Privacy Policy

Last updated: 1 July 2026

BuiltGrid Australia Pty Ltd (ABN 63 667 799 813) of Suite 125, 585 Little Collins Street, Melbourne VIC 3000 (BuiltGrid, we, us, our) operates the BuiltGrid platform, which businesses in the residential construction supply chain (builders, trade contractors, subcontractors and suppliers) use to manage procurement, compliance, pricing and transaction records with each other, at any tier of the supply chain. This Privacy Policy explains how we collect, hold, use and disclose personal information, and how you can access and correct it or make a complaint.

We are bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth) and handle personal information in accordance with them. This policy applies to our website (builtgrid.com), our web and mobile applications (including app.builtgrid.com), our APIs and our dealings with customers, prospective customers, suppliers and visitors. Capitalised terms not defined here have the meanings given in our Platform Terms of Service at builtgrid.com/terms/.

1. Who this policy covers
We handle personal information about several groups of people:

  • People who use BuiltGrid on behalf of a Client (a builder, trade contractor, subcontractor or supplier), such as business owners, administrators, estimators, project managers and finance staff (Users).
  • People whose information appears in Client Data or Compliance Information uploaded by a Client, such as a trade business’s workers whose names appear on licences, competency cards or insurance certificates, or a builder’s customers whose site addresses appear in job information.
  • People a Client invites to join BuiltGrid as a supplier, whose name and contact details the inviting Client provides to us.
  • Visitors to our website, people who contact us, and people who receive our marketing.

2. The kinds of personal information we collect
The information we collect depends on how you interact with us. It may include:

  • Identity and contact details: name, job title, business name, ABN, email address, phone number and postal address.
  • Account information: login credentials (passwords are stored in hashed form), User role and permissions, preferences and settings.
  • Compliance Information: details on licences, registrations, competency cards, insurance certificates, safety documents and declarations uploaded by a Client, which may include the names, licence numbers, dates of birth and photographs of individuals shown on those documents.
  • Procurement and transaction information: quotes, pricing, purchase orders, invoices, variations, approvals, project and job information, which may include the names of individuals and the addresses of building sites.
  • Communications: messages sent through the Platform, emails, chat transcripts, phone call notes and support requests.
  • Payment information: billing contact and invoicing details. Card payments are processed by Stripe; we receive confirmation of payment and limited card details (such as the last four digits and expiry) but not full card numbers.
  • Technical and usage information: IP address, device and browser type, screen size, operating system, pages visited, features used, search terms, referring pages, date and time stamps and approximate location derived from IP address.

We do not ask for sensitive information (such as health, racial or ethnic origin, or criminal record information) and ask that you do not upload it to the Platform except through features designed for that purpose. If a document you upload incidentally contains sensitive information, we handle it only as part of that document and as described in this policy.

3. How we collect personal information
3.1 Directly from you, when you create an Account, complete your profile, upload documents, use the Platform, contact us, attend a demonstration or webinar, or subscribe to our communications.

3.2 From other Clients on the Platform. BuiltGrid is a network. A Client acting as a Buyer may enter your name and contact details to invite your business to connect; a trade business may upload documents that name its workers; a builder may record site addresses or customer names in job information. In each case the Client that provides the information is responsible for collecting it lawfully, and we receive it to provide the Services to that Client and to the Clients it connects with.

3.3 Automatically, through cookies, log files and analytics tools when you use our website and applications (see section 9).

3.4 From third parties, including the Australian Business Register (to confirm ABN details), third-party systems a Client connects to BuiltGrid through an Integration or the API, our payment processor, and publicly available sources.

3.5 Unsolicited information. If we receive personal information we did not ask for and could not lawfully have collected, we will destroy or de-identify it as soon as practicable, where lawful and reasonable to do so.

