Privacy Policy
Effective Date: 1st August 2026
Last Updated: 20th August 2026
This Privacy Policy explains how Bricks and Bot Ltd ("we", "us", "our") collects, uses, and protects your personal data when you use Buildsnapper (formerly Buildsnpper), Buildsnapper Assessor (formerly Buildsnpper Assessor), and Buildsnapper Manager (formerly Buildsnpper Manager) mobile applications (the "Apps").
A note on our name. These Apps were previously published as
Buildsnpper. The spelling changed to Buildsnapper on 19th August 2026.
Only the name changed — the data controller, the Apps, your account and the way
your data is handled are all unaffected, and this Policy applies equally to use of
the Apps under either name.
By using our Apps, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use our Apps.
1. DATA CONTROLLER
Bricks and Bot Ltd
Company No: 15693496
Address: 9 Quayside, Congleton, Cheshire
Email: dpo@bricksandbot.com
Phone: +33669728889
We are registered with the Information Commissioner's Office (ICO) as a data controller (registration reference ZB769071) and pay the annual data protection fee.
2. CRITICAL INFORMATION ABOUT DATA STORAGE
2.1 Local Device Storage
IMPORTANT: Photo evidence and associated metadata are stored locally on your device. You are solely responsible for:
- Backing up locally stored data
- Protecting against data loss
- Ensuring data security on your device
- Managing device storage capacity
We cannot access, recover, or be held liable for locally stored data.
2.2 What Is Stored in the Cloud
To provide the service, some data is stored server-side:
- Project and plot records (names, addresses, progress, photo metadata — not the photographs themselves) are synced to our cloud database (see Section 5) so your account works across sign-ins
- Sent reports and photo archives: when you send a report, the report PDF and a photo archive are uploaded and stored (see Sections 5.1 and 5.8) so your assessor can access them
- Photographs are never uploaded until you send a report — unsent photos exist only on your device (see 2.1)
3. DATA WE COLLECT
3.1 Information You Provide
- Account information (name, email address, contact telephone number, company, DEA certification details for assessors)
- Assessor contact details recorded by builders in their in-app address book (name, email address and business telephone number)
- Subscription payment details (processed by Apple/Google for in-app purchases)
- Assessor payment information for client licence purchases (processed by Stripe via web portal)
- Project information and descriptions (including Part L evidence requirements)
- Photos and metadata (stored locally on your device; only device-level OS backups such as iCloud/Google apply until you send a report)
- Assessor profile information (for discovery in app and report branding)
3.2 Automatically Collected Information
- Device information (model, OS version, unique identifiers)
- Crash reports and performance metrics
- Location data (when permission granted)
- IP address (for security and analytics)
3.3 Third-Party Data
- Authentication data from sign-in providers
- Payment confirmation from app stores
- Client assignment data when assessors purchase licences on behalf of clients
3.4 Assessor Portal Data
When using the assessor web portal, we additionally collect:
- Licence purchase history and client assignments
- Bulk purchase preferences
- Assessor branding for reports
- Client project management data
- Evidence review and download activity
4. LEGAL BASIS FOR PROCESSING
We process your data based on:
- Contract Performance: To provide subscription services
- Legitimate Interests: For security, analytics, service improvement, and onboarding and service-related communications
- Consent: For optional features (such as device permissions) and any promotional marketing that requires it
- Legal Obligations: To comply with applicable laws
5. THIRD-PARTY SERVICES AND DATA PROCESSORS
5.1 Firebase Services (Google LLC)
- Purpose: Authentication, cloud database and storage, crash reporting, analytics and performance monitoring
- Data Processed: Account details, project and plot records, sent report PDFs (including the photographs they contain), crash logs, and basic app-usage events
- Location: Data is stored in Google Cloud's London region (europe-west2). Some supporting services (authentication, crash reporting) are operated by Google LLC in the USA under the UK Extension to the EU-US Data Privacy Framework.
- Retention: Crash data 90 days; account data until deletion; sent report PDFs until the report is deleted or withdrawn
- Privacy Policy: https://policies.google.com/privacy
5.2 Algolia
- Purpose: Search functionality within apps
- Data Processed: Search queries, project metadata
- Location: EU/US (Standard Contractual Clauses)
- Retention: 90 days
- Privacy Policy: https://www.algolia.com/policies/privacy
5.4 Stripe (Assessor Portal Only)
- Purpose: Payment processing when assessors purchase licences for clients via web portal
- Data Processed: Assessor's payment card details, billing information, transaction records
- Location: EU/US (Standard Contractual Clauses)
- Note: Card details are processed directly by Stripe; we do not store payment card information
- Privacy Policy: https://stripe.com/privacy
5.5 App Stores
- Google Play Services: Device data, purchase information, handles all in-app subscription billing
- Apple App Store: Account data, purchase information, handles all in-app subscription billing
- Note: App stores control all refund decisions for in-app purchases
5.6 Amazon Web Services — AI Support Assistant (Amazon Bedrock)
- Purpose: When you contact support, our assistant generates an instant answer drawn only from our own help-centre articles, shown to you before you submit a request. You can always skip it and have your question sent to a person.
