Privacy Policy
Last updated September 20, 2026
About this policy
This policy describes how Buildform, LLC (“Buildform,” “we,” or “us”) handles personal information when you visit our website, create an account, or use our team workspaces. It also covers signing in with Google.
Information we collect
- Account information, including your name, email address, profile image when provided, and authentication records. If you use a password, we store its hash rather than the password itself.
- Workspace information you or your organization provide, including organization names, memberships, invitations, and content submitted to the service.
- Technical and security information, including IP addresses, browser information, session records, request timing, errors, and records of administrative activity.
- Information you provide when you contact us.
Google sign-in
If you choose Google sign-in, we receive basic identity information such as your Google account identifier, name, email address, verification status, and profile image. Authentication records may include OAuth tokens. We use this information to identify you, establish your session, and manage account access. For staff sign-in, we also check your Google Workspace domain.
The current Google sign-in integration does not request access to your Gmail messages, Google Drive files, or Google Calendar. You can revoke Buildform’s connection in your Google Account settings. Revoking access does not itself delete your Buildform account or workspace records.
How we use information
We use information to operate accounts and workspaces, authenticate users, send verification and service emails, manage invitations and permissions, provide support, investigate errors, prevent abuse, and maintain service security. We do not use Google sign-in information for advertising or sell that information.
Cookies and sessions
We use cookies to keep you signed in and maintain authentication sessions. Blocking these cookies can prevent sign-in and account features from working. Our public policy pages can be read without signing in.
When information is shared
We use service providers to operate Buildform, including Google Cloud and Vercel for hosting, Neon for database storage, and Resend for transactional email. These providers process information needed to deliver their services.
Workspace administrators and authorized members may access information according to their roles. Authorized Buildform staff may access information for support, operations, and security. We may also disclose information when required by law or when necessary to protect users, the service, or legal rights.
Retention and security
We retain account and workspace information for service operation and legitimate security, legal, and business needs. Retention varies by record type; deleting an account does not necessarily remove shared workspace content, security records, or backups immediately.
We use access controls, encrypted connections, and separate workspace permissions to protect information. No system can guarantee absolute security. Information may be processed in countries where our service providers operate.
Your choices and requests
You can choose whether to use Google sign-in and can sign out to end your current session. Depending on applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information. Workspace-related requests may also require coordination with your organization’s administrator. We may need to verify your identity before acting on a request.
Changes and contact
We may update this policy as the service changes. The date above identifies the latest revision.
Contact Buildform, LLC at privacy@getbuildform.com with privacy questions or requests to access, correct, or delete your personal information.