GovSprint

Privacy Policy

1. What we collect

Account information — name, work email, company name, password hash, and the seats you invite.

Company profile — your UEI and the public registration and award history we retrieve using it from SAM.gov and USAspending. This is already public federal record; we retrieve and store it so the feed can be scored against your company.

Your working data — pipeline entries, bid/no-bid decisions, notes, tasks, recorded outcomes, saved searches.

Usage — pages viewed, features used, and the volume of AI analyses run, so we can meter fair use and understand what to improve.

Payment — handled by Stripe. We store a customer reference and subscription status. We never see or store your card number.

Diagnostics — when a page fails, we record what broke: the error message and stack trace, the address of the page, your browser’s user agent, and the first three parts of your IP address. Enough to tell one person hitting a bug repeatedly from many people hitting it once, and not enough to identify you. Messages and stack traces are automatically stripped of anything resembling a key, token or password before they are stored. If you are signed in, the report is linked to your account so we can tell you it is fixed.

2. What we do not do

3. Who processes data on our behalf

Each is bound to use the data only to provide their service to us. We do not authorise them to use it for their own purposes.

4. Government data sources

Opportunity and award records come from SAM.gov and USAspending, both public federal systems. Retrieving a public record about your company using your UEI does not transmit anything private about you to those systems.

5. Cookies

We use a session cookie to keep you signed in and a preference cookie for interface state. Cloudflare Turnstile sets a short-lived cookie when verifying a form submission. We do not use advertising or cross-site tracking cookies.

6. Retention

We keep account and working data while your account is active. After you close an account we delete or anonymise personal data within 90 days, except where we must retain records for tax, accounting or legal obligations. You can request earlier deletion at any time.

7. Your rights

You can access, correct, export or delete your data. Pipeline export is available in the product; for anything else, email privacy@govsprint.app and we will respond within 30 days. If you are in a jurisdiction with additional statutory rights — including the EU/UK under GDPR and California under the CCPA/CPRA — those rights apply and this is how to exercise them.

8. Security

Data is encrypted in transit (HTTPS is enforced at the registry level for .app domains) and at rest. Tenant data is isolated at the database level so one account cannot read another’s rows. Customer-supplied AI keys receive additional application-level encryption. Administrative access is restricted and audit-logged.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify affected account owners without undue delay.

9. Children

GovSprint is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.

10. Changes

We will post material changes here and notify account owners by email before they take effect.

11. Contact

Mako Logics LLC · privacy@govsprint.app