Legal
Privacy Policy
Last updated: August 24, 2026
This Privacy Policy explains how Build ERP (“Build,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our construction operations platform and related websites, applications, and services (collectively, the “Service”).
1. Scope
Build ERP is a business-to-business construction ERP used by contractors, owners, and their teams to manage projects, financials, documents, and related workflows. This Policy covers (1) personal information of individual users and contacts, and (2) Customer Data — business and project information submitted to the Service. It is incorporated into our Terms of Service.
2. Key definitions
- Customer — the business entity that contracts for or is authorized to use the Service.
- Authorized User — an individual invited or permitted by a Customer to access the Service.
- Customer Data — project, financial, vendor, document, and other business content submitted to the Service. Customers own their Customer Data.
- Personal Information — information that identifies or is reasonably linkable to an individual (for example, name, email, or device identifiers).
3. Information we collect
3.1 Customer Data
Depending on how a Customer uses the Service, Customer Data may include:
- Project details (names, locations, contracts, cost codes, status, and related metadata)
- Vendor, subcontractor, and company directory information
- Financial records such as invoices, purchase orders, bills, change orders, and payment status
- Field and project documents (drawings, RFIs, submittals, daily logs, transmittals, closeout items, and similar)
- Workflow history, comments, approvals, and audit trails
3.2 Account and contact information
When Authorized Users register or are invited, we collect information such as name, business email, authentication credentials (stored securely), role or membership details, and communication preferences.
3.3 Technical and usage data
We may automatically collect device and browser information, IP address, log data (pages visited, features used, timestamps), and performance or error data needed to operate and improve the Service.
3.4 Information from integrations
If a Customer connects third-party tools (for example Google sign-in and Google Drive, Procore, or QuickBooks Online), we receive data those platforms authorize for the connection. Each platform’s own terms and privacy policy also apply. How we handle Google user data, including Google Drive files and metadata, is described in Section 8.
4. How we use information
We use information to:
- Provide, operate, secure, and support the Service
- Authenticate users, manage workspaces and permissions, and process invitations
- Enable Customer-configured integrations and notifications
- Send transactional and administrative communications about the Service
- Analyze de-identified or aggregated usage to improve reliability and features
- Detect, investigate, and prevent fraud, abuse, or security incidents
- Comply with law and enforce our agreements
We do not sell Customer Data or Personal Information. We do not use Customer Data for unrelated advertising.
6. Customer Data ownership and responsibilities
As between Build ERP and the Customer, the Customer owns its Customer Data. Our license to process Customer Data is limited to providing the Service and the purposes described in this Policy and the Terms of Service. Customers are responsible for the accuracy and legality of Customer Data, for obtaining any required consents, and for configuring user access appropriately.
7. Third-party integrations
Customers control which integrations are enabled. Disconnecting an integration stops future data exchange with that platform; previously received data remains subject to our retention practices unless otherwise deleted under the Customer’s instructions or applicable law.
Google sign-in and Google Drive are described in Section 8. For QuickBooks Online specifically, see our QuickBooks Online Integration Privacy Policy and related end-user agreement. Those documents supplement—not replace—this Policy for that integration.
8. Google user data and Google Drive
Authorized Users may sign in with Google and connect Google Drive so Build ERP can manage construction project document folders inside the Service. This section describes how we access, use, store, and share Google user data, including data obtained through Google Workspace APIs. It is written for users and for Google’s OAuth verification of our Drive access. Google’s own Privacy Policy also applies to data Google holds in your Google Account and Drive.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
8.1 Google data we access
When you authorize Google, we request only the access needed to sign you in and to operate the in-app project Drive experience:
- Google Account (sign-in) — basic profile information such as your name, email address, and profile photo, used to create or match your Build ERP user account and display your identity in the Service.
-
Google Drive —
we request the Google Drive scope
(
https://www.googleapis.com/auth/drive) so the Service can create a project folder in Drive, copy a Customer-configured folder template into that project folder, list files and folders in those project folders, upload files that Authorized Users choose to store there, and check that the signed-in Google account can open the linked folder. For those operations we may receive file and folder metadata (for example identifiers, names, types, owners or permission summaries, view links, and thumbnail URLs) and, when you upload, the file you selected.
We use Drive access to provide this document-folder feature in the product interface. We do not use it to scrape, harvest, sell, or independently analyze unrelated Drive files for other products, advertising, or unrelated research.
