Privacy Policy
Effective Date: October 8, 2025
This Privacy Policy describes how BUILDMATCH LLC ("BUILD/MATCH," "we," "our," or "us") collects, uses, discloses, and otherwise processes personal data in connection with our services.
Table of Contents
1. Introduction and Scope
BUILD/MATCH is committed to protecting your privacy and ensuring transparency in how we collect, use, and share your personal information. This Privacy Policy applies to all users of our platform, including:
- Homeowners seeking home improvement services
- Professional contractors, tradespeople, and service providers
- Visitors to our website and platform
- Users of our AI-powered project requirement gathering tools
By accessing or using BUILD/MATCH, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal data as described herein.
This Privacy Policy supplements but does not replace any other privacy notices or policies that may apply to specific services, features, or jurisdictions. For residents of California, please see Section 11 regarding your specific privacy rights under the California Consumer Privacy Act (CCPA).
2. Collection of Personal Data
2.1 Information You Provide Directly
We collect personal data that you voluntarily provide to us when you:
- Create an account: Name, email address, phone number, and password (if applicable)
- Engage with our AI chat interface: Project descriptions, home details, renovation requirements, budget information, timeline preferences, and any other information you share during conversations
- Complete your profile: Address, property information, service area, professional credentials, licenses, insurance information, and business details (for professionals)
- Make payments: Billing information, payment card details, and transaction history (processed through our third-party payment processor)
- Communicate with us: Messages, feedback, support requests, and any other correspondence
- Participate in surveys or promotions: Responses, preferences, and demographic information
2.2 Information Collected Automatically
When you access or use our services, we automatically collect certain technical and usage information:
- Device information: IP address, browser type and version, device type, operating system, unique device identifiers
- Usage data: Pages visited, features used, time spent on pages, click-through data, referral sources, search terms
- Location information: Approximate geographic location derived from IP address or precise location if you grant permission
- Cookies and similar technologies: Session cookies, persistent cookies, web beacons, and local storage for authentication, preferences, and analytics
- Chat interaction data: Message timestamps, conversation flow patterns, session duration, and interaction metrics
2.3 Information from Third-Party Sources
We may receive information about you from third-party sources, including:
- Authentication providers: If you sign in using third-party authentication services
- Public databases: Contractor licensing information, business registration data, and professional credentials from government sources
- Business partners: Marketing partners, analytics providers, and service integrations
- Social media platforms: Publicly available information if you connect your social media accounts
- Google Places API: Business information, reviews, ratings, and location data for professional service providers
3. How We Use Personal Data
We use the personal data we collect for the following purposes:
3.1 Providing and Improving Our Services
- Creating and managing your account and profile
- Processing and facilitating conversations with our AI-powered chat interface
- Generating Project Requirements Documents (PRDs) based on your project information
- Matching homeowners with qualified professional service providers
- Facilitating communication between homeowners and professionals
- Processing payments and managing transactions
- Providing customer support and responding to inquiries
- Analyzing usage patterns to improve platform functionality and user experience
3.2 AI and Machine Learning Development
- Training, testing, and improving our AI models and algorithms
- Enhancing the quality and accuracy of AI-generated content and recommendations
- Developing new features and capabilities based on usage patterns
- Creating anonymized datasets for research and development purposes
3.3 Communication and Marketing
- Sending transactional emails related to your account and projects
- Providing project updates, match notifications, and service reminders
- Sending marketing communications about new features, services, and promotions (with your consent)
- Conducting surveys and gathering feedback to improve our services
3.4 Security, Fraud Prevention, and Legal Compliance
- Detecting, preventing, and investigating fraud, abuse, and security incidents
- Verifying professional credentials, licenses, and insurance information
- Enforcing our Terms of Service and other policies
- Complying with legal obligations, court orders, and regulatory requirements
- Protecting the rights, property, and safety of our users and the public
3.5 Analytics and Business Operations
- Analyzing platform performance, user engagement, and business metrics
- Conducting market research and competitive analysis
- Managing business operations, planning, and strategic decision-making
- Preparing aggregated, anonymized reports and statistics
4. How We Disclose Personal Data
We do not sell your personal data to third parties. We may disclose your personal data in the following circumstances:
4.1 Service Providers and Business Partners
We share personal data with trusted third-party service providers who perform services on our behalf, including:
- Cloud infrastructure providers: Hosting, storage, and computing services
- Payment processors: Processing payments and managing subscriptions (e.g., Stripe)
- AI service providers: Anthropic Claude API for conversational AI and content generation
- Communication services: Email delivery, SMS notifications, and customer support tools
- Analytics providers: Usage analytics, performance monitoring, and error tracking
- Security services: Fraud detection, security monitoring, and threat prevention
These service providers are contractually obligated to use your personal data only for the purposes we specify and to maintain appropriate security measures.
