📄 Privacy policy

Privacy policy

This policy explains what personal data SupaWaste collects, how we use it, and your rights under UK GDPR. We've written it to be read — not just to exist.

Last updated: March 2025  ·  Applies to supawaste.com and all SupaWaste products

Who we are

Who we are

SupaWaste is a waste collection management platform for UK local authorities. We operate the SupaWaste Authority Portal, the My Bin Day resident lookup tool, and the embeddable bin day widget used on authority websites.

For the purposes of UK GDPR, SupaWaste is the data controller for personal data collected through this website and the resident-facing tools. For data processed on behalf of local authorities through the portal, SupaWaste acts as a data processor, with the relevant authority as the data controller.

To contact us about privacy matters: privacy@supawaste.com


What we collect

What personal data we collect

Website visitors (supawaste.com)

We do not use tracking cookies or analytics scripts that collect personal data. We collect only what you choose to submit:

  • Name and work email address — if you complete the demo request or enquiry form
  • Job title and organisation — if you complete the demo request form
  • Message content — if you submit a general enquiry

Residents using the bin day widget or My Bin Day

We collect only the postcode entered to perform the lookup. This is used solely to return the correct collection schedule. It is not stored, not linked to any individual, and not used for any other purpose.

Authority portal users (staff accounts)

  • Full name and work email address — for account creation and login
  • Role and permissions — to determine access level
  • Audit log entries — a record of actions taken within the portal, linked to your account

How we use it

How we use personal data

DataPurpose
Demo / enquiry form submissionsTo respond to your request and, where relevant, follow up about SupaWaste products. We will not add you to a marketing list without your consent.
Portal staff accountsTo provide access to the Authority Portal, authenticate users, and maintain the audit trail required for GDPR compliance.
Resident postcodesTo return the correct bin collection schedule for that postcode. Not stored or used for any other purpose.
Audit log dataTo maintain a record of changes made within the portal for compliance, accountability, and GDPR subject access request purposes.

Lawful basis

Our lawful basis for processing

Processing activityLawful basis
Responding to demo and enquiry form submissionsLegitimate interests — responding to a direct request from you
Portal staff account managementContract — necessary to provide the contracted service to your authority
Audit trail maintenanceLegal obligation — required for GDPR compliance and accountability
Resident postcode lookupsNo personal data is processed — postcodes alone are not personal data under UK GDPR

Sharing data

Who we share data with

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We share data only with sub-processors necessary to deliver the service:

Sub-processorPurposeLocation
SupabaseDatabase hosting and authenticationEU / UK
VercelApplication hosting and deliveryEU / UK
ResendTransactional email deliveryEU
TwilioSMS reminder delivery (where enabled)EU

No personal data is transferred outside the UK or EEA. A full sub-processor list is available on request.


Retention

How long we keep data

DataRetention period
Demo / enquiry form submissionsUp to 12 months, or until the enquiry is resolved
Portal staff accountsFor the duration of the contract, plus 30 days following termination
Audit log entries7 years — required for compliance purposes
Resident postcodesNot retained — used only to serve the lookup response

Your rights

Your rights under UK GDPR

You have the following rights in relation to personal data we hold about you:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate or incomplete data
  • Right to erasure — ask us to delete your personal data, where no legal obligation requires us to retain it
  • Right to restrict processing — ask us to limit how we use your data in certain circumstances
  • Right to data portability — receive your personal data in a structured, machine-readable format
  • Right to object — object to processing carried out on the basis of legitimate interests

To exercise any of these rights, contact us at privacy@supawaste.com. We will respond within one calendar month.

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).


Cookies

Cookies

This website does not use advertising cookies, tracking cookies, or third-party analytics. We use only the cookies strictly necessary to operate the service:

  • Authentication cookies — used in the Authority Portal to maintain your login session. Not set for residents using the bin day widget.
  • No analytics cookies — we do not use Google Analytics, Meta Pixel, or any equivalent tracking tool on this website.

Residents using the bin day widget: No cookies are set when a resident uses the embedded widget on a council website or on my-bin-day.co.uk. No tracking, no session storage, no persistent data of any kind.

Privacy questions?

If you have a question about this policy, want to exercise your data rights, or need a copy of our Data Processing Agreement, get in touch.