Privacy Policy
Build Con · In effect from 7 September 2026
1. Who we are, and what this covers
This policy explains how [Operating entity name] (ACN [•]) (we, us) handles personal information in the Build Con web application and the emails it sends. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Two roles matter throughout. Where you sign up and manage your own account, we decide how your information is handled. Where your employer or head contractor invites you onto a project they created, they decide what goes into that project and who may see it, and we handle that information on their behalf. Requests about a project's contents are best directed to whoever runs that project; we will help if you are not sure who that is.
2. What we collect
Your account
- Your email address, and your name and phone number if you provide them. Your name and phone number are shown to other people on your projects — that is what they are for.
- How you sign in: either a Google account, or an email address with a password. Passwords are handled by our authentication provider and are stored only as a hash; we never see or store the password itself.
- Your notification preferences and interface settings.
- Your role on each project and organisation, which is what determines the data you can see — including whether you can see a project's financials at all.
What you and your team record on a project
Almost all of this is business information, but it names people, and so much of it is personal information as well:
- RFIs, defects, tasks, drawings and document registers, including who raised, was assigned, answered, closed or signed off each one.
- Site diaries — the day's weather, who and which companies were on site, hours, deliveries and notes — and the photos attached to them or to a defect, together with any date and location recorded by the camera in the photo itself.
- Project details, including the site address and its coordinates, the client, the contract sum, dates and status.
- Budget and cost information: cost plans, commitments, invoices and invoice files, variations and forecasts. This is visible only to project and site managers.
- Comments, and file attachments on any of the above.
- An activity log of who changed what and when, and the in-app notifications generated from it. The activity log is a deliberate record: it is what makes a construction record defensible, and it is not editable by anyone, including us.
- Invitations you send — the email address invited, the role offered, and whether it has been accepted.
Connections to your file storage
- The Google or Microsoft account you connect, the access and refresh tokens for it (encrypted at rest), and the identifiers of the folders and files Build Con has created for your projects.
- A record of which project member has been granted access to which project folder, so that access can be withdrawn again when they leave the project.
Technical and security information
- Ordinary web server records kept by our hosting provider — IP address, browser type, the page requested and the time — and, when something breaks, an error report containing the same sort of detail.
- Counts of failed sign-in, sign-up and password-reset attempts, used for rate limiting. Where an attempt is counted against an email address, we store a one-way hash of the address, never the address itself.
- A bot-protection check on the sign-in and sign-up forms, run by Cloudflare Turnstile, which does not profile you or track you across sites.
We do not collect payment details — Build Con charges nothing during its alpha. We do not knowingly collect sensitive information as the Privacy Act defines it, and you should not put health, union membership or similar details into a project record.
3. Where your files actually live
Build Con does not run a file store of its own. Documents, drawings, invoice attachments and site photos are uploaded into your own Google Drive or your organisation's SharePoint site, in folders Build Con creates for each project. We store the file's name, category and identifier so the register can list it, and we fetch the file when you open it in the app.
On Google Drive we request the drive.file permission only. That permission is limited by Google to files Build Con itself created — we cannot see, list or open anything else in your Drive. On SharePoint, your Microsoft 365 administrator chooses the site and controls who may browse it.
This has a consequence worth stating plainly: your files remain subject to Google's or Microsoft's terms and privacy policies as well as this one, and if you disconnect Build Con or close your account, those files stay where they are — in your Drive or your SharePoint site, yours to keep or delete.
4. Why we use it
We use personal information to:
- run the service — show you your projects, enforce who may see what, number RFIs, allocate tasks, calculate budgets and forecasts;
- create and share the project folders in your storage provider, and withdraw that sharing when someone leaves a project;
- notify you about things addressed to you, in the app and by email, according to the preferences on your settings page;
- keep the service secure — rate limiting, bot protection, and investigating misuse;
- find and fix faults, using error reports and server logs; and
- meet our legal obligations, and respond when you contact us.
We do not use your project information to train machine-learning models, we do not sell it, and we do not disclose it for advertising.
5. Who else can see it
- Other people on your projects. Anything you record on a project is visible to that project's members, subject to their role — financial information is limited to project and site managers. Your name, email and phone number are visible to the members of the projects you share.
