Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.
1. Introduction
Owner Builder Buddy Pty Ltd ("we", "our", "us") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and services.
By using our services, you consent to the collection and use of your information in accordance with this Privacy Policy. This policy complies with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information when you create an account and use our platform:
- Name, email address, phone number, and postal address
- Australian Business Number (ABN) and Australian Company Number (ACN) for trade professionals
- Professional licenses and certifications for trades
- Project details including property address, budget range, and construction timeline
- Business information for trade companies (business name, address, service areas)
- Communication records including messages between users and support interactions
- Profile photos and business documentation (licenses, insurance certificates)
- Document uploads including plans, permits, receipts, and invoices
2.2 Technical Information
We automatically collect certain technical information when you use our platform:
- IP address, browser type, and device information
- Usage data including pages visited, features used, and time spent on the platform
- Authentication and session data (login times, access patterns)
- Log files for security and error tracking
2.3 Project and Financial Information
For owner-builders and construction projects, we collect:
- Build stage progress and timeline information
- Budget tracking data and expense records
- Receipt information (vendor names, amounts, dates, payment methods)
- Product selections and supplier information
- Property details (lot size, floor area, bedrooms, bathrooms)
- Permit and inspection status information
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing and maintaining our platform and services
- Creating and managing user accounts and profiles
- Facilitating connections between owner-builders and licensed trades
- Managing construction projects, timelines, and budgets
- Storing and organizing project documents and files
- Enabling messaging between users on the platform
- Sending transactional notifications about your account and projects (project updates, new messages, system alerts)
- Providing customer support and responding to inquiries
- Improving our services and developing new features
- Ensuring platform security, preventing fraud, and enforcing our terms of service
- Complying with legal obligations and regulatory requirements
- Powering AI features including the NCC (National Construction Code) chatbot for regulatory guidance
4. Information Sharing and Disclosure
4.1 With Other Users
When you use our platform, certain information is shared with other users to facilitate construction project collaboration:
- For Trade Professionals: Your business name, location, contact details, trade categories, and professional credentials are visible to owner-builders searching for trades
- For Owner-Builders: Your name, project location, and project requirements are shared when you invite trades to quote on your project
- For All Users: Messages, document shares, and project collaboration information are shared with authorized project participants
- Reviews and Ratings: Feedback and ratings you provide or receive may be visible to other users
4.2 With Service Providers
We share your information with trusted third-party service providers who help us operate our platform:
Supabase (Database & Authentication)
Purpose: Stores all user data, authenticates users, manages database
Data shared: All personal information, project data, documents
Location: Cloud infrastructure with servers in multiple regions
Vercel (Hosting & Deployment)
Purpose: Hosts our application and delivers content to users
Data shared: Technical data, IP addresses, usage patterns
Location: Global edge network with primary servers in the United States
OpenAI (AI Features)
Purpose: Powers NCC chatbot for construction code guidance and AI assistance
Data shared: Questions you ask the chatbot, conversation context
Location: United States
Resend (Email Delivery)
Purpose: Delivers transactional emails (account verification, notifications)
Data shared: Email addresses, notification content
Location: United States
Optional Integrations: If you choose to connect optional services:
- Dropbox: If enabled, documents may be stored in your Dropbox account
- Slack: Available for admin users only for internal team communications
4.3 Legal Requirements
We may disclose your information when required by law or in response to:
- Valid legal processes (court orders, subpoenas, warrants)
- Government or regulatory authority requests
- Situations involving potential threats to safety or security
- Enforcement of our terms of service or investigation of violations
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction. We will notify you of any such change in ownership or control of your personal information.
5. Data Security
We implement industry-standard security measures to protect your personal information:
- Encryption: All data is encrypted in transit (HTTPS/TLS) and at rest in our database
- Access Controls: Row Level Security (RLS) policies ensure users can only access their authorized data
- Authentication: Secure authentication system with password hashing and session management
- Database Security: PostgreSQL database with role-based access control and audit logging
- Regular Updates: Security patches and updates applied regularly to all systems
- Secure Storage: Documents stored in secure cloud storage with access logging
- Monitoring: Automated monitoring for suspicious activity and security incidents
While we implement strong security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but continuously work to protect your data.
