Privacy Policy
This page explains what Brickloom collects when you submit the project intake form or create an account, how that information is used, and how to ask for it to be removed. Last updated 6 August 2026.
Information we collect
When you submit the project intake form, we store the details you provide so we can scope the work, generate a preview landing page, and follow up to confirm the ownership transfer. The fields captured at submission are:
- Business name, trade type, and the service area you operate in.
- An optional contact email and optional phone number.
- Optional notes you add to describe the business or the job.
- An optional photo upload, stored in our object storage provider with its storage key, the URL it is served from, and the file size in bytes.
- A
sourceTokenrecording the marketing link that referred you to the form, so we can tell which channels produced the lead. - Basic form-submit logs kept by the hosting platform: a timestamp, the IP address the request came from, and the user agent string.
Visitor analytics
As you browse the public landing pages of this site, we record a small set of visitor-and-usage data so the owner can see how much traffic the site is getting and how that traffic converts into leads and paying customers. The elements captured are:
- A pseudonymous visitor identifier assigned the first time you arrive and stored in your browser’s
localStorageunder the keypolsia_tid. It is a random uuid that identifies your browser only — it is not linked to your name, email, or any account, and there is no equivalent profile elsewhere on the site. - The landing path you viewed (for example
/pricingor/starter-pack). - The referring URL, when your browser supplied one (i.e. where you came from).
- A timestamp recording when the page was viewed.
In addition to the per-page beacons, the site records a single conversion row each time one of three actions completes: an intake-form submission, a contact-form submission, or a successful $1 preview-to-ownership unlock. The conversion row carries the type of action and the linked business record, with no additional personal data beyond what the form already collected.
How we use it
We use the submitted information to generate your preview landing page, to follow up by email or phone to confirm the schedule for the ownership-transfer checkout, and to fulfill any recurring subscription tier you purchase. We also use the aggregated trade-type and service-area mix to understand which segments the site is reaching.
We use the visitor analytics to produce a single aggregate totals panel inside the owner dashboard — visit counts, unique-browser counts over a 30-day window, per-action conversion counts, and a top-landing-path breakdown. We do not profile you across sessions, we do not build behavioral segments, and we do not re-target anyone based on this data.
We do not sell your information, and we do not run third-party advertising networks on this site.
Where it is stored and how long
Lead records are stored in a Postgres database managed by the site, applied with prisma db push. Uploaded photos are stored in our Cloudflare R2 bucket via an authenticated proxy. If you later create an account to manage your subscription, an authentication session cookie is set for the duration of your session.
Lead records are retained until you ask for them to be removed, or for up to 24 months of inactivity, whichever comes first. Visitor analytics pages and per-action conversion rows are retained alongside lead records and follow the same 24-month ceiling — the pseudonymous polsia_tid identifier expires naturally with the rows that reference it.
Who else receives it
Payments are processed by Stripe through our billing integration. Card data is collected and stored only by Stripe on their hosted checkout pages; it never reaches Brickloom’s servers. No other third party receives your submitted information, and no third party receives the visitor analytics data — the aggregate lives in our own database and is shown only to the site owner.
Cookies
We set an authentication session cookie only when you sign in to manage your subscription. We additionally write a pseudonymous visitor identifier to your browser’s localStorage under the key polsia_tidso we can count unique visitors across the landing pages — this key is distinct from the authentication cookie and holds no personal identity. We do not set advertising or cross-site tracking cookies. The platform running this site may set an aggregated-visitor analytics beacon, which does not identify you personally.
Your rights
You can ask to see the information we hold about your business, ask for it to be corrected, or ask for it to be deleted. Send your request to brickloom@proton.me and we will respond within 30 days.
Changes to this policy
We may update this page as the service evolves. The “last updated” date at the top of this page reflects the most recent revision, and continued use of the site after a revision means you accept the updated policy.