Privacy policy.

What personal data buildquarter handles, why we use it and who processes it.

Updated 3 September 2026
No advertising cookiesOnly an essential sign-in cookie
Card details stay with StripeWe retain payment records, not card numbers
No personal data salesYour information is not sold

Who we are and what we handle.

BUILDQUARTER LTD is the data controller for this service.

Company

Company number 17430405. Registered office: Monomark House, 27 Old Gloucester Street, London, England, WC1N 3AX.

Account and contact

Name, email, company, phone and an optional GitHub username.

Project

Proposals, specifications, milestones, tickets, comments, activity, files and links shared through the project.

Payment

Payment status, invoice details and amounts received from Stripe. Full card details do not pass through buildquarter.

Calls

Name, email, selected time and any notes provided when booking.

Technical

The essential session cookie, sign-in state and basic server logs.

Why we use it.

Each use is tied to delivering the service or protecting its records.

Project delivery

Contract

Run the buildroom and deliver the agreed software project.

Milestone payments

Contract and legal obligations

Take, reconcile and record project payments.

Service communication

Contract and legitimate interests

Send account invites, project updates and transactional emails.

Security and records

Legitimate interests and legal obligations

Prevent fraud and maintain security, accounting and dispute records.

Cookies and safeguards.

Implementation details are available in the Trust centre.

Session cookie

pl_session is an essential HttpOnly cookie used to keep you signed in. We do not use advertising cookies.

Credentials

Passwords are hashed with scrypt. Sessions are stored server-side and project access is scoped by account.

Payments

Stripe handles payment entry. buildquarter stores the resulting payment, invoice and milestone records.

Service providers.

External services used to operate buildquarter.

ProviderPurpose
StripePayments
ResendTransactional email
RailwayApplication hosting
GitHubCode hosting and repository access
JitsiVideo calls
AnthropicPlanning and summary generation
Namecheap Private EmailEmail inbox

Retention and transfers.

How long records remain and where providers may process them.

Retention

We keep account and project data while delivering the service and for a reasonable period afterwards for tax, accounting, security and dispute records. Data is deleted or anonymised when no longer needed.

International processing

Some providers may process data outside the UK or EEA. Where required, we rely on adequacy decisions, Standard Contractual Clauses or equivalent safeguards.

Policy changes

This page and its updated date will change when the policy changes.

Your rights.

You can ask to access, correct, delete, restrict, transfer or object to certain uses of your personal data.

You can also complain to the Information Commissioner's Office.

Make a privacy request