B
Bildyr
Log inStart Free Trial

Privacy Policy

Last updated: 24 April 2026

1. What data we collect

Demo accounts: Your name, email address, shop name, and trade type. This is the minimum we need to set up your workspace.

Paid accounts: Full business details including address, phone number, and payment information processed securely through Stripe. We also store customer data, quotes, invoices, and files you upload as part of using the service.

2. Why we collect it

  • To provide and operate the Bildyr service
  • To communicate with you about your account
  • To improve the product based on usage patterns
  • To send transactional emails (quotes, invoices, proof requests)
  • To prevent abuse and ensure platform security

3. How we store it

Your data is stored in a PostgreSQL database hosted by Supabase with encryption at rest. All connections use TLS encryption in transit. Backups are taken daily and retained for 7 days (30 days on higher-tier plans).

4. Cookies

We use a small number of cookies, all functional:

  • jf_session — Secure, httpOnly authentication cookie. Required to use the app. Expires after 7 days.
  • jf_demo — Non-sensitive marker indicating you have an active demo session. Expires after 7 days.
  • Cloudflare Turnstile — Anti-bot verification on the signup form. Set by Cloudflare.

We do not use analytics cookies, advertising cookies, or third-party tracking cookies. See our Cookie Policy for full details.

5. Third-party services

  • Clerk — Authentication and user management
  • Resend — Transactional email delivery
  • Cloudflare — CDN, DDoS protection, and CAPTCHA
  • Stripe — Payment processing (when available)
  • Supabase — Database hosting and file storage

Each service processes data under their own privacy policies. We only share the minimum data necessary for each service to function.

6. Data retention

  • Demo accounts: Automatically deleted after 7 days of inactivity, including all associated data.
  • Paid accounts: Data retained while your subscription is active. Upon cancellation, data is retained for 30 days then permanently deleted.
  • On request: You can request immediate deletion at any time by contacting us.

7. Your rights

You have the right to:

  • Access — Request a copy of all data we hold about you (available via Settings → Export Data)
  • Correction — Update or correct any inaccurate data
  • Deletion — Request permanent deletion of your account and all associated data
  • Portability — Export your data in standard formats (CSV, JSON)

To exercise any of these rights, email [CONTACT_EMAIL].

8. GDPR compliance

The data controller is [COMPANY_NAME]. For GDPR-related enquiries, contact [CONTACT_EMAIL].

We process data under the lawful basis of contract performance (providing the service you signed up for) and legitimate interest (improving the product and preventing abuse).

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email to all active account holders. The “last updated” date at the top of this page reflects the most recent revision.

Privacy Policy | Bildyr