Before this is live for real customers: replace every [bracketed] placeholder below with your actual business details, and have a solicitor review this against your specific setup - this is a solid, accurate starting draft based on exactly what BuildPack collects and does today, not a substitute for legal advice.

Who We Are

BuildPack is provided by [Your Business Name] ("we", "us", "our"), of [Your Business Address]. For anything in this policy, contact us at [Contact Email]. This policy is written to comply with UK GDPR and the Data Protection Act 2018.

Two Different Roles We Play

This matters, so we're upfront about it:

What We Collect
CategoryWhatFrom
AccountEmail addressYou, when you sign in
Project detailsClient name, email, phone, property address, contract datesYou (the contractor)
Subcontractor recordsName, company, contact details, registration/insurance numbersYou, or the subcontractor via a self-service link
Inspection recordsInspector name, dates, outcomes, notes, attached certificatesYou, or the inspector via a self-service link
Photos & documentsSite/property photos, uploaded files or linked documentsYou, or a self-service link holder
Financial recordsInvoice amounts, dates, status (internal use only, never shown to your client)You
Activity logWho did what on a project, and when (for dispute/compliance records)Generated automatically
Self-Service Links

BuildPack lets you send a link so a subcontractor, inspector, or your client can view or fill in specific information without creating an account. Anyone holding that link can use it, so treat it like a password and only send it to the intended person - you can revoke a link at any time from the project. We don't verify the identity of whoever opens a self-service link; that responsibility sits with you, as the person who sent it.

Why We Process It

We do not use your data, or your clients' data, for advertising, and we do not sell it to anyone.

Who We Share It With

We use a small number of sub-processors to run BuildPack - each only sees what it needs to do its job:

ProviderPurpose
SupabaseDatabase and file storage - holds all project data and uploaded photos/documents
VercelApplication hosting
ResendDelivering sign-in emails
Sentry (EU region)Error monitoring, so we can catch and fix bugs

[Confirm and state the specific hosting region for your Supabase project here, and add or remove rows to match your actual infrastructure before publishing this.]

We never sell personal data, and we only disclose it beyond these providers if required by law.

How Long We Keep It

Project data is kept for as long as the project exists in your account. Deleting a project permanently removes its records and files within our systems. Deleting your account removes your account and every personal project you own; if you're part of a team, projects still shared with that team are unaffected.

Your Rights

Under UK GDPR, you have the right to:

If you're a client or subcontractor whose details a contractor has entered about you (not a BuildPack account holder yourself), the same rights apply - ask the contractor directly, or contact us and we'll help.

Cookies

We only use strictly necessary cookies to keep you signed in. We don't use tracking, advertising, or analytics cookies, so there's nothing to opt in or out of.

Security

Data is encrypted in transit (HTTPS) and access to it is controlled at the database level, so an account only ever sees its own projects and whatever a team it belongs to shares. No system is completely immune to risk, but we take reasonable, industry-standard steps to protect your data.

Children

BuildPack is a business tool for construction contractors and isn't directed at children, and we don't knowingly collect data from anyone under 18.

Changes To This Policy

If we make a material change, we'll update the date at the top of this page and, where appropriate, notify you directly.