Privacy Policy

What information Builder Hut handles, why, and who it is shared with. Site owners and template developers each have their own section below.

Last updated 26 July 2026

Site Policy

This policy explains how Rakibul Islam Rafi, trading as Builder Hut, of Vatara, Dhaka, Bangladesh, handles personal information.

You can reach us about anything in this policy at contact@builder-hut.com.

1. Two different roles

Builder Hut handles personal information in two distinct capacities, and it is worth separating them before anything else.

As a controller, for the people who hold Builder Hut accounts — site owners and their team members. Sections 2 to 5 describe this.

As a processor, for the visitors and customers of the sites our users publish. That information belongs to the site owner, who decides what is collected and why; we handle it on their behalf. Sections 6 and 7 describe this. If you are a shopper on a site built with Builder Hut, the site owner’s own privacy notice governs your information, and they are the right party to contact about it.

2. Account information

Sign-in is handled by Clerk. When you register — including through Google sign-in — Clerk holds your email address, your name, your profile image where you provide one, and your credentials. Builder Hut does not store your password.

Alongside that, we store the details needed to run your account: your business name, your contact email, your site names and logos, your currency and catalogue settings, and which sites you are a member of and in what role.

3. Billing information

Payments are taken by SSLCommerz on a hosted page. Your card number, CVV, and bank credentials are entered on SSLCommerz’s systems and are never sent to or stored by Builder Hut.

We keep a record of each transaction: the transaction reference, amount, currency, status, what it was for, and the validation and bank reference identifiers SSLCommerz returns. We also keep your AI credit balance and your subscription status and dates.

To initiate a payment we pass SSLCommerz your business name and contact email along with the amount.

4. Support and enquiries

If you send us an enquiry through the contact form or by email we keep your name, email address, and the content of your message so we can respond.

5. AI features

When you use AI-assisted authoring, your prompt and the assistant’s reply are stored against your account so the conversation persists between sessions.

The request is sent to Amazon Bedrock, running an Anthropic Claude model. It contains your prompt, your recent conversation history, and a structural snapshot of your site: page names and URIs, short text previews of page elements, your design-system tokens, and the field schemas and item counts of your data collections.

The snapshot does not include the values stored in your data collections, your orders, your customers’ details, your addresses, or your reviews.

Our Bedrock configuration uses a global inference profile, which means Amazon Web Services may route an individual request to a region outside ap-south-1 to serve it.

6. Information your site collects from its visitors

The following is collected by the sites you publish, according to how you configure them. You decide what is collected; we store and process it for you.

  • Storefront customer accounts: email address, phone number, name, username, a hashed password, profile image, and saved addresses. When an account is created we also record the sign-up IP address, the browser user agent, and the country the request came from.
  • Orders: customer name, phone number, optional email address, and delivery and billing addresses, together with the items ordered.
  • Reviews: the reviewer’s account identifier, their display name at the time of writing, the rating, and the review text. Reviewer email addresses are not stored on reviews.
  • Data collection submissions: whatever fields you define. If you make a collection public, unauthenticated visitors can submit to it. Because you define the schema, you determine what personal information ends up there.
  • Customer analytics shown to you as the site owner: customer email address, order count, revenue, and first and last order dates, all derived from the orders placed on your site.

7. Analytics on published sites

Sites published with Builder Hut include first-party visit analytics. No third-party analytics provider is used and no data is sold or shared for advertising.

Each recorded event carries the page visited, the kind of page and the item it relates to, any search term entered, campaign parameters from the URL, a traffic-source category derived from the referring site, and a two-letter country code taken from the CDN edge.

Two things are deliberately not retained. The visitor’s IP address is never forwarded to or stored by the analytics pipeline — only the derived country code leaves the edge. The referring URL itself is used to classify the source and then discarded; only the category is kept.

Events are tied to a pseudonymous visitor identifier held in a cookie, not to a name or email address. Individual event rows are deleted automatically 90 days after they are recorded. A small per-visitor summary — first and last country seen, first page, and acquisition source — is retained for as long as the site remains on the platform.

Requests identified as automated crawlers are discarded rather than recorded.

8. Cookies

Builder Hut uses cookies for authentication, for functional preferences, and for the first-party visit analytics described above. Our Cookie Policy sets out each cookie, what it does, and how long it lasts.

9. Who we share information with

We do not sell personal information. We share it only with the service providers we need to operate the platform:

  • Clerk — identity and authentication for platform accounts.
  • Amazon Web Services — hosting, storage, content delivery, queuing, transactional email, search indexing, and the Bedrock AI service.
  • SSLCommerz — payment processing for subscriptions and AI credits.
  • Cloudflare — bot protection on our contact form and on storefront customer sign-up. Cloudflare independently observes the visitor’s IP address and browser characteristics when the check runs.

10. Third-party resources loaded by published sites

Sites published with Builder Hut load a web font stylesheet from Google Fonts and an icon stylesheet from the unpkg CDN at page load. As a result, a visitor’s IP address and browser user agent are visible to Google and to unpkg, independently of Builder Hut.

