Start an order

Last updated: September 27, 2026

Privacy Policy

What Buildr collects, why, where it lives, and how to ask about it.

The Buildr app sign-in screen: one phone number field and a Text me a code button
The sign-in screen

1. Who is responsible for your information

Buildr is operated by YNET PLUS INC. ("Buildr", "we", "us", "our"). This policy covers the Buildr iOS app, the web app at app.buildr.to, and support relating to them. Buildr lets trade customers configure, purchase, and arrange pickup of custom-fabricated sliding doors.

Contact our Privacy Officer about this policy, your information, or a privacy complaint:

2. Information we handle

InformationHow we receive it and why we use it
Account and contact informationYour mobile number, first and last name, and email address. We use them to sign you in, maintain your account, communicate about orders, and identify the person collecting the goods.
Work areaThe area where you work — a GTA city, or your province if you work outside the GTA — so we can tell you whether Buildr serves your area yet and plan where to open next.
Order and transaction informationDoor specifications, dimensions, quantities, prices, taxes, purchase-order references, the job label you type, pickup dates, payment and refund status, transaction identifiers, receipt links, and timestamps. Each order keeps a copy of the contact details supplied when it was placed. We use this to fulfil orders, provide support, and keep business records.
Payment informationYou enter card details into Stripe's payment interface. Stripe processes them. Our servers never receive or store your full card number or security code; we receive payment references, status, amounts, and receipt information.
Notification and session informationIf you enable push notifications, we store a device notification token to send order updates. Session credentials keep you signed in: in the iOS Keychain on your phone, or in your browser on the web.
Security and technical informationIP addresses, a device identifier sent with requests, request times, and operational logs help us run the service and prevent misuse. Our security providers process device, app, or browser signals to tell legitimate requests from automated abuse.
Support informationMessages you send us, your contact details, order references, and any files you choose to share, so we can respond. Send only what is needed.
Usage and diagnostic dataScreens viewed, taps, masked screen recordings, error reports, and device/app version, so we can see how the app is used and find and fix problems. Everything you type, every piece of on-screen text, and every hidden label or tag on the screen is hidden before a recording ever leaves your device — see section 3.

The job label exists so you can recognise an order. Use a project reference where you can. Do not enter an occupant's name, an access code, or other unnecessary personal details, and only provide another person's information when you are entitled to.

Face ID is optional. Your device performs the biometric check locally to unlock your saved Buildr session. Buildr never receives or stores your facial image or biometric data. Turning Face ID off does not delete your account.

Browser storage and provider technology. We use browser storage and security technology to keep the web app working, keep you signed in, and prevent abuse. Payment and security providers may use their own cookies or identifiers. Clearing browser storage signs you out.

3. How we use information

We use information to run accounts; calculate and process purchases; send sign-in codes and order messages; arrange fabrication and pickup; handle cancellations, refunds, and disputes; answer support requests; protect the service; and meet tax and other legal obligations.

We do not run an advertising program, do not use your information for cross-app advertising tracking, do not sell personal information, and do not currently send marketing email or text messages.

Our providers may process technical and interaction data for their own service improvement, payment security, and fraud prevention. Stripe, for example, describes analytics and fraud-prevention collection in its mobile SDK privacy information.

We use PostHog to understand how the Buildr app is used and to find and fix errors: which screens are opened, which buttons are tapped, screen recordings of app sessions, and automatic error reports. Every typed field, every piece of on-screen text, and every hidden label or tag behind the screen is masked before a recording or event ever leaves your device, so PostHog never receives what you typed, what the screen said, or any hidden detail attached to it — only that a screen was viewed or a control was tapped. We identify you to PostHog by an internal account identifier only, never by your name, phone number, or email. This information is not sold and is not used for advertising.

4. Who receives information

We share information only as needed for the purposes above or as permitted or required by law.

