This policy describes what personal data Structa collects when you use it as a builder, as a builder's client, or as a homeowner looking for a builder; why we collect it; who sees it; and your rights under the UK GDPR.
Definitions
"Structa", "we", "us": the operator of the service. "Service": the Structa website at structa.build and any related software.
Builders use Structa to price, send and track jobs and to keep a public page. Homeowners use it to see a typical price for a job and to ask builders near them. When a homeowner asks, we pass their details to the builders who take the job, as described below. We are not a builder, broker or agent, and we never take, hold or move money between a builder and a client.
Builders: your data is yours
Your rates, your material prices, the jobs you describe, the quotes you make and the clients you send them to are yours. They are never shown to another builder, and never to anyone outside the links you create yourself.
Your public page is the exception you choose: it shows what you add to it (your name, photo, areas and a few words about you) and your record on Structa (finished jobs, on time, at the quoted price). A finished job's photos and your client's words appear only with your client's consent, and only by area and month: never an address, and never the price.
We use what builders put in in aggregated or de-identified form to run and improve the engine and its cost data, and to build further services. An example that exists today: the difference between a published rate and the rate a builder sets feeds the engine's learning of local rates. No individual builder, job or client can be identified from that data.
A job or quote of yours appears in Structa's own marketing only if you tick the box that says so, on that job, in the editor's settings. You can untick it at any time and the job comes out of anything published after that.
Homeowners: who sees your request
- Your typical price is worked out from what you tell us. You do not need to give a name or contact to see it.
- When you ask for builders, builders near you who meet what you asked for can see the job: the kind of work, your postcode district (for example SW19, never the full postcode), the typical price, when you want to start, and your description with numbers, emails and links taken out. Not your name or contact details.
- Your name, email and phone go only to the builders who take your job, at most three, or to the builder you asked for by name, and only because you ticked the box agreeing to it. Each of those builders is then responsible for your details under data protection law.
- Withdraw your request at any time from the link in our email. It is then shown to no more builders; a builder who already has your details is responsible for them, and you can ask them to delete them.
Clients: confirming a finished job
When your builder finishes a job on Structa, you are asked from your link to confirm the price, and you can add a few words and your first name. They go on the builder's page only if you tick the box that allows it, and you can ask us to take them off at any time. So that the record can be trusted, we keep a one-way hash of your device and IP address with your answer, to spot a builder answering for their own client.
Clients of a builder's past jobs
A builder can list jobs he did before Structa and give us the client's email so we can ask them, once, to confirm the job. We use that email for that one message only, never share it, and delete it as soon as the client answers, or 30 days after we asked. A confirmed job shows on the builder's page by its kind, area and month: never the client's name, address or the price. A client who says no is not shown at all.
Legal basis (UK GDPR)
- Contract performance: to deliver the service you signed up for, including a builder's page and a homeowner's request.
- Consent: to give a homeowner's name and contact details to builders; to show a client's words and a finished job on a builder's page; for optional marketing. Each is withdrawable at any time.
- Legitimate interests: security, rate-limiting, anti-fraud (including checking that a builder's record is genuine, and asking the client of a past job to confirm it), improving the engine.
- Legal obligation: accounting, tax, and regulatory requests.
Who can access your data
Structa team
A small number of staff can access account data for customer support, security, content moderation and technical maintenance. Access is logged and granted only when required.
Sub-processors
- Firebase / Google Cloud: authentication, Firestore database, file storage (including job photos).
- Google (Gmail): sending our emails, such as sign-in, request and job notifications.
- Stripe: payment processing, once credits and posting fees are charged.
- Cloudflare Turnstile: checking that a request or a client's answer comes from a person, not a bot.
- Upstash: Redis-backed rate limiting.
- Google Gemini: reading the job described, reading the layout of a spreadsheet a builder uploads (which rows are items and which columns hold the prices; the prices themselves are copied from his cells, never from the model), and generating the narrative summary attached to a quote. Before any text is sent, postcodes, addresses, phone numbers and email addresses are removed from it. The model reads and asks questions; it never sets a price, a rate or a quantity; every number on a quote comes from the pricing engine, and it never guesses one. A builder's rates and margin are never shown to the client. Nothing you type is used to train any model, ours or Google's.
- xAI (Grok): the backup reader. Only when Gemini can't answer, it reads the job described under the same rules: the same details are removed first, and it never sets a price. xAI is in the United States; it keeps API requests for at most 30 days to check for abuse and does not use them to train its models.
All sub-processors are bound by data-processing agreements and process data only on our instructions.
Builders who take a homeowner's job
As above: only with the homeowner's consent, at most three builders a job, and each is then a controller of those details in their own right.
Public surfaces
- Share links generated from the builder editor are unlisted but unauthenticated. Anyone with the link can see the quote and the builder's public name. Do not share a link with anyone you would not give the quote to.
