Privacy Policy

Last updated: 23 February 2026

BuildShield Ltd (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use the BuildShield platform, website, and services (the “Platform”). By using the Platform, you consent to the practices described in this policy.

1. Data Controller

BuildShield Ltd is the data controller for personal information collected through the Platform. We are registered in England and Wales. For data protection enquiries, contact us at privacy@buildshield.uk.

2. Information We Collect

Information you provide directly:

  • Account registration details: name, email address, phone number, postal address, and account type (Customer, Tradesman, or Assessor).
  • Tradesman-specific information: business name, trade specialisations, qualifications, trade certificates, licences, insurance documentation, and company registration details.
  • Project information: project descriptions, quotes, contracts, milestone details, checklists, invoices, and related documents.
  • Communications: messages sent through the on-platform messaging system, support requests, and feedback.
  • Payment information: billing details processed securely by Stripe. We do not store full card numbers on our servers.
  • Assessment reports: inspection grades, quality reports, and assessor notes submitted through the Platform.
  • Reviews and ratings: customer reviews and satisfaction scores for completed projects.

Information collected automatically:

  • Device and browser information: IP address, browser type, operating system, and device identifiers.
  • Usage data: pages visited, features used, timestamps, click patterns, and session duration.
  • Location data: approximate location derived from IP address for directory search and lead matching.
  • Cookies and similar technologies: see Section 9 below.

3. How We Use Your Information

We use your personal information to:

  • Provide and operate the Platform, including account management, project management, and payment processing.
  • Verify tradesman qualifications and certificates using AI-assisted verification.
  • Facilitate escrow payments through Stripe, including holding, releasing, and refunding funds.
  • Match customers with qualified tradesmen through the directory and lead system.
  • Enable independent assessor inspections and publish assessment grades on tradesman profiles.
  • Generate and store digital contracts, invoices, receipts, and project documents.
  • Operate the review and rating system, including dual customer and assessor scoring.
  • Facilitate dispute resolution using stored audit trail data.
  • Send transactional notifications (project updates, payment confirmations, assessment results) via email and SMS.
  • Send marketing communications where you have opted in (you may unsubscribe at any time).
  • Improve the Platform, develop new features, and perform analytics.
  • Comply with legal obligations and enforce our Terms of Service.

4. Legal Basis for Processing

We process your personal information under the following legal bases (UK GDPR):

  • Contract performance: processing necessary to provide the Platform services you have signed up for, including escrow payments, project management, and assessor scheduling.
  • Legitimate interests: improving the Platform, fraud prevention, security, analytics, and lead matching, where these interests do not override your rights.
  • Consent: marketing communications, non-essential cookies, and optional data sharing.
  • Legal obligation: compliance with tax, accounting, anti-money laundering, and other regulatory requirements.

5. Who We Share Your Information With

We may share your personal information with:

  • Other Platform users: Customers can see Tradesman profiles including qualifications, reviews, assessor grades, and company details. Tradesmen can see relevant Customer project details. Assessor reports are published on Tradesman profiles.
  • Stripe: our payment processor, to facilitate escrow payments and fund releases. Stripe processes payment data under their own privacy policy.
  • Resend: our email service provider, to deliver transactional and notification emails.
  • Twilio: our SMS provider, to deliver text notifications for project updates and payment alerts.
  • Firebase / Google Cloud: our database and authentication infrastructure provider.
  • Vercel: our hosting provider.
  • Professional advisors: lawyers, accountants, and auditors where necessary.
  • Law enforcement: where required by law, court order, or regulatory request.

We do not sell your personal information to third parties. We do not share your data with advertisers.

6. Data Retention

We retain your personal information for as long as necessary to provide the Platform services and fulfil the purposes described in this policy. Specifically:

  • Account data: retained for the duration of your account and for 2 years after account closure.
  • Project data (contracts, invoices, assessments, messages, audit trails): retained for 7 years after project completion for legal and regulatory compliance.
  • Payment records: retained for 7 years in accordance with HMRC requirements.
  • Marketing preferences: retained until you unsubscribe or withdraw consent.

After the retention period, data is securely deleted or anonymised.

7. Your Rights

Under UK GDPR, you have the following rights:

  • Access: request a copy of the personal information we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your data, subject to legal retention requirements.
  • Restriction: request that we limit processing of your data in certain circumstances.
  • Portability: request your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests or direct marketing.
  • Withdraw consent: where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact privacy@buildshield.uk. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including encryption in transit (TLS/SSL), secure authentication via Firebase Auth, Stripe PCI-DSS compliant payment processing, access controls and audit logging, and regular security reviews. While we take reasonable precautions, no method of transmission over the internet is 100% secure.

9. Cookies

We use cookies and similar technologies for:

  • Essential cookies: required for Platform functionality, authentication, and security. These cannot be disabled.
  • Analytics cookies: to understand how users interact with the Platform and improve the experience. These are only set with your consent.

We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings.

10. International Transfers

Your data is primarily processed within the United Kingdom and European Economic Area. Where data is transferred outside the UK/EEA (for example, to US-based service providers such as Stripe, Firebase, and Vercel), we ensure appropriate safeguards are in place, including Standard Contractual Clauses and adequacy decisions where applicable.

11. Children's Privacy

The Platform is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or Platform notification at least 14 days before taking effect. The “Last updated” date at the top of this page indicates when the policy was last revised.

13. Contact Us

For any privacy-related questions or to exercise your data rights, contact us at:

BuildShield Ltd
Email: privacy@buildshield.uk
Website: buildshield.uk