Privacy Policy
Last updated: 20 July 2026
1. About This Policy
This Privacy Policy explains how BuildFair Pty Ltd (ABN 98 682 829 045) (“BuildFair”, “we”, “us”, “our”) collects, uses, stores, discloses, and protects your personal information when you use our construction payments platform, website, mobile application, and related services (collectively, the “Platform”).
We are committed to complying with the Privacy Act 1988 (Cth) (“Privacy Act”) and the thirteen Australian Privacy Principles (“APPs”). We voluntarily comply with these obligations regardless of whether we meet the annual turnover threshold, because we handle sensitive financial information and believe our users deserve full privacy protection.
This policy applies to all users of the Platform, including builders, subcontractors, suppliers, project owners, and visitors to our website at buildfair.com.au.
2. Information We Collect
2.1 Information you provide directly
- Account and registration information: full name, email address, phone number, date of birth, nationality, residential or business address, business name, ABN/ACN, builder’s licence and insurance details, and your role on the Platform (builder, subcontractor, supplier, or project owner).
- Identity verification (KYC/KYB): government-issued identification documents (driver’s licence, passport), proof of business registration, director and beneficial owner details, and source-of-funds information, collected as a condition of transacting on the Platform.
- Financial information: bank account details (BSB, account number, account name), payment instructions, invoice data, progress claim details, contract values, and transaction history.
- Project information: project names, site addresses, contract details, variations, defects, inspection records, progress payment schedules, and photos of works, defects, and rectifications that you upload.
- Photo metadata, including location: when you upload photos as payment or defect evidence, we extract embedded metadata from the image, including the GPS coordinates and capture time recorded by your camera, and we may compare them with location information supplied by your device, to verify that evidence photos were taken at the project site.
- Communications: messages, support requests, and other correspondence you send to us or through the Platform, including the content of notification emails we send you, which is retained in our systems.
- Subscription billing details: for paid plans, your chosen payment method (credit card or bank direct debit) is collected and tokenised inside our subscription billing provider’s (Zenith Payments) hosted payment page. We never see or store your full card number or bank account number, only the tokenised reference required to process billing.
- Supplier invoices forwarded to project email: PDF attachments and email content you (or your suppliers) forward to a project email address, processed for invoice extraction. The full email, including attachments, is received by our inbound email provider and then stored in our Australian cloud storage.
2.2 Information we collect automatically
- Device and browser information: IP address, device type, operating system, browser type and version, and device identifiers, including push notification tokens if you enable notifications in the mobile application.
- Usage data: pages visited, features used, session duration, login timestamps, and navigation paths.
- Location data: general geographic location inferred from your IP address. Precise device location is collected only where you enable it (for example, when capturing geo-tagged evidence photos in the mobile application) and via photo metadata as described in section 2.1.
- Log, security, and audit data: server logs, error reports, performance data, and security audit records. For security and evidentiary purposes, some audit records (for example, the record created when you approve an invoice) include your IP address and browser details at the time of the action.
Some automatic collection on our public website (page views, navigation, and approximate location from your IP address) is performed by Google Analytics, and product usage analytics inside the Platform are performed by PostHog. See sections 5, 6, and 12 for details.
2.3 Information we receive from third parties
- Identity verification providers: results of KYC/KYB checks conducted through Sumsub.
- Payment processors: transaction confirmations, settlement details, and compliance-related information from our card-processing partner ZenPay and our funds-holding partner Kobble (which operates under AFSL 545391, Yondr Money Pty Ltd).
- Subscription billing provider: subscription payment status, billing cycle, and tokenised payment instrument references from Zenith Payments.
- Banks and financial institutions: bank feed data via our banking partner, including transaction descriptions, amounts, dates, and balances, used for bank reconciliation.
- Publicly available information: business registration details from the Australian Business Register, ASIC, and similar public registers, retrieved when you enter an ABN or ACN.
2.4 Information about people who are not users
In limited cases we hold personal information about people who do not have a BuildFair account:
- contact details (name, email, phone) of people invited to a project by an existing user, held until the invitation is accepted, declined, or expires;
- contact details of supplier staff contained in invoices and emails forwarded to a project email address;
- email addresses used in failed login attempts, retained for security monitoring and attack detection; and
- details you enter when booking a call with us through our website’s scheduling widget (section 5.2).
