This policy explains what BuildMindHQ collects, why, who it is shared with, and how to get rid of it. It also explains the part that matters most for a CRM: what happens to the records your customers appear in. It is written to be read, not survived.
Insert the operating legal entity and registered business address here. Payment processors, app reviewers and enterprise buyers all check this page, and a policy with no named operator and no contact address is a common rejection reason. Replace this box with, for example: “BuildMindHQ is operated by [Legal Entity Name], [street address, city, state, ZIP, country].”
1. Two kinds of data, two different roles
BuildMindHQ is a multi-tenant CRM. Every company that uses it gets its own organisation — its own logins, its own records, its own isolated data. That produces two distinct relationships, and they are governed differently.
- Your account with us. Your email, your role, your organisation's settings and billing state. We decide how that is handled, and this policy governs it.
- The records you put into the CRM. Your customers, projects, estimates, invoices, files and notes. That is your data about your business. You decide what goes in and what it is used for; we hold and process it on your behalf, under your instructions. See section 4.
2. What we collect
Everything below is either something a person on your team typed into the app, something your organisation configured, or a record the system created as a by-product of an action someone took.
| Category | What it is |
|---|---|
| Account | Your email address and an encrypted password hash. We never store your password in readable form. |
| Organisation | The company name and slug chosen at onboarding, the branding settings (primary colour, and the logo and custom-domain fields where set), the plan tier, and the AI token balance. |
| Membership | Which organisation each user belongs to and their role — owner, admin or staff — plus pending invitations by email address. |
| Customer records | The contacts and projects your team enters: names, contact details, addresses, pipeline stage, notes and internal notes. |
| Commercial records | Price book items with your costs and markups, estimates and their line items, invoices, recorded payments, change orders and purchase orders. |
| Job records | Job timelines, checklists, materials, crew questions, daily field logs, and files or photos uploaded against a job. |
| AI requests | The input you submitted to an AI feature and the output it produced, kept so the result can be reviewed rather than trusted blind. Site photos submitted to the Vision Estimator are stored in a private bucket scoped to your organisation. |
| Activity log | Who did what and when for team-management actions — invites, role changes, removals — recorded automatically and attributed to the acting user. |
| Technical | Standard server and error logs generated by our infrastructure providers when the application is used. |
We do not collect your device identifiers for advertising, your location, your contacts, or your browsing activity on other sites. We do not use tracking cookies for advertising, we do not build profiles for marketing, and we do not sell data to anyone, ever.
3. Why we collect it
- To run your account — authenticate each user and keep your organisation's records separate from every other organisation's.
- To provide the CRM — the records are the product. A pipeline with no contacts in it does nothing.
- To price and invoice — your price book drives estimate maths; estimates become invoices; invoices become payment links.
- To answer questions about your own jobs — the AI features read the data you already hold so that what they return is grounded in it rather than generic.
- To keep your team accountable — the activity log exists so an owner can see who changed a role or removed a member.
- To keep the service running and secure — diagnose faults, meter usage, and enforce your subscription state.
4. Your customers' records
Most of what sits in BuildMindHQ is information about people who are your customers, not ours. They never signed up with us, and typically will never hear our name.
For that data you are the controller and we are the processor. In plain terms:
- You decide what goes in. We do not require any particular field, and we do not go looking for more.
- We act on your instructions. We use it to run the service for you and for nothing else. We do not use your customers' records to train models, to market to them, or to inform anything outside your organisation.
- You are responsible for having the right to hold it. Telling your customers how you handle their information, and having a lawful basis for it, is your job, not ours.
- If one of your customers contacts us asking about their data, we will point them to you, and tell you they asked. We will not act on a record inside your organisation without your instruction, except where the law compels us.
Internal notes are marked internal and are not exposed to anyone outside your team. Files carry an explicit visibility setting. Those distinctions are enforced in the data model, not by a screen remembering to hide something.
5. How the AI features use your data
The AI features send data to Anthropic, our AI provider, so it can produce a result. What gets sent depends on the feature:
| Feature | What is sent |
|---|---|
| Assistant | Your message, the conversation so far, and — where relevant — context about the job you are looking at. |
| Vision Estimator | The site photo you supplied and your organisation's price book items, so the estimate is priced against your real catalogue rather than an invented one. |
| Permit Drafter | The project address, jurisdiction and project type you entered. This feature also performs live web searches on those terms. |
| Field log | The field notes you pasted and the project they belong to. |
We do not send your password, your team's role assignments, your invoice payment records or your billing details to the AI provider. Every AI feature can be left unconfigured, in which case it does nothing at all rather than falling back to a lesser service you did not ask for.
AI output is written into review tables and is not applied to your live pipeline automatically. A person on your team reads it first.
6. Payments
Where your organisation uses the invoice payment feature, the payment itself is handled by Stripe. Your customer enters their card details on Stripe's own checkout page. Card numbers never reach BuildMindHQ, and we never store them. We keep the invoice, the amount, and the fact that it was paid.
7. Who we share data with
Only the service providers required to make the product work:
| Provider | What they handle |
|---|---|
| Supabase | Database, authentication, file storage and the server functions the application calls. |
| Anthropic | The AI features, as described in section 5. |
| Stripe | Invoice payments and, where used, contractor payout onboarding. |
We may also disclose information where we are legally required to. We do not sell, rent or trade personal data, and we do not share it for anyone else's advertising.
8. How long we keep it
- While your organisation is active — we keep your records so the product works. A CRM that forgets last year's jobs is not a CRM.
- When a member is removed — their link to your organisation is cleared immediately. The records they created stay with the organisation, because they are the organisation's records.
- On organisation deletion — contacts, projects, estimates, invoices, jobs, files, price book, logs and AI request history are permanently deleted within 30 days.
- Backups — residual copies may persist in encrypted backups for a short period after deletion, before being overwritten on the normal backup cycle.
- Records we must keep by law — billing and tax records, retained only as long as the law requires.
9. Security and tenant isolation
Every core record carries an organisation id, and database-level row security rules filter every read and write by the calling user's organisation. That isolation is enforced by the database itself rather than by application code remembering to check — which means a bug in a screen cannot leak another company's rows.
The paths that could move a user between organisations, or change their role, are handled by specific database functions with their own permission checks. Editing those columns directly is revoked outright, not merely discouraged. An organisation's last owner cannot be demoted or removed.
Data is encrypted in transit. Provider credentials and API keys are held server-side and are never exposed to the client application.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your data we will tell you, and we will tell you what we know rather than what is comfortable.
10. Your rights
Wherever you live, we will honour these in respect of your own account data:
- Access — ask for a copy of what we hold about you.
- Correction — most of it you can edit directly in the app; ask us for the rest.
- Deletion — see the data deletion instructions.
- Portability — ask for your organisation's records in a machine-readable format.
- Object — tell us to stop a particular processing activity.
Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or state privacy laws such as the CCPA. Write to us and we will apply whichever gives you more protection. We respond within 30 days and we do not charge for it.
Requests about a record inside a customer's organisation go to that organisation, not to us — see section 4.
11. Children
BuildMindHQ is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
If we change this policy we will update the date at the top. For any change that materially affects how we handle your data, we will email you before it takes effect.
13. Contact
Privacy questions, requests, or complaints: privacy@buildmindhq.com · anything else: hello@buildmindhq.com