4.2 Matched Professionals
When a professional purchases access to your project:
- We share your Project Requirements Document (PRD) with the professional
- Your contact information (name, email, phone number) is disclosed to facilitate project discussions
- Project details, timeline, budget information, and requirements are shared as specified in the PRD
- We limit access to a maximum of 3 professionals per project to ensure quality matches
4.3 Legal Obligations and Protection
We may disclose personal data when required by law or when we believe disclosure is necessary to:
- Comply with legal process, court orders, or government requests
- Enforce our Terms of Service and other agreements
- Protect the rights, property, or safety of BUILD/MATCH, our users, or the public
- Detect, prevent, or investigate fraud, security breaches, or illegal activities
- Respond to claims of intellectual property infringement
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your personal data may be transferred to the successor entity. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
4.5 With Your Consent
We may share your personal data for other purposes with your explicit consent or at your direction.
5. AI Model Training and Development
5.1 Use of Conversation Data
BUILD/MATCH uses advanced AI technology to power our conversational interface and generate Project Requirements Documents. To improve our services:
- We may use anonymized and aggregated conversation data to train and improve our AI models
- Personally identifiable information (PII) is automatically detected and removed before data is used for training
- We employ AWS Comprehend and other PII detection services to scrub sensitive information
- Training data is stored securely and access is restricted to authorized personnel only
5.2 Third-Party AI Services
We utilize Anthropic's Claude API to power our conversational AI capabilities. When you interact with our chat interface:
- Your messages are sent to Anthropic's Claude API for processing and response generation
- Anthropic processes this data in accordance with their own privacy policy and data processing agreement
- We have contractual agreements with Anthropic to protect your data and limit its use
- Anthropic does not use our customer data to train their general AI models without explicit permission
5.3 Data Minimization and Retention
We practice data minimization and only retain conversation data for as long as necessary to provide our services, improve our AI models, and comply with legal obligations. You may request deletion of your conversation history at any time, subject to our legitimate business needs and legal requirements.
6. Your Rights and Choices
Depending on your location and applicable law, you may have the following rights regarding your personal data:
6.1 Access and Portability
- Right to access: Request a copy of the personal data we hold about you
- Right to data portability: Receive your personal data in a structured, commonly used, machine-readable format
- Download your data: Export your conversation history, PRDs, and profile information through your account settings
6.2 Correction and Deletion
- Right to rectification: Correct inaccurate or incomplete personal data
- Right to erasure: Request deletion of your personal data, subject to certain exceptions
- Account deletion: Delete your account and associated data through your account settings
6.3 Control and Restriction
- Right to restrict processing: Limit how we use your personal data in certain circumstances
- Right to object: Object to processing of your personal data for direct marketing or other purposes
- Opt-out of marketing: Unsubscribe from marketing emails using the link in any marketing message
- Cookie preferences: Manage cookie settings through your browser or our cookie preference center
6.4 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@buildmatch.ai. We will respond to your request within 30 days (or as required by applicable law).
We may need to verify your identity before processing your request. If we cannot fulfill your request, we will explain why and inform you of any appeal rights you may have.
7. International Data Transfers
BUILD/MATCH is based in the United States. Your personal data may be transferred to, stored in, and processed in the United States and other countries where our service providers operate.