2.5 Sensitive information
We do not generally collect sensitive information as defined under the Privacy Act. Where identity verification requires biometric comparison (for example, facial comparison against a government ID during verification with our identity verification provider), such information is collected only with your explicit consent and solely for verification purposes. Biometric authentication on your mobile device (fingerprint or face unlock) is processed entirely on your device by its operating system; no biometric data is transmitted to or stored by BuildFair.
3. How We Use Your Information
3.1 Providing the Platform
- Creating and managing your account.
- Processing payments, progress claims, and invoices between parties on a project.
- Maintaining the double-entry, append-only ledger that records all financial transactions.
- Facilitating project management, contract administration, and compliance tracking.
- Processing supplier invoices forwarded to project email addresses, including OCR text extraction and AI-assisted field extraction to draft invoices for builder approval.
- Verifying payment and defect evidence, including checking photo metadata against project site locations.
- Charging your platform subscription using a tokenised card or bank direct debit instrument held by Zenith Payments.
- Generating reports, audit trails, and compliance exports.
3.2 Legal and regulatory compliance
BuildFair is not an AUSTRAC reporting entity. We perform identity verification, ongoing due diligence, and transaction monitoring as a matter of platform policy, because verifying every party on the platform is part of how we make construction payments trustworthy. Our banking and card partners perform their own regulated compliance processes. Where we believe a transaction is suspicious or where we are required to do so by law, we may share information with regulators or law enforcement.
- Performing customer identification, ongoing due diligence, and transaction monitoring as a matter of policy.
- Responding to lawful requests from regulators, law enforcement, or courts.
- Maintaining records as required by Australian taxation and corporate law.
3.3 Platform improvement and communication
- Analysing usage patterns to improve features, performance, and user experience.
- Sending transactional notifications (invoice approvals, payment confirmations, project updates).
- Sending service announcements, security alerts, and policy updates.
- Providing customer support and responding to your enquiries.
3.4 Security and fraud prevention
- Detecting, preventing, and investigating fraud, unauthorised access, and other security incidents.
- Monitoring for suspicious transactions or activity on the Platform, including automated detection of unusual payment patterns.
- Enforcing our Terms of Use and Acceptable Use Policy.
We will not use your personal information for direct marketing without your prior consent. You may withdraw marketing consent at any time by contacting us (see section 16).
4. Automated Decision-Making
BuildFair uses automated processes in certain areas of the Platform, including:
- Invoice OCR and AI-assisted field extraction: supplier invoices forwarded to your project email address are processed using Azure AI Document Intelligence (optical character recognition) and Azure OpenAI (GPT-4o) to extract supplier details, line items, totals, GST, and project references. The extracted draft invoice is presented to the builder for review and approval. No payment is made on the basis of the extraction alone.
- Invoice matching and categorisation: automated systems match extracted supplier and project references against existing platform records, flagging mismatches for human review.
- Bank reconciliation: automated matching of bank transactions against ledger entries to identify discrepancies. Low-confidence matches can automatically place a protective freeze on project payouts pending human review.
- Payment workflow rules: configurable rules for hold periods, dual-approval requirements for variations, and payment scheduling.
- Fraud and anomaly detection: automated monitoring of transaction patterns (including velocity and structuring patterns) to flag potentially suspicious activity for human review.
These automated processes assist in the operation of the Platform but are subject to human oversight. No automated decision made by the Platform will have a significant adverse effect on you without human review. You have the right to request information about how any automated decision affecting you was made, and to request human review of that decision.
This disclosure is provided in accordance with the automated decision-making transparency requirements under the Privacy and Other Legislation Amendment Act 2024, effective 10 December 2026.
5. Who We Share Your Information With
5.1 Other Platform users
Information necessary for the operation of a project is shared between parties on that project. For example, a builder will see subcontractor business names, invoice details, and payment status for their project. A subcontractor will see the builder’s business name and project details. We only share information relevant to the project relationship.
