Privacy Policy
BuilderBase AB ("BuilderBase", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the BuilderBase platform ("Platform").
BuilderBase AB is a Swedish company and complies with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Information We Collect
1.1 Account Information (Required)
When you create an account, we collect:
- Name
- Email address
- Authentication method (Google OAuth, GitHub OAuth, or email)
- Account creation date
- User ID (automatically generated)
1.2 Profile Information (Optional)
You may choose to provide:
- Profile photo
- Skills and interests
- Experience level
- Location (city/country)
- Social links (GitHub, LinkedIn, personal website)
- Bio or description
- Resume/CV uploads
1.3 Event Registration Data
When you register for events, we collect:
- Responses to organizer-defined registration questions
- Event preferences and track selections
- Application materials (if required by organizer)
- Screening status and approval decisions
1.4 Event Participation Data
During event participation, we collect:
- Team membership and formation history
- Project submissions (code, files, videos, documentation)
- Check-in records and attendance
- Help requests and mentor interactions
- Team chat messages (if using platform messaging)
- Judging scores and feedback received
- Awards and achievements
1.5 Platform Usage Data
We automatically collect:
- Session logs and timestamps
- Feature usage patterns
- Error reports and diagnostic data (anonymized)
- Device type and browser information
- IP address (for security and fraud detection)
1.6 Cookies and Tracking Technologies
We use:
- Essential cookies: Required for authentication and platform functionality
- Analytics cookies: To understand usage patterns and improve the platform (anonymized)
You can control cookie preferences in your browser settings.
2. How We Use Your Information
We use your personal data for the following purposes:
2.1 Platform Operations
- Create and manage your account
- Authenticate your identity and maintain security
- Provide platform features and functionality
- Process event registrations and applications
- Facilitate team formation and collaboration
- Enable project submissions and judging
- Deliver notifications and platform communications
2.2 Event Management
- Share your registration data with event organizers for events you register for
- Enable organizers to screen, approve, and manage participants
- Facilitate communication between participants, mentors, judges, and organizers
- Support team formation, help queues, and mentorship
- Process judging, scoring, and award distribution
2.3 Builder Profile and Reputation
- Build your cross-event participation history and achievements
- Create a merit-based builder profile that follows you across events
- Track your skills development and project portfolio
- Enable you to showcase your work to potential collaborators and opportunities
2.4 Platform Improvement
- Analyze usage patterns to improve user experience
- Identify and fix bugs and technical issues
- Develop new features and functionality
- Conduct research and analytics (using anonymized data)
2.5 Security and Fraud Prevention
- Detect and prevent cheating, plagiarism, and fraudulent activity
- Compare code submissions across events globally to detect pre-builds
- Verify submission timestamps and team formation integrity
- Protect the Platform and users from security threats
2.6 Legal Compliance
- Comply with legal obligations and regulatory requirements
- Respond to legal requests and prevent illegal activity
- Enforce our Terms and Conditions
3. How We Share Your Information
BuilderBase operates on an organizer-controlled data access model. We share your data only as described below:
3.1 Event Organizers
When you register for an event, the event organizer receives:
- Your registration information and responses
- Profile information (name, email, skills, experience, optional fields)
- Team membership and project submissions
- Participation data (check-ins, help requests, engagement)
- Judging results and awards
Organizers use this data to manage their events, select participants, coordinate activities, and evaluate projects.
3.2 Mentors and Judges
Mentors and judges for events you participate in can access:
- Your name and profile information
- Team information and project details
- Submissions and materials relevant to their role
- Communication within help queues or judging workflows
3.3 Other Participants
Within events you participate in, other participants can see:
- Your name and public profile information
- Your team membership
- Public project submissions (as configured by organizers)
3.4 Sponsors and Partners
By default, sponsors do NOT receive raw participant data.
Sponsors receive:
- Aggregated, anonymized metrics (e.g., number of participants, engagement statistics)
- Access to projects that use their technology (if configured by organizer)
- Opt-in contact from participants who choose to share their information
Any raw data sharing with sponsors requires explicit organizer approval, and you control your profile visibility to sponsors.
3.5 Service Providers
We share data with trusted third-party service providers who help us operate the Platform:
- Hosting: Cloudflare Workers (infrastructure)
- Database: Supabase (data storage and authentication)
- Email: Email service providers for transactional emails
- Analytics: Anonymized usage analytics tools
All service providers are bound by data protection agreements and process data only as instructed by us.
