Privacy policy
What personal data RFP.co collects, why, who it is shared with, how long it is kept, where it is processed and what rights you have over it.
Last updated August 8, 2026
Governed by Arkansas law
This policy explains what personal data RFP.co handles, why, and what you can ask for. It covers our website, our applications and the people who use them. It is written to be checkable: where a period or a recipient is named, it is one the software actually enforces or calls.
1. The distinction this policy turns on
There are two different relationships here and the rights you have depend on which one you are in.
We are the controller of the data we hold to run our own business: your account, your billing, your support conversations, and the traffic to our website. This policy governs that data and you can exercise your rights against us directly.
We are a processor of everything a customer puts into their workspace — proposal content, uploaded documents, comments, approvals, the personal data inside a résumé or a past-performance reference. The customer decides what goes in and why; we act on their instructions. If you are an employee of a customer, or a person named in a document they uploaded, your rights over that data run against them, and we will support them in answering you. The Data Processing Addendum sets out those terms.
2. What we collect, and why
Account and profile
| Data | Why | Basis |
|---|---|---|
| Name, work email, password hash | To create an account and authenticate you | Performance of a contract |
| Organization name, role, workspace membership | To place you in the right workspace with the right permissions | Performance of a contract |
| Google account identifier, where you sign in with Google | To authenticate you without a second password | Performance of a contract |
| Notification preferences | To send only what you asked for | Performance of a contract |
Passwords are stored as an Argon2id hash and never in a form we can read. Session tokens are stored as a keyed hash, so a copy of our database is not a set of live sessions.
Billing
Billing contact name and email, billing address, tax identifiers where collected, and the history of subscriptions, invoices and payments. Card details go directly to Stripe and are never received or stored by us. Basis: performance of a contract, and legal obligation for the records tax law requires us to keep.
Usage and security
Request logs containing IP address, user agent, path and timestamp; audit records of security-relevant actions such as sign-in, permission change and administrative action; and counts of feature usage measured against plan allowances. Basis: our legitimate interest in operating a secure service and in billing accurately, balanced against the limited nature of what is recorded.
Support and marketing
What you send us when you ask for help, and the address you send it from. If you subscribe to product updates we keep your address until you unsubscribe; every message carries a working unsubscribe link. Basis: legitimate interest for support, consent for marketing.
Customer workspace content — where we are the processor
Solicitation documents and their attachments, company profiles, past performance and case studies, team member profiles and résumés, proposal drafts, comments, approvals and pricing. Some of this contains personal data about employees, referees and buyer contacts. We process it on the customer’s instructions to provide the platform, and for no purpose of our own.
Public source content
The platform collects published solicitations and award records. These sometimes name a contracting officer or a point of contact, because the issuer published that name in a procurement notice. We process it in our legitimate interest in operating a procurement information service, and a person named can ask us to remove them — see §8.
3. What we do not do
- We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under U.S. state privacy laws.
- We do not train models on customer content. Text sent to a model provider is sent to answer a request the customer made, under terms prohibiting training on it.
- We run no advertising or analytics trackers. There is no tag manager, no advertising pixel and no third-party analytics on either site — see the cookie policy, which lists every cookie we set.
- We do not make automated decisions with legal effect about individuals. Scores and recommendations the platform produces are about opportunities and are advisory to the customer’s own decision.
4. Who we share it with
Subprocessors. The vendors that host, deliver, process payment for and add capability to the platform. Each is named on the subprocessor page with exactly what it receives, and each is bound by a written agreement to process only on our instructions.
Within a customer’s workspace. Content is visible to that workspace’s members according to the roles its administrators set, and to external reviewers they invite through a revocable link. We do not decide who those people are.
Professional advisers — lawyers, accountants, auditors — under a duty of confidence.
Legal and safety. Where we are legally compelled, or where disclosure is necessary to protect rights, safety or the integrity of the platform. We will tell the affected customer unless we are prohibited from doing so.
A corporate transaction. If we are involved in a merger, acquisition or sale of assets, data may transfer. The acquirer remains bound by this policy or gives notice before anything material changes.
5. Where it is processed
The platform is hosted in the European Union. Some subprocessors process data in the United States, and our own operations are in the United States. Personal data therefore crosses borders in both directions.
For transfers out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with the supplementary measures described in the Data Processing Addendum. A copy of the clauses is available on request at privacy@rfp.co.
6. How long we keep it
| Category | Kept for |
|---|---|
| Account records | The life of the account, then 90 days |
| Customer workspace content | The life of the account, then 90 days for export, then deleted |
| Sessions | 30 days maximum, and 14 days of inactivity ends one sooner |
| Password reset links | 1 hour |
| Invitations | 14 days |
| Billing and tax records | 7 years, as tax law requires |
| Security audit records | Retained on their own schedule, longer than product activity |
| Request logs | Rotated in the ordinary course; not retained for analytics |
| Backups | Expire on their own cycle after deletion from the live system |
A deletion request is honoured in the live system promptly; backups are not surgically edited and the data leaves them as they expire. We say this plainly rather than claiming instant erasure everywhere, because the second is not true of any system that keeps backups.
7. Security
Technical and organisational measures are set out in full in the Data Processing Addendum. In summary: encryption in transit and at rest; Argon2id password hashing; keyed hashes for session and share tokens; tenant isolation enforced at the query layer rather than by route-level checks; least-privilege access; append-only audit records for security-relevant events; virus scanning of uploads before they are readable; and separate environments for development and production.
No system is perfectly secure. If you believe you have found a vulnerability, write to security@rfp.co. We will not pursue claims against researchers acting in good faith within the boundaries in our Acceptable Use Policy.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to our processing, receive it in a portable form, and withdraw consent where consent is the basis. You may also complain to your supervisory authority.
Under U.S. state privacy laws — including in California, Colorado, Connecticut, Virginia, Utah and Texas — you may have rights to know, delete, correct and to opt out of sale, sharing or targeted advertising. We do not sell or share personal data or serve targeted advertising, so those opt-outs have nothing to act on. We will not discriminate against you for exercising a right.
Ask at privacy@rfp.co. We will verify your identity in proportion to the sensitivity of the request and answer within 30 days, extending once where the law allows and telling you if we do. You may use an authorised agent.
If your request is about a customer’s workspace, we will tell you so and, where we can identify them, refer it to that customer as controller. We will not delete a customer’s content on the instruction of somebody who is not that customer, because doing so would let anybody destroy a company’s proposal by asking us to.
9. Children
The platform is a business tool and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, write to privacy@rfp.co and we will delete it.
10. Changes
We will post any change here with a new date at the top. Where a change materially affects how we use personal data we will give notice by email to account administrators before it takes effect.
11. Contact
Nead, LLC
1425 Broadway, Suite 22689, Seattle, WA 98112, United States
privacy@rfp.co
This policy is governed by the laws of the State of Arkansas, without regard to its conflict of law provisions, without limiting rights you have under the privacy law of your own jurisdiction.
See what you are not bidding on.
Connect a source, describe what your company does, and look at the opportunities that come back before deciding whether any of this is worth your time.