- Data Processed: The text of your support question and our help-centre content. No photographs, evidence files, or account data beyond what you type into your support message.
- Location: European Economic Area — AWS Europe (Ireland). Processed transiently to produce the answer; not stored by AWS and not used to train any AI model.
- Model: Claude (by Anthropic), run within AWS Bedrock; Anthropic does not receive your data for training.
- Privacy Policy: https://aws.amazon.com/privacy/
5.7 Amazon Web Services — Support Ticket Storage (DynamoDB)
- Purpose: Storing and tracking the support requests you submit, and their status.
- Data Processed: Your name, email address, the support request you send, and (for in-app reports) the basic diagnostic details shown to you before you send them.
- Location: United Kingdom — AWS Europe (London) region.
- Retention: Automatically deleted 6 months after your request is resolved.
- Privacy Policy: https://aws.amazon.com/privacy/
5.8 Amazon Web Services — Photo Archive Delivery and Email (S3 & SES)
- Purpose: Storing sent photo archives so your assessor can access them, and sending transactional emails (report notifications, support ticket updates, account emails). Sent report PDFs are stored in Firebase (see 5.1).
- Data Processed: Sent photo archives (zips of your report photographs) and the content of transactional emails (including your email address).
- Location: United Kingdom — AWS Europe (London) region.
- Retention: Sent photo archives are retained after the associated report or account is deleted; their removal from storage is a periodic manual housekeeping step rather than an immediate, automated deletion. You can request earlier deletion at any time (see Section 8).
- Privacy Policy: https://aws.amazon.com/privacy/
5.9 RevenueCat
- Purpose: Managing in-app subscription status (linking your app-store purchase to your account and confirming entitlement).
- Data Processed: App user identifier, subscription and purchase status from Apple/Google. No payment card details.
- Location: USA (Standard Contractual Clauses / UK International Data Transfer Addendum)
- Privacy Policy: https://www.revenuecat.com/privacy/
5.10 Sentry (Functional Software, Inc.)
- Purpose: Error monitoring on our web services, so faults are found and fixed quickly.
- Data Processed: Technical error details (error type, affected page/endpoint, device/browser information, IP address). We configure Sentry so that the content of what you submit — such as support messages — is never attached to error reports.
- Location: European Union (Sentry EU data residency, Germany).
- Privacy Policy: https://sentry.io/privacy/
5.11 Google Maps Platform
- Purpose: Rendering the location map page included in generated reports.
- Data Processed: The plot photograph coordinates needed to draw the map. No account information is sent with map requests.
- Location: USA (Data Privacy Framework certified)
- Privacy Policy: https://policies.google.com/privacy
5.12 MongoDB Atlas
- Purpose: Storing web portal account data.
- Data Processed: Portal account details (name, email address, securely hashed password) and licence purchase records.
- Location: European Economic Area — hosted on AWS Europe (Ireland). Transfers rely on the UK's adequacy regulations for the EEA.
- Privacy Policy: https://www.mongodb.com/legal/privacy-policy
5.13 Amazon Web Services — Photo Evidence Archive (S3 Glacier Deep Archive)
- Purpose: Optional paid long-term archiving of plot photo evidence, so it remains available for Part L / EPC audit purposes long after a report is sent.
- Data Processed: The archived photo evidence zip for each plot (photographs and their metadata) and an accompanying manifest.
- Location: United Kingdom — AWS Europe (London) region as the primary copy, with a disaster-recovery copy in AWS Europe (Ireland). The transfer to Ireland relies on the UK's adequacy regulations for the EEA (see Section 6).
- Retention: 15 years from archiving, plus a grace period of up to 6 months before removal. Archives are stored with write-once-read-many (WORM) immutability, so they cannot be altered or deleted during the retention term — including by us.
- Privacy Policy: https://aws.amazon.com/privacy/
6. INTERNATIONAL DATA TRANSFERS
Your data may be transferred outside the UK. We only transfer personal data where a lawful transfer mechanism applies:
- Adequacy: the UK has adequacy regulations covering the European Economic Area (EEA), so transfers to EEA countries (such as Ireland) are permitted on that basis;
- Standard Contractual Clauses / the UK International Data Transfer Addendum, for transfers to countries without an adequacy decision;
- Data Privacy Framework certification, where a US recipient is certified.
AI support assistant (AWS Europe, Ireland): When you contact support, the text of your question is processed by our support assistant, which uses Amazon Bedrock in AWS's Europe (Ireland) region to generate an answer from our help-centre articles (see 5.6 above). This transfer from the UK to Ireland relies on the UK's adequacy regulations for the EEA. Your question is processed transiently and is not stored by AWS or used to train any AI model.
