CanadianBids.ai ("we," "us," or "our") operates the website at canadianbidsai.ca and provides AI-powered Canadian procurement intelligence services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
By using our platform, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide
When you create an account or use our services, we collect:
- Account information: email address and password (encrypted)
- Company profile: company name, province, website URL, description, employee count, typical contract size range, keywords, industry categories, service/goods/construction types, certifications, security clearance level, provinces of operation, supply arrangement registrations, bonding capacity, and licensed trades
- Payment information: processed securely by Stripe — we do not store credit card numbers, CVVs, or full card details on our servers
- Communication preferences: email alert and notification settings
1.2 Information Collected Automatically
- Usage data: pages visited, features used, tenders viewed and saved, search queries, and session duration
- Device information: browser type, operating system, screen resolution, and IP address
- Cookies: session tokens for authentication (see Section 7)
1.3 Information from Public Sources
We use publicly available Canadian federal procurement data from CanadaBuys (canadabuys.canada.ca), including contract award history, tender notices, and supplier information published by the Government of Canada under its Open Data licence. This data is used to pre-populate company profiles during onboarding and to power our matching engine.
2. How We Use Your Information
We use your personal information for the following purposes:
- AI-powered matching: Your company profile is processed by our matching engine — which uses keyword analysis, AI semantic scoring, and historical contract pattern analysis — to match you with relevant government tenders
- Account management: to create and maintain your account, authenticate your sessions, and manage your subscription
- Service improvement: to understand how users interact with our platform and improve features
- Communications: to send you tender match alerts, closing deadline reminders, and account-related notifications you have opted into
- Payment processing: to process subscription payments through Stripe
- Legal compliance: to comply with applicable laws and respond to lawful requests
3. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only with third-party service providers who are necessary to operate our platform and run our matching algorithm. Each provider is contractually obligated to protect your data and use it only for the services they provide to us.
We may also disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4. Data Storage and Security
Your data is stored on servers operated by Supabase (cloud infrastructure). We implement the following security measures:
- Passwords are hashed and never stored in plaintext
- All data transmission uses TLS/SSL encryption (HTTPS)
- Authentication tokens are securely managed with automatic expiration and refresh
- Database access is restricted by Row Level Security (RLS) policies
- API endpoints are protected by authentication and secret-based access controls
- Payment data is handled entirely by Stripe — a PCI DSS Level 1 certified provider
While we take reasonable measures to protect your data, no system is 100% secure. We encourage you to use a strong, unique password for your account.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our services. Specifically:
- Account and profile data: retained until you delete your account
- Match history: recalculated regularly; previous matches are overwritten
- Payment records: retained as required for tax and legal purposes (typically 7 years)
When you delete your account, we delete your profile data and match records from our database. Some data may persist in encrypted backups for a limited period.
6. Your Rights Under PIPEDA
Under Canadian privacy law, you have the right to:
- Access the personal information we hold about you
- Correct any inaccurate or incomplete information — you can update your profile at any time through the platform
- Withdraw consent for data processing — you can adjust notification preferences or delete your account
- Request deletion of your personal information — use the "Delete Account" feature in your profile settings or contact us directly
- File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated
To exercise any of these rights, contact us at julie@getcanadianbidsai.com. We will respond to requests within 30 days.
7. Cookies and Tracking
We use the following cookies and similar technologies:
- Essential cookies: authentication session tokens required for the platform to function — these cannot be disabled
We do not use advertising cookies or analytics tracking cookies. You can manage cookies through your browser settings, though disabling essential cookies will prevent you from using the platform.
8. Third-Party Links
Our platform contains links to external websites, including CanadaBuys (canadabuys.canada.ca) and other Government of Canada procurement portals. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
9. Children's Privacy
Our services are intended for business use and are not directed at individuals under 18 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users or by posting a prominent notice on our website. The "Effective Date" at the top of this page indicates when the policy was last revised.
11. Contact Us
CanadianBids.ai
Email: julie@getcanadianbidsai.com