Legal
Privacy Policy
Last updated September 2026
BuildTag collects as little as it can. This policy explains what we store, why, and what we deliberately do not store.
What we collect from owners
Account: email address and password hash (handled by our authentication provider), username, display name and optional avatar, bio, general location text and website.
Build data: vehicle details, photos, performance figures, modifications, part links and social media links you choose to add.
Uploaded photos are re-encoded on our servers, which removes embedded EXIF data such as GPS coordinates.
What we collect from visitors who scan a BuildTag
A scan records the time, the country reported by our hosting provider's edge network, a coarse device type (phone, tablet, desktop) and the referring site's hostname. We do not store IP addresses or user agent strings in scan records.
Likes and reports use an anonymous, non-reversible key derived from a first-party cookie and coarse network information. It cannot be used to identify you.
We do not use third-party advertising trackers.
What is public
Anything on a public or unlisted build page is visible to anyone with the link, including search engines for public builds. Private builds are visible only to their owner while signed in.
Your email address and internal identifiers are never shown publicly.
Where data lives
BuildTag runs on Vercel and Supabase. Data may be processed in the United States. Photos are stored in Supabase Storage.
Your rights
You can edit or delete your builds and photos at any time from the dashboard. Contact us to delete your account entirely or to request a copy of your data.
Cookies
We use strictly necessary cookies for sign-in sessions and one anonymous visitor cookie for likes and abuse prevention.