5.2 Service providers
We engage third-party service providers who process personal information on our behalf, subject to contractual obligations to protect that information:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Kobble (project accounts and payouts; AFSL 545391, Yondr Money Pty Ltd) | Project fund holding, payouts, and bank feeds | Business name, ABN/ACN, contact details, beneficiary name and bank details, transaction data | Australia (primary) |
| ZenPay (Zenith Payments) | Card payment processing and subscription billing (card and direct debit) | Name, email, business name, ABN, tokenised payment instrument, billing status, transaction amounts | Australia |
| Microsoft Azure (compute, storage, database, monitoring) | Cloud hosting, infrastructure, and service telemetry (Application Insights) | All Platform data (encrypted) | Australia East |
| Azure AI Document Intelligence | Optical character recognition for invoice PDFs | Invoice PDF content (transient processing only) | Australia East |
| Azure OpenAI (GPT-4o) | AI-assisted invoice field extraction | Extracted invoice text (no full PDFs sent to the model) | Australia East (regional deployment) |
| Sumsub | Identity verification (eKYC/KYB) | Name, date of birth, address, government ID, business registration, source-of-funds information | EU / US |
| Twilio | SMS delivery (MFA and security codes) | Phone number, message content | US (primary) |
| Resend | Transactional email delivery, and receipt of inbound supplier emails sent to project email addresses | Outbound: name, email, notification content. Inbound: the full email, including sender details, message body, and attachments, before it is stored in our Australian cloud storage | US (primary) |
| Google Places | Address autocomplete and geocoding for project sites | Address strings typed during project setup | US (Google global infrastructure) |
| Google reCAPTCHA | Bot and abuse protection on public website forms | IP address and browser interaction signals | US (Google global infrastructure) |
| Google Analytics | Website analytics (traffic and page views on our public website only; not used inside the logged-in Platform) | Pseudonymous usage and page-view events, approximate location from IP address; no financial data | US |
| PostHog | Product analytics inside the Platform (feature usage and adoption) | Account identifier, email address, role, and feature-usage events (for example, that an invoice was approved). No transaction amounts, documents, card details, or KYC content. Session recording is disabled | US |
| Calendly | Scheduling widget for booking a call on our website | Name, email, phone, and any details you enter in the booking form | US |
| Expo push services (with Apple and Google push notification services) | Delivery of mobile push notifications you enable | Device push token and notification content | US |
| Australian Business Register / ASIC | Verification of business registration details | ABN/ACN you enter, used to retrieve public register details | Australia |
In addition, the card payment page loads a supporting script (jQuery) from a public content delivery network (code.jquery.com), which receives your IP address and standard browser metadata in the course of serving that file. No payment or personal data is sent to the CDN.
5.3 Regulatory and legal disclosures
We may disclose personal information where required or authorised by law, including to:
- AUSTRAC, in connection with financial crime matters.
- ASIC, in connection with corporate and financial services regulation.
- Australian Taxation Office, in connection with tax reporting obligations.
- Courts, tribunals, or dispute resolution bodies, in connection with legal proceedings.
- Law enforcement agencies, in response to lawful requests.
- Office of the Australian Information Commissioner (OAIC), in connection with privacy complaints or investigations.
5.4 Business transactions
In the event of a merger, acquisition, restructure, or sale of all or part of our business, personal information may be transferred to the acquiring entity. We will notify you of any such transfer and any changes to this policy that result from it.
6. Cross-Border Disclosure of Personal Information
We store all primary Platform data in Microsoft Azure’s Australia East region within Australia, and AI-assisted invoice extraction runs on a regional Azure OpenAI deployment whose processing occurs in the Australia East region. However, some personal information may be transferred overseas in the following circumstances:
- Payment and funds-holding providers (ZenPay and Kobble) may operate global infrastructure, and some processing may occur outside Australia in connection with international payment networks.
- Zenith Payments processes subscription billing in Australia. Card network authorisations may transit international networks (Visa, Mastercard, American Express) outside Australia in the normal course of card processing.
- Sumsub may process identity verification data in the European Union or United States.
- Twilio processes SMS delivery through infrastructure primarily located in the United States.
- Resend processes outbound transactional email, and receives inbound supplier emails (including attachments), through infrastructure primarily located in the United States.
- Google (Places, reCAPTCHA, and Analytics) processes the data described in section 5.2 through its global infrastructure, primarily in the United States.
- PostHog processes product analytics events in the United States.
- Calendly processes call-booking details in the United States.
- Expo, Apple, and Google push services process push notification tokens and content in the United States.
