Privacy Policy
Last updated 7 September 2026.
This document is a starting point and not legal advice. A lawyer should review it before launch. Placeholders such as [COMPANY LEGAL NAME] are not yet filled in.
1. Who we are
SaaS RFP is operated by [COMPANY LEGAL NAME]. For any question about this policy, write to [CONTACT EMAIL].
2. What we collect and why
We collect only what the service needs to run. There is no file upload anywhere on the site. We never collect a contract, an order form or an invoice.
Account
- Your email address, to sign you in and to contact you about your account.
- Your password, stored only as a bcrypt hash. We cannot read your password and we never store it in plain text.
- A handle, which forms your public URL.
- Your role (member or admin) and, if an admin suspends your account, the date of the suspension.
Profile
- Display name, company, job title, bio, website, a public contact email and an avatar URL. You choose what to fill in. Everything on a profile is public.
- A setting that controls whether your stack page is public.
RFPs
- The vendor you want to replace, a title and a description.
- Structured figures: annual spend, seat count and usage stats such as a contact count.
- A renewal date, if you give one.
- The list of features you use, with an optional usage note for each.
- Whether you posted anonymously.
- The date and time you confirmed that you have the right to disclose the information. We keep this as evidence.
Products and bids
- A product's name, description, links, pricing model and pricing note.
- A bid's annual price, price note, demo link, notes, a coverage claim for each RFP feature and any extra features.
- Whether the bid is anonymous.
Stack entries
- The vendor you use for each category, a status and an optional note.
Reports
- When you file a takedown notice or a dispute: the target, the reason, your description and, if you have no account, your email address so we can reply.
Admin audit log
- Every action an administrator takes is recorded with the actor, the target, a summary and the before and after values. This log is append-only. It is never edited or deleted.
3. Cookies
The session cookie is the only cookie we set. It keeps you signed in. We do not use an analytics tracker or an advertising tracker. If that changes, we will update this policy before the change takes effect.
4. The Chrome extension
The SaaS RFP Usage Scanner runs in your browser. It reads the pages of the SaaS account you have open, works out which features the account appears to use, and shows you a checklist. All of this happens locally on your machine.
- Every probe is read-only. The extension never writes to your account.
- It never reads a password field, an API key field or a payment card field.
- It sends data to exactly one destination: the SaaS RFP site URL you set in the extension options. It sends only the payload you review and confirm, and only when you click to confirm.
- It sends nothing in the background and nothing to any other party.
- Scan results stay in the extension's local storage on your machine until you run a new scan or clear the extension data.
5. What is public
SaaS RFP is a public marketplace. An RFP's figures and feature list, a bid's price and coverage claims, a product listing, a profile and a public stack page are all visible to anyone without an account. Anonymity hides your identity from the public; it does not hide the figures. An anonymous seller is still visible to the buyer of the RFP. See the Terms of Service for the full list.
Public content may be cached or indexed by search engines and copied by third parties. Once published, it cannot be fully recalled, even after we hide or delete it.
6. Where your data is processed
We use these providers to run the service:
- Vercel, which runs the application.
- Neon, which stores the database.
We do not sell your data. We do not share it with an advertiser.
7. How long we keep data
- Your account and content are kept while your account exists.
- When an administrator hides content after a complaint, the content is retained, not deleted. It is removed from public pages. You and an administrator can still see it.
- Reports, disputes and their outcomes are retained as a record of the decision.
- The admin audit log is append-only and is retained permanently.
- When you delete your account, your profile, RFPs, products, bids and stack entries are deleted. The audit log keeps a record of any admin action that referenced them.
8. Your rights
You may ask us to:
- Access the data we hold about you.
- Correct data that is wrong. You can edit most of it yourself in your settings.
- Export your data in a machine-readable format.
- Delete your account and your content.
Send a request to [CONTACT EMAIL] from the email address on your account. We aim to respond within 30 days. Depending on where you live, you may also have the right to complain to a data protection authority.
9. Security
We store passwords as bcrypt hashes and we send all traffic over HTTPS. No system is fully secure. If we learn of a breach that affects you, we will tell you.
10. Children
The service is for business use. It is not directed at anyone under 18.
11. Changes to this policy
We may update this policy. The date at the top of this page shows the current version.