RFP Recon Inc. ("RFP Recon," "we," "us," or "our") operates the RFP Recon platform at app.rfprecon.com and the marketing website at rfprecon.com (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Service.
By using the Service, you agree to the practices described in this Privacy Policy.
1. Who We Are
RFP Recon Inc. is a Delaware C-Corporation operating from Washington State, United States. We provide federal contracting intelligence software to small and mid-size federal contractors.
For privacy questions, contact us at hello@rfprecon.com.
2. Information We Collect
2.1 Information You Provide
Account Information. When you create an account, we collect your name, email address, company name, role, and authentication credentials. If you sign in via a third-party identity provider, we receive basic profile information from that provider.
Capability Profile Data. To deliver our analysis, you provide information about your company, including past performance records, certifications, key personnel, target agencies, contract vehicles, NAICS codes, set-aside status, and similar federal contracting information. We treat this information as Confidential Business Information under your Terms of Use.
Solicitation Content. You may upload or import federal solicitation documents (RFPs, RFQs, RFIs, and related attachments). These documents are typically public records sourced from SAM.gov, but may include content you have authored or received.
Decision Tracking. When you record your bid/no-bid decision, outcome (won, lost, cancelled), or notes on an analysis, we retain that history as part of your account. This information is treated as Confidential Business Information under your Terms of Use.
Payment Information. We use Stripe, Inc. to process payments. We do not store full payment card numbers on our servers. We retain Stripe customer identifiers, billing email, billing address, and transaction history.
Communications. When you contact us by email, chat, or form, we retain the contents of those communications.
2.2 Information Collected Automatically
Usage Data. We collect information about how you interact with the Service, including pages viewed, features used, analyses run, search queries, and timestamps. This is collected via PostHog (see Subprocessors below). Per our internal privacy practice, we send aggregated metrics such as keyword counts and lengths rather than the underlying text content where feasible.
Device and Log Data. Our hosting and analytics providers automatically log IP address, browser type and version, operating system, referring URL, and similar technical information.
Cookies and Similar Technologies. We use first-party cookies for authentication and session management, and analytics cookies for product improvement. We do not use advertising cookies or sell data to advertisers.
2.3 Information from Public Sources
The Service queries public federal data sources on your behalf, including SAM.gov, FPDS-NG, and USAspending.gov. Information returned from these public sources is processed as part of delivering your analyses and is not personal information about you.
2.4 Information for Prospect Outreach
If you have not signed up but received outreach from us, we may have collected your business contact information from public sources including SAM.gov entity registrations and publicly available company websites. Our legal basis is our legitimate interest in offering relevant business services to federal contracting companies. You may opt out of further outreach at any time by replying to any outreach email or contacting hello@rfprecon.com.
3. How We Use Information
We use the information we collect to:
- Provide, operate, and improve the Service
- Generate analyses, field reports, decision memos, and related outputs
- Authenticate users and secure accounts
- Process payments and manage subscriptions
- Communicate with you about your account, the Service, billing, and support
- Send transactional and, with your consent, marketing communications
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Use
- Conduct aggregated, de-identified analysis to improve product quality
We do not sell your personal information. We do not share your information with advertisers.
4. AI Processing and Model Training
The Service uses third-party large language model providers, currently Anthropic PBC, to generate parts of the analysis output. When you run an analysis, the relevant solicitation content and capability profile context are transmitted to the AI provider's API for the duration of the request.
We do not use your Customer Data to train AI models. Our AI subprocessor is contractually prohibited from using API inputs and outputs to train its models. Under our AI provider's standard commercial terms, prompts and responses may be retained by the provider for a limited period (up to 30 days) for trust, safety, and abuse-prevention purposes, after which they are deleted, except where a longer period is required to enforce the provider's Usage Policy. We do not retain prompt or response content beyond what is required to deliver the analysis to you.
"Customer Data" means the capability profile information you provide and the solicitation content you upload or import.
5. How We Share Information
We share information only as described below.
Subprocessors. We use the following service providers to operate the Service. Each is contractually bound to handle information consistently with this Privacy Policy:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services / Supabase | Application hosting and database | United States |
| Vercel, Inc. | Frontend hosting and edge compute | United States |
| Clerk, Inc. | Authentication and user identity | United States |
| Inngest, Inc. | Background job orchestration | United States |
| Anthropic PBC | AI model inference (analysis generation) | United States |
| Stripe, Inc. | Payment processing | United States |
| PostHog, Inc. | Product analytics | United States |
| Resend | Transactional email delivery | United States |
| Hunter.io (Email Hunter SAS) | Business contact enrichment for prospect outreach (no Customer Data) | France / European Union |
| Google LLC (Workspace) | Business email and document storage | United States |
| Mercury (Choice Financial Group) | Business banking (no Customer Data) | United States |
We will update this list when subprocessors change. Material changes will be communicated to active customers.
Legal Requirements. We may disclose information when required by law, subpoena, court order, or other legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.
Business Transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you and apply this Privacy Policy to the transferred information, or notify you if a different policy will apply.
With Your Consent. We may share information for other purposes with your consent or at your direction.
6. Data Security
We use commercially reasonable technical and organizational measures to protect information, including encryption in transit (TLS 1.2 or higher), encryption at rest, access controls, audit logging, and regular review of our security posture. No system is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a security incident affecting your Customer Data, we will notify you without undue delay consistent with applicable law and our contractual obligations.
7. Data Retention
We retain your account information and Customer Data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce our agreements.
- Active accounts: retained while your subscription is active.
- Closed accounts: Customer Data is retained for a reasonable period after account closure (generally up to 90 days) to allow account recovery, then deleted upon your request or as part of our periodic data hygiene process. Backup copies are overwritten on our hosting provider's standard rotation.
- Analyses and field reports: retained for the life of your account; you may delete individual analyses at any time.
- Billing records: retained for 7 years to satisfy tax and accounting obligations.
- Marketing prospect data: retained until opt-out, then minimal records are kept to honor the opt-out.
You may request earlier deletion by contacting hello@rfprecon.com.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Access. Request a copy of the personal information we hold about you.
- Correction. Request that we correct inaccurate personal information.
- Deletion. Request deletion of your personal information, subject to legal retention requirements.
- Portability. Request a machine-readable export of personal information you have provided.
- Opt-out of marketing. Unsubscribe from marketing emails using the link in any marketing message or by emailing us.
- Restrict or object to processing. Where applicable under law, request restriction or object to processing.
To exercise these rights, email hello@rfprecon.com from the address associated with your account. We will respond within 30 days. We do not discriminate against users who exercise their privacy rights.
California Residents (CCPA / CPRA)
If you are a California resident, you have the rights described above. The categories of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share information are described in Sections 2, 3, and 5. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under California law.
EEA / UK Residents (GDPR)
If you are in the European Economic Area or the United Kingdom, our legal bases for processing are: (a) performance of a contract for account holders; (b) legitimate interests in operating and improving the Service and conducting business outreach to companies; (c) consent where required; and (d) compliance with legal obligations. You have the right to lodge a complaint with your local supervisory authority.
9. International Data Transfers
The Service is operated from the United States. Our subprocessors are primarily located in the United States, with one (Hunter.io) located in the European Union. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and, where applicable, the European Union. By using the Service, you consent to these transfers.
10. Children's Privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided information to us, contact hello@rfprecon.com and we will delete it.
11. Third-Party Links and Services
The Service may link to third-party websites or services (such as SAM.gov). We are not responsible for their privacy practices. Review their privacy policies before providing information to them.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent change. Material changes will be communicated by email to active customers or a notice in the Service at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
RFP Recon Inc. Email: hello@rfprecon.com Mailing address available upon request.