8.2 How we use Google Drive data
Drive data is used only to provide and improve the user-facing project document features that appear in the Service, specifically to:
- Create a Google Drive folder for a construction project and copy a standard folder template into it
- Show Authorized Users the contents of that project folder (and subfolders they open) inside Build ERP
- Upload files that an Authorized User selects into a chosen project Drive folder
- Confirm folder access and keep the project linked to the correct Drive folder
- Refresh Google authorization tokens so the Drive connection can continue to work
We do not use Google user data, including Drive files or metadata, to serve advertisements, for credit, lending, or insurance decisions, or to create, train, or improve generalized machine-learning or artificial-intelligence models. We do not sell Google user data.
8.3 How we store Google Drive data
- File contents stay in Google Drive. Project documents created or uploaded through this integration remain stored in the user’s (or Customer’s) Google Drive. Build ERP is not a permanent archive of Drive file bodies.
- What we keep in our systems: OAuth access and refresh tokens needed to maintain the Google connection; the Google Drive folder identifier linked to a project; and account identifiers from Google sign-in (such as email) used for authentication. Folder and file metadata may be retrieved and displayed while you browse a project Drive folder in the Service.
- Temporary upload files: when an Authorized User uploads a file through the Service, we may briefly write that file to temporary storage on our servers solely to send it to Google Drive, then delete the temporary copy.
8.4 How we share Google Drive data
We do not transfer Google user data to third parties except as needed to operate the Service and as allowed by Google’s Limited Use rules, including:
- Google, which hosts Drive and processes OAuth as the platform you authorized
- Infrastructure and security vendors that host or protect the Service, under confidentiality obligations
- Other Authorized Users in the same Customer workspace, only as the project’s permissions and Google Drive sharing settings already allow
- When required by law, to investigate abuse or security incidents, or as part of a merger or sale of our business after obtaining any consent Google’s policies require
Our personnel do not read Google Drive file contents except where necessary to provide support you request, to investigate a security or abuse issue, to comply with law, or where data is aggregated and anonymized for internal operations. We do not transfer or sell Google user data to advertising platforms, data brokers, or information resellers.
8.5 Managing and deleting Google Drive access
You can revoke Build ERP’s access to your Google Account and Drive at any time in your Google Account’s third-party access settings (Google Account → Security → Third-party apps & services). After revocation we can no longer call the Drive API with your credentials. Tokens we stored for that connection are no longer usable; you may also request deletion of remaining Google-related identifiers we hold by emailing info@builderp.com with the subject “Privacy Request.” Folder identifiers stored on a project record can be updated or removed by a Customer administrator in the Service. Files that already exist in Google Drive remain in Drive until you or the Drive owner delete them there; revoking app access does not by itself delete those Drive files.
10. Security
We maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data and Personal Information. No method of transmission or storage is completely secure. Customers and Authorized Users are responsible for safeguarding their credentials and devices. If you become aware of a security incident related to the Service, please contact us promptly.
11. Data retention
We retain Customer Data while a Customer’s account is active and for a reasonable period afterward to allow export or wind-down, unless a longer retention period is required by law or needed to resolve disputes and enforce agreements. Personal Information of Authorized Users is retained as needed to provide the Service and meet those same obligations. Aggregated statistics that do not identify individuals may be retained longer.
12. Your choices
- Authorized Users may update profile information through account settings where available.
- Customers’ administrators manage invitations, membership, and workspace access.
- You may opt out of non-essential promotional emails (transactional messages will continue).
- Customers may disconnect integrations from applicable settings in the Service.
- You may revoke Google Drive and Google sign-in access as described in Section 8.5.
13. Privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of certain Personal Information, or to object to or restrict certain processing. Many requests related to Customer Data should be directed to the Customer that administers your workspace. For Personal Information we control directly, contact us at the email below. We will verify requests as required by applicable law. We will not discriminate against you for exercising privacy rights available to you.
If you are a California resident, you may have additional rights under the CCPA/CPRA, including the right to know, delete, and correct Personal Information. We do not sell Personal Information or share it for cross-context behavioral advertising.
14. International users
The Service may be hosted and processed in the United States or other locations where we or our service providers operate. If you access the Service from another country, your information may be transferred to and processed in those locations subject to applicable law.
15. Children’s privacy
The Service is designed for business professionals and is not directed to children under 16. We do not knowingly collect Personal Information from children. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.
16. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes may also be communicated by email or in-product notice. Continued use of the Service after the effective date of an update constitutes acceptance of the revised Policy, except where applicable law requires additional consent.
17. Contact us
For privacy questions or requests, email info@builderp.com with the subject line “Privacy Request.”
Questions? Contact us at info@builderp.com.