HonestyBox.uk is operated by Colletta & Co., a doing-business-as name of One Eye Open LLC ("we", "us", "our"). This page explains what personal data we process and your rights under UK GDPR. The canonical company policy at oneeyeopen.com/privacy.html governs any matter not addressed below.

HonestyBox.scot and HonestyBox.uk are two front doors for the same service. One user record, one dataset, the same team. Write to either inbox — both reach us.

1. What data we collect

Browsing without an account

You can browse the map, view listings, and read comments without giving us anything. Your browser sends standard request metadata (IP, user-agent, referrer) which our hosting provider processes to deliver pages and block abuse.

Your location on the map

If you use "My location" on the map — to sort boxes by distance or to follow your position live as you travel — your device's location is processed in your browser only, to show your position and work out how far each box is. We do not transmit it to our servers, store it, or keep any history of where you've been; it stops the moment you turn it off or leave the map. Your browser asks for permission the first time and shows its own "location in use" indicator while it's on. (The one exception: when you sort by distance, the single coordinate we sort against is sent with that request and not retained.)

Which listings you look up

When you open a box's page we record it: the date and time, which listing, your IP address, your browser's user-agent, the page you came from, and — if you are signed in — your account. When the map or the listings page serves you a batch of locations at once, we record the request and how many locations it served, not which ones.

We do this for one reason, and it follows from what this site is for. Most of these boxes sit at someone's home, and putting them on a map is the service we offer their owners: we help people find a box, and we help owners be found. The same record is what lets us help an owner when something goes wrong. If a box is broken into, emptied or repeatedly interfered with, these details may be used in helping the owner respond to the incident.

We do not record your searches, and we do not record it when the map shows you only the approximate areas boxes are in rather than their locations. It is never used to advertise to you or to profile you, it is not shared with anyone except as described in §4, and it is deleted on the schedule in §5.

Account data

  • Email — for sign-in and transactional emails (verify, reset, welcome).
  • Password — stored as an Argon2id hash. We never see or store the plaintext.
  • Username and display name — shown publicly when you contribute; you pick them.
  • Avatar, bio, social links (all optional) — shown on your public profile if set.
  • Sign-up and sign-in records — the date and time, your IP address, your browser's user-agent and how you signed in. We record sign-ups, successful and failed sign-in attempts, sign-outs, email verifications, password-reset requests, and any occasion when an account reaches our usage limits or is suspended. Kept to investigate abuse and to spot accounts created in bulk to harvest listing locations.

Contributions

  • Listings, photos, comments, edits — public, attributed to your username unless your profile is private. Photos are re-encoded server-side to strip EXIF metadata (including any GPS tagged by your camera) before storage.
  • Ownership claims — including any proof and optional contact phone.
  • Reports — including the reason; visible only to admins.
  • Saved listings (stars) — visible only to you.
  • Visit confirmations ("I saw it today") — recorded against the listing for freshness.

Cookies

We set three first-party cookies, all strictly necessary or functional:

  • hb_access — short-lived signed-in session token.
  • hb_refresh — long-lived rotating refresh token, scoped to the refresh endpoint, used to re-issue hb_access.
  • hb_map_rail — remembers whether you collapsed the map controls panel. UI preference only.

None are used for cross-site tracking, advertising, or third-party analytics. Under PECR they fall in the strictly-necessary or functional categories that are exempt from consent. We do not show a cookie banner.

2. Why we process it

For each category we rely on the most appropriate UK GDPR Article 6 lawful basis:

  • Account creation, authentication, transactional emails — contract (Art. 6(1)(b)).
  • Public contributions — consent when you choose to publish, plus our legitimate interests in operating an accurate directory.
  • Reports, anti-abuse blocks, rate-limiting, server logs — legitimate interests in keeping the service accurate, available, and secure.
  • Records of which listings you look up, and sign-up / sign-in records — legitimate interests (Art. 6(1)(f)) in protecting the people whose homes these boxes sit at, enforcing these terms, and being able to help when a theft is reported to us or to the police. We have carried out and documented the balancing test behind that decision, and will explain it to you in plain English on request — write to the address at the foot of this page.
  • Aggregate traffic analytics — legitimate interests. We use Cloudflare Web Analytics (cookieless, fingerprinting-free) and self-hosted Umami pageview analytics on our own infrastructure. Both are cookieless, set no device storage, and identify no individual user — which is why they're ungated.

3. How we use it

Account data is used to authenticate you and contact you about your account. Public contributions are shown publicly and attributed to your username unless you set your profile to private. Private signals (reports, claims, stars, sign-in records, and the records of which listings you look up) are visible only to you and to admins where moderation or an investigation requires it. We do not sell your data, share it with advertisers, profile you, or use it to target ads.

4. Who we share data with

We use the following processors. Each is bound by their own privacy policy and, where required, a Data Processing Agreement.

