What information Builder Hut handles, why, and who it is shared with. Site owners and template developers each have their own section below.
Last updated 26 July 2026
This policy explains how Rakibul Islam Rafi, trading as Builder Hut, of Vatara, Dhaka, Bangladesh, handles personal information.
You can reach us about anything in this policy at contact@builder-hut.com.
Builder Hut handles personal information in two distinct capacities, and it is worth separating them before anything else.
As a controller, for the people who hold Builder Hut accounts — site owners and their team members. Sections 2 to 5 describe this.
As a processor, for the visitors and customers of the sites our users publish. That information belongs to the site owner, who decides what is collected and why; we handle it on their behalf. Sections 6 and 7 describe this. If you are a shopper on a site built with Builder Hut, the site owner’s own privacy notice governs your information, and they are the right party to contact about it.
Sign-in is handled by Clerk. When you register — including through Google sign-in — Clerk holds your email address, your name, your profile image where you provide one, and your credentials. Builder Hut does not store your password.
Alongside that, we store the details needed to run your account: your business name, your contact email, your site names and logos, your currency and catalogue settings, and which sites you are a member of and in what role.
Payments are taken by SSLCommerz on a hosted page. Your card number, CVV, and bank credentials are entered on SSLCommerz’s systems and are never sent to or stored by Builder Hut.
We keep a record of each transaction: the transaction reference, amount, currency, status, what it was for, and the validation and bank reference identifiers SSLCommerz returns. We also keep your AI credit balance and your subscription status and dates.
To initiate a payment we pass SSLCommerz your business name and contact email along with the amount.
If you send us an enquiry through the contact form or by email we keep your name, email address, and the content of your message so we can respond.
When you use AI-assisted authoring, your prompt and the assistant’s reply are stored against your account so the conversation persists between sessions.
The request is sent to Amazon Bedrock, running an Anthropic Claude model. It contains your prompt, your recent conversation history, and a structural snapshot of your site: page names and URIs, short text previews of page elements, your design-system tokens, and the field schemas and item counts of your data collections.
The snapshot does not include the values stored in your data collections, your orders, your customers’ details, your addresses, or your reviews.
Our Bedrock configuration uses a global inference profile, which means Amazon Web Services may route an individual request to a region outside ap-south-1 to serve it.
The following is collected by the sites you publish, according to how you configure them. You decide what is collected; we store and process it for you.
Sites published with Builder Hut include first-party visit analytics. No third-party analytics provider is used and no data is sold or shared for advertising.
Each recorded event carries the page visited, the kind of page and the item it relates to, any search term entered, campaign parameters from the URL, a traffic-source category derived from the referring site, and a two-letter country code taken from the CDN edge.
Two things are deliberately not retained. The visitor’s IP address is never forwarded to or stored by the analytics pipeline — only the derived country code leaves the edge. The referring URL itself is used to classify the source and then discarded; only the category is kept.
Events are tied to a pseudonymous visitor identifier held in a cookie, not to a name or email address. Individual event rows are deleted automatically 90 days after they are recorded. A small per-visitor summary — first and last country seen, first page, and acquisition source — is retained for as long as the site remains on the platform.
Requests identified as automated crawlers are discarded rather than recorded.
Builder Hut uses cookies for authentication, for functional preferences, and for the first-party visit analytics described above. Our Cookie Policy sets out each cookie, what it does, and how long it lasts.
We do not sell personal information. We share it only with the service providers we need to operate the platform:
Sites published with Builder Hut load a web font stylesheet from Google Fonts and an icon stylesheet from the unpkg CDN at page load. As a result, a visitor’s IP address and browser user agent are visible to Google and to unpkg, independently of Builder Hut.
If a site owner adds an optional embed, further third parties may be involved: the Facebook page plugin loads from Facebook, and video embeds use YouTube’s privacy-enhanced no-cookie domain. WhatsApp and Messenger elements are outbound links only and load nothing.
Our databases, file storage, queues, and application servers run in the Amazon Web Services Asia Pacific (Mumbai) region, ap-south-1.
Published sites are served through Amazon CloudFront, a global content delivery network, so cached page content is distributed to edge locations worldwide.
