Privacy Policy

Last updated: 30th January 2026
This Privacy Policy explains how Bildby (“Bildby”, “we”, “us”, or “our”) collects, uses, and shares information about you when you use:
1. our website and landing pages,
2. our web application for building and managing online forms (the “App”), and
3. any related services, features, or content we provide (together, the “Services”).
It also explains the choices and rights you have in relation to your personal data.By using the Services, you agree to the terms of this Privacy Policy. If you do not agree, you should stop using the Services.

1. Who we are and scope

This Privacy Policy applies to:
1. Account owners and users who sign up for a Bildby account to create or manage forms.
2. Visitors who browse our marketing website without creating an account.
3. Form respondents who submit responses to forms built with Bildby (“Respondents”).

For most of the data we collect about our own users and visitors, Bildby acts as a data controller (we decide why and how your data is processed).

For data collected through forms created by our users (i.e., the content of responses, files uploaded, etc.), the user (form owner) is generally the data controller, and Bildby acts as a data processor, processing such data on their behalf and according to their instructions.

If you are responding to a form built with Bildby and you have questions about how your data is used, please contact the form owner directly.

2. Data we collect

We collect different types of information depending on how you interact with the Services.

2.1 Account data (sign-up and profile)
When you create a Bildby account or update your profile, we may collect:
1. First name;
2. Last name
3. Email address
4. Workspace or organization details (if provided)
5. Any other information you choose to add to your profile
We do not store your password. Bildby uses email-based one-time codes or secure links (OTP / magic link login) for authentication.

2.2 Billing and payment data
If you subscribe to a paid plan, payments are processed by our third-party payment provider Paddle.What we receive from Paddle may include:
1. Your name
2. Email address
3. Billing address and country
4. Subscription plan, status, and transaction details (e.g., invoice number, last 4 digits of card, expiry month/year)

What we do not collect or store:
1. We do not store your full credit card number or full payment instrument details. These are collected and processed directly by Paddle.

For more information on how Paddle processes your payment data, please refer to their own privacy notice.

2.3 Usage and device data
When you access or use the Services, we may automatically collect:
1. IP address
2. Browser type and version
3. Device type and operating system
4. Language and time zone
5. Referring URL or domain name
6. Pages viewed, features used, and actions taken in the App
7. Date and time of access, session duration, and error logs
We use this information to operate, secure, and improve the Services.

2.4 Cookies and similar technologies
We use cookies and similar technologies to:
1. Keep you logged in and maintain your session (strictly necessary httpOnly cookies);
2. Remember your preferences (e.g., language, UI settings);
3. Measure usage of the Services and improve performance (analytics cookies, where enabled)
Where required by law (for example, in the EU/UK), we will request your consent before placing non-essential cookies such as analytics cookies. You can change your cookie preferences at any time via the cookie banner or settings we provide.
Strictly necessary cookies that are essential for the operation of the Services (such as authentication cookies) cannot be disabled and generally do not require consent.

2.5 Form content and responses
When you use Bildby to create forms, we store the content of your forms and any responses submitted by Respondents, including:
1. Questions, labels, and form configuration;
2. Responses entered by Respondents (which may include personal data, depending on what you ask);
3. Files uploaded by Respondents (subject to size limits and fair usage policy)
As a form owner, you decide what information to collect from Respondents. You’re responsible for ensuring that your own forms and notices comply with applicable privacy laws.

2.6 Integrations and third-party accounts (e.g., Google)
If you choose to connect Bildby to third-party services (for example, “Sign in with Google” or integrating with Google APIs), we may receive information from those services such as:
1. Name and email address associated with your account;
2. Profile image (if provided by the third party);
3. Other data you explicitly authorize (e.g., files or spreadsheets you select)We only access the minimum amount of data needed to provide the requested integration.
Our use and transfer to any other app of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.

2.7 Communications and support
If you contact us (e.g., via email or in-app chat), we may collect:
1. Your name and email address;
2. The content of your message and any attachments;
3. Our correspondence and internal notes about your request
We use this information to respond to your questions and provide support.

3. Why we use your data (purposes and legal bases)

We only process your data when we have a valid legal basis. Depending on your location, these may include performance of a contract, legitimate interest, consent, and legal obligations.

3.1 Providing and maintaining the Services
We use your data to:
1. Create and manage your account and workspaces;
2. Authenticate you and keep your session secure;
3. Provide core functionality to build, share, and manage forms and responses;
4. Process your subscription and payments
Legal bases: performance of a contract; legitimate interest (running an online service).

3.2 Improving and securing the Services
We use usage, device, and log data to:
1. Monitor performance and fix errors;
2. Prevent fraud and abuse;
3. Improve the usability and features of the App;
4. Analyze how users interact with features to guide product decisions
Legal bases: legitimate interest (improving and securing the Services); consent for analytics cookies where required by law.