Before disclosing personal information overseas, we take reasonable steps to ensure that the overseas recipient handles the information in accordance with the APPs (APP 8), including through contractual arrangements that require equivalent data protection standards.
7. Government Identifiers
We collect government identifiers (such as driver’s licence numbers and passport numbers) only where required for identity verification, and tax-related identifiers only where required for tax reporting obligations under the Taxation Administration Act 1953 (Cth). We do not use government identifiers as our own identifier for you, nor do we disclose them except as required by law (APP 9).
8. Data Quality
We take reasonable steps to ensure the personal information we collect, use, and disclose is accurate, up-to-date, complete, and relevant (APP 10). You can update your profile, company details, and contact information through your account settings at any time. Some changes (such as bank account details) may require re-verification for security purposes.
9. Data Security
We implement technical and organisational measures to protect your personal information in accordance with APP 11.
9.1 Technical measures
- All data is encrypted at rest at the storage layer, with additional application-level AES-256 encryption applied to bank account details and payment credentials.
- Data in transit over the public internet is encrypted using TLS.
- Multi-factor authentication (MFA) is required on production user accounts.
- Role-based access controls restricting access based on job function and need-to-know.
- Database-enforced row-level security providing tenant isolation, so users can only access data belonging to their own organisation and projects.
- An append-only, hash-chained audit trail for financial events, designed to make tampering detectable.
- Automated dependency vulnerability scanning, code review gates, and internal security reviews.
- Automated monitoring and alerting for security incidents, including rate limiting and login-attack detection.
- Encrypted database backups with point-in-time recovery, geo-replicated to a second Azure region within Australia.
9.2 Organisational measures
- Access to personal information limited to personnel who require it for their role, with administrative access to sensitive records logged.
- All personnel with access to personal information bound by confidentiality obligations.
- Access privileges reviewed regularly and revoked promptly when no longer needed.
- Security incident response procedures documented.
- Third-party service providers assessed for security practices before engagement.
10. Access, Correction, and Deletion
10.1 Access (APP 12)
You may request access to the personal information we hold about you by emailing support@buildfair.com.au. Requests are handled by our team and we will respond within 30 days. We may charge a reasonable fee for requests requiring substantial effort, but will inform you of any fee before proceeding.
10.2 Correction (APP 13)
You may request that we correct any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond within 30 days. If we refuse to correct information, we will provide written reasons and inform you of your right to request that a statement of the correction sought be associated with the information.
10.3 Account closure and deletion requests
You may request closure of your account and deletion of your personal information by contacting support@buildfair.com.au. Deletion requests are assessed and actioned by our team. Because we operate a financial platform, significant categories of information cannot be deleted on request: financial records, identity verification records, and the audit trail must be retained for the periods described in section 13, and the ledger is append-only by design. Where information is not subject to a retention requirement, we will delete or de-identify it within a reasonable period and confirm the outcome to you, including which categories were retained and why.
Closure of your account may affect other users on shared projects. We handle closures in a way that preserves the integrity of project records while removing or de-identifying personal identifiers where possible.
10.4 Data export
You may request an export of your personal data, including your profile data, transaction history, invoices, and project records. Contact us at support@buildfair.com.au and our team will prepare the export in a standard, machine-readable format.
11. Notifiable Data Breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Conduct an assessment within 30 days (or sooner where practicable) to determine whether the breach is an “eligible data breach”.
- Promptly notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if the breach meets the threshold of serious harm.
- Include in our notification: a description of the breach, the kinds of information involved, and recommended steps for affected individuals.
12. Cookies and Tracking Technologies
Our Platform uses cookies and similar technologies for the following purposes:
- Strictly necessary cookies: required for authentication, session management, and security. These cannot be disabled.
- Product analytics (inside the Platform): we use PostHog to understand how users interact with the Platform (pages visited, features used, session length) so we can improve the experience. Analytics events are associated with your account identifier, email address, and role. We do not send PostHog any transaction amounts, financial documents, KYC content, or payment instruments, and session recording is disabled. You can limit analytics via your browser’s Do Not Track setting, which PostHog is configured to respect.
- Website analytics (public website only): our public website uses Google Analytics to measure aggregate traffic and page views (for example, pages visited and approximate location derived from your IP address) so we can improve our content. Google Analytics sets first-party cookies (such as _ga) and processes this data on Google’s infrastructure in the United States. Google Analytics is not used inside the logged-in Platform. You can opt out using the Google Analytics opt-out browser add-on or by configuring your browser to refuse cookies.
