Privacy statement
Last updated: 10 August 2026
Requires legal review before production
This statement describes what the BuildMatch platform actually does with personal data, written from a technical review of the system. It has not yet been reviewed by a qualified lawyer, and the entity details below are unfilled. It must not be treated as the final published policy.
1. Who is responsible for your data
BuildMatch is the controller of the personal data described here. The registered details below still need to be supplied:
- Legal name:
TODO: registered legal name - Registered address:
TODO: registered address - Company registration:
TODO: chamber-of-commerce / company registration number - Privacy contact:
TODO: privacy contact address (e.g. privacy@…) - Data Protection Officer:
TODO: confirm whether a Data Protection Officer is appointed
Until those details are published, reach us through support.
2. What we collect, why, and on what basis
You can browse projects, use filters and compare developments without an account. Most of the data below only exists once you sign up, save something, or ask for an advisor.
Account and profile
- What:
- Your email address and password (held by our authentication provider), your display name, language and — for buyers — whether you currently work with an advisor.
- Why:
- To create and secure your account and to show you your own saved items.
- Lawful basis:
- Performance of a contract (our terms of use).
Search and preference data
- What:
- Favorites, comparisons, saved searches and the filters they contain (budget, region, property type, amenities).
- Why:
- To show you your saved items, to notify you when new projects match a saved search, and — if you have an advisor — so they can work from what you've actually saved.
- Lawful basis:
- Performance of a contract; legitimate interest in operating the search service.
Advisor enquiries
- What:
- The name, email address, phone number and message you submit when you ask for an advisor. This form can be used without an account, in which case the enquiry is not linked to a user profile.
- Why:
- To respond to your request and assign an advisor.
- Lawful basis:
- Steps taken at your request prior to entering into a contract.
Communications with your advisor
- What:
- Messages exchanged between you and your advisor on the platform, viewing appointments and their notes, and internal notes your advisor writes about your requirements.
- Why:
- To deliver the advisory service and keep a usable history of what was discussed and agreed.
- Lawful basis:
- Performance of a contract; legitimate interest in service quality.
Documents you upload
- What:
- Documents supplied during a purchase — which may include identity documents and proof of funds — together with their status and who uploaded them.
- Why:
- To progress a reservation and purchase, and because a Spanish property transaction requires them.
- Lawful basis:
- Performance of a contract; legal obligation where identity or source-of-funds checks apply.
Transaction and roadmap data
- What:
- Reservations and their status, and your purchase roadmap: the steps in your journey, their status, who is responsible for each, and a log of changes to them.
- Why:
- To carry out and track your purchase, and to show you and your advisor where it stands.
- Lawful basis:
- Performance of a contract.
Reviews
- What:
- A rating, review text and the display label you choose for yourself. Reviews can only be written after a purchase completes, and are published only after moderation.
- Why:
- To publish verified buyer experiences.
- Lawful basis:
- Consent — you choose to write and submit a review, including the name it appears under.
Support
- What:
- Support tickets and the messages in them, plus — where you are helped with an account issue — a time-limited access grant recording that a support agent was given access.
- Why:
- To answer your question and keep a record of what was done.
- Lawful basis:
- Performance of a contract; legitimate interest in supporting our users.
Referrals
- What:
- Your personal referral code and a record of accounts created through it.
- Why:
- To attribute referrals correctly.
- Lawful basis:
- Legitimate interest in operating the referral feature.
Technical and security data
- What:
- Error reports generated when something breaks, and an internal audit log recording sensitive administrative actions (who changed what, and when) using account identifiers rather than names.
- Why:
- To keep the platform working and to be able to investigate misuse.
- Lawful basis:
- Legitimate interest in security and reliability.
TODO: legal review — confirm the lawful basis stated for each category above
3. Who inside BuildMatch can see your data
Access is enforced by the database itself rather than only by what the interface chooses to display. In practice:
- You can see your own data.