7. DATA RETENTION
| Data Type |
Retention Period |
| Account Data |
Duration of account, then permanently deleted 30 days after account deletion (transaction and tax records are kept per the Financial Records row) |
| Local Device Data |
Until you delete from device |
| Cloud-Synced Project Records |
Until you delete them or your account |
| Deleted Account (Recovery Window) |
30 days, then permanently deleted |
| Sent Report PDFs |
Until the report is deleted or withdrawn |
| Sent Photo Archives |
Retained after report/account deletion; removed by periodic manual housekeeping (not immediate) — earlier deletion on request (Section 8) |
| Photo Evidence Archive (paid add-on) |
15 years plus up to 6 months' grace; WORM-immutable for the retention term (see 5.13) |
| Support Tickets |
6 months after resolution, then automatically deleted |
| Crash & Diagnostic Data |
90 days |
| Financial Records |
7 years (UK tax requirements) |
| Payment Data |
Transaction records retained per legal requirements; card details not stored |
| Marketing Data |
Until consent withdrawn |
8. YOUR RIGHTS
Under UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Complain to the Information Commissioner's Office (ICO)
Contact dpo@bricksandbot.com to exercise your rights.
9. DATA SECURITY
9.1 Technical Measures
- Encryption in transit (TLS)
- Secure authentication
- Regular security updates
- Access controls
- No storage of payment card details (handled by Stripe/App Stores)
9.2 Your Responsibilities
- Device security (PIN, biometric locks)
- Regular backups of local data
- Secure network usage
- Strong password selection
10. COOKIES AND TRACKING
10.1 Mobile Apps
- The Apps contain no advertising trackers, and your advertising identifier is not collected — the advertising ID permission is removed from every build
- Firebase Analytics records basic app-usage events (such as app opens, screen views and session length) to help us understand which features are used. It is not used for advertising or profiling
- Crash reporting (Firebase Crashlytics — essential for app stability)
- Performance monitoring (helps improve app reliability)
10.2 Website Analytics
Our website and web portal use Simple Analytics, a privacy-first, cookie-free analytics service that collects no personal data and respects Do Not Track.
10.3 Managing Preferences
- Device-level tracking controls apply as normal
- Do Not Track respected where technically feasible
11. CHILDREN'S PRIVACY
Our Apps are not intended for children under 18. We do not knowingly collect children's data. Contact us immediately if you believe we have collected data from a child.
12. DATA BREACH NOTIFICATION
In case of a data breach affecting your rights and freedoms:
- We will notify the ICO within 72 hours
- We will notify affected users without undue delay
- We will provide information about the breach and mitigation steps
13. PRIVACY BY DESIGN
We implement privacy by design principles:
- Data minimisation
- Purpose limitation
- Privacy defaults
- Transparency
- User control
14. MARKETING COMMUNICATIONS
14.1 Onboarding and Marketing Emails
- When you create an account we may send onboarding and service-related emails on the basis of our legitimate interest (and, where applicable, the PECR “soft opt-in” for our own similar products and services)
- Any separate promotional marketing is sent only where we have a lawful basis to do so
- Managed through MailerLite
- You can opt out at any time using the unsubscribe link in every email
15. CHANGES TO THIS POLICY
15.1 Updates
We may update this Privacy Policy to reflect changes in our practices or legal requirements.
15.2 Notification
Material changes will be notified through:
- In-app notifications
- Email to registered users
- 30 days' notice before changes take effect (unless required sooner by law)
15.3 Your Options
If you disagree with Privacy Policy changes:
- You may stop using the Apps and request data deletion
- Subscription users: Continue access until current paid period ends under previous policy
- Free users: Must accept new policy or lose access immediately
- Passive acceptance: Continued use after notice period constitutes acceptance
- After the current period, continued use requires acceptance of the new policy
- No refunds for unused subscription time if you choose to discontinue use
- You retain the right to request deletion of your personal data per Section 8
15.4 Legal Requirements
Changes required by law or regulatory requirements may take effect immediately with notice.
16. CONTACT US
17. LOCATION SERVICES
With your permission, the Apps collect your device's location for:
- Geolocation Services: Adding location metadata to Part L compliance photographs — this is what makes a photograph usable as evidence
- Compliance Requirements: Location data may be required for certain building regulation evidence requirements
Location is used only while you are using the app, and you can change the permission at any time in your device settings (photographs captured without location may not meet evidence requirements).
18. THE BASIS OF OUR PROCESSING
We process personal data on the lawful bases set out in Section 4. Where we rely on your consent (for example, marketing communications or device permissions such as location), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. Using the Apps is not itself treated as consent — where the law requires consent, we ask for it explicitly.