Skip to content
HomeHow we deliverThe benchBlogReferSite auditBook a 20-minute call
Book a 20-minute call
HomeHow we deliverThe benchBlogRefer a projectSite auditContactBook a 20-minute call

Registered in the United States. We contract, invoice and bank in the US. Built by our own team.

Legal

Privacy policy

Plain-English version: we keep what you give us and a record of how you use this website, measured by our own analytics (no Google Analytics, no advertisers). Where the law asks for your permission first, we ask first. We use it to answer you and to make the site better, we never sell it, and you can have all of it deleted by sending one email.

Effective date: October 2, 2026. This policy covers buildwithik.com and the software services we operate. "BuildWithIK" is the trading name of Indra Kamal International Private Limited, registered in Nepal at Ward No. 3, Krishnagalli, Lalitpur, Nepal, 44700, and Build With IK LLC, registered in the USA at 30 N Gould St, STE R, Sheridan, WY 82801, USA (together, "we" and "us"). Questions or requests: [email protected].

What we collect

  • Information you give us: when you book a call, ask for a call back, chat with June (our site assistant), request a site audit or write to us: your name, email address, phone number, company, website, time zone, and what you tell us, and for a booking the time you chose. What you type to June is kept with the conversation. If you talk to June instead of typing, your browser’s own speech recognition turns your voice into text (depending on the browser, its maker’s speech service may do this, for example Google in Chrome); we receive only the text, never the audio.
  • How you use this website: we run our own analytics, on our own servers at Cloudflare (no Google Analytics, no advertising or social-media trackers). What we record depends on where you are and what you chose (see Your privacy choices):
    • Full analytics: your IP address and the approximate location Cloudflare derives from it (country, region, city, postal code, time zone and approximate coordinates), your network provider, browser, device, operating system and language, the page or link that brought you here (including campaign tags such as UTM parameters and ad click IDs), the pages you view, your clicks, scrolling and time on each page, the names of form fields you use (not what you type in them, except the contact details you choose to send us), errors, and how fast pages load.
    • Coarse count only: the page, the time, your country, the kind of device, the browser family, the domain of the website that sent you and its campaign tags. No IP address, no cookie that recognises you, nothing that links one page to the next.
  • Cookies: first-party only, never third-party. With full analytics, bwk_v recognises a returning browser (up to 13 months) and bwk_s groups the pages of one visit (30 minutes). Always, because they are needed to respect your choice: bwk_c remembers whether you accepted or rejected analytics (12 months), bwk_r remembers which rules apply to your visit, with no location detail (1 day), and bwk_n remembers that you have seen a privacy notice, where we show one (12 months). The booking form’s spam check (Cloudflare Turnstile) runs a short challenge in your browser.
  • Automated visitors: search engines, AI crawlers and other bots are recorded by name, without cookies.
  • Linking: with full analytics, when you give us your email or phone number (a booking, a form or the chat), we link it to the visits made from that browser, so the founder who answers you knows what you have already seen. With the coarse count, nothing is linked.
  • Referral partners: if you join our referral program, your name, email address, country, how you plan to find clients, the link or campaign that brought you, and the network address and browser you signed up and sign in from. Before your first payout: a government ID, a tax form (W-9 in the US, W-8BEN or W-8BEN-E elsewhere), your postal address and your payout details (a Wise account, or a US bank account for US partners). The ID, the tax form, the address and the payout details are encrypted before they are stored, and only the founders can open them. If you fill in and sign your tax form online, we also keep the record of your signature with the form, for as long as we keep the form: when you opened the signing page, agreed to sign electronically and signed, from which network address and browser, and your account’s email address; the record is sealed so that anyone holding its document ID can check that it has not changed (the check shows no personal data). Before we pay a commission, we check partners’ names against the US Treasury’s (OFAC’s) sanctions lists, by hand or automatically (against the lists as the US government publishes them in its Consolidated Screening List, trade.gov), and keep a record of each check for as long as we keep your name.
  • If a partner introduced you: the partner gave us your name, company, contact details and a short description of your project, and told us you agreed to the introduction. You can ask us to delete it at any time.
  • Partner links, client records and signed proposals: if you arrive through a referral partner’s personal link, a first-party cookie, bwk_pr, remembers that partner’s code for 90 days where full analytics are on (otherwise only until you close your browser), so that the partner is credited if you book a call or leave your details and learns only your company’s name (or your email’s domain) and how far our work together goes, never what you tell us; we keep everything you send us in one client record per email address, with our notes and the history of our contact; and when you sign a proposal online we keep a sealed record of the signature (your typed name, title and company, your email address, network address and browser, when you opened, viewed and signed it, and a fingerprint of the exact document) that anyone holding its document ID can check without seeing any personal data.
  • Nothing else. We don’t buy data about you and we don’t combine it with data from other sources.

