Skip to content

Privacy Policy

Version 1· effective Sep 5, 2026Template — review with counsel before launch

What we collect, why, and the controls you have.

Privacy Policy

Template notice. This document is a template provided with the BuildMarket platform. It has not been reviewed by counsel for your jurisdiction or business. Replace or approve it in the admin panel before public launch.

Last updated: 2026-09-05

What we collect

  • Account data: name, email, password hash, optional profile details.
  • Project data you connect: repository metadata and derived metrics (languages, file counts, commit activity, dependency health, test presence, secret-pattern findings). We do not permanently store complete copies of private repositories.
  • Revenue and usage metrics: aggregate metrics (for example MRR, active subscriptions) read from providers you connect (Stripe, RevenueCat, Paddle, Lemon Squeezy). We do not import your end customers' personal data.
  • Transaction data: bids, offers, transactions, escrow status, transfer checklist events, messages, files you upload to deal rooms.
  • Technical data: hashed IP addresses and hashed device identifiers for security (suspicious-login detection, fraud prevention). We do not store raw IP addresses in analytics.
  • Analytics: first-party product analytics events (page views, funnel steps). No third-party advertising trackers.

Why we process it

To operate the marketplace, generate valuations, run auctions and transactions, prevent fraud, send transactional notifications, comply with law, and improve the product. Where required we rely on consent (for example marketing emails), contract performance, legal obligation, or legitimate interests (security, fraud prevention).

Sharing

  • With the escrow provider and payment processor to complete transactions.
  • With counterparties: sellers and buyers see each other's display name and what they share in deal rooms or messages. We do not reveal your email address by default.
  • With service providers (hosting, email delivery, error monitoring) under data processing terms.
  • When required by law or to protect rights and safety.

Your controls

  • Privacy settings: choose what listing metrics are public, whether your portfolio is public, and notification preferences.
  • Integrations: disconnect any integration at any time; we delete the associated OAuth credentials immediately.
  • Export: download a copy of your data from Settings → Privacy.
  • Deletion: delete your account from Settings → Privacy. Deletion is verified by email and completes once active transactions are finished. Some records (transaction logs, invoices, legal acceptances) are retained as required by law.

Retention

Account data for the life of the account. Transaction and audit records for the period required by tax and commercial law. Analytics events are pseudonymous and aggregated after 24 months.

International transfers

Where data leaves your region we use appropriate safeguards such as standard contractual clauses.

Contact

legal@buildmarket.com. If you are in the EU/UK you may also contact your local supervisory authority.