Legal
Privacy Policy
The short version. We collect your email, your billing status, and whatever you choose to put in the product. We never see your full card number. We do not sell your data, we do not run advertising or third-party analytics on the app, and no other customer can see your pipeline, quotes, margins, or watch lists. Email us at Support@dibbsradar.com and we will export or delete your data.
1. What we collect
Account information
Your email address and an account identifier, handled through our authentication provider. If you set a password it is stored hashed by that provider, not by us in readable form.
Billing information
We store your subscription status, plan, trial end date, and the customer and subscription identifiers issued by Stripe. Card details are collected and stored by Stripe — we never receive or store your full card number.
What you put into the product
This is the bulk of it, and it is entirely under your control:
- Your bid pipeline — solicitations you track, their status, vendor quotes, unit costs, your bid amounts, award outcomes, delivery and inspection costs, supplier names, and your notes.
- Watch lists and alert settings — the NSN and CAGE groups you build and whether you want a daily digest for them.
- Saved searches and filters, and which solicitations you have viewed or dismissed, so the feed can dim what you have already reviewed.
Technical information
Our servers keep ordinary operational logs — request paths, timestamps, status codes, IP address, and user agent — used to run and secure the service and to diagnose faults. Authentication headers are redacted from logs.
2. What we do not collect
- Your full payment card number, or bank credentials.
- Government identifiers such as Social Security numbers.
- Location beyond what an IP address implies.
- We do not run third-party advertising or behavioural tracking inside the application, and we do not build advertising profiles.
Note that our public marketing site loads web fonts from Google, which means Google receives a request from your browser (including your IP address) when you visit it. The application itself is behind login.
3. How we use it
- To operate the service — show you the feed, run your filters, store your pipeline, send the alerts you asked for.
- To bill you and manage your subscription.
- To support you when you contact us.
- To keep the service secure, enforce rate limits, and investigate abuse.
- To diagnose faults and improve the product.
- To comply with legal obligations.
We do not use your data to train machine-learning models sold or offered to other customers, and we do not use your pipeline data to inform anyone else's bidding.
4. Who else processes it
We use these service providers. Each receives only what it needs to do its job:
| Provider | Purpose | What it can see |
|---|---|---|
| Supabase | Database and authentication | Account email, and all application data you enter |
| Stripe | Payments and subscription billing | Name, email, billing address, card details, payment history |
| Render | Application hosting | Traffic to the app, server logs |
| Cloudflare R2 | Storage of public solicitation PDF documents | No customer data — public documents only |
| Resend | Sending alert and transactional email | Your email address and the content of those emails |
| DigitalOcean | Server that ingests the public DLA data | No customer data — public source data only |
We may add or change providers as the product evolves; we will update this table when we do.
5. Sharing, selling, and your competitors
DibbsRadar customers bid against each other. Your pipeline can reveal your costs, your margins, and your suppliers. No other customer can see any of it — not directly, not aggregated, not anonymized. We do not sell or rent your data to anyone. The operator of DibbsRadar also bids on government contracts and will not use customer data to inform that bidding.
We disclose personal information only: to the service providers listed above; when you ask us to; if required by law or valid legal process; to protect our rights, safety, or the integrity of the service; or to an acquirer if the business is sold, in which case this policy continues to apply until you are given notice of any change.
6. Email you receive
We send two kinds of email: transactional messages needed to run your account (sign-in, password reset, billing and receipts), and alert digests for the NSN and CAGE watch lists you have explicitly opted in. Alerts are off by default and must be enabled per group.
You can turn alerts off at any time in your account settings, or by replying to Support@dibbsradar.com. Because transactional messages are necessary to operate your account, they continue while your account exists.
7. Cookies and local storage
We use browser storage for things the product needs to work, not for tracking:
- Your login session, so you stay signed in.
- Interface preferences, such as which result columns you have chosen to show.
We do not use third-party advertising or cross-site tracking cookies. You can clear this storage in your browser at any time; doing so signs you out.
8. How long we keep it
- Account and application data — while your account is active, and for 30 days after you close it, so an accidental cancellation can be undone. After that it is deleted.
- Billing records — retained as long as tax and accounting law requires, typically several years, even after your account is closed.
- Server logs — retained for a short operational period, then rotated out.
Public government data in the product (solicitations, awards, catalog records) is not personal data and is retained independently of any account.
9. Your rights and how to exercise them
Depending on where you live you may have the right to access, correct, export, delete, or restrict processing of your personal information, and to object to certain uses. Regardless of where you live, we will honour these requests:
- Get a copy of the personal data we hold about you.
- Correct anything inaccurate.
- Delete your account and its data.
Email Support@dibbsradar.com from your account address and we will respond within 30 days. We will not discriminate against you for exercising these rights. We do not sell personal information, so there is nothing to opt out of on that front.
10. Security
Measures in place include: encrypted connections (HTTPS/TLS) with certificate validation; encryption at rest by our database and storage providers; authentication on every non-public endpoint with server-side checks that fail closed; database row-level security; rate limiting; redaction of credentials from logs; and regular backups.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data we will notify you and any required authority without undue delay. If you believe you have found a vulnerability, please report it to Support@dibbsradar.com rather than disclosing it publicly.
11. Children
DibbsRadar is a business tool and is not directed at anyone under 18. We do not knowingly collect personal information from children. If we learn we have, we will delete it.
12. Changes
We will update this policy as the product changes. Material changes will be notified by email or in the app before taking effect. The "last updated" date above always reflects the current version.
13. Contact
DIBBSRADAR LLC
10730 Potranco Rd, Ste 122 #535
San Antonio, TX 78251
Support@dibbsradar.com