Legal
Privacy & Security Policy
Version 1.0 · Last updated March 10, 2026
BuildSupply, Inc. (“BuildSupply,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal and business information. This policy describes how we collect, use, store, and protect data when you use our platform, and outlines your rights as a customer. By using our services, you agree to the practices described herein.
1. Information We Collect
Account & Contact Information
When you register or place an order, we collect:
- Full name, business name, email address, and phone number
- Billing and shipping addresses
- Account credentials (passwords are hashed using bcrypt — we never store plain-text passwords)
- Job title and company role where provided
Transaction & Order Data
We retain complete records of your:
- Orders, order items, quantities, and pricing
- Quote requests and custom pricing agreements
- Applied promotional codes and discount history
- Wishlists and saved product lists
Usage & Behavioral Data
- Products viewed and browsing patterns (used to power recommendations)
- Search queries within the platform
- Device type, browser, and approximate geographic region (derived from IP)
- Session timestamps and page interactions
Communications
- Contact form submissions and support inquiries
- Quote communications and negotiation history
- Job applications, including uploaded resumes (stored securely in our database)
2. How We Use Your Information
To Fulfill Your Orders
We use your information to process purchases, generate quotes, send order confirmations, manage shipping and returns, and provide customer support.
To Personalize Your Experience
Browsing and order history powers features like “Recently Viewed” and “Similar Products.” We do not sell this data to third parties or use it for cross-site advertising.
To Communicate with You
- Transactional emails: order confirmations, quote updates, shipping notifications
- Account security alerts: password changes, suspicious login attempts
- Service updates: policy changes, platform maintenance
- Marketing communications: only with your explicit consent, and always with an unsubscribe option
To Improve Our Platform
Aggregated, anonymized usage data helps us improve search relevance, catalog organization, and site performance. No individual customer is identified in this analysis.
3. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information. We share data only with:
Service Providers
- Neon (database hosting) — stores all platform data in SOC 2 compliant infrastructure on Azure
- Vercel (application hosting) — serves the BuildSupply platform
- Resend (email delivery) — sends transactional emails; no access to order or account data
Legal Requirements
We may disclose information if required by law, court order, or to protect the rights and safety of BuildSupply, our customers, or the public.
Business Transfers
In the event of a merger, acquisition, or sale of assets, customer data may transfer to the acquiring entity under the same protections described in this policy.
4. Data Security
Technical Safeguards
- All data transmitted via HTTPS/TLS encryption
- Database access restricted to application-level credentials; no direct public access
- Passwords hashed using bcrypt with a cost factor of 12
- Session tokens signed with a secure secret and expire after 7 days
- Admin panel restricted to authorized personnel with role-based access control
- Resume files stored as encrypted base64 in the database — never publicly accessible
Organizational Safeguards
- Production system access limited to essential personnel only
- All admin actions are logged and auditable via the Error Logs system
- Security incidents are reviewed and remediated promptly
- Error logs retained for debugging and purged on a rolling 90-day basis
Breach Notification
In the event of a data breach that materially affects your personal information, we will notify affected customers within 72 hours of discovery via the email address on file.
5. Cookies & Tracking
Essential Cookies
We use a session cookie (bs_token) to maintain your logged-in state. This cookie is strictly necessary for the platform to function and cannot be disabled while you are signed in.
Preference Storage
We store your admin theme preference (admin-theme) in localStorage to preserve your light/dark mode choice across sessions.
Analytics
We do not use third-party analytics platforms (e.g., Google Analytics). All usage data is stored in our own database and not shared with advertising networks.
Your Consent
By continuing to use the BuildSupply platform after being presented with our consent notice, you acknowledge this policy and consent to the data practices described above.
6. Data Retention
- Account data: retained for the life of your account, plus 3 years after closure
- Order records: retained for 7 years to meet commercial and tax record-keeping requirements
- Quote history: retained for 5 years
- Job applications: retained for 2 years after submission; resumes deleted upon request
- Contact form submissions: retained for 1 year
- Error logs: rolling 90-day retention
- Product view history: retained for 18 months
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate or incomplete information
- Deletion — Request erasure of your data (subject to legal retention requirements)
- Portability — Receive your data in a structured, machine-readable format
- Objection — Object to processing for marketing purposes at any time
- Withdrawal — Withdraw consent without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at privacy@buildsupply.com. We will respond within 30 days.
8. Children's Privacy
BuildSupply is a B2B platform intended for businesses and professionals. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with information, contact us at privacy@buildsupply.com immediately.
9. International Users
BuildSupply is operated from the United States. If you access our platform from outside the U.S., your data will be transferred to and processed in the U.S. in accordance with this policy and applicable data protection laws.
10. Changes to This Policy
We may update this policy periodically. When we do:
- The version number and Last Updated date will be revised
- Existing logged-in users will see the consent banner again on their next visit
- Material changes will be communicated via email
- Continued use of the platform constitutes acceptance of the revised policy
Contact Our Privacy Team
For privacy requests, data inquiries, or security concerns: