BuildFetch Inc. Cloud Services Privacy Policy
Last Updated: September 13, 2026
BuildFetch Inc. (“BuildFetch,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our Cloud Services (as defined in our Cloud Services Terms of Service at https://buildfetch.com/tos), the website at buildfetch.com and any subdomains, relevant public and beta APIs, and any additional or future cloud-hosted products or services (collectively, the “Cloud Services”).
This Policy applies to personal information about visitors to our website and Cloud Services, prospective and current Customers, and individuals associated with Customer Orgs and Projects, including authorized Users. It also describes our handling of account, configuration, usage, and technical information relating to Agents and Systems. BuildFetch acts as a controller or business, as applicable, for personal information that we process for our own purposes, such as account administration, billing, website operations, support, security, and permitted marketing. For purposes of this Policy, “Personal Data” means personal information contained in Customer Data that BuildFetch processes on behalf of Customer, as further defined in the Data Processing Addendum. For Personal Data that we process on behalf of a Customer, BuildFetch acts as a processor, subprocessor, service provider, or contractor, as applicable, and the Customer acts as a controller or processor, as applicable. Our Data Processing Addendum at https://buildfetch.com/dpa governs that processing where applicable.
This Policy provides notice of our privacy practices. Your use of the Cloud Services is governed by the Cloud Services Terms of Service and any other applicable agreement with BuildFetch.
1. INFORMATION WE COLLECT
1.1 Account and Contact Information. When you register an Org, create a Project, subscribe, or interact with us, we collect:
- Name, email address, Org name, Project names, and information regarding Users, Agents, or Systems associated with the Org or Projects.
- Billing and payment information (processed by third-party payment providers; we do not store full payment method details).
- Login credentials, authentication data, and account security information.
1.2 Usage and Technical Data. We may automatically collect:
- IP address, device type, browser information, and operating system.
- Page URLs or paths, referrer information, usage metrics, analytics data, logs, request information, performance data, and security events.
1.3 Customer Data. Any data, files, metadata, or content that Customer or its authorized Users, Agents, or Systems upload, store, or transmit through the Cloud Services (“Customer Data”). Customer Data may include Personal Data relating to Customer’s employees, contractors, authorized Users, and other personnel. The Cloud Services are not intended for Customer to Process Personal Data relating to other individuals. If such Personal Data is incidentally included in Customer Data, Customer is responsible for promptly removing it or requesting BuildFetch’s assistance with deletion as described in the Data Processing Addendum. Customer retains ownership of Customer Data as provided in the Cloud Services Terms of Service.
1.4 Aggregated Data. “Aggregated Data” means data derived from Customer Data that has been de-identified and aggregated such that it cannot reasonably be used to identify Customer, any individual, or any specific Project.
1.5 Other Information. We may collect communications with support, feedback, survey responses, and information that you otherwise provide to us.
1.6 Information from Third Parties. We may receive information about you, your Org, Projects, Users, Agents, or Systems from service providers, integration partners, public sources, business directories, or referral sources as permitted by law and as reasonably necessary to administer, secure, support, or improve the Cloud Services or our business operations.
1.7 Sensitive and Regulated Data. The Cloud Services are not intended to Process protected health information subject to HIPAA (“PHI”) unless BuildFetch and the applicable Customer have executed a Business Associate Agreement (“BAA”) covering the relevant Cloud Services and the Customer uses only HIPAA-eligible Cloud Services and configurations identified by BuildFetch. Where BuildFetch Processes PHI as a business associate, that Processing is governed by the applicable BAA and HIPAA Rules in addition to other applicable agreements. This Privacy Policy is not a HIPAA Notice of Privacy Practices. Unless BuildFetch expressly agrees otherwise in writing, the Cloud Services are also not intended for cardholder data or sensitive authentication data subject to PCI DSS, government-classified information, or other data subject to sector-specific requirements that impose obligations on BuildFetch beyond those expressly accepted under the Cloud Services Terms of Service or Data Processing Addendum.
2. HOW WE USE INFORMATION
For account, contact, billing, usage, technical, support, and similar information that BuildFetch processes for its own purposes, we may use information to:
- Provide, administer, secure, maintain, troubleshoot, support, and improve the Cloud Services and our business operations.
- Manage Orgs, Projects, Subscription Plans, billing, and account access.
- Communicate about accounts, service updates, support, security, and, where permitted, marketing.
- Detect and prevent fraud, abuse, security incidents, and unlawful activity.
- Enforce our agreements and comply with legal obligations.
- Respond to applicable privacy rights requests.
For Customer Data, BuildFetch processes it only as necessary to provide, operate, secure, maintain, troubleshoot, and support the Cloud Services and as otherwise permitted by the Cloud Services Terms of Service, this Privacy Policy, and the Data Processing Addendum. BuildFetch does not sell, lease, or commercially exploit Customer Data. BuildFetch may disclose Customer Data to personnel, contractors, service providers, and subprocessors only as necessary to provide, secure, maintain, or support the Cloud Services, as directed or authorized by Customer, or as required by law, subject to appropriate confidentiality and, where applicable, data-protection obligations.
BuildFetch may create, use, retain, and disclose Aggregated Data for legitimate business purposes, including product improvement, analytics, benchmarking, and marketing, provided it cannot reasonably identify Customer, any individual, or any specific Project.
3. LEGAL BASES FOR PROCESSING
Where applicable, BuildFetch relies on legal bases including:
- Performance of a contract, including providing and administering the Cloud Services.
- Legitimate interests, including operating and improving our business and Cloud Services, maintaining security, preventing fraud and abuse, supporting Customers, and permitted marketing.
- Compliance with legal obligations.
- Consent where required, such as for certain marketing communications or non-essential cookies.
Where BuildFetch acts as a processor or subprocessor for Personal Data in Customer Data, BuildFetch processes that Personal Data on the documented instructions of Customer as described in the Data Processing Addendum.
Certain account, contact, authentication, and other information necessary to establish and administer an Org or Project is required to create and maintain the relevant account or use the affected Cloud Services. Billing information is required for paid Services. If required information is not provided, BuildFetch may be unable to create or maintain the relevant account, process billing, or provide the affected Services.
4. SHARING AND DISCLOSURE OF INFORMATION
BuildFetch does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and California Privacy Rights Act.
We may disclose personal information to:
- Service Providers and Subprocessors: Cloud infrastructure providers, payment processors, analytics providers, communications providers, security providers, and support vendors that require access to perform services for BuildFetch. Current subprocessors are listed at https://buildfetch.com/subprocessors.
- Affiliates: BuildFetch affiliates where reasonably necessary for administration, support, security, or other lawful business purposes.
- Business Transfers: Relevant account, corporate, and business records in connection with an actual or proposed merger, acquisition, financing, corporate reorganization, or sale of assets, subject to appropriate confidentiality protections. Customer Data is disclosed in such transactions only as permitted by the Cloud Services Terms of Service and Data Processing Addendum.
- Legal Requirements: Where required by law, regulation, court order, subpoena, or other legal process, or where otherwise permitted by law to protect rights, safety, security, or the integrity of the Cloud Services.
- At Your Direction: As directed or authorized by Customer or the relevant individual.
Customer Data is subject to the additional disclosure restrictions in the Cloud Services Terms of Service. Details regarding subprocessors, including notice of intended additions or replacements and applicable objection rights, are set forth in Section 6 of the Data Processing Addendum.
5. DATA SECURITY
BuildFetch maintains a risk-based information security program designed to protect the confidentiality, integrity, and availability of personal information, including appropriate administrative, technical, organizational, and physical safeguards. No system can be guaranteed to be completely secure.
Customer is responsible for protecting its credentials and appropriately configuring and managing access to the Cloud Services.
When BuildFetch acts as a processor or subprocessor and becomes aware of a Personal Data Breach affecting Customer Data, BuildFetch will notify the affected Customer without undue delay and, where reasonably practicable, within seventy-two (72) hours, and will provide the information and cooperation described in the Data Processing Addendum. When BuildFetch acts as a controller for affected personal information, BuildFetch will provide notices to regulators or individuals as required by applicable law.
Upon reasonable request, BuildFetch will provide Customer with a high-level summary of its technical and organizational security measures or relevant third-party certifications, subject to appropriate confidentiality protections.
6. DATA RETENTION
BuildFetch retains personal information for no longer than reasonably necessary for the purposes described in this Policy, subject to applicable legal, accounting, security, and dispute-resolution requirements.
- Account and billing information: Retained while the account is active and for the period reasonably necessary for tax, accounting, legal, security, and dispute-resolution purposes.
- Customer Data: Some Cloud Services may store Customer Data only temporarily or subject to retention, capacity, usage, Customer-configured, or other data-management limits. Customer Data may be automatically deleted, overwritten, or otherwise removed in accordance with the applicable Subscription Plan, published documentation, Customer-configured settings, or the ordinary operation of the Cloud Services. Unless BuildFetch expressly commits to a minimum retention period, no minimum retention period is guaranteed. Following termination, BuildFetch may delete Customer Data then remaining in accordance with the Cloud Services Terms of Service and Data Processing Addendum.
- Usage and technical data: Retained for periods reasonably necessary for operations, billing, accounting, security, analytics, support, legal compliance, or in aggregated or de-identified form.
- Aggregated Data: May be retained for legitimate business purposes where it cannot reasonably identify Customer, any individual, or any specific Project.
Customers may use available Cloud Services controls or contact BuildFetch to request deletion where supported. Statutory privacy rights requests are not conditioned on payment of outstanding Fees and are handled in accordance with applicable law.