As noted in section 5, AI requests may be routed by AWS to a region outside ap-south-1.
Account, site, order, and billing records are kept for as long as the account is active, and afterwards where we need them for accounting or legal reasons.
Some data expires automatically: individual analytics event rows after 90 days, daily-uniqueness markers after about 48 hours, and AI job records after 24 hours.
AI conversation history is retained with your account.
Traffic to and from the platform is encrypted in transit. Storefront customer passwords are stored hashed with bcrypt, never in plain text. Platform account credentials are held by Clerk and never reach our systems. Service credentials are held in AWS Secrets Manager.
No system is perfectly secure, and we cannot guarantee absolute security.
Builder Hut is a business tool and is not directed at children. Do not create an account if you are under 18 or the age of majority where you live.
We may update this policy. When we do, we will change the date shown at the top of this page, and we will give notice through the product or by email where a change materially affects you.
Write to us at contact@builder-hut.com, or by post to Rakibul Islam Rafi, Vatara, Dhaka, Bangladesh.
If you are a customer of a site built with Builder Hut and your question is about your order, your account on that site, or the information that site holds about you, contact the site owner directly — they control that information, not us.
This policy covers developer.builder-hut.com, operated by Rakibul Islam Rafi, trading as Builder Hut, of Vatara, Dhaka, Bangladesh.
It applies to you as a template developer. If you also run a site on the Builder Hut platform, the Site Policy section above covers that. Reach us about either at contact@builder-hut.com.
Sign-in is handled by Clerk. When you register — including through Google sign-in — Clerk holds your email address, your name, your profile image where you provide one, and your credentials. Builder Hut does not store your password.
We keep a developer record containing your Clerk user identifier, email address, name, and profile image, retrieved from Clerk. This is what identifies you as the owner of your templates.
We store the templates you author: pages, components, design systems, collections, uploaded media, and the demo content you add.
Template content is not personal information about you, but remember that anything you put into it — including in demo content — is stored by us and, once published, copied into other users' sites. Do not put personal information into templates.
AI credits are purchased through SSLCommerz on a hosted page. Your card number, CVV, and bank credentials are entered on SSLCommerz's systems and are never sent to or stored by Builder Hut.
We keep a record of each transaction — reference, amount, currency, status, and the identifiers the gateway returns — together with your AI credit balance.
When you use AI-assisted authoring, your prompt and the assistant's reply are stored against your account so the conversation persists between sessions.
The request is sent to Amazon Bedrock, running an Anthropic Claude model. It contains your prompt, your recent conversation history, and a structural snapshot of the template: page names and URIs, short text previews of page elements, design tokens, and the field schemas and item counts of your collections.
Our Bedrock configuration uses a global inference profile, which means Amazon Web Services may route an individual request to a region outside ap-south-1 to serve it.
The developer portal does not collect or process personal information about the customers or visitors of live sites. It has no storefront checkout, no customer accounts, and no visitor analytics. Those exist only on the platform side, and are covered by the Site Policy section above.
We do not sell personal information and we do not share it for advertising.
Our databases, file storage, and application servers run in the Amazon Web Services Asia Pacific (Mumbai) region, ap-south-1. Template previews are served through Amazon CloudFront, a global content delivery network. AI requests may be routed by AWS to another region, as described in section 4.
Your developer record, templates, and billing records are kept for as long as your account is active, and afterwards where we need them for accounting or legal reasons. AI conversation history is retained with your account. AI job records expire automatically after 24 hours.
Traffic to and from the portal is encrypted in transit. Your credentials are held by Clerk and never reach our systems. Service credentials are held in AWS Secrets Manager. No system is perfectly secure, and we cannot guarantee absolute security.
The portal uses cookies for authentication and for interface preferences. The Developer Policy section of our Cookie Policy sets out each one.
The developer portal is a professional tool and is not directed at children. Do not create an account if you are under 18 or the age of majority where you live.
We may update this policy. When we do, we will change the date shown at the top of this page and give notice where a change materially affects you.
Write to us at contact@builder-hut.com, or by post to Rakibul Islam Rafi, Vatara, Dhaka, Bangladesh.
Related policies