Legal

Privacy Policy

Your privacy matters to us. This policy explains how Bidlync collects, uses, and protects your personal information.

Effective: April 10, 2026 Last Updated: April 10, 2026

Overview

Bidlync ("we," "our," or "us") operates the Bidlync platform, including the website at bidlync.manus.space, the Bidlync mobile application, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

Bidlync is a software-as-a-service (SaaS) platform that helps small businesses find and bid on federal government contracts and grants. We aggregate publicly available data from SAM.gov and Grants.gov and provide AI-powered tools to assist with the bidding process. We are not affiliated with, endorsed by, or connected to the U.S. federal government.

Information We Collect

We collect several types of information to provide and improve our Service. The categories of information we collect include:

Account Information

When you create an account, we collect your name and email address through our authentication provider (Manus OAuth). We do not collect or store passwords directly; authentication is handled by our third-party identity provider.

Payment Information

When you subscribe to a paid plan, payment processing is handled entirely by Stripe, Inc. We do not collect, store, or have access to your full credit card number, debit card number, or bank account details. Stripe may share with us limited information such as the last four digits of your card, card type, and billing address for record-keeping and customer support purposes.

Usage Data

We collect information about how you interact with our Service, including: search queries and filter selections, contracts and grants you view, bookmark, or add to your watchlist, pipeline tracking data (opportunity status, notes), comments and discussions you post, AI Bid Assistant inputs and outputs, and pages visited and features used.

Device and Technical Information

We automatically collect certain technical information when you access our Service, including: device type, operating system, and browser type, IP address and approximate geographic location, referring URLs and pages visited, session duration and interaction patterns, and push notification tokens (if you opt in to notifications on mobile).

AI Interaction Data

When you use our AI Bid Assistant or AI-powered features, we process the text you submit (such as Statements of Work or grant descriptions) to generate responses. This content is sent to our AI service provider for processing and is not used to train AI models.

How We Use Your Information

We use the information we collect for the following purposes:

  • Provide and maintain the Service. Including contract and grant search, watchlist management, pipeline tracking, and AI-powered bid assistance.
  • Process transactions. To manage your subscription, process payments through Stripe, and provide access to paid features.
  • Send notifications. Including email alerts for new contract and grant opportunities matching your saved searches, and important account updates.
  • Improve and personalize the Service. To understand how users interact with our platform, identify trends, and enhance features and user experience.
  • Provide customer support. To respond to your inquiries, troubleshoot issues, and assist with your account.
  • Ensure security and prevent fraud. To detect, investigate, and prevent unauthorized access, abuse, or fraudulent activity.
  • Comply with legal obligations. To meet applicable laws, regulations, legal processes, or enforceable governmental requests.
  • Communicate with you. To send service-related announcements, updates about new features, and (with your consent) marketing communications.

How We Share Your Information

We do not sell your personal information to third parties. We may share your information in the following limited circumstances:

Service Providers

We share information with trusted third-party service providers who assist us in operating the Service, processing payments, and delivering features. These providers are contractually obligated to use your information only for the purposes we specify and in accordance with this Privacy Policy.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order, subpoena, or government agency request).

Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

With Your Consent

We may share your information for other purposes with your explicit consent.

Public Content

Comments and discussions you post on contract opportunities are visible to other authenticated users of the Service. Your display name and avatar are shown alongside your comments.

Third-Party Services

Our Service integrates with the following third-party services. Each has its own privacy policy governing its use of your data:

ServicePurposeData Shared
StripePayment processingName, email, payment method details
Manus OAuthAuthenticationName, email, user identifier
SAM.gov APIFederal contract dataSearch queries (no personal data sent)
Grants.gov APIFederal grant dataSearch queries (no personal data sent)
OpenAIAI Bid Assistant, news briefings, blog generationText prompts (SOW content, grant descriptions)

We encourage you to review the privacy policies of these third-party services:

Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using TLS/SSL (HTTPS)
  • Encryption of sensitive data at rest in our databases
  • Secure authentication through OAuth 2.0 with session-based tokens
  • Payment data handled exclusively by PCI DSS-compliant Stripe
  • Regular security reviews and monitoring of our infrastructure
  • Access controls limiting employee access to personal data on a need-to-know basis
  • Secure cloud hosting with automated backups and disaster recovery

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Service. Specifically:

  • Account data: Retained for the duration of your account. Deleted within 30 days of account deletion request.
  • Usage and search data: Retained for up to 24 months for service improvement, then anonymized or deleted.
  • Payment records: Retained as required by tax and financial regulations (typically 7 years for transaction records).
  • AI interaction data: Processed in real-time and not stored beyond the session. Prompts are not retained by our AI provider for training purposes.
  • Comments and discussions: Retained for the duration of your account. You may delete your own comments at any time.
  • Email alert preferences: Retained for the duration of your account or until you unsubscribe.

After the applicable retention period, we will securely delete or anonymize your information. We may retain certain information as required by law or for legitimate business purposes, such as resolving disputes or enforcing our agreements.

Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal information:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Request correction of inaccurate or incomplete personal information.
  • Deletion. Request deletion of your personal information, subject to certain exceptions.
  • Data Portability. Request a machine-readable copy of your data.
  • Opt-Out of Communications. Unsubscribe from marketing emails at any time using the link in the email or by managing your notification preferences in your Dashboard.
  • Withdraw Consent. Where we rely on your consent to process data, you may withdraw consent at any time.
  • Restrict Processing. Request that we limit the processing of your personal information in certain circumstances.

To exercise any of these rights, please contact us at the email address provided in the Contact Us section below. We will respond to your request within 30 days (or sooner if required by applicable law). We may ask you to verify your identity before processing your request.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:

Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, the business purpose for collecting it, and the categories of third parties with whom we share it.

Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions provided by law.

Right to Opt-Out of Sale

We do not sell your personal information. If this practice changes in the future, we will update this policy and provide you with the right to opt out.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices, or provide a different level of quality for exercising your rights.

Right to Correct

You have the right to request correction of inaccurate personal information that we maintain about you.

To exercise your California privacy rights, contact us at [email protected]. You may also designate an authorized agent to make a request on your behalf.

European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides you with additional protections. We process your personal data based on the following legal bases:

  • Contract Performance. Processing necessary to provide the Service you have requested (e.g., account management, contract search, subscription services).
  • Legitimate Interests. Processing necessary for our legitimate business interests, such as improving the Service, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
  • Consent. Processing based on your explicit consent, such as sending marketing communications or processing AI Bid Assistant inputs. You may withdraw consent at any time.
  • Legal Obligation. Processing necessary to comply with applicable laws and regulations.

In addition to the rights listed in the "Your Rights & Choices" section, GDPR provides you with the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.

Children's Privacy

Our Service is not directed to individuals under the age of 13 (or under the age of 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information promptly.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at the email address below so we can take appropriate action.

Cookies & Tracking Technologies

We use cookies and similar tracking technologies to operate and improve our Service. The types of cookies we use include:

Essential Cookies

Required for the Service to function properly. These include session cookies for authentication and security tokens. You cannot opt out of essential cookies as they are necessary for the Service to work.

Functional Cookies

Used to remember your preferences, such as theme settings, PWA install prompt dismissal, and search filter defaults. These enhance your experience but are not strictly necessary.

Analytics Cookies

Help us understand how users interact with the Service by collecting anonymized usage statistics. This data helps us improve features and user experience.

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. However, disabling essential cookies may prevent you from using certain features of the Service.

International Data Transfers

Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy, including the use of Standard Contractual Clauses approved by the European Commission where applicable.

By using the Service, you consent to the transfer of your information to the United States and other countries where we and our service providers operate.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, providing additional notice (such as an in-app notification or email).

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Subject Line: Privacy Inquiry — Bidlync

We aim to respond to all privacy-related inquiries within 30 days. For California residents exercising CCPA/CPRA rights, we will respond within 45 days as required by law. For GDPR-related requests from EEA residents, we will respond within one month.