BBidPacket
← Back to home

Privacy Policy

BidPacket — a service of ThePMToolkit LLC Effective date: July 30, 2026

Plain language, like everything else we write. This policy explains what we collect at bidpacket.co, why, and what we do with it.

What we collect

Documents you upload. RFPs, plan sets, scopes — whatever you submit for a preview or Packet. These often contain project details like addresses and client names; treat that as expected, since it's what the Service reads.

Order information. Your email address (collected by Stripe at checkout, or by you if you create an account), what you bought, when, and the order's processing history.

Payment details. Handled entirely by Stripe. We receive confirmation that you paid and the last details Stripe shares with merchants (like your email). We never see or store your card number.

Usage analytics. We use PostHog to understand how the Service is used — pages viewed, uploads started, purchases completed. This is product analytics, not advertising tracking. We don't run ads and we don't sell data.

Analytics cookies. On the public site (bidpacket.co) we also use Google Analytics to see which pages are read and which are ignored. That sets a cookie, so it is the one piece of tracking you are asked about, and you can say no — see Cookies and your choice below.

What we do with it

One thing, mostly: run the Service. Your documents are processed to generate your preview and Packets — including processing by Anthropic's Claude API, the AI service that performs the document analysis. Your order information delivers your Packets, powers your account if you create one, and lets us help you at [email protected]. Analytics helps us fix what's broken and improve what isn't.

Things we do not do:

  • We do not sell your data. To anyone.
  • We do not use your documents or generated Packets to train AI models, and our service providers are not permitted to either.
  • We do not share your documents with other customers or use one customer's documents to inform another's results.
  • We do not run advertising or share your data with ad networks.

Cookies and your choice

The public site sets one non-essential cookie: Google Analytics. It tells us which pages get read, so we can fix or drop the ones that don't. We don't use advertising cookies, we don't run ad networks, and we never sell or share what it collects.

  • Visitors in the EU, UK, Switzerland, Iceland, Liechtenstein and Norway are asked first. Nothing is stored until they choose, and the analytics tag sends no cookie until they accept.
  • Everyone else gets analytics by default, with a card in the corner to turn it off — one click, no account, no email required.
  • Either answer works. The site is fully usable with analytics declined. Nothing about your documents touches it.
  • Changing your mind is as easy as the first choice: the Cookie settings link in the footer of every page reopens the card. Your browser's Do Not Track setting is honoured as a decline.
  • The product itself (upload, preview, checkout, your packet) doesn't depend on any of it.

[CONFIRM: if you add any other tag, pixel, chat widget or A/B tool, name it here in the same breath — an undisclosed one is the finding that costs you credibility in a security review.]

Who touches your data

The Service runs on infrastructure providers who process data on our behalf, under their own security and privacy commitments: Supabase (database and file storage), Railway (hosting), Stripe (payments), Anthropic (document analysis via the Claude API), PostHog (product analytics, run server-side), and Google Analytics (site analytics on the public pages, only after a visitor accepts where consent is required). We share only what each needs to do its job.

We'll disclose information if the law genuinely requires it (a valid subpoena or court order), and we'd tell you unless legally barred from doing so.

How long we keep it

  • Uploaded documents: kept for 30 days after your order, then deleted from storage. (You always have your originals.)
  • Generated Packets: kept indefinitely so you can re-download what you bought — unless you delete them yourself or close your account, which removes them for good.
  • Order records: kept as long as we need them for bookkeeping, taxes, and support history. These stay even if you close your account, with your name and email detached from them.
  • Account data: your sign-in and company details are kept until you close your account, and are deleted when you do.

Your choices

  • No account needed. You can use BidPacket as a guest — upload, pay, download, done.
  • Delete a project's files. Any project you're looking at can be deleted, which removes the plans you uploaded and the documents we generated for it. This can't be undone — if you bought a Packet, download it first.
  • Close your account. If you have an account, Settings → Close Account deletes your sign-in and company details and permanently removes every file from every project. Your purchase records stay for bookkeeping, detached from your name and email. This can't be undone either.
  • Or just ask. Prefer we handle it? Email [email protected] and we'll do it and confirm when it's done.
  • Cookie settings. The footer link on any page reopens the cookie card so you can switch analytics off (or back on) at any time.
  • Access. Ask us what we have associated with your email, and we'll tell you.

Security

Files and data are stored with access controls, private storage (downloads use expiring signed links, never public URLs), and encryption in transit. No internet service can promise perfect security, but we've built this one so that private documents stay private by default.

Children

BidPacket is a business tool for contractors and isn't directed at children under 13, and we don't knowingly collect their information.

Changes

If this policy changes materially, we'll update the effective date above and note the change on this page.

July 30, 2026. You can now delete a project's files, or close your account entirely, from inside the app — you no longer have to email us. We also spelled out what closing your account does and doesn't remove: files go, purchase records stay for bookkeeping with your name and email detached.

Contact

ThePMToolkit LLC (d/b/a BidPacket) — [email protected]

Terms of ServicePrivacy[email protected]