♻️ Sustainable Move
Back to App

Privacy Policy

Effective Date: August 18, 2026

Updated September 3, 2026 to identify MaybeItsSoftware Ltd as the data controller. Updated August 22, 2026 to describe the optional location attached to a waste-compliance report. Updated August 18, 2026 to describe the optional AI valuation feature, which sends a photo you choose to analyse to a third-party AI provider. See sections 1.C, 2, 3 and 5.

The Sustainable Move Initiative ("we," "us," or "our") operates the Sustainable Move mobile application (the "App") and associated services. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App.

The App is published by MaybeItsSoftware Ltd, a company registered in the United Kingdom, which is the data controller for the personal data described in this policy. General privacy enquiries can be sent to privacy@maybeitssoftware.co.uk; account deletion requests should use the address in section 6.

Please read this Privacy Policy carefully. By accessing or using the App, you consent to the collection and use of your information as described herein.


1. Information We Collect

We collect information about you in a variety of ways when you interact with the App. The information we may collect includes:

A. Personal Data

Account Information: When you log in using Google Sign-In, we collect your name, email address, and profile picture URL. This is used solely to authenticate your identity, determine your role-based access level (Frontline, QC, Admin, Charity, or POS), and display user-specific metrics and configurations.

B. Native Device & Sensor Data

Camera Access: We request permission to access your device's camera. This access is used for:

  • Capturing and uploading photos of donation boxes during the sealing process. These photos are uploaded directly to our secure Cloudflare R2 bucket.
  • Scanning QR codes and barcodes to look up box details and view audit histories. Camera feeds are processed locally on your device for scanning and are not streamed or saved unless you capture a box seal photo.

Bluetooth (BLE) Access: We request permission to access your device's Bluetooth. This is used exclusively to scan for, connect to, and print tracking labels on compatible Bluetooth label printers (specifically Niimbot printers). We do not collect or store any information regarding other Bluetooth devices in your vicinity.

Location Data: There are two separate reasons the App may ask for location, and they behave differently.

  • Bluetooth printing (Android only). On Android versions before 12, Google requires Location Permission to perform Bluetooth Low Energy scanning at all. Location is accessed solely to find the label printer. Nothing is recorded, mapped or stored.
  • Waste-compliance reports. When you file a report about a waste or recycling issue, you may tap “Attach my location” to record where you observed it. If you do, we store the coordinates and how accurate the device said they were, alongside the report. This is the one place the App stores a location.

Attaching a location to a report is always optional and never automatic. The App does not ask until you tap the button, reports submit perfectly well without it, and there is no background or continuous location tracking of any kind — a single reading is taken at the moment you ask for one, and nothing is recorded between reports. Coordinates are stored only against the compliance report you attached them to, and are visible to administrators and supervisors reviewing that report.

C. Uploaded Media

Box Seal Photos: The photos captured during box sealing are stored in our secure Cloudflare R2 cloud storage. They are used as a visual audit trail to verify donation quality, resolve sorting violations, and assist charities in claiming items.

Item Photos: Staff may also photograph individual items being processed, together with a short written description, condition, and estimated value. These are stored in the same Cloudflare R2 storage and used to record and value what has been collected.

A note on what ends up in a photo: photographs taken during a clearance can incidentally capture more than the item itself — papers, packaging bearing a name or address, or a person passing through frame. Please photograph the item and not its surroundings, and do not photograph documents or anything identifying a resident.


2. How We Use Your Information

We use the information we collect to:

  • Authenticate user accounts and enforce role-based access control.
  • Link box seal photos, Quality Control checklists, and audits to specific boxes.
  • Print physical tracking labels via Bluetooth connection.
  • Track batch histories, create audit trails, and process point-of-sale claims.
  • Monitor sorting and waste violations.
  • Estimate the resale value and condition of an item or box, where a member of staff chooses to run the AI valuation described in section 5.

3. Sharing of Your Information

We do not sell, rent, or trade your personal data. We only share information in the following circumstances:

  • Third-Party Cloud Infrastructure Providers: We upload files to Cloudflare R2 and run our database on Neon PostgreSQL. These services are secured under enterprise-grade encryption.
  • AI Valuation Provider (OpenAI): When a member of staff presses "Analyse" on an item or box, that one photograph and the details already recorded against it are sent to OpenAI, which returns an estimated value and condition. This happens only on that deliberate action — photographs are never sent automatically when uploaded, and photographs nobody analyses are never sent at all. We do not send your name, email address, or profile picture. See section 5.
  • Internal Dashboard Access: Because this is an inventory tracking tool, audit logs indicating which user created a batch, approved a box, or logged a violation are visible to authenticated Admin and Supervisor users within your organization.
  • Legal Requirements: If required by law, we may disclose your information to comply with legal processes or protect public safety.

4. Data Security & Retention

We implement robust security measures to protect your data. All database traffic is encrypted in transit using SSL/TLS. We retain your personal data and audit logs only as long as necessary to fulfill the inventory tracking requirements of the university move-out program.

Reports raised from a delivery QR code

If you scan the code on a box and report a problem, you can do so entirely anonymously. If you choose to give a name and contact details so we can reply, we keep them for six months after the report is closed, and then erase them automatically. Any photographs you attached are deleted from storage at the same time. A report that is never closed is erased twelve months after it was made, whatever its status.

What survives is the report itself — its category, what you wrote, which delivery it concerned and when — with nothing left in it that identifies you. We keep that so the programme can answer questions like how many hygiene issues a site produced in a given year. Because we cannot tell whether you typed your own details into the message box itself, please avoid putting contact information there rather than in the fields provided.

You can ask us to erase a report entirely at any time before then, using the contact address in section 6.


5. AI Valuation

The App can estimate what a photographed item or box would fetch resold, so that goods are routed to reuse, donation, or recycling on better information than a guess.

When it runs

Only when a member of staff presses "Analyse" on a particular item or box. It never runs automatically, never runs in the background, and never runs on a photograph nobody has chosen to analyse.

What is sent

The single photograph being analysed, together with the details already recorded against that item or box — its name, category, condition, location or site, item count, and any notes a member of staff has typed. This is sent to OpenAI, which processes it and returns an estimate. Your name, email address, and profile picture are not sent.

What comes back, and what it decides

An identification, a condition grade, an estimated resale range, a suggested onward route, and a confidence score. It is advisory. It makes no decision about any person and has no effect on anyone's access, employment, or rights — a member of staff decides what happens to the goods.

What staff have entered is treated as fact. The AI is used to fill gaps and to estimate value; its output is stored separately from, and is never written over, anything a person recorded. Results the model is unsure of are flagged for a human to check.

If it is switched off

The feature is optional and can be disabled for an organisation. With it off, no photograph is sent to any AI provider, and the rest of the App is unaffected.


6. Account Deletion & Data Rights

You have the right to access, update, or request the deletion of your account and associated personal data at any time.

How to Request Account Deletion:

To request that your account be deleted, please send an email from your registered email address to:

admin@sustainablemove.live

Please include "Account Deletion Request" in the subject line. Requests are processed within 30 days.

Data Handling Upon Deletion Request:

  • Data Deleted: Upon account deletion, all personal data associated with your user account (including your name, email address, profile picture URL, and authentication credentials) will be permanently deleted from our primary user database.
  • Data Retained: Operational waste tracking logs, donation batch records, item counts, and quality control checklists submitted during program operations will be retained for business, audit, and environmental impact reporting. Any retained records will be fully disassociated from your deleted user account and stored in an anonymized format.