1. Information we collect
Depending on how you use the services, we may collect account and contact details, company and project information, subscription and transaction records, communications, support requests, uploaded content, device and browser data, IP address, usage events, and approximate location derived from IP. Payment providers process card details on our behalf.
2. How we use information
- provide, secure, personalize, and improve the services;
- authenticate users and enforce company and project permissions;
- process subscriptions, send service messages, and provide support;
- analyze performance, prevent fraud and abuse, and comply with law; and
- communicate about products where permitted, subject to available opt-outs.
3. Project content, confidentiality, and storage
Customers retain ownership and control of their documents and project content. Customer data is stored in BuildFlow-CM’s Supabase database environment. Supabase serves as an infrastructure and data processor for BuildFlow-CM; its processing is governed by its service terms and data-protection commitments. We do not routinely read, review, or investigate document contents and do not use them for an independent business purpose. Our systems process content only as needed to provide and secure features requested by the customer. Limited human access may occur where reasonably necessary to resolve customer-authorized support, respond to a security or abuse issue, or comply with a valid legal obligation. When a user deliberately invokes an AI-enabled feature, the content or prompts necessary for that request may be sent to an AI service provider to generate the result. Administrators and collaborators authorized by the customer may access content according to configured permissions.
4. No release of customer documents
We do not sell, publish, or voluntarily release customer documents or their contents to third parties. Documents may be handled only by confidential hosting, database, security, support, or other infrastructure providers acting as processors on our instructions; shared with users and integrations the customer authorizes; or sent to a provider when a user deliberately invokes that provider’s feature. We may disclose content if legally compelled by a valid order and, where legally permitted, will seek to notify the affected customer first. Business contact, billing, and technical information—not customer document contents—may be handled by payment, email, analytics, and similar providers as needed to operate the service. We do not sell personal information for money.
5. Cookies and local storage
We may use cookies and similar storage for authentication, preferences, security, analytics, and legal acknowledgments. Browser controls can limit these technologies, but some features may stop working.
6. Customer control and protection
BuildFlow-CM is designed to separate company and project access according to authenticated roles and permissions. Customers are responsible for choosing authorized users and administrators, removing access when it is no longer needed, and protecting account credentials. We limit our own access to personnel and processors with an operational need and appropriate confidentiality obligations. These commitments should be supported in production by tested Supabase Row Level Security policies, least-privilege service credentials, audit logging, secure backups, and an incident-response process.
7. Retention and security
We retain information for as long as reasonably necessary for the purposes described, including account operation, legal compliance, dispute handling, and security. We use administrative, technical, and organizational safeguards, but no system is completely secure. If a breach triggers a legal notification duty, we will provide notice as required by applicable law.
8. Your choices and rights
You may update account information, manage communications, or request access, correction, deletion, or another applicable privacy right by contacting us. We may verify identity and retain information where legally permitted. Organization-managed account requests may be directed to the organization administrator.
9. Children and international use
The services are intended for business users and not children under 13. Information may be processed in the United States and other places where providers operate, subject to applicable safeguards.
10. Contact
Email privacy questions or requests to support@buildflowcm.com.