Skip to main content

Effective · 26 July 2026

Privacy

This page explains how BenNest handles account, listing and conversation data.

What is collected

Student accounts can include a Bennett email, name, phone, course, optional profile photo and profile preferences. Property-owner accounts can include any verified email address, the owner or manager's name and a required phone number.

Listings can include property or room details, private owner contact information and photos. Vehicle review additionally collects registration, chassis and RC evidence.

Enquiries, callback requests, conversations, support requests, wishlist choices and listing activity can be attached to your account.

Where data is kept

Account and business data is stored securely on BenNest's hosted service so it can follow you across devices. The app uses short-lived in-memory copies and does not keep accounts, listings, messages or other business records on your device.

An HttpOnly signed cookie keeps you signed in. Theme changes and dismissed banners live only in memory and reset when the page is reloaded.

What becomes public

Only approved listing fields are returned in public catalogues. A property or vehicle owner's chosen display name can appear publicly; private phone numbers, email addresses, RC/chassis evidence, account identity and exact property coordinates are excluded from public responses.

Moderation reduces obvious risk but is not a guarantee that a listing, person, price or availability is genuine.

Enquiries and callbacks

When a student deliberately sends an enquiry, requests a callback or starts a message, BenNest shares the student's name and account email with the listing owner and the BenNest review team so they can respond and coordinate safely. BenNest staff may use the account phone for follow-up; only a callback request shares a phone number with the listing owner.

The review team can see the request type, its listing, the parties' contact details and follow-up status. Message text and later replies are available only to the student and listing owner, except where access is required to investigate a reported safety, abuse or legal issue.

Opening a listing or adding it to a wishlist does not share the student's identity with a listing owner and is not treated as an enquiry.

Service providers

BenNest may use Supabase to store account information, listings and conversations, Cloudinary or Supabase to store listing media, and Brevo to send one-time codes and activity notifications. Each provider receives only the data needed to provide that feature.

When you type an address into location search, the server forwards that search text to OpenStreetMap's Nominatim service to return matching places. BenNest does not retain that search text on your device.

Retention, access and deletion

Account export and deletion requests are handled through Support while self-service controls are being developed. Some records may be retained when needed for safety, fraud prevention or legal obligations.

Do not upload identity evidence or personal information unless you are comfortable submitting it for manual review.