Legal
Privacy Policy
Last updated: 24 May 2026
We collect only the personal data we need to run BuildSpain, we never sell it, and you can ask us to delete it at any time. Below is the detail. Questions go to info@buildinspain.com.
1. Who we are (the data controller)
BuildSpain operates buildinspain.com (the “Service”) and is the data controller for any personal data you provide to us. Contact: info@buildinspain.com.
2. What data we collect
We collect only what we need:
- Account data: name, email, hashed password, role (owner / builder).
- Owner inquiries: project description, location, timeline, budget, optional phone.
- Builder applications: company name, business contact details, services, area covered, references.
- Builder profile content: public bio, gallery photos, languages, service tags, you choose to publish.
- Messages: the content of conversations you send and receive on the platform.
- Billing: for paid builders, your Stripe customer ID and subscription state (start, current period end, status). We do not store card numbers — Stripe holds those.
- Technical: IP address, browser and OS string, basic access logs, for security and abuse prevention.
3. How we use your data
- To create and run your account.
- To match owners with builders in the right region.
- To deliver messages and email notifications you'd expect (new lead, new message, trial ending).
- To process membership payments via Stripe.
- To detect fraud, abuse and platform misuse.
- To improve the Service (in aggregate, never to single you out).
4. Legal basis (GDPR)
We rely on:
- Contract — for the data needed to run your account and deliver the Service.
- Legitimate interest — for security logs, fraud prevention and improving the Service.
- Consent — for any future analytics or marketing emails (we'll ask explicitly before turning these on).
- Legal obligation — when we have to retain data for tax or law-enforcement reasons.
6. International transfers
Stripe and Resend are based in the USA. Data sent to them is covered by the EU-US Data Privacy Framework adequacy decision and their own Standard Contractual Clauses. Hosting is in the EU.
7. How long we keep your data
- Active account: as long as your account exists.
- Deleted account: we delete profile and inquiry data within 30 days, except where law requires retention (e.g. payment records for 7 years).
- Messages: kept for the lifetime of the conversation between you and the other party; deleted with the account.
- Server logs: 90 days, then rotated.
8. Your rights (GDPR)
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct anything that's wrong (most of this you can do yourself in your dashboard).
- Erasure — ask us to delete your data (“right to be forgotten”).
- Portability — get your data in a machine-readable format.
- Restriction — ask us to pause processing while a dispute is sorted.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — wherever processing relies on your consent.
- Complain — to the UK ICO (ico.org.uk) or the Spanish AEPD (aepd.es).
Email info@buildinspain.com with “Privacy request” in the subject line and we'll respond within 30 days.
10. Children
BuildSpain is a marketplace for adults arranging professional building work. It's not intended for users under 18 and we don't knowingly collect data from children.
11. Changes to this policy
If we change how we handle data in a meaningful way, we'll update this page and notify registered users by email. The “last updated” date at the top reflects the most recent change.
12. Contact
Email info@buildinspain.com for anything privacy-related.
See also our Terms of Service for the rules of using the platform.