Privacy Policy
This policy covers the Bidwire website and the Bidwire iPhone application. It says what we collect, why, where it lives, and what we will never do with it. We have tried to write it so you can actually read it.
The short version
- We do not sell your personal information, and never have. We do not share it for cross-context behavioural advertising.
- There is no advertising software of any kind in the app or on this site.
- We never see or store your card number.
- We never store your raw IP address. Where we need one for security or for a submission record, we keep only an irreversible hash of it.
- You can ask us to delete your account and its data, and we will.
What we collect
Because you gave it to us
- Your email address, and your name if you enter one. Your email address is also your credential: sign-in is a one-time link, and there is no password.
- Your business profile — your company website address, the codes, keywords, locations and certifications you want matched on, and the text we read back from your website to propose them. We keep a copy of that fetched website text so the profile can be re-derived without fetching your site again.
- What you save, dismiss, and prepare — the opportunities you keep, the ones you rule out, and any response drafted for you.
- Your record of a send. When you use the app to prepare a response and press send yourself, we record that you did: the time, the statement you agreed to, the recipient, a hash of your IP address, and your device or browser identifier string. That record exists to protect you — it is the evidence of who authorised the response, and it is kept for the life of your account.
Because the service has to work
- Account and plan data — the organisation you belong to, your role in it, your plan, subscription status and billing period, and counters for the usage limits your plan sets.
- Device tokens, if you turn on alerts, so a notification can reach your phone.
- Email delivery events — whether a message we sent you was delivered, bounced, or was marked as spam, so we stop sending to an address that does not work.
- Security and abuse records — a security log of significant account actions (with a hashed IP and your browser or device identifier string), short-lived rate-limit counters, and the one-time sign-in tokens themselves, stored hashed and deleted once used or expired.
- Server logs. Our hosting provider records ordinary web-request logs, which include IP addresses, for a limited period. We do not control that retention, and we do not copy those logs into our own database.
Analytics and cookies
This website uses Vercel Web Analytics, which counts page views without cookies and without building a profile of you. It does not follow you to other sites.
The only cookie we set is the sign-in cookie that keeps you signed in after you use your one-time link. There are no advertising, marketing, or tracking cookies on this site.
What the app collects on your phone
The application collects your account identifiers, your profile and saved items, and a push token if you allow notifications. It does not access your contacts, photos, calendar, microphone, camera, or precise location.
Why we use it
- To run your account and show you opportunities that match the profile you set.
- To send the alerts, digests and reminders you ask for, and service messages.
- To take payment and manage your subscription.
- To keep the service secure, enforce plan limits, and prevent abuse.
- To keep the record of any response you authorised and sent yourself.
- To meet our legal obligations.
If you are in the UK or the EEA: we rely on performance of our contract with you for running the service and taking payment, on our legitimate interests in security, abuse prevention and improving the service, on your consent for push notifications and any marketing email, and on legal obligation where one applies. You may object to processing based on legitimate interests.
Where it lives, and who else touches it
Your data is stored in a managed PostgreSQL database hosted in the United States. We share the minimum necessary with service providers who act on our instructions and may not use it for their own purposes:
- Hosting and analytics — Vercel, which serves this site and the interface the app talks to, and records ordinary request logs.
- Database — Neon, which hosts the PostgreSQL database in the United States.
- Payments — Stripe. Checkout and the billing portal are hosted by Stripe, which is what keeps your card details out of our systems entirely. We receive a customer identifier, subscription status, and the billing email.
- Email — Brevo, which delivers your sign-in links, digests and alerts and reports back whether they arrived.
- Push notifications — Apple, which delivers notifications to your device.
- Text analysis — a provider under contract that reads the text of public notices and of your business website to produce the summaries and match reasons you see. It is contractually barred from using that content for any purpose of its own.
If Delvir is ever sold or merged, your data may transfer with the business; this policy continues to apply until you are told otherwise. We will also disclose information if the law compels us to, or to protect the rights and safety of our users.
How long we keep it
- Account, profile and saved items: for as long as your account is open.
- Records of a response you authorised and sent: for the life of the account.
- Sign-in tokens: deleted once used, or when they expire (15 minutes).
- Rate-limit counters: hours.
- After you ask us to delete your account we remove your personal data within 30 days, except records we must keep for tax, accounting or legal-defence reasons — and the opportunity data itself, which is public and is not personal to you.
Your rights
Wherever you live, you may ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to stop sending you email, or ask us to restrict or object to certain processing. Email team@bidwire.app from the address on your account and we will act within 30 days. We will not treat you differently for exercising a right.
California (CCPA/CPRA): we do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. You have the rights to know, delete, correct, and to non-discrimination, all exercised at the address above. We collect the categories described in “What we collect” — identifiers, commercial information, and internet activity — for the purposes described in “Why we use it”.
UK/EEA: you may lodge a complaint with your supervisory authority. Transfers out of the UK/EEA to our U.S. providers rely on the standard contractual clauses those providers offer.
Children
Bidwire is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 13, and the service is not intended for anyone under 18. If you believe a child has given us personal information, write to us and we will delete it.
Security
Traffic is encrypted in transit. Passwords do not exist here, so they cannot leak. One-time sign-in tokens are stored hashed. IP addresses are salted and hashed before storage. Access to production data is limited to the people who operate the service. No system is perfectly secure, and we do not claim otherwise.
Changes
If we change this policy we update the effective date above, and for a material change we tell account holders by email or in the service before it takes effect.
Contact
team@bidwire.app, or team@delvir.co — Delvir Limited Liability Co., 30 N Gould St, Ste R, Sheridan, WY 82801, United States. See also our Terms of Service.