Privacy Policy

Effective June 13, 2026 | Revised 2026-10-02 | Version 2.7

This Privacy Policy explains what personal information Buildthru ("we", "us") collects when you use Buildthru, how we use it, who we share it with, and the rights you have. We never sell your data, and we never use your data or conversations to train AI models.

It applies to users anywhere in Canada, including Quebec. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) and applicable provincial privacy laws, including Quebec's Act respecting the protection of personal information in the private sector (Law 25, RLRQ, c. P-39.1). Where those laws set different standards, we apply the stricter one to your information.

Privacy Officer

The person responsible for the protection of personal information at Buildthru is Leila Allahham, Founder. For any privacy question, access request or complaint, contact our Privacy Officer at hello@buildthru.ca.

Information we collect

  • Account information - the email address and password you provide to sign up. Passwords are stored in hashed form by our authentication provider (Google Firebase Authentication); we never see them in plain text.
  • Intake and content information - your business name, description, style preferences, the pages you want, your domain and email preferences, and the rest of the conversation you have with our intake assistant. This is what we use to generate your website.
  • Technical information - basic request data, including your approximate IP address and timestamps, used to run the service securely and prevent abuse. Cloudflare, which serves all Buildthru-hosted customer websites, also processes request-level technical data such as IP addresses and request metadata as part of its network security and content delivery functions. Cloudflare Turnstile runs when a page of the Buildthru app loads, and never on a website we generate for you, and processes limited signals from your browser to decide whether you are a human; it does not track you and is not used for advertising.
  • Paid services information - if and when you buy paid services: payment details, handled by Stripe, and domain-registration details (your registrant name, address and phone number, shared with Porkbun). Collected only at the time of purchase.
  • Website import information, when that feature is available - we temporarily fetch the URL you give us to seed your website, and extract only the business information you confirm. We keep a consent record, including the source URL, a version identifier for the consent text, a timestamp and your IP address. The fetched page itself is not retained beyond that step.

We do not ask for passwords to your other accounts, and our assistant is instructed to refuse them.

How we use your information

  • To run the intake conversation and generate your website preview and, if you subscribe, your live website.
  • To create and secure your account, and to send you service emails such as email verification, your preview link, receipts and renewal reminders.
  • To check domain availability when you ask, and to register a domain you buy.
  • To send you marketing about Buildthru, only where you have given separate express consent.
  • To prevent abuse, investigate security incidents, and enforce our Terms of Service.
  • To meet our legal obligations, including keeping records required by the Income Tax Act (R.S.C. 1985, c. 1) and applicable privacy laws.

Service providers we share data with

We use a small number of trusted providers to operate Buildthru. Each processes data only to provide their service to us. Where a provider offers a Data Processing Agreement we have one in place, with terms covering cross-border transfers. Four do not, and we would rather say so: Unsplash, Porkbun, Google Public DNS, and whichever registrar holds your own domain when we check whether it supports automated DNS setup. The last two are public lookups rather than contracted services.

  • Google Firebase - authentication, database, hosting and storage for the Buildthru app (receives account data, project data, content models and conversation transcripts).
  • Google (Gemini & generative APIs) - to power the intake assistant and generate your website. We use paid tiers, which do not use your content to train models.
  • Cloudflare - CDN, customer site hosting, custom-domain SSL and email routing for customer websites. It receives all requests to Buildthru-hosted customer sites, including visitor IP addresses and request metadata, and may process them across its global network.
  • Cloudflare Turnstile - a privacy-preserving "are you human" check that runs in the Buildthru app only, and never on a website we generate for you, to protect our forms and AI features from bots and automated abuse. It processes limited technical and interaction signals from your browser to make that determination, and does not use them to track you or for advertising. See Cloudflare's Turnstile Privacy Addendum.
  • Resend - to deliver our emails, and to deliver enquiries from your website to you (receives your email address, and the contents of an enquiry a visitor sends you).
  • Porkbun - our domain registrar (receives the domain name you ask us to check, and, for paid registrations, your registrant details).
  • Google Fonts - typefaces for the Buildthru app itself, loaded from Google's servers rather than ours. Google receives your IP address and browser type each time you load a page of the Buildthru app. This is the same arrangement described under “What your published site loads from other companies”, applied to our own site.
  • Unsplash - to source photography for the websites we generate. Two separate things: the SEARCH is made by our servers and sends only a short description of the image we are looking for, or whatever you type into the photo picker. The picker also shows thumbnails loaded from Unsplash, so Unsplash sees your own IP address while you choose, while the DELIVERY is made by your visitor's browser, because photos are hotlinked rather than copied onto Buildthru. See “What your published site loads from other companies” below.
  • Stripe, for paid services - payment processing. Card details are handled directly by Stripe under its PCI DSS-compliant infrastructure; we never see or store full card numbers.

