Legal
How BuildrHub collects, uses, stores and shares personal information, and what you can do about it. Written for Australian privacy law, in plain English.
Last updated 1 September 2026
BuildrHub is job management software for Australian trades. It is operated by Chase Tech, trading as BuildrHub.
This policy covers the BuildrHub website at buildrhub.app, the BuildrHub app, and every email, SMS and document sent through it.
If you have a question about privacy, email privacy@buildrhub.app and a person will answer.
This part matters more than anything else here, so it comes first.
Some information is about you, the person who signed up. Your name, your email, your login, your subscription. We decide how that gets used, and we are accountable for it under the Privacy Act.
Most of what sits in BuildrHub is different. It is your business data. Your clients, your jobs, your quotes, your invoices, your staff timesheets. Some of that is personal information about other people. You decide what goes in and why. We only hold it and process it on your instructions, so you are the one accountable for it and we act on your behalf.
The practical effect is simple. If one of your clients asks what BuildrHub knows about them, we send them to you rather than answering for you. And you need the right to put their information into BuildrHub in the first place.
Account information. Your name, email address, phone number, business name, and the password you set. If you sign in with Google, we receive your name, email address and profile picture from Google, and nothing else.
Business data you enter. Clients and their contact details, jobs, quotes, invoices, variations, tasks, calendar events, timesheets, expenses, planners, notes and comments.
Files and photos. Anything you upload, including site photos, receipts, plans and signed documents.
Subscription and billing information. Your plan, seat count, billing history and subscription status. Card numbers go straight to Stripe. We never see or store them.
Payments you take from your clients. Payment status, amounts and references flow back from Stripe so your invoices can show what has been paid. The card details behind those payments stay with Stripe.
Technical information collected automatically. IP address, browser and device type, operating system, referring pages, the pages you open in the app, the features you use, and timestamps. This keeps the service running and shows us what people actually use.
We do not collect sensitive information as the Privacy Act defines it, meaning health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record. Please do not put that kind of detail into BuildrHub.
To run the service. Show you your data, generate quotes, invoices and PDFs, send documents to your clients, take subscription payments, and keep backups.
To support you. When something breaks we may look at your account to work out why. We do that to fix the problem, not to browse.
To keep the service secure. Detecting suspicious sign-ins, blocking abuse, and investigating anything that looks like unauthorised access.
To improve the product. We look at which features get used and where people get stuck. That analysis works on patterns across accounts, not on reading individual records.
To contact you. Emails about your account, billing, and changes that affect you. Those are part of the service and you cannot opt out while you have an account. Marketing emails are separate, and every one has an unsubscribe link.
To meet our legal obligations, including tax and accounting record keeping.
Nova and the other AI features in BuildrHub send parts of your data to AI providers so they can answer a question or draft a document. What gets sent depends on what you ask. A question about a job sends that job. A request to build a quote sends the client, the job and your price list.
We use established third party AI providers to do this, reached through a gateway so we can move between them. Some Nova tasks also run generated code inside an isolated sandbox, so the work happens without that code touching our systems directly.
Your data is not used to train any AI model. Our agreements with these providers do not permit it.
AI output can be wrong. Check anything that affects a price, a legal commitment or a payment before it goes to a client. What you send out of BuildrHub is your responsibility, whether a person or Nova drafted it.
If you would rather no data reached an AI provider at all, do not use the Nova features. The rest of BuildrHub works without them.
When you add a client, invite a team member, or log someone's hours, you are the one deciding what gets collected and why.
You confirm you have the right to give us that information, and that the people it belongs to have been told how you use it. If your business is covered by the Privacy Act, your own privacy policy needs to account for BuildrHub holding this data.
We use it only to run the service for you. We do not market to your clients, contact them for our own purposes, or use their details for anything except delivering what you asked BuildrHub to do.
Emails and SMS that BuildrHub sends to your clients are sent on your behalf. You need consent to message them under the Spam Act 2003, and you remain the sender as far as they are concerned.
Our database is hosted in Australia where the provider offers it. Some of the providers above operate outside Australia, so some information is stored or processed overseas, including in the United States and the European Union.
Before sending information overseas we take reasonable steps to satisfy ourselves that the provider handles it to a standard consistent with the Australian Privacy Principles, through the contract we hold with them.
This is Australian Privacy Principle 8, and it applies whether or not you notice it happening. If you want the current country list for a specific provider, ask us.
Data is encrypted in transit, and our infrastructure providers encrypt it at rest.
Every workspace's data is separated at the query layer. A request that does not prove membership of a workspace cannot read that workspace's records, and roles control what each member can see and change inside it.
Passwords are hashed, never stored in readable form, and nobody at BuildrHub can see yours.
Access to production systems is limited to the people who need it to run the service.
None of that makes any system perfectly secure, and nobody who tells you otherwise is being straight with you. Sending information over the internet always carries some risk. Use a strong, unique password, and tell us straight away if you think someone else has got into your account.
Australia's Notifiable Data Breaches scheme applies to us. If personal information is lost or accessed without authorisation and it is likely to cause serious harm, we will tell the affected people and the Office of the Australian Information Commissioner.
We assess any suspected breach promptly, and within 30 days at the outside, which is what the scheme requires.
If the breach involves your business data, we will tell you quickly enough for you to meet your own obligations to your clients.
We keep your data while your account is open.
After you cancel we hold it for 30 days so you can come back or export it, then delete it from our active systems. Backups roll off on their own cycle after that.
Some records we keep longer where tax and accounting law requires it, including subscription invoices and payment history. Those are kept for seven years and used for nothing else.
You can export your data at any time while your account is active. Do that before you cancel rather than after.
BuildrHub is business software and is not for anyone under 18. We do not knowingly collect information from children.
If you believe a child has given us information, email privacy@buildrhub.app and we will delete it.
You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Most of it you can see and change yourself in the app.
For anything else, email us and we will respond within 30 days. We may need to confirm who you are before handing anything over.
There are limits. We may keep information where the law requires it, or where it is needed to resolve a dispute or investigate misuse.
If you are one of our customers' clients rather than an account holder, contact that business directly. They control their own records and we cannot act on their data without them.
If you are unhappy with how we have handled a privacy issue, tell us first and we will try to sort it out. If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Most browsers offer a Do Not Track setting. There is still no agreed standard for what a website should do when it sees one, so we do not respond to it.
If a standard is settled on and applies to us, we will follow it and say so here.
We update this policy as the product changes. The date at the top always shows the current version.
If a change materially affects how we handle your information, we will email you before it takes effect rather than quietly editing the page.
Email privacy@buildrhub.app for anything to do with privacy, including access and correction requests.
You can also write to Chase Tech, 15 Headlam Parade, Springfield, New South Wales 2250, Australia.