If a site owner adds an optional embed, further third parties may be involved: the Facebook page plugin loads from Facebook, and video embeds use YouTube’s privacy-enhanced no-cookie domain. WhatsApp and Messenger elements are outbound links only and load nothing.

11. Where information is stored

Our databases, file storage, queues, and application servers run in the Amazon Web Services Asia Pacific (Mumbai) region, ap-south-1.

Published sites are served through Amazon CloudFront, a global content delivery network, so cached page content is distributed to edge locations worldwide.

As noted in section 5, AI requests may be routed by AWS to a region outside ap-south-1.

12. How long information is kept

Account, site, order, and billing records are kept for as long as the account is active, and afterwards where we need them for accounting or legal reasons.

Some data expires automatically: individual analytics event rows after 90 days, daily-uniqueness markers after about 48 hours, and AI job records after 24 hours.

AI conversation history is retained with your account.

13. Security

Traffic to and from the platform is encrypted in transit. Storefront customer passwords are stored hashed with bcrypt, never in plain text. Platform account credentials are held by Clerk and never reach our systems. Service credentials are held in AWS Secrets Manager.

No system is perfectly secure, and we cannot guarantee absolute security.

14. Children

Builder Hut is a business tool and is not directed at children. Do not create an account if you are under 18 or the age of majority where you live.

15. Changes to this policy

We may update this policy. When we do, we will change the date shown at the top of this page, and we will give notice through the product or by email where a change materially affects you.

16. Contact

Write to us at contact@builder-hut.com, or by post to Rakibul Islam Rafi, Vatara, Dhaka, Bangladesh.

If you are a customer of a site built with Builder Hut and your question is about your order, your account on that site, or the information that site holds about you, contact the site owner directly — they control that information, not us.

Developer Policy

This policy covers developer.builder-hut.com, operated by Rakibul Islam Rafi, trading as Builder Hut, of Vatara, Dhaka, Bangladesh.

It applies to you as a template developer. If you also run a site on the Builder Hut platform, the Site Policy section above covers that. Reach us about either at contact@builder-hut.com.

1. Account information

Sign-in is handled by Clerk. When you register — including through Google sign-in — Clerk holds your email address, your name, your profile image where you provide one, and your credentials. Builder Hut does not store your password.

We keep a developer record containing your Clerk user identifier, email address, name, and profile image, retrieved from Clerk. This is what identifies you as the owner of your templates.

2. The templates you create

We store the templates you author: pages, components, design systems, collections, uploaded media, and the demo content you add.

Template content is not personal information about you, but remember that anything you put into it — including in demo content — is stored by us and, once published, copied into other users' sites. Do not put personal information into templates.

3. Billing information

AI credits are purchased through SSLCommerz on a hosted page. Your card number, CVV, and bank credentials are entered on SSLCommerz's systems and are never sent to or stored by Builder Hut.

We keep a record of each transaction — reference, amount, currency, status, and the identifiers the gateway returns — together with your AI credit balance.

4. AI features

When you use AI-assisted authoring, your prompt and the assistant's reply are stored against your account so the conversation persists between sessions.

The request is sent to Amazon Bedrock, running an Anthropic Claude model. It contains your prompt, your recent conversation history, and a structural snapshot of the template: page names and URIs, short text previews of page elements, design tokens, and the field schemas and item counts of your collections.

Our Bedrock configuration uses a global inference profile, which means Amazon Web Services may route an individual request to a region outside ap-south-1 to serve it.

5. What this portal does not handle

The developer portal does not collect or process personal information about the customers or visitors of live sites. It has no storefront checkout, no customer accounts, and no visitor analytics. Those exist only on the platform side, and are covered by the Site Policy section above.

6. Who we share information with

We do not sell personal information and we do not share it for advertising.

  • Clerk — identity and authentication.
  • Amazon Web Services — hosting, storage, content delivery, queuing, transactional email, and the Bedrock AI service.
  • SSLCommerz — payment processing for AI credit purchases.

7. Where information is stored

Our databases, file storage, and application servers run in the Amazon Web Services Asia Pacific (Mumbai) region, ap-south-1. Template previews are served through Amazon CloudFront, a global content delivery network. AI requests may be routed by AWS to another region, as described in section 4.

8. How long information is kept

Your developer record, templates, and billing records are kept for as long as your account is active, and afterwards where we need them for accounting or legal reasons. AI conversation history is retained with your account. AI job records expire automatically after 24 hours.

9. Security

Traffic to and from the portal is encrypted in transit. Your credentials are held by Clerk and never reach our systems. Service credentials are held in AWS Secrets Manager. No system is perfectly secure, and we cannot guarantee absolute security.

10. Cookies

The portal uses cookies for authentication and for interface preferences. The Developer Policy section of our Cookie Policy sets out each one.

11. Children

The developer portal is a professional tool and is not directed at children. Do not create an account if you are under 18 or the age of majority where you live.

12. Changes to this policy

We may update this policy. When we do, we will change the date shown at the top of this page and give notice where a change materially affects you.

13. Contact

Write to us at contact@builder-hut.com, or by post to Rakibul Islam Rafi, Vatara, Dhaka, Bangladesh.