Where your data is stored

Your account and project data is stored in Buildthru's Google Cloud and Firebase project, in data centres in the United States (Firebase nam5 region, Iowa). Customer website files are served through Cloudflare's global content delivery network, which operates data centres worldwide.

By using Buildthru you understand that your information is transferred to and processed in the United States and by the providers listed above. Those transfers are covered by the agreements described above, including, where the provider offers them, Standard Contractual Clauses. The four providers named there as having no Data Processing Agreement are not covered by one, and we say so rather than implying otherwise.

Quebec residents: transfers of personal information outside Quebec are made under written agreements requiring equivalent protection, with each provider that offers one. The assessments Law 25 asks for in relation to these transfers are not yet written up, which is the same open work described under Privacy Impact Assessments below.

Retention and deletion

We keep different kinds of information for different periods:

  • Account and project data - while your account is active, and deleted when you delete your account, at the time you ask.
  • Preview sites - expire automatically within 7 days of generation.
  • Financial and transaction records - six years from the end of the taxation year the records relate to, which the Income Tax Act requires (s. 230(4)(b)). That is longer than six years from the transaction itself.
  • Import consent records - 3 years from the date of consent.
  • Rate-limit and abuse counters - 48 hours, expired automatically.
  • Operational and security logs - kept under Google Cloud Logging's default retention, 30 days at the time of writing.
  • Enquiries sent through your website, and the consent record stored with each - no automatic expiry (see below).
  • Confidentiality incident register - kept for at least five years from when we became aware of the incident, per the Commission d'accès à l'information's published guidance.
  • Internal cost and usage records - anonymized when you delete your account, then kept in aggregate.

You can delete your account and all associated data at any time from your dashboard ("Delete account & data"), which removes your projects, conversation transcripts, and account. One thing it does not remove today: if you asked us for something Buildthru could not yet do, we kept that request, including your email and your own words. Email us and we will remove it, and we are fixing the gap so you do not have to ask. You can also email us at hello@buildthru.ca to request deletion. Financial and transaction records are kept for six years after the end of the taxation year they relate to, because the law requires it; your right to deletion covers personal and project data, not records we must keep.

Enquiries sent through your website are not deleted on a schedule. They are your business's records, so how long you keep them is your decision. They are deleted when you delete an enquiry, delete the site, or delete your account. Taking a site offline does not delete them: unpublishing stops new enquiries arriving and leaves the ones you already have exactly where they are.

We also keep internal records of what your usage cost us to serve, used only to understand our own costs and pricing. When you delete your account these are anonymized: the link to you is destroyed and replaced with a random identifier, and every identifying detail is removed, leaving only monthly totals that cannot be traced back to you or your business.

Your rights

Under PIPEDA and applicable provincial privacy laws, including Quebec's Law 25, you have the right to:

  • Access - ask for a copy of the personal information we hold about you.
  • Correction - ask us to correct information that is wrong or incomplete.
  • Deletion - ask us to delete your personal information, subject to the legal retention obligations above.
  • Data portability - receive your information in a structured, commonly used, machine-readable format. Quebec residents have held this right since 22 September 2024. We are building a self-serve export in your dashboard; until it is there, email us and we will send it.
  • Withdraw consent - at any time, subject to legal and contractual exceptions. Withdrawing marketing consent is described below.
  • Complain - to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or, for Quebec residents, the Commission d'accès à l'information at cai.gouv.qc.ca.

