Privacy policy
We collect very little, and we'd rather tell you exactly what that is than hide it behind six pages of legal boilerplate. This page describes every piece of data this website touches, who else sees it, why, and how to make us delete it.
Everything below covers buildwithsharepoint.com: the contact form, the checklist download, server logs and the handful of third-party services the page loads.
It does not cover the work we do for clients. When we build for you, the SharePoint sites, Power Apps, flows and reports all live inside your own Microsoft 365 tenant. We work in your tenant as an invited guest or licensed user — we don't copy your business data out, we don't host it, and we never take custody of it. How that access is handled is set out in your engagement agreement, not here.
1. Who we are and how to contact us
BuildWithSharePoint is an independent SharePoint and Power Platform consultancy based in Miami, Florida, USA. We work remotely with clients across the USA, Canada, the UK, Europe, the Gulf, Australia and New Zealand.
For data protection purposes, BuildWithSharePoint is the controller of the personal data described on this page — meaning we decide what is collected here and why.
- Email: [email protected] — the fastest route for any privacy question or request.
- WhatsApp: +1 (786) 957-8651
- Based in: Miami, Florida, USA — we work remotely, so there is no walk-in office. If you need a postal address for a formal written request, email us and we'll give you one.
We have not appointed a separate data protection officer — our scale doesn't require one. Privacy questions go to the email address above and are answered by a human.
2. What information we collect
There are exactly four ways this site ends up with information about you — plus one anti-spam mechanism that collects nothing at all. That's the whole list.
a. The contact form
When you use the contact form to book a free audit or ask a question, we collect your name, your work email address, your company name (optional) and the message you write. The form is processed by Web3Forms and the result arrives in our inbox as an email. We use it to reply to you and, if it turns into a conversation, to keep track of what we discussed.
Please don't put confidential client information, passwords, tenant credentials or anything sensitive into the message box. It's an email form — treat it like an email.
b. The governance checklist download
To download the free SharePoint governance checklist we ask for your work email address (required) and your name (optional). The email address is how we send the PDF and it tells us which kinds of organizations find the checklist useful. That's it — no drip campaign, no automated sequence.
c. Anti-spam honeypot fields
Both forms contain hidden fields that only automated bots fill in. If you're a real person using a browser, they collect nothing about you at all. They exist purely so we're not drowning in spam.
d. Web server logs
Like every web server on the internet, ours records each request: IP address, timestamp, the page requested, the response code and your browser's user agent string. We don't use these to build a picture of you — they exist so we can see if the site is broken, being attacked, or being hammered by a bad bot.
e. Analytics
We keep analytics deliberately minimal. Our analytics provider is Cloudflare Web Analytics, which is cookieless by design: it counts page views, referrers and rough country-level location without setting cookies, without tracking you across other websites, and without building a profile of you as an individual. We have never run any other analytics or advertising tracker on this site, and if that ever changes we will update this page first.
3. What we do not do
Sometimes the absences matter more than the list above. On this website:
- We do not sell, rent, trade or share your data with anyone for marketing purposes. Not ever, not to anyone.
- We run no advertising and no remarketing or retargeting pixels — no Meta pixel, no LinkedIn Insight Tag, no Google Ads tag.
- We use no newsletter or marketing-automation platform. Nobody is added to a mailing list because they filled in a form.
- We do no profiling and no automated decision-making. Nothing here scores you, ranks you or decides anything about you automatically.
- We take no payments on this site, so no card or bank details are ever entered here.
- The site sets no first-party cookies and stores nothing in your browser's local or session storage.
4. Cookies
Here's the honest version, which is shorter than most cookie policies.
This website sets no cookies of its own. There's no login, no basket, no session to remember, so there's nothing for us to store — which is also why you won't find a cookie banner nagging you on arrival.
Two third parties can set their own cookies in your browser while you're here:
- Google reCAPTCHA runs invisibly on the contact form to block spam bots. Google may set cookies and read device and browser signals to decide whether you're human. See Google's Privacy Policy and Terms of Service.
- YouTube hosts one embedded explainer video on the home page. We use YouTube's privacy-enhanced mode (
youtube-nocookie.com), which means YouTube does not set tracking cookies unless you actually press play. If you never play the video, it never tracks you. If you do, Google's Privacy Policy applies to that playback.
If you'd rather block these entirely, your browser settings or an extension can do it and the site still works — the contact form will still send, it simply loses its spam protection, and the embedded video won't load. You're always welcome to email us instead.
5. The third parties involved, and why
These are all of them. Each one is here because it does a specific job, and each entry says exactly what it receives.
- Web3Forms — form processing Receives: whatever you type into a form — name, work email, company, message. Why: it turns your form submission into an email to [email protected]. Without it a static site can't send you a reply at all. Web3Forms privacy policy
- Google reCAPTCHA v3 — spam protection Receives: device and browser signals plus your IP address while you're on the contact page. It does not receive the content of your message. Why: without it, the contact form fills up with bot submissions and genuine enquiries get lost. Google privacy policy
- Google Fonts — webfonts Receives: your IP address, because your browser has to request the font files from Google's servers. Why: it's how the site's typography loads. Google Fonts privacy FAQ
- YouTube (privacy-enhanced mode) — one embedded video Receives: your IP address when the player frame loads; fuller playback data only if you press play. Why: a short explainer video on the home page. Privacy-enhanced mode is used specifically so no tracking cookies are set unless you choose to watch. Google privacy policy
- Cloudflare Web Analytics — visitor counts Receives: aggregate page-view data — page, referrer, approximate country, device type. No cookies, no cross-site identifier, no individual profile. Why: so we know which pages are actually useful and which ones nobody reads. Cloudflare privacy policy
- Our web host — serving the site Receives: standard server log data — IP address, timestamp, page requested, user agent. Why: the site is static HTML served by Nginx on an Oracle Cloud instance. Logging is how any web server is operated and secured.