RecipientRole
York Home Products Inc., Concord, OntarioFabricates your doors and hands them over at pickup for Buildr. We give York the order configuration, purchase-order reference, the name on the order, the job label, and pickup information needed for that work.
Amazon Web Services (AWS)Hosts our accounts, application, and database in Canada; delivers our email (SES) and push notifications (SNS); stores operational logs.
TwilioDelivers the sign-in text message you request.
Stripe and payment participantsProcess payments, refunds, fraud checks, and payment disputes; Stripe passes information to card networks and issuers as necessary.
AppleProvides the iOS platform and delivers push notifications you enabled. Face ID processing stays on your device.
Google FirebaseChecks that requests come from a genuine copy of the iOS app (App Check).
CloudflareRuns the Turnstile security check on the web app.
PostHogProduct analytics, screen-tap tracking, session recordings (with inputs and text masked), and error tracking, so we can see how the app is used and fix problems. Processes information in the United States.
Support channelsWhen you email us or choose WhatsApp, the provider of that channel (for WhatsApp, Meta) handles the message under its own terms. Email is always available if you prefer not to use WhatsApp.

We use contractual and other safeguards with organisations that process information on our behalf, and we remain responsible for our own collection and sharing decisions. We may provide necessary information to professional advisers or public authorities to meet a legal obligation, resolve a dispute, or protect legal rights where the law allows.

5. Where information is processed

Our application database and account infrastructure are hosted on AWS in Canada. Payment, SMS, notification, security, analytics, and support providers may process or access information in the United States and other countries where they operate, and it may be accessible to the authorities of those countries under their laws. PostHog processes usage and diagnostic data in the United States. Contact our Privacy Officer with questions about our providers.

6. Your choices

7. Account deletion and retention

Delete your account in the iOS app: Settings → Delete account, type DELETE, confirm. If you cannot sign in, email hi@buildr.to with the subject "Account deletion"; we may verify your identity in a proportionate way.

Deleting an account removes its sign-in identity and push tokens and removes or de-identifies the active customer profile. Order, invoice, payment, refund, and dispute records may remain because we need them for outstanding obligations or legal record-keeping, and some of those records may still identify you. Deletion does not cancel an existing order or create a refund entitlement; contact support separately about an outstanding order. Eligible data in our active systems is removed within 30 days of a verified request; sign-in is disabled as soon as the deletion is confirmed.

Record categoryRetention rule
Active account profileWhile needed to provide the account. Accounts with no sign-in or order for 24 months are reviewed and, with 30 days' notice, closed where nothing is outstanding.
Tax, invoice, payment, and refund recordsGenerally six years from the end of the last tax year they relate to, longer where a legal hold or specific rule requires, keeping only the identity information those records need.
Order contact snapshots and job labels not needed in required recordsRemoved within 90 days after pickup or final cancellation/refund unless a documented outstanding matter needs them.
Application logs30 days; security logs 90 days; incident evidence for as long as an investigation or legal obligation requires.
Email delivery events90 days.
Support correspondenceUp to 24 months after the request is resolved, unless a contractual or legal need is documented.
Device notification tokensRemoved on account deletion, when the token becomes invalid, or when we detect notifications were disabled.
Session credentialsUp to 90 days; terminated on account deletion; cleared on sign-out.
BackupsExpire through the backup cycle, at most 35 days; deletion instructions are re-applied if a backup is restored.
Records of privacy breachesAt least 24 months after we determine a breach occurred.

Records retained after deletion are access-restricted and are never used to rebuild an active customer profile or to market to you. Information no longer needed is securely deleted or irreversibly anonymised.

8. Access, correction, and complaints

You may ask what personal information we hold about you and how it is used or disclosed, and request access or correction, by contacting our Privacy Officer. We may need reasonable information to verify your identity. We ordinarily respond to a written access request within 30 days; where the law allows an extension or limits disclosure, we will say why.

You may also contact the Office of the Privacy Commissioner of Canada (priv.gc.ca). Using our support channels never waives a legal complaint right.

9. Security

We use administrative, technical, and physical safeguards appropriate to the information we handle, including limiting access to authorised personnel and protecting account credentials. No system is perfectly secure; we assess privacy incidents and notify when the law requires. Never send us a sign-in code, a full card number, or identity documents in a support message.

10. Age, and changes to this policy

Buildr is for adult trade customers; the minimum account age is 18. If you believe a child has provided us personal information, contact us so we can address it.

We may update this policy as the service or our legal obligations change. We publish the revised policy with its date and give additional notice or seek consent where required.

Start an order