Privacy policy
Privacy Policy
Effective August 26, 2026
This policy explains how Built Long handles information when businesses publish a site and manage project inquiries, and when prospects or invited clients interact with a business.
Who operates Built Long
Built Long is operated by Long Play Works, Inc. In this policy, “Built Long,” “we,” “us,” and “our” refer to the Built Long service. This policy applies to builtlong.com, Built Long-hosted business sites, authenticated dashboards, and related inquiry, client-space, payment, billing, domain, and Managed Ads features. Use the contact form to reach us.
Information we collect
We collect information in the following categories:
- Account information, including name, email address, one-time-code challenge and browser-bound session records, roles, and limited security signals used to prevent abuse.
- Business and public-site information, including business name, service area, services, process, availability, selected work and metadata, style settings, rights confirmations, and image descriptions.
- Project inquiry information, including a prospect’s name, contact details, location, project type, optional organization type, description, timing, budget range, optional decision-makers, and notes.
- Opportunity and client-space information, including pipeline state, invited members, selected media, messages, review requests, decisions, and retained activity.
- Payment and subscription information, including payment-account, checkout, subscription, payment, refund, and receipt identifiers and status. Hosted payment surfaces handle card and bank details; Built Long does not receive full card numbers.
- Domain, managed advertising consent, support, operational audit, attribution, and technical delivery records needed to operate and secure the service.
- Support messages, reviewed proposals, confirmations, and bounded change evidence when a business uses Support.
- Bounded first-touch attribution, including a coarse channel, safe landing path, referrer origin, campaign fields, and reviewed click identifiers when supplied. This is not a complete browsing or session history.
Information we do not need
An initial project inquiry does not need an exact street address, access or security instructions, floor plans, internal budgets, financial-account credentials, or confidential client files. Businesses and prospects should provide only the information needed for the next fit decision. Built Long does not need full payment-card numbers and does not use sensitive project details to build advertising audiences.
How we use information
- Provide, secure, troubleshoot, and improve Built Long.
- Answer Support questions and prepare only the website changes a business explicitly reviews and confirms.
- Authenticate business users and operate their public sites and private dashboards.
- Save a project inquiry, deliver it to the selected business, and support authorized follow-up and opportunity tracking.
- Operate invited client spaces, bounded review decisions, connected payments, receipts, subscriptions, and domains.
- Support authorized managed advertising services and record the business's approvals.
- Comply with law, enforce our terms, and prevent abuse.
When information is disclosed
Inquiry information is available to the selected business. Client-space information is available only to authorized business users and invited members of that space. Businesses are independent businesses responsible for their own use of that information and for their professional and client relationships.
We use service providers needed to operate the product, including providers for connected client payments and separate Built Long subscription billing. If a business uses managed advertising, the configured advertising service may receive activity and conversion information the business has authorized. Providers process information under their own terms and policies.
When configured, a model service processes the business's Support question, selected reviewed Help content, and bounded public-site fields needed for the answer or proposal. Provider response storage is disabled. Do not include credentials or private client details in Support.
We may disclose information when reasonably necessary to comply with law, protect people or the service, investigate abuse, or complete a corporate transaction. Built Long does not sell inquiry information or operate a data brokerage or shared-lead marketplace.
Cookies and abuse prevention
Built Long uses essential cookies to bind a one-time-code request to the requesting browser, maintain a signed-in session, and authorize invited client-space access. Signed first-touch cookies last for up to 30 days so a provider signup or project inquiry can retain the first known acquisition source. Blocking essential cookies may prevent those features from working.
Form protection
Public forms use an abuse-prevention service that may process limited network, device, browser, interaction, and IP-address information to distinguish ordinary submissions from automated traffic.
Retention and choices
Inquiry and related opportunity details are retained while the business uses them for the project relationship and afterward when reasonably needed for support, disputes, or legal obligations. One-time-code challenges and invitations are time-limited. Account, payment, consent, review-decision, and audit records may remain after an account closes when reasonably needed for security, accounting, dispute resolution, or legal compliance. Detailed attribution fields are removed after 90 days; coarse channel, safe landing path, and inquiry or account relationships may remain for aggregate outcome reporting.
An authenticated customer can open Account settings and permanently delete an eligible Built Long account. Deletion immediately ends account authority, revokes sessions and sign-in challenges, removes private Support and assistant content, and replaces the account name and email with a non-routable tombstone. Active ownership, payer or client-space participation, subscriptions, client-payment access, domain obligations, or ambiguous work must be resolved first. There is no customer recovery grace period.
Depending on where you live, you may request access, correction, export, or deletion of personal information. Submit those requests through the contact form. We may verify your identity and relationship to the relevant business or client space before completing a request.
Security, changes, and contact
We use technical and organizational safeguards designed to protect information, including encrypted transport, restricted credentials, tenant-scoped records, role authorization, and time-limited access tokens. No online service can guarantee absolute security.
We may update this policy as Built Long changes. We will update the effective date and provide additional notice when a material change requires it. Questions can be sent through the contact form.