MOBILE APPLICATION PRIVACY POLICY
Last modified: July 1, 2024
Introduction
Bokka Group, Inc., a Colorado corporation (“Company” or “we”) respect your privacy and are committed to protecting it through our compliance with this policy. This policy describes:
- The types of information we may collect or that you may provide when you download, install, register with, access, or use the Builder Signal mobile application (the “App”), the web-based admin dashboard, homeowner-facing websites, and the Builder Signal website.
- Our practices for collecting, using, maintaining, protecting, and disclosing that information.
This policy applies only to information we collect in this App.
This policy DOES NOT apply to information that:
- We collect offline or on any other Company apps or websites, including websites you may access through this App.
- You provide to or is collected by any third party (see Third-Party Information Collection).
Our websites and apps, and these other third parties have their own privacy policies, which we encourage you to read before providing information on or through them.
Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, do not download, register with, or use this App. By downloading, registering with, or using this App, you agree to this privacy policy. This policy may change from time to time (see Changes to Our Privacy Policy). Your continued use of this App after we revise this policy means you accept those changes, so please check the policy periodically for updates.
Children Under the Age of 18
The App is not intended for children under 18 years of age, and we do not knowingly collect personal information from children under 18. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at [email protected].
Information We Collect and How We Collect It
We collect information from and about users of our App:
- Directly from you when you provide it to us.
- Automatically when you use the App.
Information You Provide to Us
When you download, register with, or use this App, we may ask you provide information:
- By which you may be personally identified, such as name, postal address, email address, telephone number, or any other identifier by which you may be contacted online or offline (“personal information”).
- That is about you but individually does not identify you, such as user behavior, analytics, and survey data.
This information includes:
- Information that you provide by filling in forms in the App.
- Records and copies of your correspondence (including email addresses and phone numbers), if you contact us.
- Your responses to surveys that we might ask you to complete for research purposes.
- Details of transactions you carry out through the App and of the fulfillment of your orders. You may be required to provide financial information before placing an order through the App.
Additional Information We Collect:
- User account information: Including but not limited to name, email address, and password.
- Profile data: Such as title, phone number, and address.
- Content data: Including posts, media uploads, and comments.
- Home and community related data: Information about users’ homes and communities.
- Builder and homeowner information: Relevant details for both builders and homeowners.
- Usage data: Such as last login time and account status.
- Voluntary survey data (on an opt-in basis): Including satisfaction ratings, current phase of construction, and feelings about the construction process.
- Basic analytics data: Such as page views and user behavior within the app.
Please note that our app does not collect any financial information, biometric data, or use any automated decision-making processes based on the collected data.
Security Roles and Access
Here is a list of security roles we employ at Bokka Group with relation to Builder Signal and third party services. Bokka Group grants access to resources on an as-needed basis. Each service listed in the Service Providers section below will have an indication of which role has access to that service.
- Principle: People with an ownership stake in Bokka Group. It is assumed that Principles at Bokka Group may have access to all services unless otherwise stated.
- Manager: A manager at Bokka Bokka Group who may need access to services for the purposes of billing or user management.
- Developer: A developer at Bokka Group who needs access to services for the purposes of ongoing maintenance, feature development, troubleshooting user issues, etc. Due to the nature of software development, the Developer role requires access to most if not all services so that they may accomplish the technical implementation of each service with Builder Signal.
- Analyst: A person who analyzes data for the purposes of delivering a better user experience and generating reports from sources such as Customer Experience Surveys and user behavioral data.
- Support: A person providing user support to Builder Signal users. A Support team member may have access to user support requests and builder admin dashboards as needed for the purposes of troubleshooting user issues and training.
Automatic Information Collection
When you download, access, and use the App, it may use technology to automatically collect:
- Usage Details. When you access and use the App, we may automatically collect certain details of your access to and use of the App, including traffic data, location data, logs, and other communication data and the resources that you access and use on or through the App.
- Device Information. We may collect information about your mobile device and internet connection, including the device’s unique device identifier, IP address, operating system, browser type, mobile network information, and the device’s telephone number.
- Stored Information and Files. The App also may access metadata and other information associated with other files stored on your device. This may include, for example, photographs, audio and video clips, personal contacts, and address book information.
- Location Information. This App does not collect real-time information about the location of your device.
If you do not want us to collect this information do not download the App or delete it from your device/you may opt out at any time by contacting the Company. Note, however, that opting out of the App’s collection of location information will cause its location-based features to be disabled.
Information Collection Technologies
The technologies we use for automatic information collection may include:
- Cookies (or mobile cookies). A cookie is a small file placed on your smartphone. It may be possible to refuse to accept mobile cookies by activating the appropriate setting on your smartphone. However, if you select this setting you may be unable to access certain parts of our App.
- Web Beacons. Pages of the App may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages and for other related app statistics (for example, recording the popularity of certain app content and verifying system and server integrity).
Service Providers and Security Measures
- Encryption: All communication between the app and the server is encrypted using SSL/TLS. The encryption helps protect the confidentiality and integrity of the data as it moves between the client and the server. Any third-party APIs integrated with your app also use secure communication protocols to maintain a high standard of data security.
