BuildBase
Terms Refunds Home

Privacy Policy

Effective Date: 20 February 2026  |  Last Updated: 20 February 2026

Plain-language summary: We collect only the data we need to run BuildBase — your email, account info, project data, and payment details (processed by Stripe). We never sell your personal information. Your project data belongs to you. We use Firebase (Google) for infrastructure and Stripe for payments. You have rights over your data, and we explain how to exercise them below.

Contents

  1. Who We Are
  2. Scope of This Policy
  3. Information We Collect
  4. How We Use Your Information
  5. Legal Basis for Processing (GDPR)
  6. Who We Share Your Information With
  7. International Data Transfers
  8. Data Retention
  9. Data Security
  10. Your Rights
  11. Cookies & Tracking
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact & Complaints

1. Who We Are

BuildBase is operated by BUILDBASE SOFTWARE, ABN 22 673 457 592 ("we," "us," "our"). We are the data controller (for GDPR purposes) and the APP entity (for Australian Privacy Act purposes) responsible for your personal information when you use the BuildBase service ("Service").

Data Controller / APP Entity:
BUILDBASE SOFTWARE
ABN: 22 673 457 592
Email: [email protected]
Address: PO Box 38, Ormeau, QLD 4208, Australia

2. Scope of This Policy

This Privacy Policy applies to all personal information collected through the BuildBase website, web application, and any related services. It does not apply to third-party websites or services that may be linked from our Service.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

3. Information We Collect

3.1 Information You Provide Directly

Data Type Examples When Collected
Account Information Email address, password (hashed), display name Account registration
Google Account Data Email, display name, profile photo URL (if you sign in with Google) Google OAuth sign-in
Project Data Project names, descriptions, budgets, BOMs, tasks, notes, timeline entries When you create and use projects
Uploaded Files Documents, images, CAD files, PDFs, and other attachments When you upload files to projects
Payment Information Billing name, card details, billing address Subscription checkout (processed and stored by Stripe — we do not store full card numbers)
Communications Email correspondence, support requests, feedback When you contact us

3.2 Information Collected Automatically

Data Type Examples Purpose
Device & Browser Data Browser type, operating system, screen resolution, device type Service optimisation and compatibility
Log Data IP address, access times, pages visited, referring URLs Security, debugging, and analytics
Usage Data Features used, actions taken, session duration Service improvement
Firebase Authentication Data Authentication tokens, sign-in method, last sign-in timestamp Account security and session management

3.3 Information We Do Not Collect

We do not knowingly collect sensitive information (also known as "special category data") such as racial or ethnic origin, political opinions, religious beliefs, health information, sexual orientation, or biometric data. We do not collect information about children under 18.

4. How We Use Your Information

We use your personal information for the following purposes:

Purpose Data Used
Providing the Service — creating your account, storing your projects, syncing data across devices, processing file uploads Account info, project data, uploaded files
Processing Payments — managing subscriptions, processing charges, handling refunds Payment info (via Stripe), email
Communications — sending account-related emails (verification, password reset, billing receipts, important service notices) Email address
Security & Fraud Prevention — detecting and preventing unauthorised access, abuse, or security incidents Log data, IP address, authentication data
Service Improvement — understanding how features are used, identifying bugs, improving performance Usage data, device data (aggregated/anonymised where possible)
Legal Compliance — responding to legal requests, enforcing our terms, complying with applicable laws Any data as required by law

We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We will never do this.

5. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom (UK), or another jurisdiction that requires a legal basis for processing personal data, we rely on the following:

Legal Basis Applies To
Performance of a Contract Providing the Service, processing payments, managing your account — these are necessary to fulfil our contract with you (the Terms of Service).
Legitimate Interests Security and fraud prevention, service improvement and analytics, responding to support requests. Our legitimate interests do not override your fundamental rights and freedoms.
Legal Obligation Complying with tax, accounting, and other legal requirements.
Consent Where we send optional marketing communications (you can withdraw consent at any time). We currently do not send marketing emails.

6. Who We Share Your Information With

We share your information only with the following categories of third parties, and only to the extent necessary to provide and improve the Service:

6.1 Service Providers (Sub-Processors)

Provider Purpose Data Shared Location
Google Firebase
(Google LLC)
Authentication, database (Firestore), file storage (Cloud Storage), hosting Account data, project data, uploaded files, authentication tokens United States (Google Cloud infrastructure)
Stripe, Inc. Payment processing, subscription management, invoicing Email, payment details, billing address, subscription status United States

Each of these providers is bound by their own privacy policies and data processing agreements. We encourage you to review:

  • Google Firebase Privacy & Security
  • Stripe Privacy Policy

6.2 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, the safety of others, investigate fraud, or respond to a legal request.

6.3 Business Transfers

If BuildBase is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you (via email or notice on the Service) of any such change and any choices you may have regarding your information.

