Free shipping on orders $500+
Sign InCreate AccountContact Us
BuildSupply
Cart

Legal

Privacy & Security Policy

Version 1.0  ·  Last updated March 10, 2026

BuildSupply, Inc. (“BuildSupply,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal and business information. This policy describes how we collect, use, store, and protect data when you use our platform, and outlines your rights as a customer. By using our services, you agree to the practices described herein.

1. Information We Collect

Account & Contact Information

When you register or place an order, we collect:

  • Full name, business name, email address, and phone number
  • Billing and shipping addresses
  • Account credentials (passwords are hashed using bcrypt — we never store plain-text passwords)
  • Job title and company role where provided

Transaction & Order Data

We retain complete records of your:

  • Orders, order items, quantities, and pricing
  • Quote requests and custom pricing agreements
  • Applied promotional codes and discount history
  • Wishlists and saved product lists

Usage & Behavioral Data

  • Products viewed and browsing patterns (used to power recommendations)
  • Search queries within the platform
  • Device type, browser, and approximate geographic region (derived from IP)
  • Session timestamps and page interactions

Communications

  • Contact form submissions and support inquiries
  • Quote communications and negotiation history
  • Job applications, including uploaded resumes (stored securely in our database)

2. How We Use Your Information

To Fulfill Your Orders

We use your information to process purchases, generate quotes, send order confirmations, manage shipping and returns, and provide customer support.

To Personalize Your Experience

Browsing and order history powers features like “Recently Viewed” and “Similar Products.” We do not sell this data to third parties or use it for cross-site advertising.

To Communicate with You

  • Transactional emails: order confirmations, quote updates, shipping notifications
  • Account security alerts: password changes, suspicious login attempts
  • Service updates: policy changes, platform maintenance
  • Marketing communications: only with your explicit consent, and always with an unsubscribe option

To Improve Our Platform

Aggregated, anonymized usage data helps us improve search relevance, catalog organization, and site performance. No individual customer is identified in this analysis.

3. Data Sharing & Third Parties

We do not sell, rent, or trade your personal information. We share data only with:

Service Providers

  • Neon (database hosting) — stores all platform data in SOC 2 compliant infrastructure on Azure
  • Vercel (application hosting) — serves the BuildSupply platform
  • Resend (email delivery) — sends transactional emails; no access to order or account data

Legal Requirements

We may disclose information if required by law, court order, or to protect the rights and safety of BuildSupply, our customers, or the public.

Business Transfers

In the event of a merger, acquisition, or sale of assets, customer data may transfer to the acquiring entity under the same protections described in this policy.

4. Data Security

Technical Safeguards

  • All data transmitted via HTTPS/TLS encryption
  • Database access restricted to application-level credentials; no direct public access
  • Passwords hashed using bcrypt with a cost factor of 12
  • Session tokens signed with a secure secret and expire after 7 days
  • Admin panel restricted to authorized personnel with role-based access control
  • Resume files stored as encrypted base64 in the database — never publicly accessible

Organizational Safeguards

  • Production system access limited to essential personnel only
  • All admin actions are logged and auditable via the Error Logs system
  • Security incidents are reviewed and remediated promptly
  • Error logs retained for debugging and purged on a rolling 90-day basis

Breach Notification

In the event of a data breach that materially affects your personal information, we will notify affected customers within 72 hours of discovery via the email address on file.

5. Cookies & Tracking

Essential Cookies

We use a session cookie (bs_token) to maintain your logged-in state. This cookie is strictly necessary for the platform to function and cannot be disabled while you are signed in.

Preference Storage

We store your admin theme preference (admin-theme) in localStorage to preserve your light/dark mode choice across sessions.

Analytics

We do not use third-party analytics platforms (e.g., Google Analytics). All usage data is stored in our own database and not shared with advertising networks.

Your Consent

By continuing to use the BuildSupply platform after being presented with our consent notice, you acknowledge this policy and consent to the data practices described above.

6. Data Retention

  • Account data: retained for the life of your account, plus 3 years after closure
  • Order records: retained for 7 years to meet commercial and tax record-keeping requirements
  • Quote history: retained for 5 years
  • Job applications: retained for 2 years after submission; resumes deleted upon request
  • Contact form submissions: retained for 1 year
  • Error logs: rolling 90-day retention
  • Product view history: retained for 18 months

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — Request a copy of the personal data we hold about you
  • Correction — Request correction of inaccurate or incomplete information
  • Deletion — Request erasure of your data (subject to legal retention requirements)
  • Portability — Receive your data in a structured, machine-readable format
  • Objection — Object to processing for marketing purposes at any time
  • Withdrawal — Withdraw consent without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at privacy@buildsupply.com. We will respond within 30 days.

8. Children's Privacy

BuildSupply is a B2B platform intended for businesses and professionals. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with information, contact us at privacy@buildsupply.com immediately.

9. International Users

BuildSupply is operated from the United States. If you access our platform from outside the U.S., your data will be transferred to and processed in the U.S. in accordance with this policy and applicable data protection laws.

10. Changes to This Policy

We may update this policy periodically. When we do:

  • The version number and Last Updated date will be revised
  • Existing logged-in users will see the consent banner again on their next visit
  • Material changes will be communicated via email
  • Continued use of the platform constitutes acceptance of the revised policy

Contact Our Privacy Team

For privacy requests, data inquiries, or security concerns:

Email

privacy@buildsupply.com

Company

BuildSupply, Inc.

Policy Version

1.0 · March 10, 2026