Privacy Policy
How we collect, use, and protect your data.
Data We Collect
When you use Build Factory X, we collect the following information to process and fulfil your orders:
- Full Name, Email Address, and Mobile Number (provided during registration or checkout).
- Delivery Address (street, landmark, city, PIN code) for shipping purposes.
- PC build configuration selections, order history, and budget preferences.
- Login/logout actions are rate-limited by email address for abuse prevention.
Authentication — Firebase
We use Google Firebase Authentication to handle user login via Google Sign-In. Firebase processes your Google account data (name, email, profile photo) to authenticate your identity. Firebase stores a session token locally in your browser using Local Persistence, keeping you signed in across page reloads. For full details, see Firebase’s Privacy Policy.
Data Storage — MongoDB
All order data, user profiles, rate-limit records, and PC build catalogue information are stored securely in a MongoDB Atlas cloud database. Your data is encrypted in transit (TLS) and at rest. Cancelled orders are automatically purged from the database 6 hours after cancellation. See MongoDB’s Privacy Policy.
Cookies & Session Persistence
We use the following cookies and local storage mechanisms:
- Firebase Auth Token — stored in browser Local Storage to maintain your login session across visits.
- Admin JWT Cookie — an HTTP-only session cookie issued to verified admin users for secure dashboard access.
- Cart Data — your shopping cart contents are saved in Local Storage and optionally synced to the server for persistence.
- Auth Rate Limit — login/logout attempts are tracked in-memory by email address (no persistent storage).
Payments — Zoho Pay & Razorpay
Payments are processed securely through Zoho Payments (Zoho Pay) and Razorpay. Build Factory X does not store your card details, bank account numbers, or UPI PINs. All payment transactions are handled directly by our payment partners in PCI-DSS compliant environments. For more details, see Zoho’s Privacy Policy and Razorpay’s Privacy Policy.
Data Retention & Deletion
- Active order data is retained until the order is completed or cancelled.
- Cancelled orders are automatically deleted from our database 6 hours after cancellation.
- Rate-limiting records (login/logout attempts) expire automatically per their configured TTL.
- You may request full account and data deletion by contacting us at buildfactoryx@zohomail.in.
6-Hour Security Session Expiration
To protect customer accounts against session hijacking and token theft, Build Factory X enforces a strict 6-hour maximum session lifetime.
- After 6 hours, your browser session token (
bfx_token) and authentication cookies automatically expire. - Expiring session tokens purges transient authentication credentials from your browser only. Your account profile, saved addresses, and complete order history remain permanently and safely encrypted in our database.
Customer Support & Automated AI Assistance
Support tickets created through our Support Portal (/contact) are reviewed directly by the Build Factory X team.
- If a support ticket experiences a response delay exceeding 2 to 3 hours, BFX Support AI automatically posts an automated message in the ticket thread to confirm your issue is under active investigation.
- Full support conversation records are maintained so that support agents can resolve your query as quickly as possible.
Zero-Tolerance Security Policy & Permanent Ban Rule
Build Factory X actively monitors and logs all access attempts to administrative routes (/admin).
Strict Permanent Blacklist Rule:Any user, email address, or device IP that attempts to access, probe, or breach the Admin Portal or administrative features without verified store owner authorization will be PERMANENTLY BLOCKED AND BLACKLISTED from all Build Factory X services, custom configurators, orders, and support channels immediately. Real-time security intrusion alerts containing user identity, email, and IP details are dispatched instantly to store administrators.
BFX AI Assistant & Admin Orb AI
Our chatbot assistant uses the Google Gemini API and Groq API to generate responses to your queries. Please do not enter any private personal details (such as credit card numbers, passwords, bank account info, or government IDs) in the chat box. Build Factory X does not store, process, or ask for payment credentials in the chat, and BFX is not responsible for any security issues or data exposure resulting from sharing private details in the chatbot window.
Communications
We use Resend to send transactional emails (order confirmations, status updates). We do not send marketing or promotional emails unless you explicitly opt-in.
This policy was last updated on August 2026. We reserve the right to update this policy at any time. Continued use of the platform constitutes acceptance of the latest policy.