6.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so.

7. International Data Transfers

BuildBase is operated from Australia. However, as we use Firebase (Google Cloud) and Stripe, your data may be processed and stored in the United States and other countries where these providers operate infrastructure.

Where your data is transferred outside of Australia or the EEA, we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
  • Reliance on the data protection frameworks and certifications maintained by our service providers (such as Google's and Stripe's GDPR compliance programmes).
  • Compliance with the Australian Privacy Principles regarding cross-border disclosure (APP 8).

By using the Service, you acknowledge and consent to the transfer of your information to countries outside your country of residence, which may have different data protection standards.

8. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes described in this Policy:

Data Type Retention Period
Account data For the duration of your account, plus 30 days after account closure to allow for reactivation.
Project data & uploaded files For the duration of your active Subscription, plus 30 days after Subscription cancellation or account closure.
Payment & billing records As required by tax and accounting laws (typically 7 years in Australia under ATO requirements).
Log data & usage analytics Up to 12 months, then aggregated or deleted.
Support correspondence Up to 24 months after the issue is resolved, unless a longer retention period is required for legal purposes.

After the applicable retention period, personal data is either permanently deleted or irreversibly anonymised. Anonymised data that can no longer identify you may be retained indefinitely for statistical purposes.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
  • Encryption at rest: Data stored in Firebase Firestore and Cloud Storage is encrypted at rest using Google's default encryption.
  • Authentication security: Passwords are securely hashed by Firebase Authentication. We never store plaintext passwords.
  • Access controls: Firestore security rules enforce that users can only access their own data. We follow the principle of least privilege for all administrative access.
  • Payment security: All payment processing is handled by Stripe, which is PCI DSS Level 1 certified — the highest level of payment security certification. We never see or store your full card number.
  • Regular monitoring: We monitor for security incidents and unauthorised access attempts.

While we take reasonable steps to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we commit to promptly notifying affected users and relevant authorities in the event of a data breach, in accordance with the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act and GDPR breach notification requirements where applicable.

10. Your Rights

Depending on your location, you may have some or all of the following rights regarding your personal information:

10.1 Rights for All Users

  • Access: You can access your project data at any time through the Service. You can request a copy of the personal information we hold about you.
  • Correction: You can update your account information through the Service, or contact us to correct any inaccuracies.
  • Deletion: You can delete your account through the Account settings. You can also request that we delete specific personal information.
  • Data Export: You can export your project data in PDF and CSV formats through the Service.

10.2 Additional Rights for Australian Users

Under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), you have the right to:

  • Request access to the personal information we hold about you (APP 12).
  • Request correction of any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
  • Complain about a breach of the APPs and have your complaint dealt with (see Section 14).

10.3 Additional Rights for EEA/UK Users (GDPR)

If you are located in the EEA or UK, you additionally have the right to:

  • Restriction of processing: Request that we restrict the processing of your personal data in certain circumstances.
  • Data portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Objection: Object to the processing of your personal data based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time.
  • Lodge a complaint: File a complaint with your local Data Protection Authority.

10.4 Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing certain requests.

We will not discriminate against you for exercising any of your privacy rights.

11. Cookies & Tracking Technologies

11.1 What We Use

BuildBase uses a minimal set of cookies and similar technologies:

Cookie / Technology Type Purpose Duration
Firebase Auth session Strictly Necessary Maintains your login session and authentication state Session / persistent (per Firebase defaults)
Stripe session Strictly Necessary Facilitates secure payment processing during checkout Session

11.2 What We Do Not Use

We do not currently use third-party advertising cookies, social media tracking pixels, or cross-site tracking technologies. We do not serve advertisements within the Service.

11.3 Managing Cookies

You can manage cookies through your browser settings. However, disabling strictly necessary cookies may prevent you from using the Service, as they are required for authentication and payment processing.

If we introduce analytics or non-essential cookies in the future, we will update this Policy and, where required by law, obtain your consent before deploying them.

12. Children's Privacy

The Service is not directed at, and we do not knowingly collect personal information from, children under the age of 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete that information as soon as possible. If you believe a child has provided us with personal information, please contact us at [email protected].

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes:

  • We will update the "Last Updated" date at the top of this page.
  • We will notify you via email to your registered email address at least 14 days before the changes take effect.
  • Where the changes are significant, we may also provide a notice within the Service.

We encourage you to review this Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated Policy.

14. Contact & Complaints

If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal information, please contact us:

Privacy Enquiries
BUILDBASE SOFTWARE
Email: [email protected]
Postal: PO Box 38, Ormeau, QLD 4208, Australia

Complaint Escalation

If you are not satisfied with our response to a privacy complaint, you have the right to lodge a complaint with the relevant supervisory authority:

  • Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • EU: Your local Data Protection Authority

© 2026 Buildbase. All rights reserved.