Privacy policy
Written to describe what this site actually does, not to cover every eventuality.
Last updated 2026-10-07.
The short version
We store your email address, a hashed password, and the builds you create. We do not sell data, we do not run advertising networks, and we do not use third-party analytics that tracks you across other sites. If you want everything deleted, ask and it is deleted.
What we collect
If you do not have an account: nothing that identifies you. You can build a complete plan without signing up. Our analytics is Cloudflare Web Analytics, which is privacy-first, uses no client-side state for tracking, and reports aggregate page views rather than individual people.
If you create an account:
- Your email address, so you can sign in and so we can send you the emails listed below. - A password hash. We never store your password itself - it is hashed with PBKDF2-SHA256 and a unique salt before it is written, and nobody here can read it or recover it. One honest detail: the iteration count is 100,000, which is the maximum the platform we run on supports and is below the 600,000 that current guidance recommends. We would rather say so than imply otherwise. What does the work against the attack that actually happens - someone guessing at the sign-in form - is rate limiting on two separate buckets, a 10-character minimum, and a block on the passwords that get tried first. - The builds you create: chassis, goal, budget, which parts you picked, what you marked installed, and what you said you paid. - Session cookies, which are HttpOnly, Secure and SameSite, and exist only to keep you signed in. - If you subscribe, a Stripe customer ID and the state of your subscription. We never see or store your card details - those go directly to Stripe and never touch our servers.
If you contact us: your name, email and message, kept as a support ticket so we can reply and so we can find it again if the same thing comes up.
What we do with it
Run your account, keep your builds, take payment if you are a subscriber, reply to you, and send transactional email. We also use aggregate, non-identifying usage data to decide which chassis to research next - which chassis and goal levels are popular, not who looked at them.
Email we send
- Transactional, which you cannot opt out of while you have an account: verify your email, reset your password, a receipt when you are charged, a warning if a payment fails, and a notice before a trial ends. - Product email, which you can turn off in settings at any time: price-drop alerts on parts in your own builds, and occasional notes about new chassis or features.
Who else is involved
- Cloudflare - hosting, the database (D1), file storage (R2), and email delivery. Your data lives in Cloudflare's network. - Stripe - payments, if you subscribe. Stripe is the data controller for your payment details. - Nobody else. No advertising networks, no data brokers, no cross-site tracking.
How long we keep it
Builds and account data stay until you delete them or ask us to delete your account. Support tickets are kept for two years. Server error logs are kept for 90 days. Backups are kept for 30 days, so a deletion can take up to 30 days to work through every copy.
Your choices
You can export your builds, delete any build, turn off product email, and ask for your account and everything in it to be deleted. Email support@buildsideways.com and we will do it - we do not make you argue for it. If you are in the UK or EU you have rights under the GDPR including access, rectification, erasure, restriction and portability; the same mailbox is how you use them.
Children
This is not a service for children and we do not knowingly collect data from anyone under 16.
Changes
If we change this in a way that matters, we will email account holders rather than quietly updating the date.
Honest caveat
This policy is written by the person who built the site, to describe what the site actually does. It is not legal advice and it has not been reviewed by a lawyer. If you are relying on it in a professional capacity, ask us a direct question at support@buildsideways.com and we will answer it directly.
The other documents
All six are written to describe what this specific service does, rather than copied from a generator. None of them are legal advice.
- Terms of serviceWhat you can expect from us, and what we need from you.
- Refund policyShort, because it should be.
- Cookie policyThere are three, and none of them follow you anywhere.
- Affiliate disclosureThe money, in plain terms, including the parts of it that are awkward.
- Accessibility statementWhat we have done, what we have tested, and what we know is not perfect yet.
- Help centre
- Ask us a direct question