1. Introduction
BuilderBase ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal and business information when you use our construction project management platform ("Service"). This policy complies with the New Zealand Privacy Act 2020 (including the Information Privacy Principles) and, where applicable, international data protection frameworks (such as the GDPR).
Data Controller: BuilderBase is the data controller for personal information collected through the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Company name, business registration, contact details, user names, email addresses, phone numbers, payment credentials, and role/permission configurations.
- Business & Operational Data ("Your Data"): Project files, addresses, client records, staff details, subcontractor information, financial records (invoices, estimates, bills, purchase orders, pricing, labour rates), photos, site diaries, checklists, and internal communications.
- Support Ticket Information: Problem descriptions, support request details, and temporary support authorisation keys.
2.2 Information Collected Automatically
- Usage & Diagnostic Data: Device specifications, operating systems, browser types, IP addresses, access timestamps, and error/diagnostic logs.
- Support Session Telemetry (
pagesVisited): When an authorised Superadmin support session is active, the Service automatically logs real-time route telemetry—including specific page routes visited, dwell times, and ticket context—to maintain complete audit trails of support activity. - Immutable Audit Logs: All API reads, writes, authentication events, and system administration activities are automatically logged via Google Cloud Audit Logs and Firestore audit trails.
3. How We Use Your Information
3.1 To Provide & Manage the Service
- Process and store business data, enable team collaboration, calculate financial estimates, process invoices, and facilitate authorised integrations (e.g., Xero).
- Deliver customer support strictly under user-authorised parameters.
3.2 For Security, Auditability, and Legal Compliance
- Support Transparency: Display live UI notification banners when support personnel are actively viewing an account.
- Audit Trails: Maintain tamper-proof, append-only logs of database operations and support access to prevent unauthorised browsing and support dispute resolution.
- Fraud & Abuse Defence: Detect security threats, enforce App Check bot protection, and defend platform infrastructure.
3.3 Commercial Non-Use & Non-Disclosure
- We never sell, rent, or trade your personal information or commercial business data to third parties.
- Pricing structures, labour costs, material margins, and tendering data viewed during authorised technical support are held under strict confidentiality and will never be used by BuilderBase or its personnel for commercial advantage.
4. Support Session Protocol & Admin Access Controls
Superadmin personnel cannot and do not have unrestricted backend access to browse subscriber workspaces. Admin account access is governed by strict, transparent security controls:
- Explicit User Authorisation: An administrator can only access a company workspace if a subscriber generates a temporary 6-digit support authorisation key within their account settings and links it to a Support Ticket ID.
- Live UI Transparency: While an admin is inside a workspace, an active, high-visibility notification banner is rendered across all screens for all active users of that account. This banner displays:
- The admin's name and Support Ticket ID.
- Real-time route tracking displaying the exact section/page being inspected (e.g.,
Viewing: Jobs › Estimating). - An End Support Session button allowing the user to immediately revoke access and terminate the session.
- Session Audit Trail: Every support session automatically records an immutable telemetry document storing the ticket ID, start/end timestamps, pages visited (
pagesVisited), and termination method (endedBy: “ADMIN” or “USER”).
5. Data Storage, Infrastructure & Immutable Security
5.1 Cloud Infrastructure (Google Cloud & Firebase)
Your data is processed and stored on Google Cloud Platform (GCP) and Firebase infrastructure:
- Firestore Database: Stores structured business and operational data.
- Firebase Storage & Auth: Manages encrypted document storage and user authentication.
- App Check (reCAPTCHA v3): Protects API endpoints against automated scripts and unauthorised bot traffic.
5.2 Primary Region & Backup Redundancy
- Primary Region: Data centres located in Australia and New Zealand.
- Continuous PITR Backups: Firestore Point-in-Time Recovery (PITR) maintains continuous, 7-day disaster recovery window backups.
- GCP Security Standards: Infrastructure maintains ISO 27001, SOC 2/3, and PCI DSS compliance certifications.
5.3 Immutable Audit Logging
To guarantee security and data integrity:
- All database read/write queries and system administration activities are recorded in Google Cloud Audit Logs.
- Audit logs are append-only and immutable; they cannot be edited, modified, or deleted by any user or administrator.
- Disabling or modifying logging policies automatically creates an unerasable, permanent Admin Activity audit record.
6. Data Security Measures
- Encryption in Transit & at Rest: TLS/SSL encryption for data in transit; AES-256 encryption at rest within Firebase/GCP.
- Restricted API Keys: Client-side API keys (e.g., Google Maps, Firebase) are domain-restricted and protected by Firebase App Check.
- Data Breach Notification: In the event of a privacy breach affecting personal information, we will notify affected individuals and the New Zealand Privacy Commissioner in accordance with the Privacy Act 2020 (typically within 72 hours).
7. Data Sharing and Third Parties
7.1 Service Providers
We share data with vetted infrastructure partners solely to operate the Service:
- Google Cloud Platform / Firebase: Cloud hosting, database, authentication, and audit logging.
- Google Gemini AI: Powers assistive chatbot support and analysis. Customer business data is never used to train public AI models.
- Xero (Optional Integration): Financial syncing authorised directly by the user.
7.2 Legal & Regulatory Disclosures
We may disclose information if required by New Zealand law, court orders, or statutory regulatory requests (such as inquiries under the Commerce Act 1986).
8. Your Rights Under the NZ Privacy Act 2020
You possess clear legal rights regarding your personal information:
- Access (IPP 6): Right to request access to any personal information we hold about you.
- Correction (IPP 7): Right to request corrections to inaccurate personal records.
- Data Portability & Export: You may export your entire company dataset in structured JSON format at any time via Company Settings → Export Data.
- Deletion & Retention: You may request account deletion. Active data is retained for 90 days following subscription cancellation before permanent purging.
- Complaints: You have the right to lodge a privacy complaint with us or directly with the New Zealand Privacy Commissioner (privacy.org.nz).
9. AI and Automated Processing
AI features (powered by Google Gemini) function exclusively as assistive tools for site analysis, checklist generation, and support query resolution. All business decisions remain under human control and oversight.
10. Changes to This Privacy Policy
We may update this policy periodically to reflect operational, legal, or security enhancements. Material updates will be notified via email or in-app notices 30 days prior to taking effect.
11. Contact Us
For privacy inquiries, audit log requests, or Privacy Act rights exercise, please contact:
Privacy Officer