This Privacy Policy explains what personal information Buildthru ("we", "us") collects when you use Buildthru, how we use it, who we share it with, and the rights you have. We never sell your data, and we never use your data or conversations to train AI models.
It applies to users anywhere in Canada, including Quebec. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) and applicable provincial privacy laws, including Quebec's Act respecting the protection of personal information in the private sector (Law 25, RLRQ, c. P-39.1). Where those laws set different standards, we apply the stricter one to your information.
The person responsible for the protection of personal information at Buildthru is Leila Allahham, Founder. For any privacy question, access request or complaint, contact our Privacy Officer at hello@buildthru.ca.
We do not ask for passwords to your other accounts, and our assistant is instructed to refuse them.
We use a small number of trusted providers to operate Buildthru. Each processes data only to provide their service to us. Where a provider offers a Data Processing Agreement we have one in place, with terms covering cross-border transfers. Four do not, and we would rather say so: Unsplash, Porkbun, Google Public DNS, and whichever registrar holds your own domain when we check whether it supports automated DNS setup. The last two are public lookups rather than contracted services.
Your account and project data is stored in Buildthru's Google Cloud and Firebase project, in data centres in the United States (Firebase nam5 region, Iowa). Customer website files are served through Cloudflare's global content delivery network, which operates data centres worldwide.
By using Buildthru you understand that your information is transferred to and processed in the United States and by the providers listed above. Those transfers are covered by the agreements described above, including, where the provider offers them, Standard Contractual Clauses. The four providers named there as having no Data Processing Agreement are not covered by one, and we say so rather than implying otherwise.
Quebec residents: transfers of personal information outside Quebec are made under written agreements requiring equivalent protection, with each provider that offers one. The assessments Law 25 asks for in relation to these transfers are not yet written up, which is the same open work described under Privacy Impact Assessments below.
We keep different kinds of information for different periods:
You can delete your account and all associated data at any time from your dashboard ("Delete account & data"), which removes your projects, conversation transcripts, and account. One thing it does not remove today: if you asked us for something Buildthru could not yet do, we kept that request, including your email and your own words. Email us and we will remove it, and we are fixing the gap so you do not have to ask. You can also email us at hello@buildthru.ca to request deletion. Financial and transaction records are kept for six years after the end of the taxation year they relate to, because the law requires it; your right to deletion covers personal and project data, not records we must keep.
Enquiries sent through your website are not deleted on a schedule. They are your business's records, so how long you keep them is your decision. They are deleted when you delete an enquiry, delete the site, or delete your account. Taking a site offline does not delete them: unpublishing stops new enquiries arriving and leaves the ones you already have exactly where they are.
We also keep internal records of what your usage cost us to serve, used only to understand our own costs and pricing. When you delete your account these are anonymized: the link to you is destroyed and replaced with a random identifier, and every identifying detail is removed, leaving only monthly totals that cannot be traced back to you or your business.
Under PIPEDA and applicable provincial privacy laws, including Quebec's Law 25, you have the right to:
To exercise any of these, email hello@buildthru.ca. We will acknowledge your request within 5 business days and respond within 30 days.
What keeps you signed in is not a cookie. We store your sign-in token in your browser's session storage, which your browser clears when you close the tab, and hold it in memory if session storage is unavailable. The Buildthru app sets no cookies of its own.
Cloudflare, which serves Buildthru and the websites we host, may set its own. Cloudflare describes every cookie it sets as strictly necessary and not used for advertising, such as one for bot management and one recorded when a visitor passes a challenge. See Cloudflare Cookies.
What we do not use. We do not use analytics cookies, advertising trackers, or any technology that profiles you across sites on buildthru.ca.
If that changes, we will update this policy and, where the law requires it, including Quebec's Law 25, ask for your express opt-in before those technologies activate.
If you have given separate, express consent, we may send you promotional emails about features, updates and offers. You can withdraw that consent at any time using the unsubscribe link in any marketing email, or by emailing hello@buildthru.ca.
Withdrawing marketing consent does not affect your account or the service emails we send you, such as receipts, security alerts and renewal reminders, which go to you on the basis of your contract with us.
If a security or confidentiality incident involves your personal information, we act on whichever threshold applies. PIPEDA's is a real risk of significant harm; Quebec's Act uses a risk of serious injury (s. 3.5). They are worded differently, so we apply each to its own regulator rather than treating one as covering both. Where either is met, we will:
Buildthru is built for business owners and is not directed at anyone under 18. We do not knowingly collect personal information from minors. If you believe we have, email hello@buildthru.ca and we will delete it promptly.
When your website has an enquiry form, the people who fill it in are sending their information to you. In law you are the data controller of it and we are your data processor: we hold and deliver it on your behalf and never use it for our own purposes. You are responsible for having a privacy policy on your own website, and for answering privacy requests from your visitors.
