Privacy Policy
Draft last updated: August 25, 2026
1. What we collect
Depending on how you use TenderTriage:
- The company description you type and the structured profile our AI extracts from it
- Which tenders were shown to you and your thumbs up/down feedback on them, if given
- RFP analysis metadata — file name, file size, and the resulting recommendation/score. The PDF content itself is not stored — it's processed in memory for that one analysis and sent to our AI provider, but never written to disk or saved by TenderTriage
- An anonymous per-browser identifier (stored in your browser's local storage) used to group the events above — not tied to your identity unless you also sign in
- If you create an account: your name, email address, and profile image (from whichever sign-in method you use), plus your saved company profile
2. Why we collect it
To run the core product (matching your company against open tenders), to save your profile between visits if you're signed in, and to understand whether the matching is actually useful (the feedback and telemetry above) so we can improve it. We do not sell personal information, and we do not use third-party advertising trackers.
3. Who we share it with
Data is processed by these third parties, each for a specific purpose:
- Anthropic (the AI provider behind Claude) — receives your company description, structured profile, tender details, and (if you upload one) RFP PDF content, to generate the analysis. Under Anthropic's commercial API terms, this data is not used to train their models by default.
- Resend — receives your email address to send magic-link sign-in emails, if you use that sign-in method.
- Google / Microsoft — if you sign in with one of these, we receive your basic profile (name, email, photo) from them via standard OAuth; we don't send them any other TenderTriage data.
- Vercel and Neon — our hosting provider and database provider, respectively. They process and store data on our behalf as infrastructure, not as independent users of it.
- CanadaBuys — we fetch public tender data from them; we do not send them any of your data.
Some of this infrastructure is hosted outside Canada (notably, US-based), meaning your data may be processed or stored there. We don't yet have a formal cross-border-transfer policy written up — flagged here honestly as something to finalize during legal review, not glossed over.
4. Cookies and local storage
If you sign in, we set a session cookie to keep you signed in — that's required for the account to function. We also use your browser's local storage to hold the anonymous session identifier described above. We don't currently use marketing or advertising cookies.
5. How long we keep it
We don't yet have a formal data-retention schedule — this is on the list for legal review rather than something we're asserting here without having actually implemented it. In the meantime, a saved company profile persists until you delete your account or request its removal; other usage data is retained to understand product performance over time.
6. Your rights
You can ask us what personal information we hold about you, correct it, or have it deleted, by emailing support@tendertriage.com. If you have an account, signing out and no longer using TenderTriage stops any new data collection tied to that account immediately.
7. Children
TenderTriage is a business tool and isn't directed at children. We don't knowingly collect personal information from anyone under the age of majority in their jurisdiction.
8. Changes
This policy may be updated as the product changes. Material changes will be reflected by an updated date on this page.
9. Contact
Questions about this policy, or a privacy request: support@tendertriage.com.