Privacy
Privacy Policy
Last updated: 2026-06-06. This page explains what we collect, why, who we share it with, and the choices you have. We've kept the legalese to a minimum.
The short version
- We don't sell your data. No advertising business, no data broker, no resale to third parties.
- You own your building's data. Export it as a single archive at any time, or delete it on demand.
- Residents don't need to hand over personal info. BuildingHQ runs end-to-end with residents identified only by unit number. Names, emails, and phone numbers are optional.
- Your data isn't used to train AI models. Where we use LLM providers to parse an import file for you, prompts run under commercial terms that prohibit training on submitted data.
- We collect the minimum needed to operate. Service logs, billing records, and your active session — no tracking, no analytics that follow you around the web.
Who we are
"BuildingHQ" (we / us / our) refers to BuildingHQ Inc. and our affiliates that operate the BuildingHQ web app, desktop app, and supporting services (collectively, the "Service"). If you need to reach us about privacy, write to support@buildinghq.app.
For your building's data, BuildingHQ acts as a processor on behalf of your strata corporation or HOA, which is the controller of that data. Our Data Processing Addendum sets out the processor terms.
What we collect
Account information. When you create an account, we collect your name, email address, and the building(s) you administer. If you authenticate through a third-party identity provider (Auth0 / Google / Apple), we receive the identifiers those providers send us.
Building content. Log entries, equipment records, vendor contacts, attached photos, voice notes, manuals, and runbooks that you, your contributors, or your residents create inside BuildingHQ. You decide what to enter and how much detail to include.
Resident records (optional). A board can add resident names, contact details, vehicles, and parking passes if it chooses. None of these are required for the product to work. Where a board enters resident data, that board is the data controller for that data and is responsible for telling residents about it.
Technical data. Server logs (request paths, response codes, IP address, timestamps, user-agent string), device identifiers used to deliver auto-updates, and a sparse heartbeat from desktop installs (no content). We use these to keep the service running and to investigate problems.
Billing. If you subscribe to a paid tier, our payment processor collects the information needed to charge you. We retain the resulting invoices and payment receipts; we don't store full card numbers.
Why we use it
We use the data we collect to deliver and improve the Service: authenticating you, syncing your building between devices, sending operational emails, processing payment, preventing abuse, and complying with legal obligations. We do not profile you for advertising and we do not sell your personal information.
AI-assisted import
When you upload a spreadsheet through the smart importer, the column headers and a bounded sample of rows are sent to a large-language-model provider (currently Anthropic and Google) to determine which column maps to which field. These providers process the request under commercial API terms that prohibit training on submitted data. Import content stays associated with your building only; it never crosses tenants. If you don't want to use the smart importer, every screen also supports plain manual entry.
Who we share with
We share your data only with the service providers ("sub- processors") who help us operate BuildingHQ. The current list lives at /subprocessors and is the authoritative version — we notify customers of material changes at least 30 days before they take effect.
We don't share your data with advertisers, brokers, or governments except where required by valid legal process. If we receive such a request, we will notify you unless we are legally prohibited from doing so.
Where data is stored
BuildingHQ is operated from the United States and Canada and our primary infrastructure is hosted in AWS US regions. If you access the Service from outside those regions, your data is transferred to and processed there.
How long we keep it
- Building content — for as long as your account is active. When you delete a building, content is soft-deleted immediately and permanently purged within 30 days, except where a court order or active investigation requires preservation.
- Account records — for as long as you have an account, plus the period required for billing reconciliation and tax compliance.
- Backups — encrypted backups are retained for up to 35 days and then rotated out.
- Server logs — typically 30 days, longer for security incident investigation.
Your choices
You can access, correct, export, or delete your account data at any time from inside the product. Building admins can do the same for content their building owns. Residents whose data has been added by a board can ask the board to make those changes, or contact us at support@buildinghq.app if their board is unresponsive.
Security
A summary of our security practices lives at /security. The short version: all data is encrypted in transit (TLS 1.2+) and at rest (AES-256), every tenant is isolated at the query layer, secrets are managed in a vault and never committed to source control, and every endpoint that touches tenant data verifies authentication, authorisation, and tenancy before doing anything else.
Children
BuildingHQ is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact us and we will delete it.
Cookies
We use a small set of strictly-necessary cookies and similar technologies. The details are at /cookies.
Changes
If we make material changes to this policy we'll notify account holders by email and post a banner inside the product. The "Last updated" date at the top of this page always reflects the current version.
Contact
Questions, requests, or complaints: support@buildinghq.app.