- Your advisor can see your profile, your saved items, your conversation with them, your documents, your reservations and your roadmap — for as long as they are your advisor.
- Developers cannot see who you are while you are browsing or being advised. A developer only gains access to your name and contact details once a reservation links you to one of their specific units, and they never gain access to your documents, your messages or your roadmap.
- BuildMatch staff see what their role requires: support agents see support tickets, administrators can see account data for platform administration. Sensitive administrative actions are recorded in an audit log.
4. Service providers who process data for us
| Provider | What they do for us |
|---|---|
| Supabase | Database, authentication and file metadata. Holds effectively all platform data, including your email address and password credentials. |
| Cloudinary | Storage of uploaded files. Buyer documents are stored as private assets — they are never given a public address, and are retrieved through links that expire after five minutes. |
| OpenAI | AI features used by our advisors: summarising an advisor conversation, drafting a translation of an advisor's message, and suggesting projects that match a buyer's criteria. Where a summary or translation is requested, the underlying message text is sent to OpenAI to produce it. No prompt or response text is stored in our AI logs. |
| Resend | Sending transactional email (notifications, advisor updates, account email). |
| Sentry | Error monitoring. Configured not to send personal data by default; cookies and request headers are stripped before an error report leaves the application. |
| Google Maps | Map display on project and search pages. When a map loads, your browser contacts Google directly and Google receives your IP address under its own privacy terms. |
| Netlify | Hosting and delivery of the website. |
We do not sell personal data, and we do not share it with developers for their own marketing.
TODO: legal review — confirm signed data-processing agreements with each provider, and state the transfer mechanism for providers processing data outside the EEA
5. AI features
BuildMatch uses AI in a small number of places, all of them tools for our advisors rather than automated decisions about you. An advisor can ask for a summary of their conversation with you, for a translation of a message they are drafting, or for suggestions of projects matching a buyer's criteria. Producing a summary or translation means sending the relevant message text to our AI provider.
No AI output reaches you without a person reviewing and confirming it first, and no AI feature makes a decision that affects you on its own. Our internal AI activity log records that a request happened — it does not store the text sent or returned.
6. Cookies and local storage
BuildMatch sets cookies to keep you signed in. These are necessary for the site to work and are not used to track you across other websites.
Some things are stored in your own browser rather than on our servers: recently used search terms, favorites saved before you create an account, the projects you have put in a comparison, and your currency preference. Clearing your browser storage removes them.
We currently use no third-party analytics, advertising or tracking cookies. If that changes, this section and the consent mechanism will change with it — before, not after.
7. How long we keep data
Account and purchase data is kept while your account exists and, where a transaction has taken place, for as long as tax and anti-money-laundering obligations require records to be kept.
TODO: legal review — set concrete retention periods per data category, including the statutory minimums, and implement the corresponding deletion routine We would rather state that this is outstanding than publish retention periods we do not yet apply.
8. Your rights
Under the GDPR you can ask for access to your personal data, correction of it, deletion of it, restriction of or objection to processing, and a copy of data you provided in a portable form. Where processing is based on consent, you can withdraw that consent at any time. You can also complain to your national data protection authority.
You can change your display name and language yourself in your account settings. Everything else — access, deletion, a copy of your data — is currently handled manually by our team: contact us through support and we will deal with it. There is not yet a self-service “download my data” or “delete my account” button; building one is on our roadmap and we are not going to pretend it already exists.
9. Security
Access rules are enforced in the database, so a mistake in the interface cannot by itself expose someone else's data. Uploaded documents are stored privately and are only reachable through short-lived links issued to someone already entitled to see them. Staff accounts with elevated access require two-factor authentication, and sensitive administrative actions are written to an audit log that cannot be edited or deleted.
No system is perfectly secure. If you believe you have found a vulnerability, please report it through support rather than disclosing it publicly.
10. Changes to this statement
When this statement changes we update the date at the top. For changes that materially affect how we use your data, we will tell account holders directly rather than relying on you to re-read this page.