Privacy Policy

Last updated: 20 January 2026

1. Introduction

Bidflow ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Password (encrypted and never stored in plain text)

Profile Information

You may provide:

  • Company name
  • NAICS codes
  • Set-aside preferences (veteran-owned, small business, etc.)
  • Location preferences
  • Keywords and capability descriptions

Payment Information

Payment information (credit card details) is collected and processed by Stripe, our payment processor. We do not store your full credit card information on our servers. We only store your Stripe customer ID to manage your subscription.

Usage Data

We automatically collect:

  • IP address
  • Browser type and version
  • Pages visited and time spent on pages
  • Opportunities you view, save, or track
  • Search queries and filters applied

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Match contract opportunities to your profile
  • Send you alerts about relevant opportunities
  • Process your subscription payments
  • Send you important service updates and notifications
  • Improve and optimise the Service
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. Data Sources

Bidflow aggregates publicly available government contract opportunity data from SAM.gov and USASpending.gov. This data is provided by the U.S. government and is in the public domain. We do not collect any personal information from these sources.

5. Third-Party Services

Stripe

We use Stripe for payment processing. Stripe's privacy policy is available at stripe.com/privacy

Supabase

We use Supabase for database hosting and authentication. Supabase's privacy policy is available at supabase.com/privacy

6. Cookies and Tracking

We use cookies and similar tracking technologies to:

  • Keep you logged in
  • Remember your preferences
  • Analyse how you use the Service

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Service.

7. Data Sharing and Disclosure

We do not sell or rent your personal information to third parties. We may share your information:

  • With service providers: Stripe (payments), Supabase (hosting), Vercel (hosting)
  • For legal reasons: If required by law, court order, or government request
  • Business transfers: In the event of a merger, acquisition, or sale of assets
  • With your consent: When you explicitly authorise us to share information

8. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including encryption, secure servers, and access controls. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

9. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. If you cancel your subscription, we will retain your data for 90 days before deletion, unless required by law to retain it longer.

10. Your Rights

Under applicable data protection law, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Restriction: Restrict processing of your data
  • Portability: Receive your data in a portable format
  • Objection: Object to processing of your data
  • Withdraw consent: Withdraw consent at any time

To exercise these rights, contact us at privacy@bidflow.app

11. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us.

12. International Data Transfers

Your information is stored and processed in the United States. If you are accessing the Service from outside the United States, your information will be transferred to, stored, and processed in the United States.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on the Service. Your continued use after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: privacy@bidflow.app