- Embedded third-party widgets: the booking page on our website embeds Calendly, and public forms use Google reCAPTCHA; each sets its own cookies when you use those pages, as described in section 5.2.
We do not use advertising cookies, and we do not use cookies to track you across other websites or sell your personal information to third parties. You can configure your browser to refuse cookies, though this may affect your ability to use the Platform.
13. Data Retention
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, and for at least the minimum periods required by law:
| Data category | Retention period | Legal basis |
|---|---|---|
| Account information | Duration of account, plus at least 7 years after closure | Tax and corporate record-keeping law |
| Transaction, ledger, and payment records | At least 7 years from the date of the transaction. The ledger and its audit chain are append-only and retained for the life of the related records | Corporations Act, tax law, audit integrity |
| Identity verification records | At least 7 years after the end of the customer relationship | Record-keeping and fraud prevention |
| Project records | At least 7 years from project completion | Limitation periods, security of payment legislation, tax law |
| Bank reconciliation data | At least 7 years from the date of the transaction | Tax law, audit requirements |
| Usage and analytics data | Per the configured retention of our analytics providers (Google Analytics defaults to 14 months) | Internal policy; provider configuration |
| Support correspondence | Approximately 3 years from resolution | Internal policy |
| Server and application logs | Platform operational logs are retained for approximately 31 days; security audit records are retained with the financial records they relate to | Internal policy; audit integrity |
When personal information is no longer required and is not subject to a legal retention obligation, we take reasonable steps to destroy or de-identify it (APP 11.2).
14. Children's Privacy
BuildFair is a business platform and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it as soon as practicable.
15. Financial Crime Prevention
BuildFair is not an AUSTRAC reporting entity. We perform identity verification, ongoing due diligence, and transaction monitoring as a matter of platform policy, because verifying every party on the platform is part of how we make construction payments trustworthy. Our banking partner (Kobble, under AFSL 545391) and card partner (Zenith Payments) perform their own regulated compliance processes. Where we believe a transaction is suspicious or where we are required to do so by law, we may share information with regulators or law enforcement.
As a matter of policy, we:
- Verify the identity of all users before they can transact on the Platform.
- Monitor transactions for unusual or suspicious activity and review flagged matters internally.
- Maintain internal compliance procedures, including risk assessments and policy reviews.
- Retain identity verification and transaction records for at least 7 years for tax and audit purposes.
The collection and retention of personal information for these purposes is a condition of using our Platform.
16. Direct Marketing
We may use your personal information to send you communications about our services, features, and updates that are relevant to your use of the Platform (APP 7), only where you have consented or would reasonably expect it. You can opt out of marketing communications at any time by:
- Using the opt-out mechanism included in any marketing communication we send.
- Contacting us at support@buildfair.com.au.
Opting out of marketing communications will not affect transactional or security-related notifications necessary for your use of the Platform.
17. Anonymity and Pseudonymity
You have the option of not identifying yourself, or using a pseudonym, when browsing our public website or making general enquiries (APP 2). However, due to the nature of our services (including payment processing, identity verification, and contractual obligations), it is impracticable for us to provide Platform services to individuals who have not identified themselves.
18. Complaints
If you believe we have breached the APPs or mishandled your personal information, you may lodge a complaint with us:
- Email: support@buildfair.com.au
- Subject line: “Privacy Complaint”
We will acknowledge your complaint within 5 business days and provide a written response within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
- Mail: GPO Box 5218, Sydney NSW 2001
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on our Platform and, where appropriate, by email or in-app notification. The “Last updated” date at the top of this page indicates when this policy was most recently revised.
Your continued use of the Platform after changes are posted constitutes your acknowledgement of the updated policy.
20. Contact Us
If you have questions about this Privacy Policy or how we handle your personal information, contact us:
- Email: support@buildfair.com.au
- BuildFair Pty Ltd (ABN 98 682 829 045), Melbourne, Victoria, Australia
For unresolved complaints, contact the Office of the Australian Information Commissioner: www.oaic.gov.au | 1300 363 992 | enquiries@oaic.gov.au | GPO Box 5218, Sydney NSW 2001
Have questions about our privacy practices?
Contact us