Privacy Policy

Last updated: 5 August 2026

Buildocker is pre-launch and does not yet charge for access or serve paying customers. Full legal entity details, a named Grievance Officer, and a registered address will be published here before the service is offered commercially. These documents are provided in good faith and have not yet been reviewed by a lawyer qualified in Indian data protection law.

This Privacy Policy explains how Buildocker ("we", "us") collects, uses, stores, and protects personal data when you use Buildocker (buildocker.com and its subdomains), in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000.

1. What we collect

Only what the product actually needs to function:

  • Account information: name, email address, phone number (optional), and your role (contractor or client). Your password is never stored by us directly — it's handled entirely by our authentication provider (Supabase Auth) using industry-standard hashing.
  • Contractor profile (optional, contractor accounts only): business bio, tagline, logo, cover photo, brochure, pricing rates, and a custom domain if you configure one.
  • Project data: project names, addresses, budgets, photos, documents, timeline updates, payment milestone records, and messages you send within a project's chat.
  • Enquiry data: if you submit an enquiry through a contractor's public page without creating an account, we collect the name, email, phone, and project details you provide, on that contractor's behalf.
  • Technical data: IP address (used for rate-limiting/abuse prevention, and to derive a coarse country/region/city for internal analytics — see Section 3), and standard server logs.
  • Usage analytics: which pages you visit and when you log in, logged by our own servers — not a third-party analytics tool, and not cookie-based (see our Cookie Policy). Used internally to understand product usage; see Section 3.
  • Precise location (only if you choose to share it): if you use "Share my location" in Settings, your device's GPS coordinates at that moment. Your browser will always ask you to confirm this directly — it's never requested or captured without that explicit action.

We do not collect government ID numbers, financial account details, or biometric data. Precise location is collected only when you explicitly choose to share it, never by default or silently.

2. Cookies

Buildocker uses a single essential cookie to keep you signed in (managed by Supabase Auth). We do not use advertising cookies, third-party tracking cookies, or analytics cookies of any kind at this time. See our Cookie Policy for details.

3. How we use your data

  • To provide the core service — project tracking, client portals, payment schedules, and communication.
  • To authenticate you and keep your account secure, including optional two-factor authentication.
  • To send transactional emails (password resets, notifications you've opted into).
  • To generate an AI-written project update when you explicitly click "Generate AI Update" — see Section 6 for what that sends to a third-party AI provider.
  • To respond to support requests.
  • To understand how the product is used (which pages get visited, how often people log in, and a coarse sense of where our users are located) — logged directly by our own servers, not through a third-party analytics tool or a tracking cookie. Used internally for product decisions, not shared or sold.

We do not sell personal data, and we do not use your data for advertising.

4. Who we share data with

We share data only with the service providers that operate Buildocker, and only what each needs to do its job:

  • Supabase — our database, authentication, and file storage provider.
  • Vercel — hosting and content delivery.
  • Anthropic (Claude API) — only when you use "Generate AI Update," and only the project details relevant to that update, never your account credentials.
  • Sentry — error monitoring, to help us find and fix bugs. May include technical error details, not your content.
  • Meta (WhatsApp Cloud API) — only if a contractor chooses to send a quotation via WhatsApp, and only the recipient's phone number and quotation link.
  • Hostinger — to deliver transactional emails on our behalf.

We do not share data with data brokers or advertisers. We may disclose data if legally required to (e.g. a valid court order).

5. Where your data is stored

Your data is stored on servers operated by our infrastructure providers (Supabase and Vercel). Some of these providers operate outside India, so your data may be processed outside India. If you need the exact hosting region before using the service, contact us and we will confirm it.

6. AI features

The "Generate AI Update" feature sends relevant project details — the project name, status, budget, recent timeline notes, and a recent photo count, never your login credentials or payment information — to Anthropic's Claude API to write a client-facing update. When a contractor triggers it, the generated update is posted to the project timeline and project members are notified immediately; it is not held for review first. AI-generated text may be inaccurate, so contractors should read what was posted and edit or remove it if it is wrong. The feature is rate-limited, and the project data sent to the model is length-capped and treated strictly as data rather than as instructions.

7. Your rights

Under the DPDP Act, you have the right to:

  • Access and download your data — use "Download my data" in Settings for a machine-readable copy of everything associated with your account.
  • Correct your data — edit your profile directly at any time.
  • Delete your account — use "Delete my account" in Settings. This removes your personal information (name, email, phone, profile details) and signs you out permanently. Records that other users legitimately depend on (e.g. a photo you uploaded to a shared project) are kept but re-attributed to "Deleted User" rather than removed outright, since deleting them would break other people's project history. This can't be undone.
  • Withdraw consent for any processing that relies on it — including clearing a previously-shared precise location at any time from Settings.
  • Lodge a complaint with our Grievance Officer (Section 9) or the Data Protection Board of India.

8. Data retention

We retain your data for as long as your account is active. If you delete your account, personal identifiers are removed or anonymized as described in Section 7; some project-related records may be retained in anonymized form for the legitimate business purposes of other users on shared projects (e.g. a contractor's financial/project history). Once we begin charging for the service, records required for tax and accounting purposes will be retained for the period Indian law requires, even after account deletion.

9. Grievance Officer

In accordance with the IT Act and DPDP Act, complaints or questions about this policy can be directed to:

Until Buildocker is formally registered, grievances and questions about this policy should be sent to support@buildocker.com, and are handled directly by the individual who operates the service. A named Grievance Officer and registered address will be published here before Buildocker is offered commercially.

10. Security

We take security seriously — concretely, not just as a policy statement:

  • All traffic is encrypted in transit (HTTPS/TLS).
  • Passwords are handled by our authentication provider using industry-standard hashing — we never see or store them in plain text.
  • Optional two-factor authentication (TOTP) is available on every account.
  • Access to your data is enforced at the database level (row-level security), not just in application code.
  • A Content Security Policy and other browser security headers are enforced on every page.
  • File uploads are validated against their actual content, not just a claimed file type.
  • We run automated dependency and code security scanning.

No system is perfectly secure. If we become aware of a data breach affecting your personal data, we will notify you and the Data Protection Board of India as required by the DPDP Act.

11. Children's data

Buildocker is a business tool for construction professionals and their clients, and isn't directed at or intended for use by children.

12. Changes to this policy

We'll update the "Last updated" date above when this policy changes, and notify account holders of material changes.

13. Contact

Buildocker is an independent product operated by an individual based in India. It is not yet incorporated as a company. You can reach us at support@buildocker.com.