Before this is live for real customers: replace every [bracketed] placeholder below with your actual business details, and have a solicitor review this against your specific setup - this is a solid, accurate starting draft based on exactly what BuildPack collects and does today, not a substitute for legal advice.
BuildPack is provided by [Your Business Name] ("we", "us", "our"), of [Your Business Address]. For anything in this policy, contact us at [Contact Email]. This policy is written to comply with UK GDPR and the Data Protection Act 2018.
This matters, so we're upfront about it:
| Category | What | From |
|---|---|---|
| Account | Email address | You, when you sign in |
| Project details | Client name, email, phone, property address, contract dates | You (the contractor) |
| Subcontractor records | Name, company, contact details, registration/insurance numbers | You, or the subcontractor via a self-service link |
| Inspection records | Inspector name, dates, outcomes, notes, attached certificates | You, or the inspector via a self-service link |
| Photos & documents | Site/property photos, uploaded files or linked documents | You, or a self-service link holder |
| Financial records | Invoice amounts, dates, status (internal use only, never shown to your client) | You |
| Activity log | Who did what on a project, and when (for dispute/compliance records) | Generated automatically |
BuildPack lets you send a link so a subcontractor, inspector, or your client can view or fill in specific information without creating an account. Anyone holding that link can use it, so treat it like a password and only send it to the intended person - you can revoke a link at any time from the project. We don't verify the identity of whoever opens a self-service link; that responsibility sits with you, as the person who sent it.
We do not use your data, or your clients' data, for advertising, and we do not sell it to anyone.
We use a small number of sub-processors to run BuildPack - each only sees what it needs to do its job:
| Provider | Purpose |
|---|---|
| Supabase | Database and file storage - holds all project data and uploaded photos/documents |
| Vercel | Application hosting |
| Resend | Delivering sign-in emails |
| Sentry (EU region) | Error monitoring, so we can catch and fix bugs |
[Confirm and state the specific hosting region for your Supabase project here, and add or remove rows to match your actual infrastructure before publishing this.]
We never sell personal data, and we only disclose it beyond these providers if required by law.
Project data is kept for as long as the project exists in your account. Deleting a project permanently removes its records and files within our systems. Deleting your account removes your account and every personal project you own; if you're part of a team, projects still shared with that team are unaffected.
Under UK GDPR, you have the right to:
If you're a client or subcontractor whose details a contractor has entered about you (not a BuildPack account holder yourself), the same rights apply - ask the contractor directly, or contact us and we'll help.
We only use strictly necessary cookies to keep you signed in. We don't use tracking, advertising, or analytics cookies, so there's nothing to opt in or out of.
Data is encrypted in transit (HTTPS) and access to it is controlled at the database level, so an account only ever sees its own projects and whatever a team it belongs to shares. No system is completely immune to risk, but we take reasonable, industry-standard steps to protect your data.
BuildPack is a business tool for construction contractors and isn't directed at children, and we don't knowingly collect data from anyone under 18.
If we make a material change, we'll update the date at the top of this page and, where appropriate, notify you directly.