4. Why we collect, hold, use and disclose personal information
We use personal information for the following purposes:

  • To provide the Services: creating and managing Accounts, operating the Platform, storing and displaying Client Data, and providing support.
  • To operate the network: sharing profile, Compliance Information, compliance status, pricing and transaction information between Clients that have connected with each other, and across tiers of the supply chain where a Supplier chooses to allow it, as they direct through their Platform settings (see section 5).
  • To verify identity and business details, including ABN lookups, and to prevent fraud and misuse.
  • To bill and collect payment, issue invoices and manage Subscriptions.
  • To communicate with you about the Services, including service notices, renewal reminders, security alerts and changes to our terms.
  • To secure the Services, investigate incidents and enforce our terms.
  • To understand how the Services are used and to improve them, including analytics, testing and product development.
  • To market our Services to businesses that may be interested in them (see section 8).
  • To produce aggregated and de-identified insights and benchmarks (see section 6).
  • To comply with our legal obligations and to establish, exercise or defend legal claims.
    We may also use personal information for other purposes to which you consent or that are otherwise permitted or required by law.

5. Sharing between Clients on the Platform
5.1 Buyers and Suppliers. In every connection on BuiltGrid, one Client acts as the Buyer (it sets procurement and compliance requirements and procures goods or services) and the other as the Supplier (it meets those requirements and supplies). A builder is usually a Buyer, a trade contractor or materials supplier is usually a Supplier, but roles are set per connection: a trade contractor that engages its own subcontractors is the Buyer in those connections, and a builder that supplies services to another builder is the Supplier in that connection.

5.2 How sharing works. When two Clients connect, each chooses what information to share with the other. A Supplier typically shares its business profile, Compliance Information, pricing, availability, quotes and invoices; a Buyer typically shares its procurement and compliance requirements, project and job information, purchase orders and approvals. Sharing is controlled by each Client’s settings and can be ended by either Client at any time.

5.3 What this means for individuals. If you work for a Supplier, information about you on licences, competency cards or insurance certificates that your business uploads may be shared with the Buyers your business connects with, so they can confirm your business meets their compliance requirements. If you are a builder’s customer, your site address and related job information may be shared with the trades and suppliers engaged for your project, and by them with their own subcontractors and suppliers to the extent needed for the work.

5.4 Sharing across tiers of the supply chain. Where the Platform offers it, a Supplier may choose to make its compliance status (an indicator showing whether it appears to meet its Buyer’s requirements) visible to Clients further up the chain, such as the builder its head contractor works for. This is the Supplier’s choice, can be switched off at any time, and does not include the Supplier’s pricing, quotes or transaction records unless the Supplier expressly chooses to include them. Anyone who receives information this way is bound by the same rules as the Supplier’s direct Buyer. Otherwise, information does not pass from one connection to another.

5.5 Rules that apply to the receiving Client. Under our Platform Terms, a Client that receives shared information may use it only to evaluate, engage, procure from, supply to and manage its relationship with the sharing Client and to meet its own legal and record-keeping obligations. It must keep the information confidential, must not sell, publish or use it to build directories or benchmarks, must not pass a Supplier’s pricing to that Supplier’s competitors or up the chain, and must comply with the Privacy Act. After a connection ends, the receiving Client may retain records it received for its legal and record-keeping purposes, subject to the same restrictions.

5.6 Discoverable profiles. A Client may choose to make its profile discoverable to Buyers on the Platform. Pricing and Compliance Information are not included in a discoverable profile unless the Client chooses to include them.

5.7 Each Client’s responsibility. Each Client is responsible for its own handling of personal information it receives through the Platform. If you have a concern about how a Buyer or Supplier has handled your information, you can raise it with them directly or contact us and we will help where we can.

6. Aggregated and de-identified data
We create aggregated and de-identified data from information on the Platform and from how the Services are used. We use it to operate and improve the Services, develop new features and produce industry benchmarks, indices, reports and insights, which we may license to third parties such as industry associations, corporations, federal and local governments to help the construction industry. Before we do so we ensure the data does not identify any Client, User or individual, does not disclose any Client’s specific pricing or transactions, and is aggregated across enough Clients that an individual Client’s data cannot reasonably be inferred. We require recipients not to attempt to re-identify any Client or individual. Once de-identified in this way, the data is no longer personal information.