Your privacy choices

Where you are decides how our analytics start:

  • In the European Economic Area, the United Kingdom, Switzerland, Brazil, Turkey, South Korea, China and Quebec: nothing that identifies you is recorded until you choose Accept. Until then, and if you choose Reject, we keep only the coarse count.
  • Everywhere else: full analytics are on. You can choose Reject at any time with Privacy choices, and we switch to the coarse count.
  • Everywhere: a Global Privacy Control or Do Not Track signal from your browser counts as Reject, even if you accepted before. You can change your choice at any time with Privacy choices at the bottom of every page.

How we use it

  • To respond to you, schedule calls, and deliver the services you request.
  • To run tools you invoke. For example, our AI site audit and chat process the text and URLs you submit in order to produce their results.
  • To keep the site secure, and to understand how it’s used so we can improve it (for example, which pages lead people to book a call).
  • To run the referral program: to confirm who a partner is, to meet our tax obligations, to check payouts against sanctions lists, and to pay commissions.
  • We do not sell or rent personal information, we do not share it for cross-context behavioural advertising, and we do not use it for third-party advertising.

Legal bases (EEA, UK and Switzerland)

We answer you, book calls and run the tools you ask for because you asked, as steps before or under a contract with you. We keep the coarse count, the bot log and our security records under our legitimate interest in running a safe, working website; they hold nothing that identifies you. Full analytics in these places run only on your consent, which you can withdraw at any time with Privacy choices. We keep records the law requires (tax and accounting, for example) because we must.

Data from connected platforms (including Meta)

Some of our products connect to third-party platforms, such as Facebook Pages, Instagram or WhatsApp via Meta’s APIs, on behalf of business clients who explicitly authorize that connection through the platform’s own login and permission flow. For such data we act as follows: we access only the data the platform permissions cover (for example, comments and messages on the client’s own pages and accounts); we use it solely to provide the contracted service to that client (such as customer-feedback analysis); we do not sell it, use it for advertising, or share it beyond the service providers needed to operate the product; and we handle it in accordance with the Meta Platform Terms and Developer Policies. Platform data is deleted when the client disconnects the integration, when our agreement with the client ends, or upon request as described below.

Who we share it with

Only the service providers that make the site and our products work, each bound to use the data only to provide their service to us:

  • Cloudflare: hosting, storage, analytics infrastructure and the spam check.
  • Resend: email delivery (booking confirmations, reminders and our replies).
  • Google: when you book a call, the booking (your name, email address, the time and what you wrote) is added to our Google Workspace calendar, and Google Calendar sends you the invitation with its Google Meet link.
  • Zoom: if you choose Zoom for your call, Zoom creates the meeting in our account; it receives the time, the call’s title with your name, and what you wrote about your project.
  • AI model providers (currently Groq, and Google’s Gemini API as a fallback): they process the text you submit to the site audit and the chat, to produce the answer.
  • Wise and our US bank: to pay a referral partner’s commission, they receive the partner’s name, payout details and the amount.

Products we build for clients use open models on hardware we control; client data is not sent to consumer AI services. We may also disclose information if the law requires it.

Where it is processed

We work from the United States and Nepal, and our providers process data in the United States and other countries where they operate. Where the law requires it, transfers rely on our providers' standard contractual clauses or equivalent safeguards.

