Privacy Policy
Last updated: July 16, 2026
This policy explains what BuildMyMTB does — and does not — do with your information. It is written to match how the site actually works, not from a generic template.
BuildMyMTB (the “Site”, “we”, “us”) is a free tool for picking mountain-bike parts and checking whether they fit together, with a running price and weight. It is operated by Douglas Wills, operating as a sole proprietor. You can reach us at Doug@buildmymtb.com.
The short version. You can use the whole Site without an account, and if you do, nothing that identifies you is sent to us. The only analytics we use is cookie-less, aggregate page-view counting (Cloudflare Web Analytics) that cannot identify or follow you; we use no advertising and no cross-site tracking. The only data we store about you is what you actively create if you choose to sign in — your login email, the builds you save, your parts inventory, and anything you post in the forum. You can delete it at any time.
1. Using the Site without an account
The build checker runs entirely in your browser from a built-in catalog. If you never sign in:
- No account is created and no personal information is sent to us.
- Your in-progress build lives only in your browser. A share link encodes the build inside the URL itself (client-side) — it is not saved on any server of ours. Anyone you send that link to can open the same build.
- We store two small functional preferences in your browser’s local
storage so the Site remembers how you like it:
tb-theme(light or dark mode) andtb-view(card or list layout). These never leave your device and are not used to identify or track you.
2. If you create an account (optional)
Accounts are optional and exist so you can save builds and track the parts you own. Sign-in is handled by Supabase (our authentication and database provider) using either:
- a one-time “magic link” sent to your email address, or
- Sign in with GitHub, in which case GitHub shares your basic profile and email with our authentication provider so an account can be created.
When you have an account, we store:
- Your email address — used to identify your account and send the sign-in link.
- Saved builds (“Garage”) — the parts in a build, plus a name and a status you set.
- Your parts inventory (“Inventory”) — the catalog parts you mark as owned, and a quantity.
- Forum posts — any threads or replies you write (see below).
Every one of these rows is tied to your account and is protected by database Row-Level Security, so only you can read or change your builds and inventory. Your account identifier is never sent from your browser — the database assigns it from your logged-in session.
3. The community forum
If the forum is enabled, threads and replies you post are stored by Supabase and tied to your account. Forum posts are public — anyone visiting the Site, signed in or not, can read them, so please don’t include anything private in a post. Only you (via your logged-in session) can edit or delete your own posts.
4. Reporting a wrong result or a bug
If you use the “report a wrong verdict” feature, you can either copy the report to your own clipboard, or open a GitHub issue. Choosing the GitHub option takes you to GitHub, where the report (the build details and any notes you add) becomes part of a public issue on our repository. What is submitted is shown to you first, and GitHub’s own privacy terms apply once you are on their site.
5. Analytics, cookies and tracking
We deliberately built the Site to be privacy-friendly:
- Cookie-less, aggregate analytics only. We use Cloudflare Web Analytics to count page views. It sets no cookies, stores nothing on your device, and does not fingerprint or identify individual visitors — we see aggregate numbers (pages viewed, referrer, country, browser type), never a profile of you. No Google Analytics, no Segment, no ad-tech analytics of any kind.
- No advertising or cross-site tracking, no tracking pixels, and no data brokers.
- No tracking cookies. The Site does not set cookies to follow you. Sign-in uses functional browser storage to keep you logged in on your device; the theme and layout preferences above are the only other storage we use.
Because the only storage we use is functional (needed to make the Site work as you asked), no cookie-consent banner is required. As with any website, our hosting provider (see below) processes standard technical request data — such as your IP address — in its server logs to deliver the pages and guard against abuse; we do not build profiles from this.
6. Third-party processors
We keep the moving parts to a minimum. The services that may process your data are:
- Supabase (Supabase, Inc.) — authentication and the database that stores your account email, saved builds, inventory, and forum posts. See Supabase’s privacy policy.
- GitHub (GitHub, Inc., a Microsoft company) — hosts the Site via GitHub Pages (and, as host, processes standard request logs); receives any bug report you choose to file as an issue; and provides the optional “Sign in with GitHub” option. See GitHub’s privacy statement.
- Cloudflare (Cloudflare, Inc.) — provides the cookie-less web analytics described in section 5 (aggregate page-view metrics; no cookies, no fingerprinting, no cross-site tracking) and our domain’s DNS/email routing. See Cloudflare’s privacy policy.
We do not sell your data, and we do not share it for advertising. These services are based in the United States, so if you use the Site from elsewhere your data may be processed there.
7. Retailer and affiliate links
Some parts link out to retailers, and some of those are affiliate links. When you click one you leave BuildMyMTB and go to the retailer’s own site, which has its own privacy practices and may set its own cookies. See our Affiliate Disclosure for how this works and why it never affects the compatibility results.
8. How long we keep data, and your rights
We keep your account data until you delete it or ask us to. You can:
- Delete individual builds and inventory items yourself, in the app.
- Delete or edit your own forum posts yourself.
- Delete your whole account and everything tied to it — email us at Doug@buildmymtb.com and we’ll remove it.
- Ask what we hold about you, or ask for a copy — email the same address.
Depending on where you live, you may have additional rights (such as access, correction, deletion, or objection) under laws like the GDPR or the CCPA. We’ll honor those requests; just contact us.
9. Children
The Site is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will delete it.
10. Security
Account data is owner-scoped at the database level by Row-Level Security, and sign-in uses a modern authentication flow. No method of transmission or storage is ever 100% secure, so we can’t guarantee absolute security, but we keep the surface area small on purpose.
11. Changes to this policy
If we change how we handle data, we’ll update this page and change the “last updated” date above. Material changes will be made clear on the Site.
12. Contact
Questions about privacy? Email Doug@buildmymtb.com (Douglas Wills).