These countries may have data protection laws that differ from those in your country of residence. When we transfer personal data internationally, we implement appropriate safeguards, including:
- Standard contractual clauses approved by the European Commission or other relevant authorities
- Data processing agreements with third-party service providers requiring adequate data protection
- Technical and organizational measures to protect data during transfer and storage
- Compliance with applicable data protection frameworks and regulations
By using our services, you consent to the transfer of your personal data to the United States and other countries as necessary to provide our services.
8. Data Retention and Security
8.1 Data Retention
We retain personal data for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal obligations, resolve disputes, and enforce our agreements
- Improve our AI models and develop new features (using anonymized data)
- Maintain business records and conduct analytics
Specific retention periods:
- Account data: Retained while your account is active and for up to 90 days after deletion
- Conversation history: Retained for the duration of your account plus 1 year for AI training purposes (anonymized)
- Transaction records: Retained for 7 years to comply with tax and financial regulations
- Marketing data: Retained until you opt out or for 3 years of inactivity
- Google Places data: Automatically expired after 30 days in compliance with Google's Terms of Service
8.2 Security Measures
We implement industry-standard technical and organizational security measures to protect your personal data, including:
- Encryption: Data encrypted in transit using TLS 1.3+ and at rest using AES-256
- Access controls: Role-based access controls and principle of least privilege
- Authentication: Secure authentication mechanisms including magic link authentication
- Monitoring: Continuous security monitoring, logging, and incident response procedures
- Regular audits: Periodic security assessments and vulnerability scanning
- Employee training: Security awareness training for all personnel with access to personal data
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying you and relevant authorities of any data breach as required by law.
9. Children's Privacy
BUILD/MATCH is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18 years of age.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@buildmatch.ai. We will take steps to delete such information from our systems.
By using our services, you represent and warrant that you are at least 18 years of age and have the legal capacity to enter into binding agreements.
10. Third-Party Services and Links
Our platform may contain links to third-party websites, services, or integrations that are not owned or controlled by BUILD/MATCH. This Privacy Policy does not apply to third-party services.
We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services before providing them with your personal data.
Third-party services we integrate with include:
- Stripe: Payment processing (Stripe Privacy Policy)
- Anthropic Claude: AI services (Anthropic Privacy Policy)
- Google Places API: Professional discovery and location services (Google Privacy Policy)
- Email service providers: Transactional and marketing email delivery
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
11.1 Right to Know
You have the right to request that we disclose:
- The categories of personal information we collected about you
- The categories of sources from which we collected personal information
- Our business or commercial purpose for collecting personal information
- The categories of third parties with whom we share personal information
- The specific pieces of personal information we collected about you
11.2 Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions (e.g., to complete transactions, detect security incidents, comply with legal obligations).
11.3 Right to Opt-Out of Sale
BUILD/MATCH does not sell personal information as defined by the CCPA. We do not and will not sell your personal data to third parties.
11.4 Right to Non-Discrimination
You have the right not to receive discriminatory treatment for exercising your CCPA rights. We will not deny services, charge different prices, or provide different quality of service based on your exercise of these rights.
11.5 Authorized Agent
You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority and your identity before processing such requests.
To exercise your CCPA rights, contact us at privacy@buildmatch.ai or call us at 1-800-BUILD-MATCH. We will respond to verifiable requests within 45 days.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Effective Date" at the top of this policy
- Notify you via email or through a prominent notice on our platform
- Provide a summary of material changes in the notification
- In some cases, seek your consent for significant changes affecting how we use your personal data
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
Your continued use of BUILD/MATCH after we publish or send notice of changes constitutes your acceptance of the updated Privacy Policy.
13. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
BUILDMATCH LLC
Email: privacy@buildmatch.ai
Legal inquiries: legal@buildmatch.ai
Data protection officer: dpo@buildmatch.ai
We will respond to your inquiry within 30 days. For urgent privacy concerns, please mark your communication as "Urgent Privacy Matter."