Buildtan Technologies

Effective September 1, 2026

Privacy Policy

This policy explains how Buildtan Technologies collects, uses, and protects information when you visit our website, contact us, or use our products. The sections here apply to everything we make. Sections for a specific platform and for a specific product follow at the end, and they add to what the general sections say.

Our role

For this website and for support conversations, Buildtan Technologies decides how information is handled. When our products process information on behalf of a business that uses them, that business decides, and we act on their instructions as a service provider. If you are a customer of a business that runs one of our products, and you want to exercise a privacy right, contact that business first. We help them respond.

Information we collect

When you install or sign up for one of our products, we receive what we need to identify your account:

  • An account or business identifier.
  • The name and email address of the person who set it up.
  • A credential that lets the product act on your behalf.

We store the settings you configure and a record of the agreements you have accepted. We collect what you send us directly, such as support messages and product feedback.

Each product also processes the information it needs to run its features. Its own section says what it records, and what it deliberately does not.

How we use information

  • Provide, maintain, secure, and improve our products.
  • Respond to support requests and communicate about service changes.
  • Bill for paid plans and confirm which features your plan includes.
  • Monitor reliability, prevent abuse, and meet legal obligations.

IP addresses

Our servers read the requesting IP address to rate limit our endpoints against abuse. The value is held in memory for the length of the rate limit window, and it is never written to our database or to our logs.

Service providers

We use a small number of infrastructure providers to host our application, database, logs, and secrets. They act on our instructions under contract, and we do not allow them to use what they process for their own purposes. We can name our current providers on request. Where a product is distributed through a platform, that platform hosts the environment the product runs in and handles billing for it, and the section for that platform names it.

We use no analytics, advertising, or customer data platform. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We may disclose information when the law requires it or to protect users, our services, or the public.

International transfers

Our infrastructure runs in the United States. If you use our products from outside the United States, information reaches servers there. Where required, we rely on standard contractual clauses through our processors.

Retention

  • We keep application logs for 30 days.
  • We keep database backups for one week.
  • When you stop using a product, we delete the data we hold for it, including settings, records, keys, and credentials. Where a platform sets a deadline for that deletion, we follow it.

Each product’s section says how long it keeps the records it produces for you.

Security

We use reasonable administrative, technical, and organizational measures to protect information. Access tokens and our signing keys are encrypted at rest, connections are encrypted in transit, and requests are authenticated before they reach our code. No system is perfectly secure, and we do not claim otherwise.

Children

Our products are sold to businesses, not to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, write to us and we will delete it.

This website

Our website is a set of static pages. It sets no cookies, runs no analytics, and embeds no third-party trackers. Our hosting provider records standard server request logs, which include IP addresses, for reliability and abuse prevention.

Your choices

You can ask to access, correct, export, or delete personal information associated with you. You can also object to or restrict certain processing. Both are subject to applicable law. Write to us from the email address associated with your account. We do not charge for these requests or discriminate against anyone who makes one.

Changes to this policy

We may update this policy as our products or legal obligations change. We post the revised policy here with a new effective date.

Contact

Send questions or privacy requests to support@buildtan.com. Our Terms of Service cover the rest of the agreement.

Apps on the Shopify platform

This section applies to any of our apps you install from the Shopify App Store, and it makes the general sections concrete for that platform.

What Shopify gives us

At install, Shopify gives us a session containing your store domain and the name, email address, and locale of the staff member who installed the app, along with an access token. Shopify hosts the store our app runs in, and Shopify handles billing.

Scopes

An app can read and write only what its access scopes allow, which Shopify shows you on the install screen. Each app’s section states the scopes it requests and what it does with them.

Uninstalling

When you uninstall, Shopify asks us to erase the store 48 hours later, and we delete everything we hold for it, including settings, records, signing keys, and sessions.

Privacy requests through Shopify

We implement all three of Shopify’s mandatory privacy webhooks, so a customer data request or erasure request that a merchant raises through Shopify reaches us. What an app can return or delete depends on what it holds, and its own section says what that is.

Hatchway Age Gate for Shopify

This section adds to the sections above and describes Hatchway Age Gate specifically. Hatchway is a self-declaration age gate: it asks a shopper to confirm they meet an age the merchant sets. It does not verify identity, and it holds no shopper personal data.

What it does not collect

  • When a shopper enters a date of birth, the browser compares it against the merchant’s threshold and discards it. The date is never sent to us and never stored.
  • We request no Shopify customer scopes, so we cannot read a merchant’s customer records, and we do not.
  • Age check records carry no name, email address, phone number, IP address, or customer identifier.
  • We run no advertising, tracking, or profiling on a merchant’s storefront, and we share nothing with advertising networks.

What it records

When a shopper answers the gate, the storefront sends one request to us. We record the outcome so a merchant can report on it:

  • A confirmation record: a random reference code, the time, the minimum age asked for, the gate mode, the product page the gate appeared on, and the technical components of the token issued.
  • Daily counts of confirmations and declines, grouped by minimum age, page context, product handle, and language.

None of this is keyed to a shopper. The counts are totals, and each grouping is counted separately, so no row links a language to a product to a person.

What it stores on a shopper’s device

After a shopper confirms their age, the gate stores a signed token and its reference code in the browser’s local storage. That is what stops the gate asking again during the period the merchant sets. It also writes the token to a Shopify cart attribute, which carries onto the resulting order in the merchant’s own records. The gate needs both to work. We do not use either for tracking, and clearing site data removes them.

How long the records last

Confirmation records and daily counts stay for the life of the install, because they are the record a merchant keeps. We delete them with the rest of the store’s data after uninstall, on the schedule described in Retention.

Shopper privacy requests

Hatchway holds no shopper personal data. A customer data request or erasure request forwarded by Shopify therefore has nothing to return or delete, and we tell the merchant so.

Children and the age gate

An age gate necessarily involves people who turn out to be under the threshold. Handling a birth date in the browser and discarding it is a deliberate choice, so that answering a gate creates no record of a minor anywhere in our systems.