- WhatsApp — link only, not an embed Receives: nothing at all unless you click the link. It's an ordinary outbound link, not a tracking widget. Why: some clients simply prefer WhatsApp to email. If you click through and message us, WhatsApp's own terms apply to that conversation.
Beyond these, the only other places your enquiry lands are our own email inbox and, if you become a client, our project records.
6. Our lawful bases for using your data (UK/EU GDPR)
If GDPR applies to you, here are the legal grounds we rely on — in plain terms.
- Consent — for the governance checklist. You give us your email address specifically so we can send you the PDF. You chose to hand it over, and you can withdraw that at any time by emailing us.
- Legitimate interests — for replying to an enquiry. If you contact us asking about our services, it's plainly in both our interests that we read your message and answer it. You'd be quite annoyed if we didn't.
- Legitimate interests — for security and spam prevention. Server logs and reCAPTCHA exist to keep the site online and the inbox usable. We've weighed this against your privacy: the data involved is minimal, short-lived and never used for marketing.
- Contract — if you become a client, we process the contact details needed to actually deliver the engagement you've signed up for.
If you think we've got that balance wrong for any of these, tell us — see your rights below.
7. How long we keep things
We'd rather delete data than store it. Our periods:
- Enquiry emails — kept for up to 24 months from our last exchange with you, then deleted. If a conversation clearly goes nowhere, it usually gets deleted sooner.
- Checklist download records — the email address is kept for up to 24 months, then deleted, unless you've become a client in the meantime.
- Client records — for as long as we're working together, and afterwards only as long as tax, accounting and legal obligations require (typically 7 years for financial records).
- Web server logs — rotated and deleted on a short cycle, typically within 30 days.
- Analytics — aggregate only, with no personal record to delete.
If you'd like your details gone before any of these periods are up, just ask. We'll do it.
8. International transfers
We're a US business, and the services this site uses are US-based. So if you're contacting us from the UK, the EU/EEA, the Gulf, Australia or anywhere else, your data will be processed in the United States by Web3Forms, Google (reCAPTCHA, Fonts, YouTube) and Cloudflare, and stored in our US-based email systems.
These providers operate international data transfer safeguards — Standard Contractual Clauses and, where applicable, the EU-US and UK extension of the Data Privacy Framework. We rely on those safeguards rather than pretending the data stays in Europe. If that matters to your organization, say so before you send anything and we'll agree a route that works for you.
Separately, and worth repeating: your project data never travels this route. Client work happens inside your own Microsoft 365 tenant, in whichever region Microsoft holds it for you.
9. Your rights
Depending on where you live, you have some or all of the following rights over your personal data. We honour all of them for everyone who asks, wherever you're based — it's simpler than checking jurisdictions.
- Access — ask for a copy of what we hold about you.
- Rectification — have anything inaccurate corrected.
- Erasure — ask us to delete it.
- Restriction — ask us to keep it but stop using it while something is being resolved.
- Objection — object to processing we've based on legitimate interests.
- Portability — receive your data in a portable, machine-readable format.
- Withdraw consent — where we relied on consent (the checklist download), withdraw it at any time. This doesn't undo anything lawfully done before you withdrew it.
- Complain — to a data protection authority, if you're not happy with how we've handled it.
How to exercise them
Email [email protected] and say what you want — "please delete everything you have on me" is a perfectly good request, no special wording needed. Send it from the email address you originally used if you can, since that's the simplest way for us to be sure it's really you; if you can't, we may ask a question or two to confirm. We'll respond within 30 days, and it's free.
If you're in the UK and you're unhappy with our response, you can complain to the Information Commissioner's Office at ico.org.uk. If you're in the EU or EEA, you can complain to your own national data protection authority. We'd genuinely prefer you came to us first so we can fix it.
10. Children
This is a business-to-business service. The site is aimed at IT managers, operations leads and business owners — it is not directed at children, and we don't knowingly collect data from anyone under 16. If you believe a child has submitted information through one of our forms, email us and we'll delete it straight away.
11. Security
Reasonable, honest measures rather than security theatre:
- The whole site is served over HTTPS, so anything you type into a form is encrypted in transit.
- The site is static HTML — there's no database, no login and no user accounts on it, which removes an entire category of risk.
- Enquiries land in a mailbox protected by strong authentication, with access limited to the people who need it.
- We host no client data. Your SharePoint sites, files, apps and reports stay in your Microsoft 365 tenant, under your tenant's own security and compliance controls.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If we ever became aware of a breach affecting your personal data, we'd tell you and the relevant authority within the legally required timeframes.
12. Changes to this policy
If we change how the site handles data — a new tool, a different form processor, a change of analytics provider — we'll update this page and change the date at the top. There's no version archive; the page you're reading is always the current one.
This policy sits alongside our terms of use, which cover everything else about using this website.
Last updated: 29 July 2026.
Questions about any of this? Email [email protected]. A real person reads it.
Still want to talk to us?
A free 30-minute audit of your Microsoft 365 tenant — what you already own, what's switched off, and the one or two changes that would save your team the most hours. No obligation, and no marketing list.