  • IONOS — hosts our server in Germany (EU/EEA), running the application, database, cache, and object store. Policy.
  • Resend — outbound SMTP for transactional emails. Your email address and rendered email body are sent for delivery. Policy.
  • Cloudflare — DNS, edge proxy, Cloudflare Web Analytics, and Cloudflare Turnstile bot protection. Turnstile runs on every page (invisible challenge to filter scraper / bot traffic) and on sign-in / sign-up / password reset forms (visible challenge). Browser metadata (User-Agent, IP, fingerprinting signals) is sent to Cloudflare for the challenge. Cloudflare Privacy Policy · Turnstile Privacy Addendum.
  • GitHub Container Registry — distributes our application container images. No visitor personal data. Policy.
  • OpenStreetMap Foundation — your browser loads map tiles directly from OSM. Your IP is sent to OSM. Policy.
  • postcodes.io — when you search a postcode, town, or place on the map, that query and your IP are sent for lookup. We do not store the search. About.
  • what3words — if you use a what3words address while adding or editing a listing, the three-word string is converted via their API. Policy.

We self-host all our fonts and icons, so no font provider (Google Fonts or otherwise) receives your IP.

Police and other lawful requests. We disclose these records only to the police or another authority with a legal power to obtain them, and only in response to a formal request that identifies the investigation or legal process it relates to. We do not act on informal approaches. That includes box owners: if an owner reports a theft we will help them take it to the police, but the records go to the police, not to the owner. We never volunteer records, we never give bulk or standing access to anyone, and we release only the specific records a request covers — not everything we hold. Where we are permitted to tell the person concerned, we will.

5. How long we keep it

  • Account data — until you delete your account or ask us to delete it. Deletion is immediate; we do not maintain a recovery window.
  • Abuse-prevention record after deletion — for 2 years after you delete your account we keep a minimal record to help us recognise a returning account associated with past abuse and manage abuse: your username, a one-way hash of your email address (so we can match a future sign-up without storing your readable email), and your account's create and delete dates. We do not keep your readable email, password, avatar, or any link back to your past contributions. After 2 years this record is purged.
  • Data export log — when you download your data we record the fact (date, size, which of our sites, and IP) for 2 years for security and accountability. If you later delete your account, this log is pseudonymised — both the link to you and the IP are removed.
  • Server access logs — 90 days, for debugging and investigating abuse.
  • Records of which listings you look up — 90 days, whether or not you have an account. Deleted automatically every night.
  • Sign-up and sign-in records — 90 days, deleted on the same nightly schedule.
  • Investigation holds — when a box owner reports a theft, we freeze the records relevant to that report for 180 days, so they are not deleted before it can be looked into. A hold is written down with a reason, covers only what the report is about, and expires on its own. It is the only thing that extends any of the periods above.
  • Account IP addresses — the IP you signed up from and the IP of your most recent login are stored against your account for security and abuse prevention. The login IP is overwritten each time you sign in; both are deleted when you delete your account.
  • Refresh tokens — revoked on logout, password change, or account deletion; otherwise rotated automatically.
  • Public contributions after account deletion — kept on the directory but reattributed to the Community persona (see §6). Private signals are deleted permanently.

6. Account deletion and the Community persona

When you delete your account from /account (or by emailing us), we hard-delete your user record, password hash, email, and avatar. We keep only a minimal, pseudonymised abuse-prevention record — your username, a one-way hash of your email, and your account's create/delete dates — for 2 years (see §5). Your contributions split two ways:

  • Public contributions — listings, photos, comments, edits, revision history — stay on the directory but are reattributed to a singleton system account, The HonestyBox Community. The content stays useful; your identifier comes off it. Admins can prune individual entries if they no longer reflect a real box.
  • Private signals — reports, claims, stars, authentication tokens — are permanently deleted. Any listing you owned through an approved claim reverts to "unclaimed".

This honours the Article 17 right to erasure while preserving the public dataset the directory exists to provide. If you want your public contributions removed too, email [email protected] with the subject Full erasure request and we will manually purge them in addition to the standard deletion.

7. Your rights under UK GDPR

  • Access — the /account page has a one-click "Download my data" button returning a JSON export.
  • Erasure — same page, "Delete my account" button. Confirms with your password; deletion is immediate.
  • Rectification — correct anything on the /account page, or edit the listings / comments you've created.
  • Portability — the "Download my data" export is machine-readable JSON.
  • Restriction, Object, Withdraw consent — at any time, without affecting prior lawful processing.

For anything the /account page can't do, email [email protected] with the subject Data rights request. We respond within one calendar month.

8. Complaints

You can complain to the UK Information Commissioner's Office: ico.org.uk · 0303 123 1113. We'd prefer the chance to address your concern first — email [email protected] before raising it with the ICO.

9. International transfers

Most personal data is stored on servers in the EU/EEA (IONOS, Germany). Some processors operate from the United States (Cloudflare, GitHub) under standard contractual clauses or the UK Extension to the EU-US Data Privacy Framework as appropriate.

10. Children

HonestyBox.uk is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

11. Changes to this policy

If we make changes, we will update the "Last updated" date above. For material changes, we will email account holders.