Privacy Policy
Effective July 28, 2026
Pepper Technology LLC operates the CleanBid Radar service. This Privacy Policy explains how Pepper Technology LLC ("we," "us," or "our") collects, uses, discloses, and protects information when you use cleanbidradar.com, create an account, purchase a subscription, or use our government-contract opportunity tools (the "Service").
1. Information we collect
We collect the following categories of information:
- Account and authentication information. Your email address, account identifier, authentication and session information, and account creation and update dates. Supabase provides authentication. We do not have access to your plaintext password.
- Company-profile information. Information you submit to personalize results, including company name, service states, nationwide availability, capabilities, certifications or business statuses, years of experience, federal experience, minimum lead time, and whether your profile is configured.
- Product, workflow, and funnel information. Opportunity identifiers and pipeline stages you save, fit-score inputs and results, referral information, digest preferences and consent records, recently seen opportunity identifiers, and limited funnel milestones such as viewing a landing page, completing a preliminary scan, starting signup, completing a profile, viewing a first match, encountering the free-plan limit, starting checkout, or opting into a digest. Funnel records use pseudonymous visitor and tab-session identifiers and coarse result or score ranges; they do not store your email address, company name, selected state, certification, IP address, user agent, full referrer, or advertising click identifiers.
- Billing information. Stripe customer and subscription identifiers, plan and subscription status, billing-period dates, and checkout or billing-portal session information. Payment-card and bank details are entered directly into Stripe-hosted forms and are not stored by CleanBid Radar.
- Email and support information. Your email address, messages you send us, email preferences, and delivery records such as send, delivery, delay, bounce, complaint, suppression, and unsubscribe status, along with provider message identifiers and timestamps.
- Business-development contact information. For limited business-to-business outreach, we may record a company name, business email address, company website, public government-registration or certification details, source links, and outreach, reply, bounce, and opt-out status. We use addresses that a business publishes on its own website, current capability statement, or authoritative public business profile, and we prefer role-based addresses for new outreach. We do not buy contact lists, use consumer people-search databases, or guess email addresses.
- AI review information. If you request an AI risk review, we process the relevant opportunity metadata, company-profile inputs, and deterministic fit-score evidence needed to produce that review.
- Technical information. Our hosting and service providers may automatically process IP address, browser and device information, request timestamps, referring pages, diagnostic information, and security or error logs when you access the Service.
2. Where information comes from
We receive information directly from you, automatically from your use of the Service, and from our service providers when they report events such as subscription changes or email delivery results. Opportunity and award information comes from public government sources, including SAM.gov and USAspending.gov. Limited business-development information may come from a company's own website or capability statement and from official public business sources such as the SBA Small Business Search and state vendor directories.
3. How we use information
We use information to:
- create accounts, authenticate users, and maintain sessions;
- build a company profile, calculate deterministic fit scores, and save pipeline activity;
- provide user-requested AI risk reviews and other paid features;
- process subscriptions, provide billing access, and maintain transaction records;
- send transactional messages and, only after opt-in, personalized opportunity digests;
- respond to support requests and administer referrals;
- identify relevant commercial janitorial businesses, prepare or send limited individualized business-development messages, measure responses, and maintain do-not-contact and bounce-suppression records;
- monitor reliability, troubleshoot errors, prevent fraud or abuse, and secure the Service;
- understand feature performance and improve the Service; and
- comply with law, enforce our terms, and protect our users, business, and rights.
4. Who receives information
We disclose only the information reasonably needed for a provider to perform its role. The current categories of recipients are:
- Supabase provides account authentication and database services and processes account, profile, pipeline, product-event, billing-status, email-delivery, and restricted business-development records.
- Stripe provides hosted checkout, subscription billing, billing-portal, payment, fraud-prevention, tax, and related services as enabled. Stripe receives information you enter on its hosted pages and the account and transaction information needed to process and support payments.
- Resend sends transactional and opted-in digest emails and provides delivery, bounce, complaint, and suppression events. It receives the recipient address, message content, and delivery metadata.
- Google Workspace (Gmail) hosts our support and business email and processes recipient and sender addresses, message content, attachments, and related email metadata.
- OpenAI processes opportunity metadata, company-profile inputs, and score evidence only when you request an AI risk review. Those API requests are sent with storage disabled. The AI review does not set or alter the deterministic fit score. When we use an OpenAI Codex-assisted workflow, OpenAI may also process selected support content or public business-development information to help categorize a request, research a business, identify follow-up items, or prepare a response or outreach draft. Email and public business information are shared only when selected for that assisted workflow.
