Public website access
BuildPath NZ's public guides, checklists, forms, calculators, glossary, problem information and legal pages can be browsed without a BuildPath account. Hosting and security services may process ordinary technical information such as IP address, browser, device, requested pages, timestamps, referrer, and error or security logs.
BuildPath accounts
BuildPath uses Firebase Authentication for email/password and Google sign-in. Firebase processes the email address, authentication credentials or provider identifiers, verification state, sign-in timestamps and account identifiers needed to operate the account. BuildPath does not receive or store a user's Google password.
Cloud workspace records
Cloud Firestore stores structured project and workspace information under the authenticated account. This may include project details, tasks, dates, contacts, quotes, budgets, procurement records, document and drawing metadata, RFIs, submittals, variations, inspections, daily reports, risks, decisions, commitments, defects, CCC readiness, handover, warranties, feasibility records, saved views, favourites, and accepted WhatsApp-derived findings.
Do not enter unnecessary sensitive personal information. Project participants should be told how their information is being used where that is required.
Offline and device storage
On first sign-in, BuildPath asks whether the device is private/trusted or shared/public. A trusted device may use Firestore's persistent browser cache and BuildPath IndexedDB recovery data. A shared device uses memory-oriented Firestore caching and BuildPath removes its workspace database at sign-out where supported. Browser or operating-system behaviour can still affect deletion and availability. Account Settings includes a control to remove offline BuildPath data from the current device.
WhatsApp imports and project files
WhatsApp exports are parsed in the browser. BuildPath does not intentionally upload or permanently store the complete raw WhatsApp ZIP, large videos or raw media in Firestore. Only findings the user reviews and accepts, limited supporting excerpts, message references and import metadata may become structured cloud records. Users must have authority to use imported conversations and remain responsible for the privacy of participants.
BuildPath stores document metadata and external links, not project-file bytes. A link may point to OneDrive, Google Drive, Dropbox, a council or consultant portal, or another system controlled by the user or project team. BuildPath does not automatically gain access to a private linked file. Records can also state that a file exists only on the current device.
Third-party processing
Firebase is provided by Google and may process account and Firestore data outside New Zealand. Existing web hosting, domain, email and security providers may also process technical or correspondence information. External links have their own terms and privacy practices.
Exports, correction and deletion
Account Settings lets users update their display name, export account and project data as JSON, remove offline data from a device, and delete the BuildPath account and known cloud project collections after confirmation and recent authentication. Independent backups remain the user's responsibility.
Use and disclosure
BuildPath uses information to provide authentication, project storage, sync, support, security, corrections and lawful operations. BuildPath does not sell user data. Information may be disclosed where required by law, to protect the service or users, or to service providers needed to operate the features described in this policy.
Security and availability
Firestore Security Rules restrict each account path to the matching authenticated user. Reasonable controls are used, but no internet, browser cache, linked third-party system or cloud service can be guaranteed perfectly secure or continuously available. Free-tier quotas can temporarily stop cloud operations; BuildPath keeps local recovery and export controls for this situation.
Contact and privacy rights
For access, correction, privacy questions or complaints, use the contact page. Users may also contact the New Zealand Office of the Privacy Commissioner.