6. Your Rights and Choices
Under Australian privacy law, you have the following rights:
Access
Request access to your personal information we hold. You can view most of your data directly in your account settings.
Correction
Update inaccurate or incomplete information through your profile settings or by contacting support.
Deletion
Request deletion of your account and personal information (subject to legal record-keeping requirements).
Notification Preferences
Control notification settings in your account preferences (email notifications, push notifications, quiet hours).
6.1 Account Deletion
When you delete your account:
- Your personal information will be anonymized or deleted within 30 days
- Some information may be retained for legal compliance (audit logs, financial records)
- Shared project data visible to other users may remain for project continuity
- Deleted accounts cannot be recovered
To exercise these rights, please contact us using the details provided below. We will respond to your request within 30 days.
7. Cookies and Session Management
Our platform uses minimal cookies for essential functionality:
Authentication Cookies
Required to keep you logged in and maintain your session securely. These cookies are essential for the platform to function.
Cookie name: sb-access-token, sb-refresh-token
Security Cookies
Used to prevent unauthorized access and protect against security threats.
We do not use third-party tracking cookies, advertising cookies, or analytics cookies. Our platform does not track your activity across other websites.
8. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services and maintain your active account
- Comply with Australian tax and business record-keeping requirements (typically 7 years for financial records)
- Resolve disputes and enforce our agreements
- Improve our services and prevent fraud
Retention Periods:
- Active accounts: Data retained while account is active
- Deleted accounts: Personal data anonymized within 30 days (except where legal retention required)
- Project records: May be retained for up to 7 years for compliance purposes
- Financial records: Retained for 7 years as required by Australian tax law
- Security logs: Retained for up to 12 months
9. International Data Transfers
Your information may be transferred to and processed in countries outside Australia:
⚠️ United States Data Processing
Our service providers (Supabase, Vercel, OpenAI, Resend) process data in the United States, which does not have an adequacy decision from the Australian Privacy Commissioner.
We ensure these providers implement appropriate safeguards including:
- Standard contractual clauses
- SOC 2 Type II certification (security controls)
- GDPR compliance (European data protection standards)
- Encryption of data in transit and at rest
By using our platform, you consent to the transfer of your personal information to these countries for processing. You may withdraw consent at any time by closing your account.
10. Children's Privacy
Our services are designed for adults involved in construction projects and are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. Construction work in Australia requires users to be 18+ to legally enter into contracts with licensed trades. If we become aware that we have collected information from a person under 18, we will take steps to delete it promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes:
- We will update the "Last updated" date at the top of this policy
- We will notify you by email if the changes significantly affect your rights
- For minor updates, we will post a notification on the platform
Your continued use of our services after such changes constitutes acceptance of the updated policy. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your personal information, please contact us:
Privacy Inquiries
Owner Builder Buddy Pty Ltd
Email: admin@ownerbuilderbuddy.com
Support: admin@ownerbuilderbuddy.com
Response Time
We aim to respond to privacy inquiries within:
• General questions: 5 business days
• Access/deletion requests: 30 days
Privacy Complaints
If you believe we have breached the Australian Privacy Principles, you have the right to lodge a complaint:
- Contact us first using the details above - we will investigate and respond within 30 days
- If unsatisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):
- Online: www.oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
🇦🇺 Australian Privacy Principles Compliance
This Privacy Policy is designed to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We are committed to protecting the privacy of Australians and handling personal information in accordance with Australian privacy law. This policy describes our APP 1 Statement - how we manage personal information in an open and transparent way.
Questions About Your Privacy?
We're committed to transparency and protecting your personal information. Contact us if you need clarification on any aspect of our privacy practices.