How long we keep it

Form submissions, bookings and correspondence: for as long as we’re talking, and up to 24 months after our last contact so we have context if you come back. Analytics: the raw log of each page request, and the visit and event records, for 90 days; the record of a browser, and any contact details linked to it, until 24 months after its last visit. Daily totals with no personal details (counts by page, source, country, city and device) are kept. Platform data connected by clients: for the duration of the client agreement.

Referral partners (and the clients they introduce): each kind of record has its own period, and we delete it when the period ends.

  • Your profile and activity (your answers when you joined, where you came from, sign-in records): 2 years after your last activity or the closing of your account, whichever is later.
  • A referred client's contact details (their name, email, phone and the brief) and our notes on that introduction: 2 years after the introduction goes quiet. We keep the company name and the money records.
  • Copies of your ID: 5 years after your last activity or your last payout, whichever is later.
  • Tax forms (W-9, W-8BEN, W-8BEN-E): 7 years after your last payout or 2 years after your last activity, whichever is later (if we never paid you, 2 years after your last activity).
  • Payout records: 7 years after each payout (the payout details on a request we did not pay: 2 years after that decision). Your current payout details: removed after 2 years without activity; you can enter them again. Commission we still owe you is never deleted.
  • Your name, email and postal address, and the record of your acceptance of the partner agreement (the version, the time and your network address): kept as long as any record above is kept, and at least 2 years after your last activity. Then we remove your name, email, address and network address.

Your rights and data deletion

You can ask us at any time to see, correct, or delete the personal information we hold about you, including the analytics records linked to you. You can also clear or block our cookies in your browser; the site works without them. To request deletion: email [email protected] with the subject "Data deletion request" from the address you used with us (or identify it), and we will delete your data from our systems within 30 days and confirm by reply. If your data reached us through a platform integration (for example, a Facebook or Instagram interaction with a business we serve), name that business and platform and we will delete the associated records the same way.

In the EEA, the UK and Switzerland you also have the right to restrict or object to our use of your data, to receive it in a portable format, to withdraw consent at any time (without affecting what happened before), and to complain to your data protection authority.

Your rights in US states (including California)

In the last 12 months we collected these categories of personal information: identifiers (name, email address, phone number, IP address and cookie IDs), internet activity on this website (pages, clicks, referrers), approximate location derived from the IP address, and professional details you give us (company and website). They come from you, from your browser, and from Cloudflare’s IP-based location, and we use them for the purposes above. We do not sell or share personal information, we do not use sensitive personal information, and we honour Global Privacy Control.

You have the right to know what we hold about you, to get a copy, to have it corrected or deleted, and not to be treated differently for using these rights. Email [email protected] from the address you used with us; we confirm the request from that address and answer within 45 days. Someone you authorise in writing may ask on your behalf.

Security

Data lives on access-controlled infrastructure (Cloudflare), transmitted over HTTPS, with credentials restricted to the people who need them. The link between our booking system and our calendar is stored encrypted. No system is perfectly secure, but we keep the surface small: we collect little, so there is little to lose.

Children

Our services are for businesses and are not directed at children under 16, and we do not knowingly collect their information.

Changes

If we change this policy, we’ll update this page and its effective date. Meaningful changes will be flagged on this page rather than buried.

Contact

Indra Kamal International Private Limited · Ward No. 3, Krishnagalli, Lalitpur, Nepal, 44700 · Build With IK LLC · 30 N Gould St, STE R, Sheridan, WY 82801, USA · [email protected]

BuildWithIK

Registered in the United States. We contract, invoice and bank in the US. Built by our own team.

Studio

HomeHow we deliverThe benchSectorsProductsBlogRefer a project

Try

Score my siteBook a 20-minute call

Contact

[email protected]Contact and addressesAsk for a call backLinkedIn

© 2026 BuildWithIK · Privacy policy · Data deletion · · [email protected]

Legal registered name in the United States: Build With IK LLC · Nepal studio: Indra Kamal International Private Limited

June

The studio’s assistant

Leave an email or number and a founder replies. Book a 20-minute call

Your privacy

We use our own analytics to see how this site is used — never ads, never sold, never handed to a third party. Choose what’s fine with you; either way you can change it later.

Privacy policy

We use our own analytics to improve this site — no ads, no data sold.