Privacy policy
Draft of September 9, 2026. Not yet reviewed by counsel.
This describes what the running service actually stores, written from its database schema rather than from a template. Where a decision is still the operator’s to make, it says so instead of guessing.
1. Who is responsible
The controller of this data is [OPERATOR: fill] legal entity name and registration number, at [OPERATOR: fill] postal address (POSTAL_ADDRESS). Contact: support@findingbase.com.
[OPERATOR: fill] If the GDPR or the UK GDPR applies, name the EU or UK representative and the data protection officer, or record why neither is required.
2. What we collect from customers
- Your account
- Your email address, an optional name, and the time you last signed in. There is no password, because we never ask for one.
- Sign-in and session security
- The IP address that asked for a sign-in link, so that we can rate-limit abuse, and the browser user-agent string attached to a session. Sign-in links are stored as a hash, never in the clear, and are single use.
- What you asked to watch
- Your NAICS codes, states, minimum contract amount, the address alerts go to, how often you want them, and the look-ahead window. This is the whole product, so it is the whole of what we need.
- Billing
- A Stripe customer id, the subscription status, the plan and how many extra NAICS codes it carries, and when the current period ends. Card numbers never reach our servers: Stripe takes the payment and we hold only the reference.
- Alerts you were sent
- Which expiring contracts each digest contained and when it went out, so that the next digest does not repeat itself, plus a random token that makes the unsubscribe link in that email work without a login.
3. What we collect about businesses we contact
Findingbase writes to federal vendors who are not customers yet. Those details come from the public SAM.gov entity registration: business name, unique entity id, NAICS codes, state, and the point of contact the business itself published there. We also keep what happened next — sent, replied, bounced, unsubscribed — and, if you reply, the text of your reply and how it was classified. The AI disclosure explains that classification, including when a reply is sent to a third-party model provider.
Every such message carries a physical mailing address, a one-click unsubscribe link and a statement that it was prepared with software assistance, as US commercial email law requires. Unsubscribing adds the address to a suppression list, which we keep precisely so that we can never write to it again.
4. What we do not collect
- No card or bank details. Stripe holds them; we hold a customer id.
- No third-party analytics, advertising or social media scripts. This site loads none.
- No tracking pixel in alert emails. The database has columns for open and click tracking and this build does not write to them.
- No sale of personal data to anybody, for any purpose.
- No special categories of data, and nothing about your bids or pricing.
5. Cookies
One cookie, named fb_session. It holds a session reference, is marked HttpOnly and SameSite, and exists so that you stay signed in. There are no analytics or advertising cookies, so there is no consent banner to click through.
6. Why we are allowed to hold it
For customers, to perform the contract you signed up for and to comply with tax and accounting law. For outreach to businesses, our legitimate interest in offering a relevant service to a registered federal vendor, balanced by an unsubscribe that works in one click. [OPERATOR: fill] Counsel to confirm the lawful bases, and whether any US state privacy law (California, Colorado, Virginia, Connecticut) applies and what it adds.
7. Who else sees it
- Stripe, for payments and the billing portal.
- Our email provider, for transactional and alert mail.
- Our hosting provider, which runs the servers this application sits on.
- The model provider named in the AI disclosure, and only for the text of a reply to our outreach email.
[OPERATOR: fill] Name each processor, the country it operates in, and the transfer mechanism where data leaves its home jurisdiction. We do not share your data with anyone else, and we do not sell it.
8. Where it is kept, and for how long
- Sign-in links expire within minutes and can be used once.
- Sessions expire 30 days after they are created, and sooner if you sign out.
- Account, watch profile and alert history are kept while the account exists.
- Deleting the account deletes the organization row, and the database cascades that to the watch profile, the subscription record, the alert history and the sessions immediately.
- Stripe keeps its own record of payments for as long as its own legal obligations require; that copy is outside our control.
- Suppression entries are kept indefinitely, on purpose: forgetting that you unsubscribed would mean writing to you again.
- [OPERATOR: fill] State the backup retention window, where backups are stored, and how long a deleted record can survive in them.
- [OPERATOR: fill] State the hosting location, since it decides which law applies.
9. How to delete your account
Sign in, open Watch profile, and use the delete panel at the bottom of that page: you type DELETE to confirm, and the organization and everything attached to it are removed. There is no undo and no soft delete, and we do not keep a shadow copy.
If you would rather we did it, write to support@findingbase.com from the address on the account.
10. Your other choices
- Change what you watch, or the address alerts go to, at any time from your profile.
- Unsubscribe from any email in one click, with no login.
- Ask for a copy of what we hold about you, or a correction, at the address above. We will answer within [OPERATOR: fill] state the response time your jurisdiction requires.
11. Children
This is a service for businesses that hold or bid on federal contracts. It is not directed at children and we do not knowingly collect anything from them.
12. Changes
If this policy changes materially we will email the address on the account before the change takes effect. The date at the top of this page is the date it was last edited.