Skip to main content

Privacy Policy

How BuildTom handles account, marketplace, payment, email, and security data.

This Privacy Policy explains how BuildTom handles information related to accounts, listings, company requests, reports, and marketplace activity.

1. Information we collect

BuildTom may collect account and authentication information such as name, email address, phone number, account status, accepted policy versions, login and recovery events, and security or abuse-prevention records. We also collect listing, company, location, contact, image, document, report, support, and moderation information submitted through the platform.

2. Premium Direct and payment information

When a user starts or completes a BuildTom paid service, we may process the service selected, listing or company reference, locked price and currency, order and checkout identifiers, payment status, provider transaction references, billing contact details, invoice, receipt, refund, credit-note, chargeback, reconciliation, and fraud-prevention information. BuildTom does not intentionally receive or store the full card number, card security code, or online-banking credentials; those payment credentials are handled by the authorised payment provider.

3. Authentication and transactional email

Supabase is used for authentication and may generate confirmation, invitation, password-recovery, and other account-security tokens or links. Resend is used as an email-delivery provider for authentication and transactional messages. Email processing may include the recipient and sender addresses, subject and message content, message identifier, delivery status, bounce or complaint status, timestamps, and limited technical delivery metadata. BuildTom does not send passwords by email.

4. How we use information

We use information to operate accounts and the marketplace; publish and moderate listings; verify companies and phone numbers; provide search, location, contact, Premium, invoice, refund, and support functions; reconcile payments; prevent duplicate charges, fraud, abuse, and account takeover; respond to disputes and lawful requests; maintain audit evidence; improve reliability; and comply with applicable legal, accounting, consumer-protection, and security obligations.

5. Service providers and sharing

BuildTom may use service providers including Supabase for authentication, database, and storage; Vercel for hosting and application delivery; Resend for transactional email; Ziina for payment and refund processing; and Google Maps services for optional location functions. We share only information reasonably needed for the relevant service, security, support, dispute, or legal purpose. Providers process information under their own legal obligations and contractual terms. BuildTom may also disclose information to competent authorities, courts, advisers, insurers, banks, payment networks, or fraud-prevention partners where required or permitted by law.

6. Public information and private records

Approved listing and public company information may be visible to marketplace visitors. Private account data, verification documents, payment records, security evidence, reports, and internal moderation notes are not intended for public display. Contact information shown by a seller on a published listing may be used by visitors to communicate directly with that seller.

7. International processing

Some technology, email, hosting, mapping, payment, support, or security providers may process or store information outside the United Arab Emirates. Where applicable, BuildTom uses contractual, technical, organisational, and provider-selection measures intended to protect information and comply with applicable transfer requirements.

8. Retention

Eligible account-deletion requests use a 30-day cancellation period. Personal identifiers may then be removed, restricted, or anonymised where appropriate. Financial, invoice, refund, credit-note, commercial listing, dispute, report, fraud-prevention, security, legal-hold, and audit evidence may be retained for at least seven years, or longer where required by law, an unresolved dispute, a legal hold, or a legitimate security need. Delivery and authentication logs are retained according to operational, security, provider, and legal requirements.

9. Analytics and anonymised insights

BuildTom may use privacy-limited interaction events and aggregated or anonymised marketplace information for reliability, safety, search quality, service improvement, trend analysis, and market insights. Launch analytics exclude message content, full search text, phone numbers, email addresses, raw IP addresses, raw user-agent values, and logged-in viewer identity. BuildTom does not sell personally identifiable information.

10. Choices and rights

Users may update available account details and communication preferences and may request access, correction, deletion, restriction, or other rights through BuildTom support, subject to identity verification, legal retention, fraud prevention, security, contractual, and dispute requirements. A request to delete an account does not require BuildTom to erase records that must lawfully be retained or that have been de-identified.

11. Security

BuildTom uses authentication, access controls, private storage, audit logs, payment verification, webhook validation, rate limits, moderation, and other technical and organisational safeguards. No online service can guarantee absolute security. Users should protect their devices, passwords, email accounts, one-time codes, and recovery links and should report suspected misuse promptly.

12. Contact and complaints

For privacy, payment-data, email-delivery, account, or security questions, use the BuildTom Contact or Report channels. This does not restrict a lawful complaint or report to a competent authority.

Contact BuildTom