Privacy

Privacy Policy

Last updated: 2026-06-06. This page explains what we collect, why, who we share it with, and the choices you have. We've kept the legalese to a minimum.

The short version

Who we are

"BuildingHQ" (we / us / our) refers to BuildingHQ Inc. and our affiliates that operate the BuildingHQ web app, desktop app, and supporting services (collectively, the "Service"). If you need to reach us about privacy, write to support@buildinghq.app.

For your building's data, BuildingHQ acts as a processor on behalf of your strata corporation or HOA, which is the controller of that data. Our Data Processing Addendum sets out the processor terms.

What we collect

Account information. When you create an account, we collect your name, email address, and the building(s) you administer. If you authenticate through a third-party identity provider (Auth0 / Google / Apple), we receive the identifiers those providers send us.

Building content. Log entries, equipment records, vendor contacts, attached photos, voice notes, manuals, and runbooks that you, your contributors, or your residents create inside BuildingHQ. You decide what to enter and how much detail to include.

Resident records (optional). A board can add resident names, contact details, vehicles, and parking passes if it chooses. None of these are required for the product to work. Where a board enters resident data, that board is the data controller for that data and is responsible for telling residents about it.

Technical data. Server logs (request paths, response codes, IP address, timestamps, user-agent string), device identifiers used to deliver auto-updates, and a sparse heartbeat from desktop installs (no content). We use these to keep the service running and to investigate problems.

Billing. If you subscribe to a paid tier, our payment processor collects the information needed to charge you. We retain the resulting invoices and payment receipts; we don't store full card numbers.

Why we use it

We use the data we collect to deliver and improve the Service: authenticating you, syncing your building between devices, sending operational emails, processing payment, preventing abuse, and complying with legal obligations. We do not profile you for advertising and we do not sell your personal information.

AI-assisted import

When you upload a spreadsheet through the smart importer, the column headers and a bounded sample of rows are sent to a large-language-model provider (currently Anthropic and Google) to determine which column maps to which field. These providers process the request under commercial API terms that prohibit training on submitted data. Import content stays associated with your building only; it never crosses tenants. If you don't want to use the smart importer, every screen also supports plain manual entry.

Who we share with

We share your data only with the service providers ("sub- processors") who help us operate BuildingHQ. The current list lives at /subprocessors and is the authoritative version — we notify customers of material changes at least 30 days before they take effect.

We don't share your data with advertisers, brokers, or governments except where required by valid legal process. If we receive such a request, we will notify you unless we are legally prohibited from doing so.

Where data is stored

BuildingHQ is operated from the United States and Canada and our primary infrastructure is hosted in AWS US regions. If you access the Service from outside those regions, your data is transferred to and processed there.

How long we keep it

Your choices

You can access, correct, export, or delete your account data at any time from inside the product. Building admins can do the same for content their building owns. Residents whose data has been added by a board can ask the board to make those changes, or contact us at support@buildinghq.app if their board is unresponsive.

Security

A summary of our security practices lives at /security. The short version: all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), every tenant is isolated at the query layer, secrets are managed in a vault and never committed to source control, and every endpoint that touches tenant data verifies authentication, authorisation, and tenancy before doing anything else.

Children

BuildingHQ is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact us and we will delete it.

Cookies

We use a small set of strictly-necessary cookies and similar technologies. The details are at /cookies.

Changes

If we make material changes to this policy we'll notify account holders by email and post a banner inside the product. The "Last updated" date at the top of this page always reflects the current version.

Contact

Questions, requests, or complaints: support@buildinghq.app.