- OpenAI Sites and hosting infrastructure deliver the Service and may process requests, network information, diagnostics, and security logs necessary to host, protect, and operate it.
- Government data services. We query SAM.gov and USAspending.gov for public opportunity and award data. We do not send your CleanBid Radar account or company-profile information to those services merely to retrieve public records. A direct browser request to a public service can include ordinary network information such as your IP address.
- Professional advisers, authorities, and transaction parties. We may disclose information to lawyers, accountants, insurers, regulators, courts, law enforcement, or a buyer or successor when reasonably necessary to comply with law, protect rights and safety, investigate misuse, or complete a merger, financing, acquisition, or sale of assets.
We do not sell personal information, and we do not disclose personal information for cross-context behavioral advertising or targeted advertising.
5. How disclosures occur
Routine disclosures to providers occur through encrypted HTTPS connections and authenticated application programming interfaces. Payment details are submitted directly from Stripe-hosted checkout and billing pages to Stripe. Stripe and Resend send account events back to CleanBid Radar through signature-verified webhooks. Support and business-development messages are transmitted through our Google Workspace mailbox, and selected content or public business information is transmitted through an authorized connection to OpenAI only when we use the assisted workflow described above. We do not publish your account or company-profile information to public government databases. Legal disclosures may be made through secure electronic transfer or another method appropriate to the request and required by law.
6. Cookies and browser storage
CleanBid Radar uses functional browser storage to keep you signed in, remember recently seen opportunity identifiers, preserve referral or campaign parameters used to measure the signup source, and support account or setup state. When cloud accounts are not configured, profile and pipeline information may be saved only in that browser. We do not currently use third-party advertising cookies.
We also set a first-party, pseudonymous visitor cookie for up to 90 days and create a random tab-session identifier that lasts until that browser tab or session is closed. These identifiers help us count funnel milestones, prevent duplicate event submissions, and connect pre-signup activity with an account after authentication. The visitor cookie is HttpOnly, Secure, and SameSite=Lax, so site scripts cannot read it and it is not available to third-party advertising networks.
Stripe-hosted payment pages may use cookies and similar technologies and may collect transaction and device-identifying information to process and authenticate payments, prevent fraud and loss, perform analytics, and operate or improve Stripe services. Those activities are governed by the Stripe Privacy Policy.
7. Retention
We retain account, profile, pipeline, and subscription information while your account is active and for as long as reasonably necessary to provide the Service. We may retain billing, integration, email-delivery, support, security, and diagnostic records longer when needed for accounting, legal compliance, fraud prevention, dispute resolution, and reliable operations. Suppression records may be retained so that we continue to honor unsubscribes, complaints, and hard bounces. Business-development prospect records are retained only while reasonably useful for a limited outreach cycle, except that the minimum information needed to honor an opt-out, complaint, or hard bounce may be retained longer. Anonymous funnel records are retained for up to 90 days, and authenticated or server-recorded funnel milestones are retained for up to 400 days. Account-linked funnel records are deleted if the associated authentication account is deleted. When information is no longer needed, we delete or anonymize it where reasonably practicable, subject to legal obligations and backup cycles.
8. Your choices and privacy rights
- You may update your company profile and pipeline information in the dashboard.
- You may turn weekly opportunity emails off in account settings or use the unsubscribe link in a digest.
- You may manage or cancel a paid subscription through the Stripe billing portal.
- You may ask to access, correct, export, or delete personal information associated with your account by contacting us. We may need to verify your identity before completing a request.
- You may stop business-development email by replying “unsubscribe” or otherwise asking us not to contact you. We will retain only the limited suppression record needed to honor that request.
We may retain information that law requires us to keep and limited records needed to prevent fraud, resolve disputes, enforce agreements, or honor communication opt-outs. Depending on where you live, you may have additional rights and the right to appeal a denied request. Contact us to exercise those rights.
9. Security practices
We use safeguards designed to protect information in proportion to its sensitivity. These include HTTPS encryption in transit; authenticated account access; user-level database row policies; restricted server-side credentials and service-only tables; signature verification for Stripe and Resend webhooks; bounded request payloads; and Stripe-hosted collection of payment details. Access to production systems and providers is limited to authorized uses needed to operate the Service. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
10. Children's privacy
The Service is intended for businesses and is not directed to children under 18. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this policy as the Service or legal requirements change. We will post the updated policy here, change the effective date, and provide additional notice when required by law.
12. Contact us
For privacy questions or requests, email the CleanBid Radar support team at support@cleanbidradar.com. CleanBid Radar is operated by Pepper Technology LLC.