1. Introduction
ClearBids LLC ("ClearBids," "we," "us," or "our") operates the ClearBids platform at clearbids.ai. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service. By using ClearBids, you consent to the practices described in this policy.
2. Information We Collect
Information you provide:
- Account information: email address, password (stored as a secure hash — we never see or store your plaintext password), company name, and role.
- Bid data: project names, addresses, trade names, subcontractor names, bid amounts, inclusions, exclusions, and notes you enter into the Service.
- Payment information: processed securely by Stripe. We do not store your credit card number, CVC, or full card details on our servers. We receive only a tokenized reference and basic card metadata (last 4 digits, expiration) from Stripe.
Information collected automatically:
- Usage data: pages visited, features used, and interaction patterns (collected via Vercel Analytics and Google Analytics).
- Error data: error logs and session replays for debugging (collected via Sentry).
- Device information: browser type, operating system, and device type.
3. How We Use Your Information
- Provide the Service: process your bids, run leveling analysis, generate reports, and manage your projects.
- Communicate with you: send bid notifications, welcome emails, trial reminders, and service-related announcements.
- Process payments: manage your subscription, billing, and invoicing through Stripe.
- Improve the Service: analyze usage patterns to fix bugs, improve performance, and develop new features.
- Ensure security: detect and prevent fraud, abuse, and unauthorized access.
4. Third-Party Service Providers
We share your information with the following third-party processors, solely to operate the Service:
| Provider | Purpose | Data Shared |
|---|
| Supabase | Authentication & database | Account info, bid data |
| Stripe | Payment processing | Email, payment details |
| Resend | Email delivery | Email address, notification content |
| Vercel | Hosting & analytics | Usage data, IP address |
| Google Analytics | Website analytics | Usage data, device info, cookies |
| Sentry | Error tracking | Error logs, session replays |
| Upstash | Rate limiting | IP address (temporary) |
We do not sell, rent, or trade your personal information to any third party.
5. Cookies
We use the following cookies:
- Authentication cookies: set by Supabase to maintain your login session. These are essential for the Service to function.
- Analytics cookies: set by Google Analytics to understand how visitors use our site. These help us improve the Service.
You can disable cookies in your browser settings, but this may prevent you from using certain features of the Service (such as staying logged in).
6. Data Retention
- We retain your account and bid data for as long as your account is active.
- When you delete your account (via Settings), all your data is permanently deleted from our database, including projects, trades, bids, and profile information.
- Backups containing your data may persist for up to 30 days after deletion before being automatically purged.
- Aggregated, anonymized usage data (which cannot identify you) may be retained indefinitely for analytics purposes.
7. Your Rights Under California Law (CCPA)
As a California-based company, we comply with the California Consumer Privacy Act (CCPA). California residents have the following rights:
- Right to know: You can request a summary of the personal information we have collected about you and how it has been used.
- Right to delete: You can request deletion of your personal information. You can also delete your account directly from your Settings page, which removes all your data.
- Right to opt-out of sale: We do not sell your personal information to third parties. There is nothing to opt out of.
- Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights.
To exercise your rights, contact us at support@clearbids.ai. We will respond within 45 days.
8. Data Security
We take reasonable measures to protect your personal information, including:
- All data transmitted between your browser and our servers is encrypted via HTTPS/TLS.
- Passwords are stored as secure hashes (never in plaintext).
- Database access is protected by Row Level Security (RLS) policies — users can only access their own data.
- Payment information is handled entirely by Stripe, which is PCI DSS Level 1 certified.
- API endpoints are rate-limited to prevent abuse.
While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
ClearBids is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on the Service. Your continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
11. Contact
If you have any questions about this Privacy Policy or our data practices, please contact us at support@clearbids.ai.
ClearBids LLC
California, United States