We store the answers the visitor gave and the date and time, and the email address they left if your form asks for one. We email the enquiry to the address you confirmed for that site, and a copy stays in your account so a missed email never loses an enquiry. If the visitor ticked the box agreeing to receive marketing emails from you, we also store the exact consent request they were shown, the time, and the IP address it came from, so that consent can be proven if it is ever questioned. The request is the checkbox wording plus the details identifying your business shown with it, which Canada's anti-spam regulations require. Sites published before September 2026 may have recorded the agreement without its wording, and the record says so rather than guessing; your Enquiries page shows which is which. We never market to your visitors.
From the Enquiries page for each site you can read every enquiry, delete a single one permanently, and download them all as a spreadsheet or as JSON. Deleting an enquiry is how you answer a visitor who asks you to erase their information: it removes the enquiry and the consent record stored with it, and it cannot be undone. The JSON file is the complete copy and is the only one that includes the IP address recorded with a marketing consent; the spreadsheet leaves it out. Deleting an enquiry, downloading your enquiries, deleting a site, and deleting your account all ask you to have signed in recently: three of them cannot be reversed, and the download copies every visitor's details out in one action.
If a visitor contacts us instead of you, we will tell them to contact the site owner and, where we can identify the site, let you know. Email hello@buildthru.ca if you would like our help answering a request.
This is about your visitors, not about you, and it is the part of your website we did not build ourselves.
Your published site tells each visitor's browser to fetch some things directly from other companies. When that happens, the visitor's browser connects to that company and the company sees at least the visitor's IP address and browser type.
Buildthru is not in the middle of those requests: once your page is open in a visitor's browser, the request goes from them straight to that company, so we cannot see it and we do not log it. What we can change is what your page asks for in the first place, because we chose that, not you. Some of it we are changing, and we say below which.
fonts.googleapis.com, fonts.gstatic.com) - on every page. Google receives the visitor's IP address and browser type on every page load.images.unsplash.com) - on any page with a photo we sourced. Unsplash receives the visitor's IP address and browser type each time an image loads.youtube-nocookie.com) - on pages with a YouTube video. We use YouTube's no-cookie domain rather than the default one; it still receives the visitor's IP address.player.vimeo.com) - on pages with a Vimeo video. We ask Vimeo for its do-not-track mode; we cannot confirm what it does with that.maps.google.com) - on pages with a map. Our assistant adds one when your business has a physical location, so you may not have asked for it.picsum.photos) - on a page whose placeholder image was never replaced with a real one. That happens when no photo could be found or fetched while your site was being built or edited. We do not currently measure how often it happens. It is a defect rather than a design, and we intend to stop it reaching a published site.The photos on your site are not stored by us. When we source a photo from Unsplash we keep the Unsplash link rather than copying the file onto Buildthru. Your page points at Unsplash's servers, so the picture your visitor sees is delivered by Unsplash and not by us. That means part of your website is served by a company other than Buildthru, and if Unsplash changes or removes an image your site is affected and we are not the ones who changed it. We are telling you this because it is your website and you should know which parts of it we actually serve.
If you would rather not rely on that, uploading your own photographs will be the way to do it. That feature is not built yet. Your own photographs are also usually better for your business than stock photography, so we would encourage it regardless.
What this may mean for you. If you publish your own privacy notice, or if a visitor asks what your site shares, these are the companies to name. We have listed them here so that you can. Your Buildthru site does not yet include a privacy notice of its own, which we are treating as a gap to close rather than as your problem to solve. If you would like any of them removed from your site, email hello@buildthru.ca and we will tell you honestly what is and is not possible today.
Our governance rules are written down: a security policy, an incident-response procedure, a register of the providers we use, and the complaint route below. They name their own gaps rather than describing a state we have not reached. There is no separate written data-retention schedule today: retention is set per collection, in code, and the table above is the authoritative statement of it. These are the Privacy Officer's and are reviewed as the product changes; the first annual review falls due on the anniversary of the effective date above.
Complaints. Email hello@buildthru.ca with a description of your concern. We will acknowledge it within 5 business days and respond with our findings within 30 days. If our response does not satisfy you, you may escalate to the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information if you live in Quebec.
Privacy Impact Assessments. Law 25 requires an assessment before acquiring, developing or overhauling an information system that involves personal information. Being accurate about where we stand: the assessments for the enquiry form and for payments are not yet written up, and are tracked as open work. We will complete them before those features carry a paying customer's data, and we would rather publish that than describe a routine we do not yet have.
When we introduce paid features (website launch, hosting, domain registration and business email), the additional information described above is processed: payment details, handled by Stripe, and domain-registration details shared with our registrar to register a domain in your name.
We may update this policy from time to time. If we make a material change we will email you before it takes effect, and the revision date above will change. Questions? Email hello@buildthru.ca. This policy is governed by the laws of the Province of Ontario, Canada.
Buildthru is operated by Leila Allahham, in Ontario, Canada. Buildthru is not incorporated; if that changes, this policy will name the company.