1. Who We Are
BuildTracker ("we", "us", "our") is a cloud-based construction project management service. This Privacy Policy explains how we handle personal information collected when you use our website and application at buildtracker.tech (the "Service"). If you have questions, contact us at support@buildtracker.tech.
2. Information We Collect
We collect the following categories of information:
- Account information — name, email address, and password (stored as a one-way hash) when you register.
- Company profile — company name, address, phone number, email, VAT/tax identifier, banking details, and logo image that you voluntarily add to brand your quotes and invoices.
- Project data — projects, clients, tasks, milestones, expenses, quotes, invoices, daily logs, and team members you create in the app.
- Billing information — if you subscribe to a paid plan, payment details (card number, billing address) are collected and processed directly by our payment processor, Paddle. We never see or store your full card number.
- Technical data — IP address, browser type, device information, and basic usage logs needed to operate and secure the Service.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Authenticate you and keep your account secure
- Process payments and manage subscriptions
- Respond to support requests and send service-related notifications
- Detect, prevent, and address fraud or abuse
- Comply with legal obligations
We do not sell, rent, or trade your personal information to third parties. We do not use your project data to train machine learning models.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases:
- Contract — to provide the Service you requested
- Legitimate interest — to secure, operate, and improve the Service
- Legal obligation — to comply with tax, accounting, and regulatory requirements
- Consent — where required, e.g. for marketing communications
5. Service Providers (Sub-processors)
We use a small number of trusted third-party providers to operate the Service. Each has its own privacy policy and processes data only on our instructions:
- Supabase — hosted PostgreSQL database and authentication (data stored in encrypted form)
- Paddle — payment processing and billing
- Vercel — web hosting and content delivery
6. Cookies and Local Storage
We use browser local storage and cookies that are strictly necessary to operate the Service — primarily to keep you signed in, remember your preferences (dark mode, currency, default view), and maintain your session. We do not use advertising cookies or third-party tracking pixels.
7. Data Security
We take reasonable technical and organisational measures to protect your information, including:
- HTTPS/TLS encryption for all data in transit
- Encrypted storage at rest
- Row-Level Security policies so only you can access your own data
- Passwords hashed using industry-standard algorithms
No system is 100% secure. In the event of a data breach that affects your personal information, we will notify you without undue delay in accordance with applicable law.
8. Data Retention
We retain your personal information for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are legally required to retain it (for example, invoice and tax records).
9. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal information we hold about you
- Correction — ask us to correct inaccurate or incomplete data
- Deletion — ask us to delete your account and associated data
- Export — request your data in a portable format (JSON export is available from within the app)
- Objection — object to certain processing activities
- Withdraw consent — where processing is based on consent
To exercise any of these rights, contact us at support@buildtracker.tech. You can also export your data directly from the Settings menu and delete your account by contacting support.
10. International Data Transfers
Your data may be stored and processed in countries outside your own, including the United States and the European Union, where our service providers operate. We ensure adequate safeguards are in place for any cross-border transfers.
11. Children's Privacy
BuildTracker is intended for users aged 18 and over. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice in the app before the changes take effect.
13. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at support@buildtracker.tech.
Last updated: April 2026