Privacy Policy
Last updated: October 5, 2026
The short version
- We collect what we need to run your account and send your alerts: mainly your email address, your watch settings and your plan.
- We do not sell your personal information or share it for advertising. Our website has no analytics or ad trackers, and our emails have no tracking pixels.
- We use one cookie, to keep you signed in. Payments are handled by Stripe; we never see your full card number.
- You can unsubscribe from any alert email in one click, and you can ask us to access, correct or delete your information.
1. Who we are and what this covers
This Privacy Policy explains how [LEGAL ENTITY NAME] ("we", "us" or "our"), which operates Record Flag, collects, uses and shares personal information when you visit our website, create an account, receive alerts or use our API (the "Service"). It also covers business contact information we collect to tell businesses about the Service. Our Terms of Service also apply.
2. Information we collect
| What | Examples | Where it comes from |
|---|---|---|
| Account information | Email address, plan, sign-in times | You |
| Watch settings | NAICS and PSC codes, set-asides, places, keywords, delivery preferences | You |
| Billing information | Stripe customer ID, plan, subscription status, invoices; your name and billing address if you give them to Stripe. Card details are collected and stored by Stripe, not by us. | You, through Stripe |
| API usage | API key identifiers (we store keys only as a one-way hash plus the last four characters), requests, timestamps, credits used | Your use of the API |
| Device and log information | IP address, browser type, pages and endpoints requested, errors | Collected automatically |
| Email records | When we sent each email, whether it was delivered or bounced, unsubscribe and preference choices | Collected automatically |
| Communications | Messages you send us and replies to our emails | You |
| Business contact information | Name, job title, business email or phone published on a company's own website | Public business websites |
| Public records | Names of businesses and people that appear in government records, such as award recipients | Government sources |
We do not ask for, and ask you not to put into watches, sensitive information such as government ID numbers, financial account numbers or health information.
3. How we use it
- To provide the Service: create your account, sign you in, match public records against your watches, send alerts and webhooks, and run the API.
- For billing: process payments through Stripe and measure API usage.
- To communicate with you: send sign-in links, receipts, security and policy notices, replies to your messages and, unless you opt out, occasional product news.
- To keep the Service safe: rate limiting, preventing abuse and fraud, and fixing problems.
- To improve the Service: for example, understanding in aggregate which kinds of alerts are useful.
- To reach businesses that may benefit: we may email business contacts whose details are published on their company's website. Every such message identifies us and lets the recipient opt out.
- To meet legal obligations and enforce our Terms.
4. How we share it
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only:
- to service providers that process it for us under contract, such as payment processing (Stripe), email delivery, hosting and backup storage, and AI model providers that help us read public records and draft business emails;
- where you direct us, for example to the webhook endpoints you configure;
- when required by law or legal process, or when needed to protect the rights, safety or security of our users, the public or us; and
- as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to the information transferred.
5. Cookies and tracking
We use one strictly necessary cookie to keep you signed in. It expires after 30 days or when you sign out. We do not use analytics, advertising or social media cookies, pixels or similar trackers on our website, and our emails contain no tracking pixels or tracked links. Stripe sets its own cookies on its checkout and billing pages to process payments and prevent fraud; see Stripe's privacy policy.
Do Not Track and Global Privacy Control. We do not track you across other websites, and we do not sell or share personal information, so these signals do not change how the Service works. We nevertheless treat a Global Privacy Control signal as a valid request to opt out of sale and sharing.
6. Email practices
- We send alerts only for watches you set up. Every alert email has a one-click unsubscribe link and a link to manage your preferences.
- Our commercial emails identify us, use accurate sender information and subject lines, include our postal address and offer a clear way to opt out.
- We honor unsubscribe requests promptly, usually immediately and always within 10 business days, and we keep a do-not-email record so we do not contact you again.
- Service messages, such as sign-in links, receipts and security or legal notices, are sent while you have an account.
7. How long we keep it
| Information | How long |
|---|---|
| Account and watch settings | While your account is open; deleted or de-identified within 30 days after you close it |
| Billing records | As long as tax and accounting law requires, generally 7 years (Stripe keeps its own records) |
| Email delivery records | Up to 24 months |
| Unsubscribe and do-not-email records | Kept so we can honor them; only the email address and the choice |
| API usage records | Up to 24 months, for billing and abuse prevention |
| Server and security logs | Up to 90 days |
| Business contact information | Up to 24 months after our last contact, or until you opt out (then only a do-not-email record) |
| Backups | Overwritten on a rolling basis, within about 5 weeks |
8. Security
We use encrypted connections (HTTPS), sign-in links that expire quickly and work once, API keys stored only as one-way hashes, and restricted access to our systems. No system is perfectly secure. If you believe you have found a security problem, please tell us at [CONTACT EMAIL].
9. Your choices and rights
- Alerts: unsubscribe from any alert email in one click, or change or delete your watches from your account.
- Access, correction and deletion: email [CONTACT EMAIL] from the address on your account. We respond within 45 days.
- Closing your account: cancel any paid plan from your account, then email us to delete the account.
We honor these requests wherever you live.
10. California privacy notice
This section applies to California residents and adds to the rest of this policy. We are a small business and may not currently meet the thresholds that make the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), apply to us. We follow its main principles anyway and will honor the requests described below.
Notice at collection
| CCPA category | What we collect | Purposes | Sold or shared? |
|---|---|---|---|
| Identifiers | Email address, IP address, account and API key identifiers | Providing the Service, security, communication | No |
| Customer records (Cal. Civ. Code 1798.80(e)) | Name and billing address, if you give them to Stripe | Billing | No |
| Commercial information | Plans purchased, billing history | Billing, support | No |
| Internet or network activity | Log data, API usage, email delivery records | Providing the Service, security, improvement | No |
| Professional information | Business contact details published on company websites | Telling businesses about the Service | No |
Sources, purposes and retention periods are described in sections 2, 3 and 7. We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. We have not sold or shared personal information in the past 12 months, and we do not knowingly sell or share the personal information of anyone under 16.
Your rights
- Know and access: ask what personal information we have collected about you, where it came from, why we use it and whom we disclose it to, and get a copy.
- Delete: ask us to delete personal information we collected from you, subject to legal exceptions (for example, records we must keep for taxes).
- Correct: ask us to correct inaccurate personal information.
- Opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of, but you may still send the request.
- No discrimination: we will not deny you service or charge you a different price for exercising these rights.
How to make a request
Email [CONTACT EMAIL] with the subject "California privacy request", or write to us at the postal address below. We verify requests by confirming that you control the email address on the account or in our records. An authorized agent may make a request for you with your signed permission; we may ask you to confirm your identity directly. We respond within 45 days and will tell you if we need up to 45 more days.
Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
11. People named in public records
The public records we process can name individuals, such as business owners, contracting officers or public officials. We use these records to provide the Service and to cite their sources. We do not use contact details of government personnel from public notices for marketing. The official source is the authoritative record; if you believe a record is shown incorrectly in the Service, contact us and we will review it.
12. Children
The Service is for businesses and professionals and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, contact us and we will delete it.
13. Where we process data
We are based in the United States, and we store account data in the United States. Some service providers, including AI model providers, may process data in other countries, where privacy laws may differ from those where you live.
14. Changes to this policy
We may update this policy. We will post the new version on this page and update the date at the top. If we make a material change, we will tell you by email or in the Service before it takes effect.
15. Contact
[LEGAL ENTITY NAME]
[POSTAL ADDRESS]
Email: [CONTACT EMAIL]