Privacy notice
This is the privacy notice for builtforprod.com. It is short because the site does very little: one contact form, analytics that only run if you allow them, and no tracking.
Scope and date
These are the terms for this website. If you are a BuiltForProd customer, how we handle data inside an engagement is governed by your customer agreement, not by this page. What the documentation site stores about a signed-in reader is described in its own knowledge base and privacy pages.
One principle runs through all of it: nothing that identifies you loads until you choose, and we never ask for more than we need to answer you.
What we collect, and why
| What | Which details | Why | On what basis |
|---|---|---|---|
| What you send us on the contact form | Your name, email address, and optionally your company and role; the topic you chose, your message, and the page you submitted it from. | To read your message, reply to it, and judge whether we are the right fit for what you need. | You chose to send it. Nothing on this site collects these fields any other way. |
| Page views, if you allow analytics | The page, the referrer, approximate location from the network address, and the kind of device. No name, no email address, no account identifier. | To see which pages help and which do not, so we write fewer useless pages. | Your consent, recorded in one cookie, which you can withdraw at any time. |
| Ordinary server and security logs | Request logs kept by our hosting provider, including network addresses, for delivering the page and blocking abuse. | To serve the site and to keep it available. These are operational records, not a profile of you. | Necessary to run the website at all. |
Do not send us secrets
The contact form is a web form, not a secure channel. Never send credentials, access keys, tokens, private key material or decrypted secrets through it, to us or to anyone else. If you need to share something sensitive during an engagement, ask and we will agree a proper channel.
Analytics, and the consent cookie
Analytics on this site is consent-first. Before you answer the banner, analytics storage is denied and no
analytics tag loads. If you allow it, your answer is stored in a cookie named
bfp_consent on .builtforprod.com for
365 days, so one choice covers this site, the blog and the documentation. If
you decline, the same cookie records the refusal so we stop asking.
If your browser sends the Global Privacy Control signal, we treat that as a decision: analytics stays off, the banner does not appear, and an earlier grant is not used. Cloudflare Web Analytics, where configured, is a cookieless beacon and sets nothing in your browser.
Each page view carries at most three non-identifying dimensions describing which part of the site the page belongs to. It never carries a user, an email address or an organization identifier. The cookies page lists every cookie by name.
Who processes your data
| Processor | What it does | What it sees |
|---|---|---|
| Cloudflare | Hosts and serves this site, and runs the spam check on the contact form when it is enabled. | Requests to the site, including network addresses; the contact form submission passes through it on its way to us. |
| An email delivery provider | Delivers the contact form message to the BuiltForProd inbox that matches the topic you chose. | The contents of your message and the address to reply to. |
| A customer relationship tool, when connected | Records the enquiry so it is not lost between people. Optional, and it never decides whether your message reaches us. | Your name, email address, company, role and message. |
| Google Analytics, only with consent | Measures page views. It never loads until you allow it, and it is not loaded at all on a deployment with no measurement id configured. | Page views with three non-identifying dimensions. Never your name, email address or organization. |
These providers operate infrastructure in several countries, so a message may be processed outside the country you sent it from. We use providers that commit to appropriate safeguards for those transfers.
How long we keep it
- Your message. We keep it while the conversation is live and for as long as we have a reason to remember it, such as an engagement that followed from it. We delete it on request.
- The customer record, where one exists. Kept while you are a customer or an active prospect, and removed on request.
- Analytics. Aggregated reporting data with no identifier attached to you, retained under the analytics provider's own retention settings.
- Server and security logs. Kept for a short operational period by the hosting provider and then rotated away.
What we do not do
- We do not sell personal data, and we do not share it with advertising networks.
- We run no tracking pixels, no advertising cookies and no cross-site identifiers.
- We do not build profiles of readers, and we do not make automated decisions about you.
- We do not load analytics before you say yes, and we honor the Global Privacy Control signal even if you said yes earlier.
- This site does not connect to your cloud accounts, your repositories or your data. It is a website.
Your choices
See what we hold
Ask, and we will tell you what is in the inbox and the customer record for your address. Write to [email protected].
Have it deleted
Ask us to delete your enquiry and any record of it, and we will do so and confirm, within 30 days. Write to [email protected].
Correct it
If we have your name, company or role wrong, tell us and we will fix it. This is usually faster than asking.
Change your analytics choice
Delete the consent cookie, or turn on Global Privacy Control in your browser, and analytics stops. The cookies page explains both.
Depending on where you live, you may also have the right to object to processing, to ask for a copy of your data in portable form, or to complain to a supervisory authority. Write to [email protected] and we will handle it without making you cite a regulation first.
Who is responsible
BuiltForProd is a brand of Nexstella, which is responsible for the personal data described on this page. Questions, requests and complaints about privacy go to [email protected], with "Privacy" in the subject line so the request is handled as one.
If we change this notice we change the date at the top, and a change that affects what we collect will be announced on the site rather than made quietly.