Privacy Policy

Effective Date: 1st August 2026
Last Updated: 20th August 2026

This Privacy Policy explains how Bricks and Bot Ltd ("we", "us", "our") collects, uses, and protects your personal data when you use Buildsnapper (formerly Buildsnpper), Buildsnapper Assessor (formerly Buildsnpper Assessor), and Buildsnapper Manager (formerly Buildsnpper Manager) mobile applications (the "Apps").

A note on our name. These Apps were previously published as Buildsnpper. The spelling changed to Buildsnapper on 19th August 2026. Only the name changed — the data controller, the Apps, your account and the way your data is handled are all unaffected, and this Policy applies equally to use of the Apps under either name.
By using our Apps, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please do not use our Apps.

1. DATA CONTROLLER

Bricks and Bot Ltd
Company No: 15693496
Address: 9 Quayside, Congleton, Cheshire
Email: dpo@bricksandbot.com
Phone: +33669728889

We are registered with the Information Commissioner's Office (ICO) as a data controller (registration reference ZB769071) and pay the annual data protection fee.

2. CRITICAL INFORMATION ABOUT DATA STORAGE

2.1 Local Device Storage

IMPORTANT: Photo evidence and associated metadata are stored locally on your device. You are solely responsible for:

  • Backing up locally stored data
  • Protecting against data loss
  • Ensuring data security on your device
  • Managing device storage capacity

We cannot access, recover, or be held liable for locally stored data.

2.2 What Is Stored in the Cloud

To provide the service, some data is stored server-side:

3. DATA WE COLLECT

3.1 Information You Provide
3.2 Automatically Collected Information
3.3 Third-Party Data
3.4 Assessor Portal Data

When using the assessor web portal, we additionally collect:

4. LEGAL BASIS FOR PROCESSING

We process your data based on:

5. THIRD-PARTY SERVICES AND DATA PROCESSORS

5.1 Firebase Services (Google LLC)
  • Purpose: Authentication, cloud database and storage, crash reporting, analytics and performance monitoring
  • Data Processed: Account details, project and plot records, sent report PDFs (including the photographs they contain), crash logs, and basic app-usage events
  • Location: Data is stored in Google Cloud's London region (europe-west2). Some supporting services (authentication, crash reporting) are operated by Google LLC in the USA under the UK Extension to the EU-US Data Privacy Framework.
  • Retention: Crash data 90 days; account data until deletion; sent report PDFs until the report is deleted or withdrawn
  • Privacy Policy: https://policies.google.com/privacy
5.2 Algolia
  • Purpose: Search functionality within apps
  • Data Processed: Search queries, project metadata
  • Location: EU/US (Standard Contractual Clauses)
  • Retention: 90 days
  • Privacy Policy: https://www.algolia.com/policies/privacy
5.3 MailerLite
5.4 Stripe (Assessor Portal Only)
  • Purpose: Payment processing when assessors purchase licences for clients via web portal
  • Data Processed: Assessor's payment card details, billing information, transaction records
  • Location: EU/US (Standard Contractual Clauses)
  • Note: Card details are processed directly by Stripe; we do not store payment card information
  • Privacy Policy: https://stripe.com/privacy
5.5 App Stores
  • Google Play Services: Device data, purchase information, handles all in-app subscription billing
  • Apple App Store: Account data, purchase information, handles all in-app subscription billing
  • Note: App stores control all refund decisions for in-app purchases
5.6 Amazon Web Services — AI Support Assistant (Amazon Bedrock)
  • Purpose: When you contact support, our assistant generates an instant answer drawn only from our own help-centre articles, shown to you before you submit a request. You can always skip it and have your question sent to a person.
  • Data Processed: The text of your support question and our help-centre content. No photographs, evidence files, or account data beyond what you type into your support message.
  • Location: European Economic Area — AWS Europe (Ireland). Processed transiently to produce the answer; not stored by AWS and not used to train any AI model.
  • Model: Claude (by Anthropic), run within AWS Bedrock; Anthropic does not receive your data for training.
  • Privacy Policy: https://aws.amazon.com/privacy/
5.7 Amazon Web Services — Support Ticket Storage (DynamoDB)
  • Purpose: Storing and tracking the support requests you submit, and their status.
  • Data Processed: Your name, email address, the support request you send, and (for in-app reports) the basic diagnostic details shown to you before you send them.
  • Location: United Kingdom — AWS Europe (London) region.
  • Retention: Automatically deleted 6 months after your request is resolved.
  • Privacy Policy: https://aws.amazon.com/privacy/
5.8 Amazon Web Services — Photo Archive Delivery and Email (S3 & SES)
  • Purpose: Storing sent photo archives so your assessor can access them, and sending transactional emails (report notifications, support ticket updates, account emails). Sent report PDFs are stored in Firebase (see 5.1).
  • Data Processed: Sent photo archives (zips of your report photographs) and the content of transactional emails (including your email address).
  • Location: United Kingdom — AWS Europe (London) region.
  • Retention: Sent photo archives are retained after the associated report or account is deleted; their removal from storage is a periodic manual housekeeping step rather than an immediate, automated deletion. You can request earlier deletion at any time (see Section 8).
  • Privacy Policy: https://aws.amazon.com/privacy/
5.9 RevenueCat
  • Purpose: Managing in-app subscription status (linking your app-store purchase to your account and confirming entitlement).
  • Data Processed: App user identifier, subscription and purchase status from Apple/Google. No payment card details.
  • Location: USA (Standard Contractual Clauses / UK International Data Transfer Addendum)
  • Privacy Policy: https://www.revenuecat.com/privacy/
5.10 Sentry (Functional Software, Inc.)
  • Purpose: Error monitoring on our web services, so faults are found and fixed quickly.
  • Data Processed: Technical error details (error type, affected page/endpoint, device/browser information, IP address). We configure Sentry so that the content of what you submit — such as support messages — is never attached to error reports.
  • Location: European Union (Sentry EU data residency, Germany).
  • Privacy Policy: https://sentry.io/privacy/
5.11 Google Maps Platform
  • Purpose: Rendering the location map page included in generated reports.
  • Data Processed: The plot photograph coordinates needed to draw the map. No account information is sent with map requests.
  • Location: USA (Data Privacy Framework certified)
  • Privacy Policy: https://policies.google.com/privacy
5.12 MongoDB Atlas
  • Purpose: Storing web portal account data.
  • Data Processed: Portal account details (name, email address, securely hashed password) and licence purchase records.
  • Location: European Economic Area — hosted on AWS Europe (Ireland). Transfers rely on the UK's adequacy regulations for the EEA.
  • Privacy Policy: https://www.mongodb.com/legal/privacy-policy
5.13 Amazon Web Services — Photo Evidence Archive (S3 Glacier Deep Archive)
  • Purpose: Optional paid long-term archiving of plot photo evidence, so it remains available for Part L / EPC audit purposes long after a report is sent.
  • Data Processed: The archived photo evidence zip for each plot (photographs and their metadata) and an accompanying manifest.
  • Location: United Kingdom — AWS Europe (London) region as the primary copy, with a disaster-recovery copy in AWS Europe (Ireland). The transfer to Ireland relies on the UK's adequacy regulations for the EEA (see Section 6).
  • Retention: 15 years from archiving, plus a grace period of up to 6 months before removal. Archives are stored with write-once-read-many (WORM) immutability, so they cannot be altered or deleted during the retention term — including by us.
  • Privacy Policy: https://aws.amazon.com/privacy/