- Amazon Web Services (AWS): For data storage and management, we use AWS services, including their Relational Database Service, automated database backups, serverless Lambda functions for image processing, S3 storage for hosting and image storage, & the CloudFront content delivery network. We rely on the top-tier security reputation of AWS infrastructure and strive to implement these services in accordance with their security recommendations, detailed [here](https://aws.amazon.com/security/). (access roles: Manager, Developer)
- Heroku: Our API software is deployed on Heroku, ensuring secure and reliable performance. In our business logic, any API endpoint that returns sensitive data (e.g. user emails), enumeration of data (e.g. list of homes), or any updates / deletions must be done by an authenticated logged-in user with proper permissions. For more information on the security measures taken by Heroku, visit [Heroku Security here](https://devcenter.heroku.com/articles/security-privacy-compliance). (access roles: Manager, Developer)
- Auth0 by Okta: User login and authentication are managed by Auth0, employing the industry standard OAuth 2.0 protocol for enhanced security. Additional details are available at [Auth0 OAuth 2.0](https://auth0.com/intro-to-iam/what-is-oauth-2). (access roles: Manager, Developer)
- Stream: Our in-app 2-way communication is powered by Stream, a messaging service that has been audited and is compliant with both SOC 2 and ISO 27001 standards. Learn more about their security [here)[https://getstream.io/blog/soc2-iso27001-security-compliance/). (access roles: Manager, Developer)
- Cloudflare: We use Cloudflare for our Domain Name System server, which comes with several security and performance benefits. Information on Cloudflare’s security can be found [here](https://www.cloudflare.com/security/). (access roles: Manager, Developer)
- Brevo: Transactional emails (e.g. update notifications) are sent through Brevo. Brevo is compliant with ISO 27001 standards and more information about their security practices can be found [here](https://www.brevo.com/security/). (access roles: Manager, Developer, Support)
- Qualtrics: On an opt-in basis, builders may participate in our periodic customer experience monitoring surveys on homeowner sites, powered by Qualtrics. The Qualtrics platform has obtained SOC 2 Type II Certification, ISO 27001, 27017, & 27018 Certifications, as well as several other 3rd-party security certifications outlined [here](https://www.qualtrics.com/security-statement/). (access roles: Manager, Developer, Analyst)
- Bitbucket by Atlassian: All source code for Builder Signal is backed up and maintained offsite in private Git repositories on Bitbucket by Atlassian. More information on their cloud security can be found [here](https://bitbucket.org/product/cloud-security). (access roles: Manager, Developer)
Third-Party Information Collection
When you use the App or its content, certain third parties may use automatic information collection technologies to collect information about you or your device. These third parties may include:
- Your employer who is our customer.
- Your home builder who is our customer.
- Your mobile device manufacturer.
- Your mobile service provider.
These third parties may use tracking technologies to collect information about you when you use this app. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites, apps, and other online services websites. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For information about how you can opt out of receiving targeted advertising from many providers, see Your Choices About Our Collection, Use, and Disclosure of Your Information.
How We Use Your Information
We use information that we collect about you or that you provide to us, including any personal information, to:
- Provide you with the App and its contents, and any other information, products or services that you request from us.
- Fulfill any other purpose for which you provide it.
- Give you notices.
- Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
- Notify you when App updates are available, and of changes to any products or services we offer or provide though it.
The usage information we collect helps us to improve our App and to deliver a better and more personalized experience by enabling us to:
- Estimate our audience size and usage patterns.
- Store information about your preferences, allowing us to customize our App according to your individual interests.
- Speed up your searches.
- Recognize you when you use the App.
Disclosure of Your Information
We may disclose aggregated information about our users, and information that does not identify any individual without restriction.
In addition, we may disclose personal information that we collect or you provide:
- To our customer who is your employer.
- To our subsidiaries and affiliates.
- To contractors, service providers, and other third parties we use to support our business.
- To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our App users is among the assets transferred.
- To fulfill the purpose for which you provide it.
- For any other purpose disclosed by us when you provide the information.
- With your consent.
- To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
- To enforce our rights arising from any contracts entered into between (a) you and us (including the App EULA), or (b) our customer for which you are an authorized user of the App.
- If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of our company, our customers or others.
Your Choices About Our Collection, Use, and Disclosure of Your Information
We strive to provide you with choices regarding the personal information you provide to us. This section describes mechanisms we provide for you to control certain uses and disclosures of your information.
- Tracking Technologies. You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies or block the use of other tracking technologies, some parts of the App may then be inaccessible or not function properly.
We do not control third parties’ collection or use of your information to serve interest-based advertising. However these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative (“NAI”) on the NAI’s website.
California residents may have additional personal information rights and choices. Please see Your California Privacy Rights for more information.
Accessing and Correcting Your Personal Information
You can review and change your personal information by logging into the App and visiting your account profile page.
You may also send us an email at [email protected] to request access to, correct, or delete any personal information that you have provided to us. We cannot delete your personal information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
If you delete your User Contributions from the App, copies of your User Contributions may remain viewable in cached and archived pages, or might have been copied or stored by other App users. Proper access and use of information provided on the App, including User Contributions, is governed by our terms of use.
California residents may have additional personal information rights and choices. Please see Your California Privacy Rights for more information.
Your California Privacy Rights
If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. To learn more about your California privacy rights, visit https://privacy.ca.gov/.
California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our App that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to [email protected].
Data Security
We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on our secure servers.
We use Auth0, a robust and secure authentication provider, to manage user authentication. This helps protect your login credentials and account information.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share your password with anyone. We urge you to be careful about giving out information in public areas of the App like in home updates. The information you share in public areas may be viewed by any user of the App or visitor to the homeowner site.
Unfortunately, the transmission of information via the internet and mobile platforms is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted through our App. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures we provide.
Changes to Our Privacy Policy
We may update our privacy policy from time to time. If we make material changes to how we treat our users’ personal information, we will post the new privacy policy on this page with a notice that the privacy policy has been updated.
The date the privacy policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you and for periodically visiting this privacy policy to check for any changes.
Contact Information
To ask questions or comment about this privacy policy and our privacy practices, contact us at:
Address: 3457 Ringsby Ct #100B, Denver, CO 80216