Record Flag

Privacy Policy

Last updated: October 5, 2026

The short version

  • We collect what we need to run your account and send your alerts: mainly your email address, your watch settings and your plan.
  • We do not sell your personal information or share it for advertising. Our website has no analytics or ad trackers, and our emails have no tracking pixels.
  • We use one cookie, to keep you signed in. Payments are handled by Stripe; we never see your full card number.
  • You can unsubscribe from any alert email in one click, and you can ask us to access, correct or delete your information.

1. Who we are and what this covers

This Privacy Policy explains how [LEGAL ENTITY NAME] ("we", "us" or "our"), which operates Record Flag, collects, uses and shares personal information when you visit our website, create an account, receive alerts or use our API (the "Service"). It also covers business contact information we collect to tell businesses about the Service. Our Terms of Service also apply.

2. Information we collect

WhatExamplesWhere it comes from
Account informationEmail address, plan, sign-in timesYou
Watch settingsNAICS and PSC codes, set-asides, places, keywords, delivery preferencesYou
Billing informationStripe customer ID, plan, subscription status, invoices; your name and billing address if you give them to Stripe. Card details are collected and stored by Stripe, not by us.You, through Stripe
API usageAPI key identifiers (we store keys only as a one-way hash plus the last four characters), requests, timestamps, credits usedYour use of the API
Device and log informationIP address, browser type, pages and endpoints requested, errorsCollected automatically
Email recordsWhen we sent each email, whether it was delivered or bounced, unsubscribe and preference choicesCollected automatically
CommunicationsMessages you send us and replies to our emailsYou
Business contact informationName, job title, business email or phone published on a company's own websitePublic business websites
Public recordsNames of businesses and people that appear in government records, such as award recipientsGovernment sources

We do not ask for, and ask you not to put into watches, sensitive information such as government ID numbers, financial account numbers or health information.

3. How we use it

4. How we share it

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only:

5. Cookies and tracking

We use one strictly necessary cookie to keep you signed in. It expires after 30 days or when you sign out. We do not use analytics, advertising or social media cookies, pixels or similar trackers on our website, and our emails contain no tracking pixels or tracked links. Stripe sets its own cookies on its checkout and billing pages to process payments and prevent fraud; see Stripe's privacy policy.

Do Not Track and Global Privacy Control. We do not track you across other websites, and we do not sell or share personal information, so these signals do not change how the Service works. We nevertheless treat a Global Privacy Control signal as a valid request to opt out of sale and sharing.

6. Email practices

7. How long we keep it

InformationHow long
Account and watch settingsWhile your account is open; deleted or de-identified within 30 days after you close it
Billing recordsAs long as tax and accounting law requires, generally 7 years (Stripe keeps its own records)
Email delivery recordsUp to 24 months
Unsubscribe and do-not-email recordsKept so we can honor them; only the email address and the choice
API usage recordsUp to 24 months, for billing and abuse prevention
Server and security logsUp to 90 days
Business contact informationUp to 24 months after our last contact, or until you opt out (then only a do-not-email record)
BackupsOverwritten on a rolling basis, within about 5 weeks

8. Security

We use encrypted connections (HTTPS), sign-in links that expire quickly and work once, API keys stored only as one-way hashes, and restricted access to our systems. No system is perfectly secure. If you believe you have found a security problem, please tell us at [CONTACT EMAIL].

9. Your choices and rights

We honor these requests wherever you live.

10. California privacy notice

This section applies to California residents and adds to the rest of this policy. We are a small business and may not currently meet the thresholds that make the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), apply to us. We follow its main principles anyway and will honor the requests described below.

Notice at collection

CCPA categoryWhat we collectPurposesSold or shared?
IdentifiersEmail address, IP address, account and API key identifiersProviding the Service, security, communicationNo
Customer records (Cal. Civ. Code 1798.80(e))Name and billing address, if you give them to StripeBillingNo
Commercial informationPlans purchased, billing historyBilling, supportNo
Internet or network activityLog data, API usage, email delivery recordsProviding the Service, security, improvementNo
Professional informationBusiness contact details published on company websitesTelling businesses about the ServiceNo

Sources, purposes and retention periods are described in sections 2, 3 and 7. We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we do not use or disclose sensitive personal information for any purpose that would give you a right to limit it. We have not sold or shared personal information in the past 12 months, and we do not knowingly sell or share the personal information of anyone under 16.

Your rights

How to make a request

Email [CONTACT EMAIL] with the subject "California privacy request", or write to us at the postal address below. We verify requests by confirming that you control the email address on the account or in our records. An authorized agent may make a request for you with your signed permission; we may ask you to confirm your identity directly. We respond within 45 days and will tell you if we need up to 45 more days.

Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.

11. People named in public records

The public records we process can name individuals, such as business owners, contracting officers or public officials. We use these records to provide the Service and to cite their sources. We do not use contact details of government personnel from public notices for marketing. The official source is the authoritative record; if you believe a record is shown incorrectly in the Service, contact us and we will review it.

12. Children

The Service is for businesses and professionals and is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, contact us and we will delete it.

13. Where we process data

We are based in the United States, and we store account data in the United States. Some service providers, including AI model providers, may process data in other countries, where privacy laws may differ from those where you live.

14. Changes to this policy

We may update this policy. We will post the new version on this page and update the date at the top. If we make a material change, we will tell you by email or in the Service before it takes effect.

15. Contact

[LEGAL ENTITY NAME]
[POSTAL ADDRESS]
Email: [CONTACT EMAIL]