To exercise any of these, email hello@buildthru.ca. We will acknowledge your request within 5 business days and respond within 30 days.

Cookies and technical technologies

What keeps you signed in is not a cookie. We store your sign-in token in your browser's session storage, which your browser clears when you close the tab, and hold it in memory if session storage is unavailable. The Buildthru app sets no cookies of its own.

Cloudflare, which serves Buildthru and the websites we host, may set its own. Cloudflare describes every cookie it sets as strictly necessary and not used for advertising, such as one for bot management and one recorded when a visitor passes a challenge. See Cloudflare Cookies.

What we do not use. We do not use analytics cookies, advertising trackers, or any technology that profiles you across sites on buildthru.ca.

If that changes, we will update this policy and, where the law requires it, including Quebec's Law 25, ask for your express opt-in before those technologies activate.

Marketing communications

If you have given separate, express consent, we may send you promotional emails about features, updates and offers. You can withdraw that consent at any time using the unsubscribe link in any marketing email, or by emailing hello@buildthru.ca.

Withdrawing marketing consent does not affect your account or the service emails we send you, such as receipts, security alerts and renewal reminders, which go to you on the basis of your contract with us.

If there is a data breach

If a security or confidentiality incident involves your personal information, we act on whichever threshold applies. PIPEDA's is a real risk of significant harm; Quebec's Act uses a risk of serious injury (s. 3.5). They are worded differently, so we apply each to its own regulator rather than treating one as covering both. Where either is met, we will:

  • notify you as soon as feasible, which is PIPEDA s. 10.1(6)'s standard, and promptly, which is Quebec's;
  • report it to the Office of the Privacy Commissioner of Canada and, for incidents subject to Quebec's Law 25, to the Commission d'accès à l'information. Neither law sets a deadline in hours: PIPEDA asks for the report “as soon as feasible” and Quebec asks for it “promptly”. We hold ourselves to 72 hours as our own target;
  • keep a confidentiality incident register, which can be provided to regulators on request.

Children's privacy

Buildthru is built for business owners and is not directed at anyone under 18. We do not knowingly collect personal information from minors. If you believe we have, email hello@buildthru.ca and we will delete it promptly.

Enquiries from your website's visitors

When your website has an enquiry form, the people who fill it in are sending their information to you. In law you are the data controller of it and we are your data processor: we hold and deliver it on your behalf and never use it for our own purposes. You are responsible for having a privacy policy on your own website, and for answering privacy requests from your visitors.

We store the answers the visitor gave and the date and time, and the email address they left if your form asks for one. We email the enquiry to the address you confirmed for that site, and a copy stays in your account so a missed email never loses an enquiry. If the visitor ticked the box agreeing to receive marketing emails from you, we also store the exact consent request they were shown, the time, and the IP address it came from, so that consent can be proven if it is ever questioned. The request is the checkbox wording plus the details identifying your business shown with it, which Canada's anti-spam regulations require. Sites published before September 2026 may have recorded the agreement without its wording, and the record says so rather than guessing; your Enquiries page shows which is which. We never market to your visitors.

From the Enquiries page for each site you can read every enquiry, delete a single one permanently, and download them all as a spreadsheet or as JSON. Deleting an enquiry is how you answer a visitor who asks you to erase their information: it removes the enquiry and the consent record stored with it, and it cannot be undone. The JSON file is the complete copy and is the only one that includes the IP address recorded with a marketing consent; the spreadsheet leaves it out. Deleting an enquiry, downloading your enquiries, deleting a site, and deleting your account all ask you to have signed in recently: three of them cannot be reversed, and the download copies every visitor's details out in one action.

