187,204bids

Privacy Policy

Effective 2026-09-01

Who we are

BidRanger is operated by Rory Watson, doing business as BidRanger, a sole proprietor based in PO Box 445, Moorcroft, WY 82721. Questions about this policy or your data? Email rory@bidrangerai.com.

What we collect

We collect only what we need to run the service:

  • Account data. Email address and password (hashed) when you sign up. Optional display name and company name on your account profile.
  • Subscription data. If you subscribe, we store which plan you bought, when, which states it covers, and your Paddle customer and subscription IDs. We never see or store your card number — Paddle handles payment data directly.
  • Saved searches and digest preferences. The search name, states, categories, and keywords you want filtered for the email digest, and whether each search is enabled.
  • Digest delivery records. When we email you a digest we record which bids it contained so we never send you the same bid twice. Resend keeps standard delivery logs (sent, delivered, bounced).
  • Usage analytics. Cookie-free page-view analytics from two tools: Umami (open-source, hosted by us) and Vercel Analytics. Both record the page viewed, the referring site, the browser and device type, and an approximate country. Neither sets a cookie or uses a cross-site identifier. Umami identifies a visit by hashing your IP address and browser user-agent together with a salt that changes every day, so the same visitor cannot be recognized from one day to the next. We don't keep IP addresses in analytics; our hosting and authentication providers keep short-lived request logs (next item).
  • Server and authentication logs. Vercel (hosting) and Supabase (authentication) keep standard request logs — timestamp, URL, response code, and IP address — for a short period for debugging, security, and abuse prevention.
  • Support email. Whatever you send to rory@bidrangerai.com, so we can answer it.

What we don't do

  • We don't sell your data. Ever.
  • We don't fingerprint your browser or device.
  • We don't run advertising or ad-conversion trackers. (A Reddit conversion pixel was used for a one-off ad test in 2026 and was removed on 2026-08-31.)
  • We don't build behavioral profiles. Page views are recorded without cookies or cross-site identifiers.

Services that handle your data

BidRanger runs on a small number of providers. Each receives only what its job needs:

  • Supabase — database and authentication. Stores your email, hashed password, account data, subscription record, and saved searches. Its authentication logs include your IP address for a short period.
  • Vercel — hosts the application and runs Vercel Analytics (cookie-free page views). Keeps request logs for a short period.
  • Umami — open-source, cookie-free analytics that we host ourselves on Vercel. Analytics data stays in our own instance; it is not shared with Umami the company.
  • Paddle (Paddle.com Market Ltd.) — our Merchant of Record. Runs the checkout and processes payments. Receives your name, email, billing address, and payment details at checkout and issues receipts and sales-tax invoices in its own name.
  • Resend — sends the daily digest from digest@bidrangerai.com and our operational emails. Receives the email address you signed up with and the content of each digest, and keeps delivery logs.
  • Anthropic — our AI provider classifies bid descriptions by trade, for bids in the states described in the FAQ. Only bid text — which is itself public-record data published by government agencies — is sent. No account information is ever included.
  • GitHub — our scheduled data jobs (scraping and classification) run on GitHub-hosted servers and do not touch user data. A manual backup copy of the digest job also runs there; when it is used, it reads subscriber email addresses in order to send the digest.
  • SaaSHub — the "Approved on SaaSHub" badge in our footer is an image loaded from SaaSHub's server on every page. As with any third-party image, their server sees your IP address, browser user-agent, and the page you were on. No account data is sent.

Cookies

We use one essential cookie: the Supabase session cookie that keeps you signed in. Neither Umami nor Vercel Analytics sets cookies. When you open the checkout, Paddle's checkout runs in your browser and may set its own cookies under Paddle's privacy policy. We don't use tracking, advertising, or other third-party cookies.

Your rights

Regardless of where you live, you can ask us to:

  • See the data we have about you. Most of it is visible in your account at /account; email us for a complete copy (profile, saved searches, subscription) as a file.
  • Correct anything that's wrong.
  • Delete your account and all associated data. Email rory@bidrangerai.com from your account email and we'll process it within 7 days.
  • Stop receiving emails. Click the unsubscribe link in any digest, or visit /unsubscribe.

California (CCPA) and EU/UK (GDPR) residents have additional rights; we honor them by default.

How long we keep things

DataRetained
Account (email, hashed password, optional display and company name)While your account is active. Removed within 7 days of a deletion request.
Subscription record (plan, status, entitled states, Paddle customer and subscription IDs)While your account is active. Paddle keeps its own transaction records for 7 years for tax compliance.
Billing webhook log (Paddle event IDs and event payloads)Kept as a billing audit trail for as long as needed to resolve disputes. Contains Paddle identifiers, never your card details.
Saved searches and digest preferencesUntil you delete them or your account.
Digest send log (which bids were emailed to you, and when)Until the referenced bid is pruned. Bids are deleted 30 days after they close, and their send-log rows go with them.
Analytics (Umami, Vercel Analytics)Aggregate page-view data is kept for reporting. It contains no cookies, no persistent identifier, and no IP address; Umami's visitor hash uses a salt that changes daily, so a visitor cannot be linked across days.
Request logs (Vercel hosting, Supabase authentication)Kept by those providers for a short period for debugging and abuse prevention, then expire. These are the only places an IP address is recorded.
Support emailIn our mailbox until the request is resolved and for a reasonable period after.
Bid data (public government records — not personal data about you)Deleted 30 days after the bid closes.

Security

All traffic is HTTPS-encrypted. Passwords are hashed with bcrypt (Supabase default). Database connections use TLS. We don't run our own servers — security at the infrastructure level is maintained by Supabase, Paddle, and Vercel under their respective SOC 2 / PCI compliance.

Changes to this policy

When we make material changes, we'll update the effective date at the top, add an entry below, and email active subscribers a summary. Continued use after a change means you accept the new policy.

  • 2026-09-01Rewritten to match what actually runs: named every service that handles data (added Umami analytics, GitHub, and the SaaSHub badge); removed the Reddit ad-pixel disclosure (the pixel was deleted on 2026-08-31); clarified what analytics record and how IP addresses are handled; added a retention table, an export right, and this change log.
  • 2026-06-26Payment processing moved from Stripe to Paddle (Paddle.com Market Ltd.) as Merchant of Record. The effective date at the top was not updated at the time; corrected on 2026-09-01.
  • 2026-05-09First published.

Contact

Rory Watson, doing business as BidRanger
PO Box 445, Moorcroft, WY 82721
rory@bidrangerai.com