Privacy Policy
Last updated: 24 September 2026
This policy explains what BuilderDesk ("the Service") collects, why, and what you can do about it. The Service is operated by Saiban Technologies.
The Service is accounting software for construction companies. Each company that signs up receives its own private workspace. Records belonging to one company are not visible to any other company using the Service.
Who controls your data
When your company creates a workspace, your company is the controller of the records inside it — your projects, expenses, suppliers and employee details. Saiban Technologies processes that data on your behalf in order to provide the Service.
What we collect
Information you give us when creating an account
- Your name
- Your email address, if you sign up with email, Google or Facebook
- Your mobile number, if you sign up or sign in with a code sent by SMS
- Your password, stored only as a one-way hash that cannot be reversed
- Your company's name
Information from Google or Facebook, if you use them to sign in
If you choose to sign in with Google or Facebook, we receive your name, email address, profile picture URL and the unique account identifier that provider assigns you. We use these to create or match your account. We do not receive your password, we do not post anything to those accounts, and we do not request access to your contacts, photos, files or any other data held by those providers.
Information your company enters into the Service
This is the substance of the product: projects, cash received, expenses, supplier records, labour records and payments. Some of this is personal data about other people — for example a worker's name, father's name, CNIC number, phone number, address and photograph. Your company decides what to enter and is responsible for having a lawful basis to do so.
Information collected automatically
- Your IP address and browser user agent, recorded against sign-in events and changes to financial records
- The date and time of each action, and which record it affected
- A session cookie, which is strictly necessary to keep you signed in
We do not use advertising cookies, analytics trackers or third-party marketing pixels on the Service.
Why we keep an audit log
The Service records who created, changed, approved or voided each financial record, along with the values before and after, the time, and the IP address. This is a core feature rather than surveillance: accounting records are only trustworthy if changes to them can be traced. Only Owners and Management within your own company can read this log.
How we use your data
- To operate the Service and show you your own company's records
- To authenticate you, including sending a one-time code by SMS if you choose phone sign-in
- To send account emails: email verification, password resets and workspace invitations
- To maintain the audit log described above
- To keep backups so your records can be restored
- To investigate abuse or security incidents
We do not sell your data. We do not share it with advertisers. We do not use your company's accounting records to train machine learning models.
Who we share it with
We share data only with service providers necessary to run the Service:
- Our hosting provider, which stores the database and uploaded files
- Our email provider, to deliver account emails
- Our SMS provider, to deliver one-time sign-in codes, which receives only the destination number and the code
We may also disclose data where we are legally required to do so, or where it is necessary to protect the rights or safety of users.
Uploaded files
Receipts, invoices, bank slips, photographs and CNIC images are stored outside the public web directory and have no public URL. They can only be reached through an authenticated request that is checked against your permissions in your own workspace.
How long we keep it
- Financial records are retained for as long as your workspace exists, because accounting records are not deleted — corrections are made by voiding an entry and recording a new one
- Audit logs are retained for as long as the records they describe
- One-time sign-in codes are deleted shortly after they expire
- If your workspace is deleted, see the section below
Your rights
You can, at any time:
- See and correct your own account details from within the Service
- Ask your workspace Owner to correct or remove records about you
- Disconnect a linked Google or Facebook account, provided you have another way to sign in
- Request deletion of your account and your data — see Data Deletion
Security
- All traffic is encrypted in transit using HTTPS
- Passwords are stored as bcrypt hashes and are never recoverable
- One-time codes and invitation tokens are stored hashed, never in plain text
- Workspace separation is enforced in the database query layer and again by permission checks, not by the interface
- Sign-in and code-request endpoints are rate limited
No system is perfectly secure. If you believe your account has been accessed without your permission, contact us immediately at support@saibanbuilders.com.
Children
The Service is business software and is not directed at anyone under 18. We do not knowingly create accounts for children.
Changes to this policy
If we make a material change, we will update the date at the top of this page and notify workspace Owners by email.
Contact
Saiban Technologies
support@saibanbuilders.com