Privacy Policy
1. Accountability and contact
BuildSafe is responsible for personal information under its control and aims to handle it in accordance with PIPEDA and applicable provincial private-sector privacy laws. Send privacy questions, access/correction requests, withdrawal requests or complaints to the BuildSafe Privacy Contact at info@buildsafe.world or use Account → Legal & Safety → Privacy help. We may verify identity proportionately before disclosing or changing account data. Do not email identity documents, passwords or verification codes.
2. Information you provide
We collect account identifiers, name, email, phone, account role, address/city/province/postal code, profile photos, business/trade details, service areas, portfolio content, project descriptions, budgets, quotes, reviews, consent records, support requests, messages, and uploaded images, audio, video or documents. Email/password accounts use a password hash rather than a readable password. Social sign-in supplies account identifiers and profile fields authorized by the provider. Identity verification and subscriptions are processed by Stripe; BuildSafe keeps references and status information rather than your full card details. Stripe processes identity documents according to its own notices.
3. Purposes and required information
We use information to create accounts, match projects and professionals, show profiles, deliver messages and quotes, manage subscriptions, provide support, investigate misuse, maintain safety, record consent and meet legal duties. Basic account and project information is necessary for the requested service; without it, some features cannot operate. Optional marketing consent, live GPS, microphone and photo-library permissions are not required to keep an account. We do not sell personal information or use homeowner project contact details as a marketing list.
4. Visibility and sharing with other users
Professional profiles and portfolio details are visible to marketplace users. Job details are shared with eligible contractors to enable quoting. Exact job addresses, contact numbers and private project documents are restricted by role, assignment and explicit sharing choices; a homeowner can share an exact address in a conversation and authorize calls. Information deliberately included in project text, images or messages may still reveal an address or identity, so review it before uploading. Some profile photos, portfolios and historical chat media use publicly retrievable URLs and may be accessible to anyone holding the link. Do not upload sensitive documents or third-party personal information as public images.
5. Location and device permissions
Typed or selected addresses and postal codes support regional matching. Mapbox processes address searches and route coordinates to provide suggestions and travel estimates. Contractor live location is optional, foreground-only and can be switched off in account settings or device settings. Discovery shows an approximate position; exact coordinates may be used server-side for route estimates. Current-location freshness expires after approximately two minutes; expiry does not mean every historical record is automatically deleted immediately. Camera, library and microphone access is used when you choose to upload media or record a voice note. No background location tracking is required.
6. Service providers and cross-border processing
BuildSafe uses hosting and MongoDB database services; Supabase and managed object storage for media/documents; Stripe for subscriptions and identity verification; Mapbox for location services; managed email and push delivery providers; and enabled Google/OpenAI AI services. Where configured, Sentry and first-party monitoring receive diagnostics. Social sign-in is handled by the chosen sign-in provider. These providers may process or store data outside Canada, where it may be accessible to foreign courts or authorities under local law. Ask our Privacy Contact for available provider/location details. We remain accountable for transfers under our control and must use appropriate contractual and security safeguards; no Canadian-only residency guarantee is made.
7. AI, diagnostics and automated suggestions
Using an AI feature sends the supplied project description, selected details and relevant uploaded media to the enabled AI provider for processing. Avoid including names, contact details, identity documents or other unnecessary sensitive data. AI may suggest trades, scope, summaries and estimates, but does not make a binding hiring decision for you. Monitoring processes error details, feature names, timings, device/app context and pseudonymous account identifiers to diagnose failures. We aim to redact secrets and unnecessary personal content; do not submit sensitive data in error reports. We do not promise that every third-party diagnostic payload is anonymous.
8. Security and offline copies
We use authenticated access, role/ownership restrictions, short-lived access tokens, session revocation and other safeguards appropriate to the service. Native offline caches use encrypted local storage and expire after up to seven days; signing out clears the app’s local cache. Browser preview storage is memory-only. No internet service is perfectly secure. Protect your device, do not share accounts, and report suspected incidents promptly. Where legally required, we will assess breaches, keep required records and notify affected people and regulators.
9. Retention and deletion
We retain active account, project and communications data as reasonably needed to deliver the service and address disputes, fraud, legal, accounting or security obligations. Closing an account removes or de-identifies eligible active records, but is not a promise of immediate erasure from all backups, provider systems, records held by other users, consent/suppression records or legally required logs. Different record types require a documented retention schedule; contact us for the applicable period and reason. We do not claim a fully automated deletion schedule for all historical uploads. We will assess verified deletion requests and explain lawful exceptions.
10. Access, correction and withdrawal
You can edit profile details, change communication preferences, stop future live location sharing, close your account or request help accessing/correcting information. We normally respond to PIPEDA access requests within 30 days; a permitted extension, applicable provincial deadline or lawful refusal will be explained where required. Withdrawal affects future processing and may limit a feature that needs the information. It cannot undo information already lawfully shared or require deletion of records we must retain. No fee is charged for changing notification or email consent. We will explain any legally permitted access cost in advance.
11. Communications and consent records
Terms acceptance and Privacy acknowledgement are recorded with the policy version, time and source. Optional communications preferences are separate from required account processing. Marketing starts off and no promotional campaign is sent through the current transactional-email integration. You can withdraw optional email consent in settings or through an unsubscribe link without signing in. Unsubscribe requests take effect in our records immediately; any future commercial-email program must process requests within 10 business days and keep its mechanism valid for at least 60 days after sending. Essential security, billing and requested support messages are not promotional subscriptions.
12. Complaints, children and updates
The marketplace is for adults and is not directed at children. Contact BuildSafe if a child’s information was submitted without authority. Raise privacy concerns first with info@buildsafe.world; you may also complain to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator. Material privacy changes will be communicated appropriately and new consent requested where required. Your statutory privacy rights are not waived by accepting platform terms.