Privacy Policy
Last updated: 25 June 2026
Bees Knees Apiary (“we”, “us”, “our”) operates the Bees Knees Apiary mobile application and web portal. This policy explains what personal data we collect, why, how we use and store it, and the rights you have over it. We are the data controller for the purposes of the UK GDPR and the Data Protection Act 2018. Contact: support@beeskneesapiary.co.uk.
1. Summary
- We collect the information you give us to run your account and store your beekeeping records.
- Your data is stored on our own servers in the UK / EEA.
- We use Google Analytics and Microsoft Clarity, and only if you accept analytics cookies - you can decline, and everything still works. Clarity runs on the public pages only. It is never loaded on your signed-in records, so your apiary locations, inspections and sales are not recorded by it. We do not use advertising SDKs, we do not sell your data, and we do not track you across other apps or websites.
- You can export all of your data, and delete your account and data, at any time.
2. What we collect
Account information: email address, name, and a salted bcrypt hash of your password (we never store or see your plain password).
Beekeeping records you create: apiaries, hives, inspections, harvests, treatments, feedings, queens, swarm events, reminders, hive weights, and financial records, plus any notes you enter.
Location data: when you add a location to an apiary or request local weather, the app uses your device location (with permission) to set map pins and fetch weather. We do not continuously track you.
Photos: photos you attach to records; where uploaded, they are stored on our servers and linked to your account.
Technical data: standard server logs needed to operate and secure the service. Not used to profile you.
We do not collect contacts, advertising identifiers, browsing history, or any data for cross-app tracking.
3. How we use your data (lawful basis)
- Create and operate your account - performance of a contract.
- Store and sync your records across devices - performance of a contract.
- Map & weather features - consent (device location permission).
- Security and abuse prevention - legitimate interests.
- Support requests - legitimate interests.
- Analytics to improve the product and our guides - consent (only if you accept analytics cookies).
4. Cookies & analytics
Essential cookies/storage keep you signed in and remember your preferences. These are always on because the app can’t work without them; they need no consent.
Analytics cookies (Google Analytics, GA4): only set after you accept via our cookie banner. They help us understand which features are used and how the site performs, so we can improve it. If you decline, Google Analytics is never loaded. You can change your mind by clearing the site’s storage in your browser. Google acts as our processor; usage data is handled under Google’s terms and we do not use it for advertising.
Microsoft Clarity (public pages only): Clarity shows us how people read our guides, using heatmaps and anonymised recordings of page interaction, so we can see where a guide loses someone and write it better. It sets two cookies, _clck and _clsk, and only after you accept. If you decline, nothing at all is requested from Microsoft: no script is fetched and no cookie is set. If you accepted before and change your mind, those two cookies are deleted when you decline.
Clarity never runs while you are signed in. It loads only on the public pages, and only for a signed-out reader, because pages like our guides can show your own hives and inspections to you while you are signed in. That boundary is enforced in three independent places in our code, because your apiary locations, inspection notes, email address and honey sales are not something we are willing to record.
5. Sharing
We share data only with service providers who help us run the app, under contract: our hosting/infrastructure provider (stores the database), a third-party weather API (an approximate location is sent to return a forecast; no account information is sent), our email provider (to send account and reminder emails), and - only with your consent - Google Analytics, and Microsoft Clarity on the public pages. We do not sell or rent your data.
5a. Support access to your account
To investigate a fault you report, an administrator may open your account in a read-only support view: we can see what you see, and cannot add, change or delete any of your records. Each of these sessions is limited to 30 minutes and is recorded in an access log - who looked, at which account, when, and the reason - which is kept even if the account is later deleted. We only do this to look into a problem or answer a support request, never to browse. Ask us at any time whether your account has been viewed, and we will tell you.
6. Storage, security and retention
Data is stored on secured servers in the UK/EEA. Connections are encrypted in transit (HTTPS/TLS); passwords are hashed with bcrypt. We keep your data while your account is active. When you delete your account, your login is permanently removed and your records are purged from active systems; residual copies in encrypted backups are removed within 30 days. You can also request deletion via our deletion page or by emailing support.
7. Your rights
Under UK GDPR you may access, rectify, erase, export, restrict, or object to processing of your data, and withdraw consent for optional features. Use Settings → Data → Export to download your data, and Settings → Account → Delete Account to erase it. To exercise any right, email support@beeskneesapiary.co.uk. You may also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
8. Children
The app is not directed at children under 13, and we do not knowingly collect their data.
9. Changes
We may update this policy. We will update the date above and, for material changes, notify you in the app.