Privacy Policy
Effective 2026-05-09
Who we are
BidRanger is operated by Rory Watson, doing business as BidRanger, a sole proprietor based in PO Box 445, Moorcroft, WY 82721. Questions about this policy or your data? Email rory@bidrangerai.com.
What we collect
We collect only what we need to run the service:
- Account data. Email address and password (hashed) when you sign up. Optional display name and company name on your account profile.
- Subscription data. If you subscribe, we store which plan you bought, when, and your Stripe customer ID. We never see or store your full credit-card number — Stripe handles payment data directly.
- Saved searches and digest preferences. The states, trades, and value range you want filtered for the email digest.
- Usage analytics. Anonymous, cookie-free page-view counts via Vercel Analytics. No cross-site tracking, no IP storage, no behavioral profiling.
- Ad-conversion attribution. When you arrive from a Reddit ad, the Reddit Pixel records the page view, account sign-up, and subscription purchase so we can measure which ads actually work. The pixel sees only that a conversion happened and the subscription amount — never your name, email, or payment details.
- Server logs. Standard request logs (timestamp, URL, response code) retained for ~30 days for debugging and abuse prevention.
What we don't collect
- We don't sell your data. Ever.
- We don't fingerprint your browser or device.
- We don't track which specific bids you click.
Subprocessors we share data with
BidRanger relies on a small number of trusted vendors to run. Each receives only the data needed for their function:
- Supabase — our database and authentication provider. Stores your email, hashed password, and account data.
- Stripe — processes payments and stores billing information. Receives your name and email at checkout.
- Resend — sends the daily email digest. Receives the email address you opted in with.
- Vercel — hosts the application and runs analytics.
- Anthropic — our AI provider classifies bid descriptions. Bid text (which is itself public-record data from government agencies) is sent to Anthropic for classification; no user account information is sent.
- Reddit — when you arrive from a Reddit ad, their pixel reports back conversion events (page view, sign-up, subscription amount) so we know which ads convert. No personal information is shared.
Cookies
We use one essential cookie: a Supabase session cookie that keeps you signed in. We don't use any tracking, advertising, or third-party cookies. Vercel Analytics is cookie-free.
Your rights
Regardless of where you live, you can ask us to:
- See the data we have about you. Most of it is visible in your account at /account.
- Correct anything that's wrong.
- Delete your account and all associated data. Email rory@bidrangerai.com from your account email and we'll process within 7 days.
- Stop receiving emails. Click the unsubscribe link in any digest, or visit /unsubscribe.
California (CCPA) and EU/UK (GDPR) residents have additional rights; we honor them by default.
Data retention
Account data is kept while your account is active. After deletion, we remove your data within 7 days, except records we're legally required to retain (Stripe transaction records: 7 years for tax compliance).
Security
All traffic is HTTPS-encrypted. Passwords are hashed with bcrypt (Supabase default). Database connections use TLS. We don't run our own servers — security at the infrastructure level is maintained by Supabase, Stripe, and Vercel under their respective SOC 2 / PCI compliance.
Changes to this policy
When we make material changes, we'll update the effective date at the top and email active subscribers a summary. Continued use after a change means you accept the new policy.
Contact
Rory Watson, doing business as BidRanger
PO Box 445, Moorcroft, WY 82721
rory@bidrangerai.com