Legal

Privacy policy

Draft for the public site. Have a solicitor review this before you take real resident data. It is not legal advice. Last updated 19 September 2026.

1. Who we are

Estate Reporter is a web (and Android) app for UK housing estates and the companies that manage them. This public site is ourground.co.uk. The controller of personal data will be the legal entity that operates the live service. Until that entity is named here, treat this page as a description of what the product is built to collect — not a finished controller notice.

Privacy and support contact: .

2. What the app does

Residents and staff report estate issues on a map, attach photos, update status, log maintenance, and publish site inspections. Accounts are required. Unauthenticated visitors cannot read estate data.

3. What we collect

DataWhyWhere it lives
Email and passwordSign-inFirebase Authentication
Display name / usernameShow who reported or actedFirestore
Real nameManagement contact records — staff onlyFirestore member_identities
Phone numberReduce spam; verify a residentAuth + Firestore
Precise location (when you report or use My location)Place the pin on the estate mapFirestore reports
Photos you attachEvidence of the problem or completed workFirebase Storage
Issues, maintenance, inspections, audit eventsRun the estate and keep a trailFirestore

This marketing website does not create accounts and does not collect that data. It uses no analytics cookies today.

4. Why we process it

To provide the service you signed up for, keep estates isolated from each other, prevent abuse, and retain an audit trail of work and inspections. Draft UK GDPR bases: contract and legitimate interests. We do not sell personal data and we do not use it for advertising.

5. Who we share with (processors)

Management-company staff for your estate can see real names. Other residents see usernames, not real names. People on a different estate cannot read yours.

6. International transfers

Google may process data outside the UK/EEA under its standard contractual clauses. The intended Firebase data region for UK users is an EU multi-region, set when the production project is created.

7. Retention

Accounts stay until you ask us to delete them or the service closes. Issues, photos, work logs and inspections are kept for the life of the estate plus a period still to be fixed (likely around 6 years for disputes/insurance). The product currently forbids deleting submitted work logs and inspections, because they are the audit trail.

8. Security

HTTPS in transit. Sign-in required for app data. Passwords hashed by Firebase Auth. Access enforced in Firestore and Storage security rules, not only in the screen layout. Multi-tenant isolation is by estate/company id.

9. Your rights

You can ask to access, correct, erase, or export your personal data, and you can complain to the ICO. Account deletion will be handled by support email at first (the in-app self-delete path is not built yet).

10. Children

The app is for residents and staff of managed housing estates. It is not directed at children under 13.

11. Cookies

The Flutter web app uses storage needed to keep you signed in. This marketing site sets no tracking cookies.

12. Changes

We will update this page if the product or processors change. The date at the top is the last edit.