3.6 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or government request, or if necessary to protect rights, property, or safety; enforce our Terms; or prevent fraud or security threats.
3.7 Business Transfers
If BuilderBase is involved in a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such change and your rights regarding your data.
4. Data Protection Commitments
4.1 No Data Sales
We will never sell your personal data to third parties for marketing, advertising, or any other purpose.
4.2 No Hidden AI Training
We do not use your personal data, project submissions, or content to train external AI models or for hidden profiling purposes.
4.3 Minimal Data Collection
We collect only the data necessary to provide platform functionality and improve user experience. Optional data is clearly marked and under your control.
4.4 Organizer Accountability
Event organizers who receive your data are independent data controllers responsible for their own data practices. We encourage organizers to respect participant privacy, but we are not responsible for organizer data handling outside the Platform.
5. Data Security
We implement industry-standard security measures to protect your data:
5.1 Technical Safeguards
- Encryption: Data is encrypted in transit (TLS/SSL) and at rest
- Access controls: Role-based access with least-privilege principles
- Database security: Row-level security policies in Supabase
- Authentication: Secure OAuth and token-based authentication
- Infrastructure: Hosting on secure, enterprise-grade platforms (Cloudflare, Supabase)
5.2 Organizational Safeguards
- Regular security audits and vulnerability assessments
- Employee access limited to necessary personnel
- Data protection training for team members
- Incident response procedures
5.3 Limitations
While we take security seriously, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and notifying us immediately of any unauthorized access.
6. Your Data Rights (GDPR)
Under the GDPR and applicable data protection laws, you have the following rights:
6.1 Right to Access
You can request a copy of all personal data we hold about you.
6.2 Right to Rectification
You can correct inaccurate or incomplete data through your profile settings or by contacting us.
6.3 Right to Erasure ("Right to Be Forgotten")
You can request deletion of your personal data. Note that deletion may affect your ability to access historical achievements and event records; some data may be retained for legal compliance or legitimate interests; organizers who received your data are independent controllers and must handle deletion separately.
6.4 Right to Restriction of Processing
You can request that we limit how we process your data in certain circumstances.
6.5 Right to Data Portability
You can request a machine-readable export of your data to transfer to another service.
6.6 Right to Object
You can object to processing of your data for certain purposes, such as direct marketing or legitimate interests.
6.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time without affecting prior processing.
6.8 Right to Lodge a Complaint
You have the right to file a complaint with a data protection authority in your country. For Sweden: Integritetsskyddsmyndigheten (IMY) — www.imy.se
6.9 How to Exercise Your Rights
To exercise any of these rights, contact us at: Email: support@builderbase.com, Subject line: "Data Rights Request". We will respond within 30 days of receiving your request.
7. Data Retention
7.1 Account Data
We retain your account and profile data for as long as your account is active or as needed to provide services.
7.2 Event Participation Data
Event participation history, submissions, and achievements are retained indefinitely to support your cross-event reputation, enable organizers to maintain historical records, and provide analytics.
7.3 Deletion Upon Request
If you request account deletion: personal data is permanently deleted within 30 days; anonymized data may be retained for analytics; some data may be retained longer for legal compliance.
7.4 Inactive Accounts
Accounts inactive for more than 5 years may be anonymized or deleted after notification.
8. International Data Transfers
BuilderBase AB is based in Sweden (EU). Your data is primarily processed within the EU/EEA. When transferring data outside the EU/EEA, we ensure adequate protections through Standard Contractual Clauses (SCCs), adequacy decisions, and service provider commitments to GDPR-equivalent protections.
9. Children's Privacy
The Platform is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. Users aged 13–17 must obtain parental or guardian consent. If we discover we have collected data from a child under 13 without proper consent, we will delete it promptly. Parents or guardians can contact us at support@builderbase.com.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes: we will update the "Last Updated" date; we will notify you via email or prominent platform notification at least 30 days before changes take effect; continued use after changes become effective constitutes acceptance. We encourage you to review this Privacy Policy periodically.
11. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
BuilderBase AB
Data Protection Officer / Privacy Team
Email: support@builderbase.com
For GDPR-related inquiries or to exercise your data rights, please use the subject line "Data Rights Request" or "GDPR Inquiry".