Legal
Privacy Policy
Last updated: August 19, 2026
This policy explains what Brick by Brick collects when you visit the wall or place a brick, what we do with it, and who else handles it. It describes how the service actually works — nothing here is aspirational.
Browsing the wall requires no account and no sign-in. We collect personal information from you only when you submit a brick and pay for it.
What we collect
When you submit a brick, we store:
- The display name, short message, website address and brick finish you chose.
- The logo image you uploaded, if you made a logo brick. It is re-encoded to WebP and resized to fit the brick face; the file name you uploaded is not kept.
- The contribution amount, in US cents.
When you pay, Stripe passes back and we store:
- The email address you gave on Stripe’s checkout page.
- Stripe identifiers and status for the transaction — the Checkout Session, the PaymentIntent, any refund, whether the payment succeeded, failed or expired, and when. We never receive or store your full card number, expiry or security code.
Operating the service also produces:
- Submission and moderation records: the state of your brick, when it was reviewed or published, the moderator’s note, and an audit entry naming the moderator who acted.
- A record of the payment events Stripe sent us, so the same event is never processed twice.
- Standard technical logs from our hosting provider — IP address, user agent, requested URL, timestamps and error information — kept for security, abuse prevention and debugging. Our own application logs are written deliberately without customer content in them.
- Sign-in information for moderators: an email address on an internal allowlist, authenticated through Supabase. This applies to us, not to visitors.
How we use it
- To take payment and to issue refunds.
- To reserve a slot for your brick and publish it once it is approved.
- To review submissions against the content rules.
- To answer your emails and provide customer service.
- To detect and prevent fraud, abuse and duplicate charges.
- To keep the site secure, available and working correctly.
- To meet our legal, tax and accounting obligations, and to handle disputes.
We do not sell your personal information, and we do not share it for advertising.
What becomes public
A brick is meant to be seen. Once yours is published, these are visible to anyone: the display name, the message, the logo, the website link, the brick finish and the brick number.
Your email address, your contribution amount and every payment identifier are not public and are never shown on the wall. Please do not put anything in a display name, message or logo that you would not want the public to see — including your own contact details.
Who else handles it
We use three service providers. There are no others, and no advertising or analytics companies are involved.
- Stripe — payment processing. Checkout happens on Stripe’s own hosted page, where Stripe collects your card details and your email directly. Stripe’s own privacy terms govern what it does with them.
- Supabase — our database, authentication, live updates and file storage. Your browser connects to Supabase directly to load published bricks and to receive live updates as new bricks appear.
- Vercel — hosting and content delivery for the website itself, including the request logs described above.
Payment information
- Stripe collects and processes your payment details on its own hosted checkout page.
- Brick by Brick does not receive, see or store full card numbers.
- We store only the amount, the transaction status and Stripe’s identifiers for it, so we can support you and issue a refund if one is due.
- Stripe’s privacy terms apply to Stripe’s processing of your payment.
Cookies and analytics
The public wall sets no analytics cookies, no advertising cookies and no cross-site tracking of any kind. We run no analytics product, no tag manager and no advertising pixel, so there is nothing to opt out of and no cookie banner to click.
Cookies are used in one place: when a moderator signs in to the admin area, Supabase sets the authentication cookies that keep that session signed in. Those are strictly necessary for the admin area and are not set by browsing the wall.
Stripe’s checkout page is Stripe’s own site, and Stripe’s cookie and privacy practices apply there.
How long we keep things
- Published brick content stays on the wall while we operate the service.
- Payment, refund, moderation and audit records are kept for as long as we need them for accounting, tax, dispute-resolution, fraud-prevention and legal purposes. They are deliberately retained even after a brick is removed from public view.
- Removing a brick from the wall removes the public content. It does not erase the transaction record behind it, and we will not claim otherwise.
- Technical logs are kept for a limited period by our hosting provider under its own retention practices.
Access, correction and removal
Email brickbybrickhello@gmail.com from the address you used at checkout and we will help you:
- Get a copy of the information we hold about your submission.
- Correct a display name, message, link or logo.
- Remove your brick’s content from the public wall.
- Ask a question about how your information was handled.
We may need to verify that the request comes from the person who made the contribution before we act on it. We answer requests as promptly as we reasonably can.
If you live in California or another place with statutory privacy rights, use the same address. We handle access, correction and deletion requests through this process regardless of whether a particular law applies to us, subject to the retention limits described above. We do not sell personal information and we do not share it for cross-context behavioural advertising.
Security
We take reasonable measures to protect the information we hold: payment details never touch our servers, secret keys are held server-side only, database access is restricted by row-level security, uploaded images are re-decoded and re-encoded before they are stored, pending submissions live in private storage, and the admin area is restricted to an allowlist of moderators. No system is perfectly secure, and we cannot guarantee absolute security.
Where information is processed
Brick by Brick is operated from the United States and our providers process and store information in the United States and in other countries where they run infrastructure. If you use the service from elsewhere, your information is transferred to and handled in those countries.
Children
The service is for adults. You must be at least 18 to contribute, and the site is not directed to children. If you believe a child has submitted information to us, email brickbybrickhello@gmail.com and we will remove it.
Changes to this policy
We will update this page if what we collect or who processes it changes. The date at the top shows when it was last revised.
Contact
Privacy questions go to brickbybrickhello@gmail.com. See also the Terms of Service and the Refund & Cancellation Policy.