7. Who we disclose personal information to
We disclose personal information to:

  • Other Clients on the Platform, as described in section 5.
  • Service providers that help us operate the Services, including cloud hosting (DigitalOcean Australia), payment processing (Stripe), email delivery, customer support and communication tools, analytics providers and professional advisers. These providers may only use personal information to provide their services to us.
  • Third-party systems a Client chooses to connect through an Integration or the API, as directed by that Client.
  • Regulators, law enforcement, courts and other parties where required or authorised by law, or to protect our rights, the Services or the safety of any person.
  • A purchaser or prospective purchaser of our business or assets, and their advisers, subject to confidentiality obligations.
  • Others with your consent.
    We do not sell personal information, and we do not disclose personal information to third parties for their own marketing purposes.

8. Direct marketing
We may send you information about our Services, features, events and industry content by email, phone or through the Platform where you have consented, where we have an existing business relationship with you, or where otherwise permitted by the Privacy Act and the Spam Act 2003 (Cth). Every marketing email includes an unsubscribe link, and you can opt out at any time by using that link, adjusting your notification settings in your Account, or contacting us at builtgrid.com/contact-us. Service notices (such as renewal reminders, security alerts and changes to our terms) are not marketing and will continue while you hold an Account.

9. Cookies, analytics and tracking
We use cookies and similar technologies to keep you logged in, remember your preferences, secure the Services and understand how our website and applications are used. We use the following categories:

  • Essential cookies: required for login, security and core functionality. These cannot be switched off without affecting the Services.
  • Analytics cookies: help us understand usage patterns so we can improve the Services. We currently use Google Analytics (privacy policy at policies.google.com/privacy) and Posthog (privacy policy at posthog.com/privacy).
  • Preference cookies: remember your settings within the Platform.

You can control cookies through your browser settings. Blocking essential cookies may prevent you from using parts of the Services. We do not respond to browser “Do Not Track” signals.

10. Overseas disclosure
Client Data and personal information held in the Platform are hosted in Australia. Some of our service providers process limited personal information outside Australia, including Stripe (which processes payment information in the United States and other countries) and providers of email, support and analytics tools. Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles, including through contractual protections.

11. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Our measures include encryption of data in transit and at rest, access controls and role-based permissions, logging and monitoring, vulnerability management, regular backups stored in Australia, and staff confidentiality obligations. Card payments are handled by Stripe, which is certified to PCI DSS Level 1; card details are sent directly from your browser to Stripe and are not stored on our systems. No method of transmission or storage is completely secure, so please keep your login credentials confidential and tell us at builtgrid.com/contact-us immediately if you suspect unauthorised access to your Account.

If a data breach occurs that is likely to result in serious harm to individuals, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. We also notify affected Clients under our Platform Terms.

12. How long we keep personal information
We keep personal information for as long as needed for the purposes described in this policy, including while a Client’s Account is active and for a reasonable period afterwards. When a Client’s agreement ends, its Client Data is available for export for 90 days and is then deleted or de-identified from our active systems within a further 60 days, with backup copies deleted in the ordinary course of our backup cycle, unless we are required by law to keep it (for example, tax and financial records, which we keep for at least 7 years). Information shared with another Client before the agreement ended may be retained by that Client as described in section 5.3.

13. Access and correction
You may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Users can view and update most of their own information in their Account settings. For other requests, contact us using the details in section 17. We will verify your identity, respond within 30 days, and generally provide access free of charge (we may charge a reasonable fee for unusually complex requests and will tell you first). If we refuse access or correction, we will tell you why in writing and how to complain.

If the information about you was uploaded by a Client (for example, your employer uploaded your licence), we may need to refer your request to that Client, because it controls the Client Data in its Account. We will help you make contact and will action changes the Client directs.

14. Anonymity and pseudonymity
You may browse our public website without identifying yourself. Because the Platform exists to let businesses verify who they are dealing with, we cannot provide Accounts or Services anonymously or under a pseudonym.

15. Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact our Privacy Officer using the details in section 17. We will acknowledge your complaint within 5 business days, investigate it and respond in writing within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.

16. Contact us
BuiltGrid at https://builtgrid.com/contact-us/

17. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, the Services or the law. The current version is always available at builtgrid.com/privacy/. We will notify Clients of material changes by email or in-product notice before they take effect. The date at the top of this policy shows when it was last updated.

Reference: Platform Terms of Service