Who this policy applies to
This policy applies to visitors, homeowners, tradespeople and other users of the BuildPair website and apps.
Depending on how you use BuildPair, information may include account identifiers, contact details, profile and business information, job posts, photos, messages, site-visit arrangements, quotes, payment stages, invoices, reviews, approximate service locations, technical logs, website and app usage, AI requests and generated responses, autosaved form-draft information used for draft recovery and product improvement, and payment-related references supplied by payment providers.
We use information to create and secure accounts, provide marketplace matching, operate profiles and jobs, enable communication, administer project stages and payments, provide and improve AI-assisted features, prevent abuse and fraud, provide support, understand where visitors and users encounter friction or leave important BuildPair journeys unfinished, improve the service and comply with legal obligations.
Anonymous visitor analytics
When someone visits the BuildPair website without signing in, BuildPair may collect privacy-conscious statistical information about how the service is used. This can include pages viewed, meaningful button or link clicks, scroll-depth milestones, time spent on pages, which named form fields were reached, referral source, campaign parameters, broad device type, browser and operating-system category, language, timezone, screen or viewport size bands, connection category and coarse country, region or city signals where the hosting or network layer supplies them. Basic analytics is aggregated and is used only to understand and improve BuildPair. BuildPair does not use basic analytics to identify or profile individual visitors.
Detailed anonymous journeys
Visitors can optionally choose to allow detailed analytics. Where they do, BuildPair creates an anonymous visitor identifier and session identifier so an authorised administrator can see the sequence of pages, meaningful clicks, scroll milestones and named form fields reached during that visit, whether the visit appears to have converted into a sign-in or signup, and whether the visitor returned during the limited identifier lifetime. This detailed journey tracking is only enabled after the visitor actively chooses it and can be turned off from the Analytics choices control. BuildPair does not use device fingerprinting to recreate an identifier after a visitor turns detailed analytics off.
What visitor analytics deliberately excludes
BuildPair visitor analytics does not record passwords, authentication secrets, payment-card or bank-account details, the contents typed into form fields, raw IP addresses, mouse-movement recordings, hidden keystroke recordings or precise GPS coordinates. Coarse location may be shown only when the infrastructure supplying the website provides a broad country, region or city signal. Exact device location is not silently requested for analytics.
Analytics choices and objection
The website provides an Analytics choices control. Visitors can use basic aggregate analytics, actively allow detailed journey analytics, or turn analytics off. A small preference value may be stored on the device solely to remember that choice. If detailed analytics is later turned off, BuildPair removes the local anonymous identifiers and requests deletion of detailed journey records associated with that stored anonymous visitor identifier. Aggregate statistics that no longer identify an individual visitor cannot be separated back out by person.
Signed-in product analytics and unfinished journeys
For signed-in users, BuildPair may record the pages and product steps used, the time of recent activity, device platform and whether important journeys such as posting a job or building a trade profile appear to have been started, completed or left unfinished. This helps BuildPair identify confusing pages, failed journeys and features that need improvement. BuildPair does not use this feature to record passwords, payment-card details, bank details or secret keystroke-by-keystroke recordings.
Some multi-step forms may save a limited draft so a user can recover unfinished work. Where server-side draft recovery is used, BuildPair limits the fields stored for product analysis and support. Sensitive authentication and payment credentials are excluded. Draft information is available only to the user through the relevant feature and to authorised administrators where reasonably needed to support the service, investigate a failed journey or improve BuildPair.
Payments, payouts and Stripe
BuildPair uses Stripe for supported payments, tradesperson onboarding and payouts. Information entered directly into Stripe payment or onboarding interfaces, including payment, bank-account and verification information, is collected by Stripe under the terms and privacy information Stripe presents to the user. BuildPair does not store raw payment-card or bank-account numbers entered into those Stripe interfaces.
Payment information BuildPair receives
BuildPair receives and stores the references and status information needed to operate and reconcile the payment workflow. This can include Stripe customer and connected-account identifiers, PaymentIntent and charge references, transfer, refund and dispute identifiers, payment amounts, stage status, fees and payout-readiness status.
Payment-stage and dispute records
For jobs using BuildPair payments, BuildPair may record when a payment stage is proposed, agreed, funded, marked complete, approved for release, transferred, disputed, refunded or otherwise changed. These records may be used for transaction reconciliation, support, fraud prevention, disputes, accounting and legal compliance.
AI-assisted features and request review
When a BuildPair AI-assisted feature is used, BuildPair may store the request or relevant job/conversation context supplied to that feature together with the generated response, technical status, model and timing information. Authorised administrators may review recent AI requests and responses to detect abuse, investigate failures, understand how people use the feature and improve BuildPair. BuildPair applies automated redaction for common secret and API-key patterns before these AI audit records are stored, but users should still avoid entering passwords, payment credentials, API keys or other unnecessary secrets into AI fields. AI audit records are normally retained for up to 90 days.
AI-assisted chat and safety analysis
Messages in BuildPair job conversations may be analysed by automated systems to provide optional reply suggestions, identify possible scams, threats, targeted abuse or other behaviour that may breach marketplace rules, and help prioritise moderation review. Automated analysis can make mistakes. BuildPair may place a warning or temporary messaging restriction on a conversation where risk indicators are detected, and serious or disputed cases may be reviewed by an authorised human moderator. Users remain responsible for checking any AI-generated draft before sending it.
Tradesperson profile information and public marketplace content may be visible to other users or visitors where that is part of the feature. Do not publish sensitive personal information in public profile fields, job descriptions or photos.
BuildPair uses specialist providers for functions such as authentication, hosting, databases, payments, email delivery, media storage and AI-assisted features. These providers process information for the services they supply and may also have their own legal obligations and privacy terms. Stripe’s own privacy information applies to data it collects directly through its payment and onboarding services.
Information is kept only for as long as reasonably needed for the purpose for which it is used, including account operation, draft recovery, product improvement, dispute handling, fraud prevention, legal compliance, transaction reconciliation and financial record keeping. AI request audit records are normally retained for up to 90 days. Anonymous detailed analytics identifiers are intentionally time-limited, while aggregate analytics may be retained longer because it is designed not to identify individual visitors. Project-payment and dispute records may therefore be retained after a job or account is otherwise inactive where this is reasonably necessary.
Subject to applicable law, you may have rights to access, correct, erase or restrict use of personal information, object to certain processing, or request portability. Some rights are subject to legal exceptions and retention requirements, including records that must be kept for financial, fraud-prevention or legal purposes.
BuildPair uses technical and organisational safeguards appropriate to the service and limits raw payment credential handling by using specialist payment-provider interfaces. No internet service can guarantee absolute security, so users should also protect their login credentials and devices.
Privacy enquiries and requests can be sent to info@buildpair.co.uk. If you remain unhappy with how personal information is handled, you may also have the right to complain to the UK Information Commissioner’s Office.