- Builders' pages are public and can be found on search engines once they show a finished job.
What data we collect
Account data
- Email address or mobile number (used for authentication).
- Password (hashed by Firebase Authentication).
- Auth provider linkage (for Google sign-in).
WhatsApp
- If you message our WhatsApp number, the message becomes a draft quote as if you had typed it into the site. Your number is stored as a one-way hash so we can link your next message to the same job for a day; the plain number is not kept. We reply only to your messages and never send marketing.
Jobs and quotes
- The job as described, typed or spoken, and the answers to the questions it asks. Addresses, postcodes, phone numbers and email addresses are removed from the text before any model reads it.
- The postcode of the job (used for regional pricing).
- If you use Find the house, the postcode is sent to the government's energy certificate (EPC) register to list the addresses there. We keep only the age band and type of the house you pick, never its address.
- Site facts: access, property age, and the like.
- A builder's rates and material prices, kept on the account and used on later quotes. Private to the builder.
- Generated line items, costs and risk notes; edits made in the editor, kept alongside the engine's baseline; read-only share links.
- The client's name and contact as the builder enters them, to send the quote.
Tracked and finished jobs
- Tasks ticked, dates, and photos the builder adds.
- The client's confirmation of the price, their first name, their words and their consent, with a hashed device and IP address.
A builder's page
- Name, photo, areas worked in and a few words, as entered.
A homeowner's request
- First name, email and, if given, phone number.
- The job, the answers given, the postcode, a budget if given, when you want to start, and which builders may see it.
- Your consent to pass your details to builders.
Payment data
- Nothing is charged while we launch. When it is, card details are never stored on Structa: Stripe takes the payment under their own terms, and we keep only your Stripe customer id and a record of what was bought, used and refunded.
Technical data
- IP address (used for rate limiting and fraud checks).
- Browser, device and basic usage telemetry.
- A daily count of visits by page and by source (a link's
utm_source or the referring site), with no identifier: one number per day, never a record of who. - Support correspondence, feedback, and problem reports sent from a quote, with the quote they are about.
Why we collect it
- To authenticate you and protect your account.
- To price, save, edit, send and track quotes and jobs.
- To show a builder's page and record.
- To pass a homeowner's job to builders near them, and email both about it.
- To keep records honest, rate-limit abusive use and prevent fraud.
- To take payment for credits and posting fees, once charged.
- To respond to support requests and problem reports.
- To meet our legal and accounting obligations.
- To improve the engine and its underlying cost data, and to build further services, in aggregated or de-identified form.
We do not sell your data or place advertising cookies. A builder's inputs and quotes are never shared with other builders or with marketers; a homeowner's contact details go only to the builders described above.
International transfers
Where personal data is transferred outside the UK (e.g. via Google, Cloudflare or Stripe infrastructure), we rely on UK adequacy regulations and / or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
Retention
- Anonymous drafts: a job described without an account is kept for 7 days, then deleted; signing in keeps it.
- Jobs, quotes and a builder's page: retained while the account is active.
- Homeowners' requests: kept while open. A request no builder could take within 30 days closes, and we tell you. Your name and contact details are deleted 60 days after the request or job closes, or you withdraw it; the job itself is kept without them. You can ask us to delete them sooner.
- A client's words on a builder's page: until the client asks us to remove them or the builder's account closes.
- Account data: retained while your account is active. Deleted on closure, subject to legal retention requirements.
- Payment records: retained for at least seven years to meet UK accounting obligations.
- Backups: purged on a rolling 90-day window.
Security
- TLS in transit; at-rest encryption on Firebase and Stripe.
- Firebase Auth handles password hashing and session tokens. We do not see your password.
- Server-side routes verify Firebase ID tokens; resource access is constrained to the authenticated owner (IDOR checks).
- Webhook signatures from Stripe are verified against the signing secret before any state change.
No system is perfectly secure. In the event of a breach that poses a high risk to individuals, we will notify the ICO within 72 hours and affected users without undue delay.
Your rights
- Access: request a copy of the data we hold about you.
- Correction: update inaccurate or incomplete data.
- Deletion: request removal of your data.
- Restriction: limit how we use your data.
- Portability: receive your data in a portable format.
- Objection: object to processing based on legitimate interests, or to direct marketing.
- Withdrawing consent: at any time, without affecting what was done before.
Email info@structa.build to exercise any of these rights. We will respond within one month and may need to verify your identity.
Cookies
We use a small number of strictly necessary cookies for session management, rate limiting and bot checks. We do not use advertising cookies. Analytics, if any, are aggregated and anonymised at source.
Children
The service is not intended for use by anyone under 18 and we do not knowingly collect data from children. If you believe a child has provided data to us, email the address below and we will remove it.
Changes
We may update this policy. Material changes will be announced on the service before they take effect.
Contact
Privacy queries and rights requests: info@structa.build.
If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.