If a visitor contacts us instead of you, we will tell them to contact the site owner and, where we can identify the site, let you know. Email hello@buildthru.ca if you would like our help answering a request.

What your published site loads from other companies

This is about your visitors, not about you, and it is the part of your website we did not build ourselves.

Your published site tells each visitor's browser to fetch some things directly from other companies. When that happens, the visitor's browser connects to that company and the company sees at least the visitor's IP address and browser type.

Buildthru is not in the middle of those requests: once your page is open in a visitor's browser, the request goes from them straight to that company, so we cannot see it and we do not log it. What we can change is what your page asks for in the first place, because we chose that, not you. Some of it we are changing, and we say below which.

  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com) - on every page. Google receives the visitor's IP address and browser type on every page load.
  • Unsplash (images.unsplash.com) - on any page with a photo we sourced. Unsplash receives the visitor's IP address and browser type each time an image loads.
  • YouTube (youtube-nocookie.com) - on pages with a YouTube video. We use YouTube's no-cookie domain rather than the default one; it still receives the visitor's IP address.
  • Vimeo (player.vimeo.com) - on pages with a Vimeo video. We ask Vimeo for its do-not-track mode; we cannot confirm what it does with that.
  • Google Maps (maps.google.com) - on pages with a map. Our assistant adds one when your business has a physical location, so you may not have asked for it.
  • Lorem Picsum (picsum.photos) - on a page whose placeholder image was never replaced with a real one. That happens when no photo could be found or fetched while your site was being built or edited. We do not currently measure how often it happens. It is a defect rather than a design, and we intend to stop it reaching a published site.

The photos on your site are not stored by us. When we source a photo from Unsplash we keep the Unsplash link rather than copying the file onto Buildthru. Your page points at Unsplash's servers, so the picture your visitor sees is delivered by Unsplash and not by us. That means part of your website is served by a company other than Buildthru, and if Unsplash changes or removes an image your site is affected and we are not the ones who changed it. We are telling you this because it is your website and you should know which parts of it we actually serve.

If you would rather not rely on that, uploading your own photographs will be the way to do it. That feature is not built yet. Your own photographs are also usually better for your business than stock photography, so we would encourage it regardless.

What this may mean for you. If you publish your own privacy notice, or if a visitor asks what your site shares, these are the companies to name. We have listed them here so that you can. Your Buildthru site does not yet include a privacy notice of its own, which we are treating as a gap to close rather than as your problem to solve. If you would like any of them removed from your site, email hello@buildthru.ca and we will tell you honestly what is and is not possible today.

How we govern privacy

Our governance rules are written down: a security policy, an incident-response procedure, a register of the providers we use, and the complaint route below. They name their own gaps rather than describing a state we have not reached. There is no separate written data-retention schedule today: retention is set per collection, in code, and the table above is the authoritative statement of it. These are the Privacy Officer's and are reviewed as the product changes; the first annual review falls due on the anniversary of the effective date above.

Complaints. Email hello@buildthru.ca with a description of your concern. We will acknowledge it within 5 business days and respond with our findings within 30 days. If our response does not satisfy you, you may escalate to the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information if you live in Quebec.

Privacy Impact Assessments. Law 25 requires an assessment before acquiring, developing or overhauling an information system that involves personal information. Being accurate about where we stand: the assessments for the enquiry form and for payments are not yet written up, and are tracked as open work. We will complete them before those features carry a paying customer's data, and we would rather publish that than describe a routine we do not yet have.

Paid services (when available)

When we introduce paid features (website launch, hosting, domain registration and business email), the additional information described above is processed: payment details, handled by Stripe, and domain-registration details shared with our registrar to register a domain in your name.

Changes & contact

We may update this policy from time to time. If we make a material change we will email you before it takes effect, and the revision date above will change. Questions? Email hello@buildthru.ca. This policy is governed by the laws of the Province of Ontario, Canada.

Buildthru is operated by Leila Allahham, in Ontario, Canada. Buildthru is not incorporated; if that changes, this policy will name the company.