable period afterwards so you can reactivate. Diagnostic data is kept for a short retention window. Records we must retain for legal or accounting reasons are kept for the required period — normally six years. Everything else is deleted when it is no longer needed.

09Your rights

You have the right to access your data, correct it, ask us to delete it, restrict or object to how we use it, request a portable copy, and withdraw consent. Email hello@bjb-digital.com and we will respond within one month.

If you are not satisfied you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

10Children

Our products are intended for people aged 13 and over. They are not directed at children under 13, we do not knowingly collect their personal data, and we do not market to them. If you believe a child under 13 has given us personal data, email us and we will delete it promptly.

11Security

We use encryption in transit, hashed credentials, access controls and regular updates to protect personal data. No system is completely secure, but we take the protection of your data seriously and will notify you and the ICO of any breach that requires it.

12Changes

We may update this policy as our products change. The date at the top shows the current version, and material changes will be notified in-app or by email where we hold your address.