3.3 Communications and support
We use your contact details to:
1. Send transactional messages (e.g., service notifications, security alerts, billing emails);
2. Respond to your support requestsSend service updates and announcements
Legal bases: performance of a contract; legitimate interest (communicating with users).

3.4 Marketing
Where allowed by applicable law, we may use your email address to:
1. Send you product updates, tips, and promotional content about Bildby;
2. Invite you to try new features or plans
You can unsubscribe from marketing emails at any time by clicking the “unsubscribe” link in the email or adjusting your email preferences.
Legal bases: legitimate interest (for existing users, where allowed); consent (where required by law).

3.5 Legal compliance and protection
We may process and disclose your data as reasonably necessary to:
1. Comply with applicable laws, legal obligations, and tax/accounting requirements;
2. Respond to lawful requests from public authorities;
3. Enforce our Terms and Conditions and protect Bildby, our users, or the public from harm
Legal bases: legal obligation; legitimate interest.

4. How we share your data

We do not sell your personal data. We may share your data with:

4.1 Service providers (processors)
We use trusted third-party providers to help us operate the Services, such as:
1. Hosting and infrastructure providers;
2. Email delivery and communication tools;
3. Analytics providers;
4. Logging and monitoring providers;
5. Payment processor (Paddle)Customer support tools
These providers only process your data on our behalf and according to our instructions. They are contractually bound to keep your data confidential and secure.

4.2 Other users in your workspace
If you collaborate within a shared workspace or team, certain information (such as your name, email, role, and activity) may be visible to other authorized members of that workspace.

4.3 Form owners and respondents
1. If you are a Respondent, information you submit through a form is shared with the form owner (and any collaborators they invite);
2. If you are a form owner, we may display your name or workspace details to Respondents where configured by you.
Form owners are responsible for their own use of data they collect via forms, including any disclosure to third parties.

4.4 Business transfers
If Bildby is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of that transaction. We will take reasonable steps to ensure the recipient continues to protect your personal data as described in this Privacy Policy.

4.5 Legal obligations
We may disclose your information if we believe in good faith that such disclosure is reasonably necessary to:
1. Comply with a legal obligation or request;
2. Protect the rights, property, or safety of Bildby, our users, or others;
3. Detect, prevent, or investigate fraud, abuse, or security incidents

5. International transfers

We may process and store your personal data in countries other than the one where you live. These locations may have different data protection laws than your country.
Where required by law, we implement appropriate safeguards (for example, standard contractual clauses) to ensure that your personal data remains protected when transferred internationally.

6. Data retention

We keep your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law (e.g., tax and accounting obligations).

In particular:
1. Account data: retained while your account is active and for a reasonable period after closure (e.g., up to 90 days) for backup, security, and record-keeping;
2. Billing and payment data: retained for the period required by applicable tax and accounting laws (often up to 7 years);
3. Usage and log data: retained for a limited period (for example, 12–24 months) for security, analytics, and troubleshooting
4. Form content and responses: retained as long as your account remains active or until you delete the forms or responses. If you close your account, we may delete or anonymize associated form data after a reasonable period, subject to backups and legal obligations.

We may retain anonymized or aggregated data that no longer identifies you, for analytics and business purposes.

7. Your rights

Depending on your location and applicable law (e.g., GDPR in the EEA/UK, certain US state laws), you may have some or all of the following rights in relation to your personal data:
1. Right of access: to know whether we process your data and to obtain a copy;
2. Right to rectification: to correct inaccurate or incomplete data about you;
3. Right to erasure: to request that we delete your personal data, in certain circumstances;
4. Right to restrict processing: to ask us to limit the processing of your data in certain cases;
5. Right to data portability: to receive your data in a structured, commonly used, machine-readable format and/or transmit it to another controller;
6. Right to object: to object to certain processing (such as direct marketing) based on legitimate interests.
7. Right to withdraw consent: where processing is based on your consent, you can withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us using the details in Section 10 (Contact us). We may need to verify your identity before responding to your request.

If you are located in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority.

8. Children’s privacy

The Services are not intended for use by children under 18 years old, and we do not knowingly collect personal data from children under 13.
If you believe we have collected data about a child without appropriate consent, please contact us and we will take steps to delete such data.

9. Security

We use appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.However, no method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

You are responsible for:
1. Keeping your account credentials confidential, and;
2. Limiting access to your devices and browser session

If you believe your account or data has been compromised, please contact us immediately.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, where appropriate, provide additional notice (for example, via email or in-app notification).

Your continued use of the Services after any changes have taken effect means you accept the updated Privacy Policy. If you do not agree with the changes, you should stop using the Services and close your account.

11. Contact

For questions or support, contact: Bildby
Email: support@bildby.com
Website: https://bildby.com