Privacy Policy

Last updated August 26, 2026

1. Who we are

fedautomate is operated by Reelze LTD (“we,” “us”), registered in the United Kingdom. This policy explains what personal data we collect, why, and what rights you have over it.

2. What we collect

  • Account data: name, email, and password (stored as a salted hash — we never see or store your plain-text password).
  • Client profile data: certifications, bonding capacity, past performance, capacity, and similar business details you enter to configure matching. This is your business data about your own clients, not personal data about individuals, in most cases.
  • Billing data: your subscription plan, status, and Stripe customer/subscription identifiers. Your card number and full payment details go directly to Stripe — we never receive or store them.
  • Usage data:standard server logs (IP address, timestamps, request paths) kept for security and debugging, plus aggregate page-view analytics via Vercel Analytics — a cookieless, privacy-friendly tool that doesn’t set tracking cookies or build a cross-site profile of you.

3. What we don’t collect

We don’t use advertising trackers or cookie-based tracking of any kind, and we don’t sell your data — client profile data or otherwise — to anyone.

4. How we use it

Client profile data is used solely to score and match opportunities for your own account. It’s scoped to your account and isn’t visible to other accounts. Solicitation data itself is public federal contracting data, shared across all accounts by design — that part isn’t personal data. Billing data is used to manage your subscription and process payments. Account data is used for authentication, password resets, email verification, and service-related communication (not marketing unless you opt in).

5. Who we share it with

  • Stripe (payment processing) — receives your billing/payment details directly; we receive back only subscription status and identifiers.
  • Resend (transactional email) — receives your email address to deliver verification, password reset, and digest emails.
  • A third-party AI provider — processes opportunity and client profile data to generate scoring rationales and compliance reviews.
  • Vercel Analytics — receives aggregate, cookieless page-view data (no personal identifiers) to help us understand traffic to the site.

We don’t share data with anyone else, and none of the above are permitted to use your data for their own purposes beyond providing the service we use them for.

6. Data retention

Your data is retained for as long as your account is active. If you cancel your subscription, your account and data remain intact (read access continues per your plan status) unless you request deletion. We delete account and client profile data within 30 days of a verified deletion request, except where we’re required to retain billing records for legal or tax purposes.

7. Your rights

You can access, correct, export, or delete your account data at any time by contacting us through the account you signed up with. If you’re in the UK or EU, you also have the right to lodge a complaint with your local data protection authority (the ICO, in the UK) if you believe we’ve mishandled your data.

8. Security

Passwords are hashed, never stored in plain text. Client data is scoped per account at the database level — every query enforces ownership before returning or modifying a record. Data in transit is encrypted (HTTPS/TLS).

9. Changes to this policy

This policy may be updated from time to time; the date above reflects the latest revision.

10. Contact

Questions about this policy, or to exercise your data rights — reach out through your account.