- People you invite. An invitation tells the recipient which project and organisation they have been invited to, and by whom.
- Your storage provider. Granting a project member access to a project folder discloses their email address to Google or Microsoft, because that is how the sharing is recorded.
- Our service providers, listed in the next clause.
- Anyone we are legally required to disclose to, or where disclosure is necessary to prevent a serious threat to life, health or safety.
- A buyer of the business, if Build Con is ever sold or merged — on terms no less protective than this policy, and we will tell you before your information transfers.
6. Service providers, and overseas disclosure
Build Con is assembled from a small number of specialist providers. Each handles information only to provide its part of the service:
| Provider | What it does for us | What it receives |
|---|---|---|
| Supabase | Authentication and the application database | Your account details and all project records |
| Vercel | Hosting and delivery of the application | Requests to the app, including IP address |
| Sign in with Google, and Google Drive file storage | Your Google identity; the files Build Con creates | |
| Microsoft | SharePoint file storage, where your organisation uses it | Your Microsoft identity; the files Build Con creates |
| Resend | Transactional email — invitations, confirmations, notifications | The recipient address and the content of the email |
| Sentry | Error monitoring, so faults are noticed and fixed | Technical details of an error, which may include your user ID |
| Cloudflare | Bot protection on the sign-in and sign-up forms | The information needed to run that check |
| Open-Meteo | Weather forecasts for a project site | The site coordinates only — no personal information |
Several of these providers are based in, or store data in, countries outside Australia — principally the United States and the European Union. By using Build Con you agree that your information may be disclosed to them for the purposes above. We take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles, but you should be aware that once information is overseas the Privacy Act may not be enforceable against them directly.
Where you connect Google Drive or SharePoint, the location of your files is determined by your own Google or Microsoft account, not by us.
7. Cookies and browser storage
Build Con sets cookies for one purpose: keeping you signed in. They are set by our authentication provider, are required for the app to work at all, and there is no advertising, profiling or analytics cookie anywhere in the product.
The app also stores a small amount of interface state in your browser's local storage — whether the navigation rail is collapsed, which panel you last had open. It never leaves your device, and clearing your browser storage only resets those preferences.
8. How we protect it
Everything travels over HTTPS. Access to a project is checked on the server for every read and every write, not merely hidden in the interface, and the database enforces the same boundaries independently. Storage refresh tokens are encrypted before they are stored. Sign-in, sign-up and password-reset attempts are rate limited, and changing your password ends your other sessions.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
9. How long we keep it
- Project records are kept for as long as the project exists in Build Con. They are construction records: an RFI answer or a defect sign-off may be needed years later, and deleting a project deletes its records for everyone on it.
- Account information is kept while your account is open, and deleted when it is closed — except where a record must be kept, such as your authorship of an activity-log entry on someone else's project, which is retained in a reduced form so that project's history stays intact.
- Security and error records are short-lived: rate-limit counters expire within hours, and error reports are retained for a limited period by our monitoring provider.
- Your files are never deleted by us when you close your account, because they are not ours to delete — see clause 3.
10. Getting at your information
You may, at any time:
- See it. Most of it is on screen already. For a copy of anything else we hold about you, email us and we will respond within 30 days.
- Correct it. Your name, phone number and notification preferences are editable on your settings page. Ask us about anything you cannot change yourself.
- Disconnect your storage. Also on the settings page. Build Con then loses its access to your Drive or SharePoint; the files stay yours.
- Delete your account. Email us and we will close it. Note the limit in clause 9: content you contributed to other people's projects remains part of those projects' records.
We do not charge for an access request, and we will not ask you why you are making one. If we refuse a request — which is rare, and only where the law allows it — we will tell you why in writing.
11. Children
Build Con is a workplace tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has an account, tell us and we will close it.
12. Changes to this policy
We will update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your information, we will tell you in the app or by email before it takes effect, rather than relying on you to notice a new date.
13. Contact, and complaints
For any privacy question, an access or correction request, or a complaint about how we have handled your information:
[Operating entity name] (ACN [•])ABN [ABN]
[Street address], [Suburb] [STATE] [Postcode], Australia
[email protected]
We will acknowledge a complaint within five business days and aim to resolve it within 30 days. If you are not satisfied with our response, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.