Privacy Policy
Effective date: 1 September 2026
1. Introduction
BIN Optimizer (“we”, “our”, or “us”) is committed to protecting the privacy of individuals who interact with our platform. This Privacy Policy explains what data we collect, how we use it, how long we keep it, and your rights under applicable data protection law, including the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR).
By accessing or using BIN Optimizer, you agree to the collection and use of your information as described in this policy.
2. What data we collect
BIN numbers
When you use the BIN analysis feature, we process Bank Identification Numbers (BINs) — the first six to eight digits of a payment card number. BINs are not cardholder data under PCI DSS v4.0 and do not identify any individual. We use them solely to resolve card attributes and return cost analysis results.
Email addresses
If you submit your email address via our “Request the report” form, we collect and store that address to send you the requested BIN variance report and, with your consent, product updates. We do not share your email address with third parties for marketing purposes.
Account data
Platform users (acquirers and processors with an account) provide a name, email address, and password. Passwords are stored as bcrypt hashes and never in plaintext.
API usage data
We log API requests for security monitoring, rate limiting, and service improvement. Log records include timestamps, request paths, HTTP status codes, and request identifiers (UUIDs). We do not log full card numbers, BINs beyond eight digits, or any sensitive cardholder data.
Technical data
We collect standard web server logs including IP addresses, browser user agent strings, and referring URLs when you visit the marketing site. This data is used to diagnose technical problems and understand aggregate usage patterns.
3. How we use your data
- Service delivery — to process BIN lookup and analysis requests, return cost results, and maintain your account.
- Communications — to send you the reports you request and, where you have opted in, to keep you informed about platform updates.
- Security and fraud prevention — to detect and prevent unauthorized access, monitor for abuse, and enforce our Terms of Service.
- Product improvement — to analyse aggregate usage patterns and improve the accuracy of our routing models. This analysis uses anonymized or aggregated data only.
- Legal compliance — to meet our obligations under applicable law, including responding to lawful requests from regulators.
Our legal basis for processing is: (a) contract performance — where processing is necessary to deliver the service you have requested; (b) legitimate interests — for security monitoring and product improvement; and (c) consent — for marketing communications, which you may withdraw at any time.
4. Data retention
- BIN lookup results — cached for 24 hours to improve response times, then automatically purged from our Redis cache. BIN records in our database are retained for up to 90 days before re-ingestion from scheme sources.
- Email addresses — retained until you unsubscribe or request deletion. Unsubscribe links are included in every email we send.
- Account data — retained for the duration of your account and for up to 90 days after account closure, unless a longer period is required by law.
- API request logs — retained for 90 days for security and audit purposes, then deleted.
- Web server logs — retained for 30 days, then deleted.
5. Third parties
We share data with the following categories of third parties:
- Mastercard BIN API — we query Mastercard’s BIN lookup API to resolve card attributes for Mastercard-issued cards. Queries contain only the BIN digits and do not include any personal data.
- Infrastructure providers — we use Amazon Web Services (AWS) to host the platform. Data is processed within the EU West 1 (Ireland) region. AWS is an approved processor under our data processing agreement with them.
- Analytics — we do not use third-party analytics or advertising trackers on this site.
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.
6. Cookies and tracking
The marketing site uses only a session cookie for functional purposes (maintaining your login state). We do not use advertising or tracking cookies. You can configure your browser to refuse cookies; the site will continue to function.
7. Your rights
Under UK GDPR and EU GDPR you have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate data.
- Right to erasure — you may ask us to delete your personal data where we no longer have a legal basis to hold it.
- Right to portability — you may request your data in a machine-readable format.
- Right to object — you may object to processing based on our legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@binoptimizer.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) in the UK, or with your national supervisory authority in the EU.
8. International transfers
Data processed by AWS is stored in the EU West 1 region. Any transfers outside the UK / EEA are governed by approved transfer mechanisms, including Standard Contractual Clauses where applicable.
9. Changes to this policy
We may update this policy from time to time. We will notify registered users by email before any material change takes effect. The “Effective date” at the top of this page indicates when the policy was last revised.
10. Contact
For privacy-related enquiries, contact our Data Protection contact at privacy@binoptimizer.com.