7. YOUR RIGHTS AND CHOICES
Depending on applicable law, individuals may have rights to access, correct, delete, obtain a copy of personal information or receive it in a portable format; object to or restrict certain processing; withdraw consent where processing is based on consent; or opt out of certain marketing or data uses.
Where BuildFetch acts as a controller for personal information, you may submit a request to [email protected] or use available Cloud Services tools. BuildFetch will verify and respond to requests within the timelines required by applicable law.
Where the GDPR or UK GDPR applies, applicable rights include the right to data portability where its legal requirements are met and the right to lodge a complaint with the competent data-protection supervisory authority. In the United Kingdom, complaints may be made to the UK Information Commissioner’s Office. In the EEA, complaints may be made to the supervisory authority in the Member State where you live or work or where the alleged infringement occurred.
Where Personal Data is contained in Customer Data and BuildFetch acts as a processor or subprocessor, the relevant Customer controls that Personal Data. Data subjects should generally direct requests to the relevant Customer. BuildFetch will notify and reasonably assist Customer with such requests as required by applicable law and the Data Processing Addendum.
California Residents. To the extent the CCPA/CPRA applies to BuildFetch as a business, California residents may have rights to know or access personal information, correct inaccurate personal information, delete personal information, opt out of sale or sharing, limit certain uses or disclosures of sensitive personal information, and not receive discriminatory treatment for exercising applicable rights. BuildFetch does not sell personal information or share personal information for cross-context behavioral advertising. BuildFetch also does not use or disclose sensitive personal information for purposes that require offering a right to limit under the CCPA/CPRA.
8. COOKIES, ANALYTICS, AND ONLINE TRACKING
BuildFetch uses cookies and similar technologies where necessary for authentication, security, functionality, and other operation of the Cloud Services. Strictly necessary technologies may be used without consent where permitted by law. Where applicable law requires consent for a particular non-essential technology or analytics activity, BuildFetch will obtain consent through available consent tools or other appropriate means.
For website and product analytics, BuildFetch uses OpenPanel. BuildFetch may send event data to OpenPanel, including page URLs or paths, referrer information, user-agent information, IP address, and event properties. OpenPanel states that it does not set analytics tracking cookies or store raw IP addresses. According to OpenPanel, IP addresses are used transiently to derive approximate geolocation and a daily-rotating anonymous identifier based on the IP address, user agent, project ID, and a rotating salt, after which the raw IP address is discarded. OpenPanel states that the resulting identifier resets daily and is not used as a persistent cross-device or cross-site identifier. BuildFetch does not use OpenPanel for cross-context behavioral advertising or to track visitors across unaffiliated websites.
California Do Not Track Disclosures. BuildFetch does not currently alter its standard analytics collection in response to legacy browser “Do Not Track” (“DNT”) signals. We do not knowingly permit analytics or advertising providers to collect personal information about your activities on BuildFetch over time and across unaffiliated websites for their own cross-site behavioral advertising. Service providers may process request and analytics data as necessary to provide services to BuildFetch, subject to applicable contractual and legal restrictions.
BuildFetch does not sell personal information or share personal information for cross-context behavioral advertising. Accordingly, there is currently no sale or sharing by BuildFetch from which a Global Privacy Control or similar opt-out preference signal would opt you out. If BuildFetch engages in an activity for which applicable law requires honoring an opt-out preference signal, BuildFetch will honor applicable signals as required by law.
9. INTERNATIONAL DATA TRANSFERS
BuildFetch Inc. is incorporated in the State of Wyoming, United States. Personal information may be transferred to, stored, and processed in the United States or other countries. Where applicable law requires a transfer mechanism, BuildFetch uses appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful UK transfer mechanism, applicable Swiss safeguards, adequacy decisions, or other lawful mechanisms. The Data Processing Addendum contains additional terms governing international transfers of Personal Data in Customer Data. Additional information about applicable international-transfer safeguards, including a copy of relevant safeguards where required by law, may be requested at [email protected].
Where Swiss data-protection law applies, destination countries for disclosures to service providers and Sub-processors are identified at https://buildfetch.com/subprocessors, including through linked provider location lists where processing locations vary dynamically.
10. CHILDREN’S PRIVACY
Our Cloud Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children through services directed to them.
11. CHANGES TO THIS PRIVACY POLICY
We may update this Policy from time to time. For existing Customers, we will provide at least thirty (30) calendar days’ prior notice of material changes by email or in-Service notice unless a shorter period is required to comply with applicable law. Subject to applicable law, material changes apply on the date stated in the notice unless Customer affirmatively acknowledges or accepts the revised Policy earlier, in which case the revised Policy applies to Customer upon that acknowledgment or acceptance. Previous versions may be made available through our website.
12. CONTACT US
For questions, requests, concerns, or to exercise applicable privacy rights:
- Email: [email protected]
- Mail: 1021 E Lincolnway Suite #8618 Cheyenne, Wyoming 82001, United States