Legal
Privacy Policy
Version 2.0 · Effective 10 October 2026 · Last updated 23 September 2026
In short
- We collect your name, email and what you search for.
- We do not sell your personal data, and we do not run advertising.
- Analytics cookies are only set if you accept them, and you can change your mind.
- You can download or delete everything we hold, from your account settings.
- If the business is ever sold or incorporated, your data would transfer with it — see section 7.
1. Who we are and how to contact us
TenderTracker UK is operated by Simon Carroll, trading as TenderTracker UK. We are the "data controller" for the personal data described in this policy, which means we decide how and why it is used.
For anything to do with your personal data, including exercising your rights, contact [email protected].
This is version 2.0, effective 10 October 2026. The previous version remains available at /privacy/v1.
2. What this policy covers
This policy covers personal data about you as a user or visitor of capitolbids.com.
It does notcover the contract notice data itself. That is published by UK contracting authorities on Find a Tender and Contracts Finder as public information, and can include the names and work contact details of procurement officers. We republish it as provided. If you are named in a published notice and want it changed, the contracting authority that published it is the controller for that data and is the right place to start — but you can also contact us and we will help.
3. What we collect
Information you give us
- Your name and email address when you register
- Your password, which we store only as a one-way hash and never in readable form
- Your alerts, saved searches, bookmarks and any notes you add
- Anything you send us by email or through the contact form
- Billing details, if you ever choose a paid plan — these go straight to Stripe and we never see or store your card number
Information we collect automatically
- The searches you run and how many results they returned
- Your IP address, used for rate limiting and abuse prevention
- Your browser and device type, and the pages you visit
- Sign-in times, used to show you your own account activity and to spot suspicious access
Information from third parties
- If you sign in with Google, we receive your name, email address and Google account identifier. We do not receive your Google password and we cannot access anything else in your Google account.
We do not collect special category data (such as health, religion or political opinions), and we ask you not to put any into free-text fields such as bookmark notes.
4. Why we use it, and our lawful basis
Under UK GDPR we must have a lawful basis for each purpose. Ours are set out below.
| What we do | Data used | Lawful basis |
|---|---|---|
| Creating and running your account, signing you in | Name, email, password hash, sign-in records | Contract — we cannot provide the service you asked for without it |
| Sending you the email alerts and digests you set up | Email, alert criteria, send history | Contract — the alert is the service you asked for |
| Verifying your email address and password resets | Email, one-time tokens | Contract, and legal obligation to keep accounts secure |
| Preventing bots, spam sign-ups and abuse of the service | IP address, request rate, bot-protection challenge results | Legitimate interests — keeping the service available and not being used as a spam relay |
| Understanding what people search for, to improve the product | Search terms and result counts, linked to your account for 90 days | Legitimate interests — improving a service you use |
| Website analytics | Pages viewed, device and browser, approximate location, a randomly generated analytics ID | Consent — set only if you accept analytics cookies, and withdrawable at any time |
| Generating AI analysis of a contract notice, when you request it | The public contract text only — not your name, email or account data | Contract — you asked for the analysis |
| Processing payment, if we ever introduce a paid plan you choose | Billing details, handled by Stripe; we store only a customer reference | Contract, and legal obligation to keep financial records |
| Responding to your support or privacy enquiries | Your message and contact details | Legitimate interests — answering the person who contacted us |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded it is not because the processing is limited, expected, and necessary to run a service you chose to use. You can object at any time — see section 10.
5. Cookies and analytics
Essential cookies keep you signed in, protect forms against cross-site request forgery, and remember display preferences such as list or grid view. These are strictly necessary to provide the service, so they are set without consent and cannot be turned off while you use the site.
Analytics cookies are set by Google Analytics and tell us which pages are used and how people move through the site. These are not set unless you accept them in the cookie banner. If you decline, or ignore the banner, no analytics cookies are set and no analytics data is sent.
You can change your choice at any time using the Cookie settings link in the footer. Declining analytics does not reduce your access to any feature.
We do not use advertising cookies, we do not run ad networks, and we do not share analytics data with advertisers.
