Skip to main content

Privacy Policy

Last updated: 26 July 2026

In short

We collect the minimum needed to run a residents' portal: your name, email address, flat and whether you are an owner, renter or short-stay guest. It is used to give you access, take facility bookings, run community votes and send building updates. It is never sold, never used for advertising, and never shared outside the building except where the law requires it.

Who we are and who is responsible

James-Square.com is a community website for residents and owners of James Square, Caledonian Crescent, Edinburgh. It is run on a voluntary, non-commercial basis by a resident on behalf of the James Square Proprietors’ Association, and is not a property management company or factor.

For the purposes of UK GDPR the data controller is the James Square Proprietors’ Association, contactable at privacy@james-square.com. We are not required to appoint a Data Protection Officer, and have not done so; privacy enquiries are handled by the site administrator with the committee.

What we collect, and why

Personal information collected by James Square, with the purpose and lawful basis for each
What we collectWhy we need itLawful basis
Your name, email address, chosen username and flat number, and whether you are an owner, renter or short-stay guestTo create your account, confirm you are connected to the building, and show your name on bookings, posts and votesContract — we cannot give you an account without it
Your passwordTo sign you in. Stored and checked by Firebase Authentication; we never see it and cannot recover itContract
Facility bookings: which facility, date, time and the account that bookedTo operate the pool, gym and sauna booking system and apply fair-use limitsContract
Message board posts, comments, replies and reactionsTo run the residents’ message boardLegitimate interests — running a community noticeboard
Votes in community and owners’ polls, including your name and flatSo each household votes once and the result can be verifiedLegitimate interests — fair and auditable community decisions
Feedback and moderation reports you submitTo respond to problems and moderate the message boardLegitimate interests
Emails you send to the committee, and records of emails the committee sends through the siteTo answer you and keep a record of what was communicated to residentsLegitimate interests
Sign-in timestamps, and an audit log of administrative actionsTo keep accounts secure and to show who changed whatLegal obligation (UK GDPR security duty) and legitimate interests
Your cookie choicesSo we honour your preferences and stop askingLegal obligation (PECR)

We do not ask for, and do not want, information such as your date of birth, telephone number, financial details, or any special category data (health, ethnicity, beliefs and so on). Please do not include such information in message board posts or emails.

Where a form asks for something, the reason is stated next to the field. If you think we are collecting more than we need, tell us — data minimisation is something we actively check.

Technical information

Like any website, ours receives technical information as a by-product of serving pages: your IP address, browser and device type, and the pages requested. This is used only to deliver the site and to protect it against abuse — for example, temporarily counting requests from an address to stop repeated guessing of an access code.

We do not store IP addresses in our own database, and do not use them to build any profile of you. Our hosting provider keeps short-term operational logs on our behalf.

Who can see your information

  • Only you can see your own account profile. Other residents cannot look up your email address, flat or account details.
  • Your name is shown alongside anything you choose to post publicly on the message board, and alongside your vote in owners’ polls, so results can be verified.
  • Bookings show as “booked” to other residents. Your email address is not revealed to them.
  • Site administrators can see resident accounts, bookings and audit logs in order to run the site. Administrative actions are logged.
  • The committee can see emails sent to committee addresses, and the archive of emails sent through the site.

We do not sell personal information, and we do not share it for marketing. It is not passed to the factor, to Myreside Management, or to any other organisation except where you have asked us to, or where we are legally required to.

Service providers

A small number of companies process data on our behalf, under contract, and only on our instructions:

Processors used by James Square
ProviderWhat they doWhere data is processed
Google (Firebase Authentication, Cloud Firestore, Cloud Functions)Sign-in, database and server-side functionsEuropean Union and United States, under Google’s standard contractual clauses
VercelWebsite hosting and deliveryEuropean Union and United States, under standard contractual clauses
ResendSending emails from the site (building updates, committee mail)European Union and United States, under standard contractual clauses

Where data reaches the United States it is protected by the safeguards named above. If you would like more detail on any transfer, please ask.

How long we keep it

Retention periods for each type of information are set out in full in our Data Retention Policy. In summary: account details are kept while your account is active, bookings for two years, audit logs for two years, and communications for as long as they are relevant to the running of the building.

How we protect it

  • All traffic is encrypted in transit (HTTPS), and the site is served only over HTTPS.
  • Passwords are handled by Firebase Authentication and are never visible to us.
  • Database rules restrict every collection so residents can read their own information and administrators can read what they need to run the site — not everything by default.
  • Administrative functions verify the caller’s identity and role on the server. Being able to reach a page is never treated as permission to use it.
  • Emails sent through the site use blind copy so recipients cannot see each other’s addresses.
  • Sensitive settings and keys are held as server-side environment variables and are never sent to your browser.

No system is perfect. If you believe you have found a security or privacy problem, please report it to privacy@james-square.com and give us a reasonable opportunity to fix it before disclosing it more widely. We will not pursue anyone who reports a genuine issue in good faith.

Your rights

Under UK GDPR you have the right to:

  • Be told what we hold about you, and get a copy of it (access).
  • Have inaccurate information corrected (rectification).
  • Have your information deleted, including closing your account (erasure).
  • Ask us to stop or limit how we use it (restriction and objection).
  • Receive your information in a portable format (portability).
  • Withdraw consent where we rely on it — for example, your cookie choices.

To exercise any of these, email privacy@james-square.com. We will respond within one month. There is no charge. We may ask you to confirm your identity — usually by replying from the email address on the account — so that we do not disclose your information to someone else.

Some things cannot simply be erased on request. Where a vote has been counted or a decision minuted, removing your record would undermine the integrity of a community decision, so we may keep the minimum needed and explain why. Content that relates to a safety or legal matter may also be retained.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner’s Office, the UK data protection regulator. We would appreciate the chance to put things right first.

Children

Accounts are intended for adult residents and owners. We do not knowingly collect information from children. Where a facility booking is made for a family, it is made by and recorded against the adult account holder.

Cookies

Cookies and similar storage are covered separately in our Cookie Policy, which lists every cookie we set and lets you change your choices at any time.

Changes to this policy

We will update this policy when the site changes or the law requires it. The “last updated” date at the top always reflects the current version. If a change materially affects how your information is used, we will say so on the site rather than change it quietly.