Bidro

Privacy Policy

Last updated: April 20, 2026

What We Collect

When you sign up, we collect your email address and a hashed password. If you're a supplier, we also collect your company name and territory ZIP codes. Optionally, you may provide a home base address (for distance calculations).

When you use the app, we log your pipeline activity (which permits you Pursued, Bid Sent, Won, Lost, Passed) and any notes you write. Supplier accounts may upload a customer-account list.

If you subscribe, Stripe handles your payment information. We never see your credit card details — we only store a Stripe customer ID.

How We Use It

We use your data solely to provide the Service: filter your feed to your trades and territory, remember your pipeline actions, match permits to your known customer accounts, send reminders and digest emails, and compute your ROI stats.

We do not sell your data. We do not share it with third parties except as required to run the Service (see "Third-Party Services" below).

Third-Party Services We Use

  • Stripe — payment processing. Stripe handles all card data per their own privacy policy.
  • Third-party AI provider — AI analysis of public permit data. Your private data (notes, pipeline status) is never sent to the AI provider.
  • Resend — transactional email delivery (welcome emails, password resets, digests, reminders).
  • Railway — application hosting.
  • Sentry — error tracking (no personally identifiable data is logged).

Public Permit Data

Bidro's permit database is built from public records retrieved from municipal open data APIs (e.g., data.austintexas.gov). General contractor names, business phone numbers, and permit descriptions are public record under applicable open-records laws. We do not claim ownership of this public data.

Cookies

We use a single HTTP-only, signed cookie to keep you logged in. We don't use third-party tracking cookies or advertising cookies.

Your Rights

You may request access to, correction of, or deletion of your personal data at any time by emailing privacy@gobidro.com. We'll respond within 30 days.

You may delete your account at any time from your Settings page. Deletion removes your login, pipeline data, notes, and customer account list. Public permit data in our database remains (it's public record, not yours).

Data Retention

We retain active account data for as long as your account exists. If you delete your account, we delete associated personal data within 30 days. We retain aggregated, non-identifying analytics (e.g., total signups by month) indefinitely.

Billing records are retained as required by tax and financial regulations (typically 7 years) via Stripe.

Security

We hash all passwords with bcrypt. All traffic is encrypted via TLS. Session cookies are HMAC-signed and HTTP-only. We follow industry-standard security practices but cannot guarantee absolute security.

Changes to This Policy

If we materially change how we handle your data, we'll notify you by email and/or in-app notice at least 14 days before the change takes effect.

Contact

Questions? Email privacy@gobidro.com.