6. Who we share it with
We do not sell your personal data. We share it only with service providers who process it on our instructions, under a contract that requires them to keep it confidential and secure:
| Provider | What they do for us | Where |
|---|---|---|
| Stripe | Payment processing (retained for any future paid plans) | USA |
| Postmark | Sending account, alert and digest emails | USA |
| Google Analytics | Website usage analytics, only where you consent to cookies | USA |
| Google (Sign in with Google) | Authenticating you if you choose to sign in with Google | USA |
| Anthropic | Generating AI analysis of a contract notice, where you request it. Only the public contract text is sent, never your account details | USA |
| Cloudflare | Bot protection on our sign-up and login forms (Turnstile), and DNS | USA / global network |
| Our server hosting provider | Running the application and storing the database | United Kingdom |
We also disclose personal data where we are legally required to — for example in response to a valid court order or a lawful request from a regulator or law enforcement — and where necessary to establish, exercise or defend legal claims.
7. If the business is sold or restructured
TenderTracker is currently operated by an individual. We may in future incorporate the business into a company, take on investment, merge with another business, or sell all or part of the business or its assets.
If that happens, personal data held about users would be disclosed to, and transferred to, the prospective or actual buyer or successor as part of the transaction, along with the accounts and data it relates to. We rely on our legitimate interests in being able to sell, restructure or transfer the business as a going concern.
Where that happens:
- Any disclosure to a prospective buyer during due diligence will be the minimum necessary, under a confidentiality agreement, and aggregated or pseudonymised wherever it can be
- The buyer or successor would become the controller of your data and would be bound to handle it in a way that is not materially less protective than this policy
- We will notify you by email, or by a prominent notice in the service, before or as soon as reasonably practicable after the transfer takes effect
- You may object to this processing, or simply delete your account, at any time — before or after a transfer
8. Sending data outside the UK
Some of our providers are based in the United States, as shown in the table in section 6. When personal data is transferred outside the UK, we rely on one of the safeguards permitted by UK data protection law — either a UK adequacy decision for the receiving country, or the UK International Data Transfer Agreement (or the EU Standard Contractual Clauses with the UK Addendum), combined with an assessment of the protections in place.
You can ask us for details of the safeguard used for a particular provider by emailing [email protected].
9. How long we keep it
- Account data(name, email, password hash) — for as long as your account exists. When you delete your account, the record is deleted immediately.
- Alerts, saved searches and bookmarks— until you delete them, or until you delete your account, whichever comes first.
- Search history— 90 days, then automatically deleted. It is also deleted when you delete your account.
- Email sending recordsheld by our email provider — in line with that provider’s own retention period, typically a matter of days to weeks.
- Analytics data— retained by Google Analytics for up to 14 months.
- Financial records, if you ever make a payment — six years, as required by UK tax law.
- Support correspondence— up to two years after the matter is closed.
Deleted data may persist briefly in encrypted backups, and is removed as those backups expire on their normal cycle. We do not restore deleted accounts from backup.
10. Your rights
Under UK GDPR you have the right to:
- Be informedabout how we use your data — this policy
- Access a copy of the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Eraseyour data ("the right to be forgotten")
- Restrict how we process your data
- Object to processing based on legitimate interests, including the business-transfer processing in section 7
- Data portability— receive your data in a structured, machine-readable format
- Withdraw consent at any time, where we rely on it (analytics cookies)
You can exercise the two most common rights yourself, immediately, from your account settings: Download your data gives you a complete JSON export, and Delete account erases everything.
For anything else, email [email protected]. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, or by calling 0303 123 1113. We would appreciate the chance to resolve it first.
11. Security
We take appropriate technical and organisational measures to protect your data, including encryption in transit (HTTPS with HSTS), passwords stored only as salted one-way hashes, restricted database access, rate limiting and bot protection on public endpoints, and regular dependency and security review.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and tell you directly without undue delay where the risk is high.
12. Automated decision-making
We do not make any decision that produces a legal or similarly significant effect on you by automated means alone. Alert matching and AI contract analysis are automated, but they only surface public information for you to read — they do not decide anything about you.
13. Children
The service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy. Each version has a version number and an effective date, and superseded versions stay available so you can see what changed.
For changes that materially affect how we use your personal data, we will give you at least 30 days’ notice by email to the address on your account, or by a prominent notice in the service, before they take effect.
15. Contact
Privacy questions and rights requests: [email protected].
Anything else: [email protected].