6. INTERNATIONAL DATA TRANSFERS

Your data may be transferred outside the UK. We only transfer personal data where a lawful transfer mechanism applies:

AI support assistant (AWS Europe, Ireland): When you contact support, the text of your question is processed by our support assistant, which uses Amazon Bedrock in AWS's Europe (Ireland) region to generate an answer from our help-centre articles (see 5.6 above). This transfer from the UK to Ireland relies on the UK's adequacy regulations for the EEA. Your question is processed transiently and is not stored by AWS or used to train any AI model.

7. DATA RETENTION

Data Type Retention Period
Account Data Duration of account, then permanently deleted 30 days after account deletion (transaction and tax records are kept per the Financial Records row)
Local Device Data Until you delete from device
Cloud-Synced Project Records Until you delete them or your account
Deleted Account (Recovery Window) 30 days, then permanently deleted
Sent Report PDFs Until the report is deleted or withdrawn
Sent Photo Archives Retained after report/account deletion; removed by periodic manual housekeeping (not immediate) — earlier deletion on request (Section 8)
Photo Evidence Archive (paid add-on) 15 years plus up to 6 months' grace; WORM-immutable for the retention term (see 5.13)
Support Tickets 6 months after resolution, then automatically deleted
Crash & Diagnostic Data 90 days
Financial Records 7 years (UK tax requirements)
Payment Data Transaction records retained per legal requirements; card details not stored
Marketing Data Until consent withdrawn

8. YOUR RIGHTS

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time
  • Complain to the Information Commissioner's Office (ICO)

Contact dpo@bricksandbot.com to exercise your rights.

9. DATA SECURITY

9.1 Technical Measures
9.2 Your Responsibilities

10. COOKIES AND TRACKING

10.1 Mobile Apps
10.2 Website Analytics

Our website and web portal use Simple Analytics, a privacy-first, cookie-free analytics service that collects no personal data and respects Do Not Track.

10.3 Managing Preferences

11. CHILDREN'S PRIVACY

Our Apps are not intended for children under 18. We do not knowingly collect children's data. Contact us immediately if you believe we have collected data from a child.

12. DATA BREACH NOTIFICATION

In case of a data breach affecting your rights and freedoms:

13. PRIVACY BY DESIGN

We implement privacy by design principles:

14. MARKETING COMMUNICATIONS

14.1 Onboarding and Marketing Emails

15. CHANGES TO THIS POLICY

15.1 Updates

We may update this Privacy Policy to reflect changes in our practices or legal requirements.

15.2 Notification

Material changes will be notified through:

15.3 Your Options

If you disagree with Privacy Policy changes:

15.4 Legal Requirements

Changes required by law or regulatory requirements may take effect immediately with notice.

16. CONTACT US

Data Protection Queries:

Email: dpo@bricksandbot.com
Phone: +33669728889
Address: 9 Quayside, Congleton, Cheshire

Data Protection Contact:

Andrew McCracken
dpo@bricksandbot.com

Supervisory Authority:

Information Commissioner's Office (ico.org.uk)


17. LOCATION SERVICES

With your permission, the Apps collect your device's location for:

Location is used only while you are using the app, and you can change the permission at any time in your device settings (photographs captured without location may not meet evidence requirements).

18. THE BASIS OF OUR PROCESSING

We process personal data on the lawful bases set out in Section 4. Where we rely on your consent (for example, marketing communications or device permissions such as location), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. Using the Apps is not itself treated as consent — where the law requires consent, we ask for it explicitly.