Contact us: hello@rfpm.ai
Privacy Policy
Last updated: September 15, 2025
At RFPM ("we," "our," or "us"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Request for Proposals Management platform and related services.
1. Information We Collect
1.1 Information You Provide to Us
- Account Information: Name, email address, company name, and contact details.
- Profile Information: Optional details such as preferences.
- Content and Documents: RFPs, proposals, resumes, and other uploaded or created content.
- Communication Data: Support messages, feedback, and surveys.
- Payment Information: Billing details processed via third-party providers. We do not store credit card numbers.
1.2 Information We Collect Automatically
- Usage Data: Features used, time spent, and user interactions.
- Device Information: Browser, IP address, OS, and device type.
- Log Data: Access times, pages visited, and system logs.
- Tracking: To enhance experience and perform analytics.
2. How We Use Your Information
2.1 Service Provision
- Maintain and improve the platform
- Authenticate users via Clerk
- Generate proposal content using AI models (e.g., OpenAI, Gemini)
- Enable collaboration features
- Provide support
2.2 Communication
- Send service updates and notifications
- Respond to inquiries
- Send optional marketing emails
2.3 Analytics and Improvement
- Analyze trends and usage patterns
- Improve algorithms and features
- Generate anonymized insights
2.4 Legal and Security
- Fulfill legal obligations
- Protect against fraud or abuse
- Enforce policies and resolve disputes
3. Information Sharing and Disclosure
We do not sell or trade your data. We only share information with:
3.1 Service Providers
- Authentication: Clerk
- Hosting: Vercel
- Storage: Upstash Redis, Neon Postgres, Vercel Blob
- Other: Email, analytics, and support tools
3.2 Business Transfers
If RFPM undergoes a business change (merger, acquisition, etc.), data may be transferred.
3.3 Legal Requirements
We may disclose data when legally required.
3.4 Internal Collaboration
Your firm data may be shared internally based on access permissions.
3.5 AI Processing
Documents may be sent to LLM providers for parsing or generating responses. Identifiers are minimized or anonymized when possible.
3.6 Messaging Disclosures
RFPM Technologies, LLC may disclose Personal Data and other information as follows:
- Third Parties that Help Provide the Messaging Service: We will not share your opt-in to an SMS short code campaign with a third party for purposes unrelated to supporting you in connection with that campaign. We may share your Personal Data with third parties that help us provide the messaging service, including, but not limited to, platform providers, phone companies, and other vendors who assist us in the delivery of text messages.
- Additional Disclosures – Affiliates: We may disclose the Personal Data to our affiliates or subsidiaries; however, if we do so, their use and disclosure of your Personal Data will be subject to this Policy.
- All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
4. Data Security
4.1 Technical Measures
- Encryption in transit and at rest via third-party providers
- Multi-factor authentication via Clerk
- Secure deployment and infrastructure practices
4.2 Administrative Measures
- Role-based access controls
- Staff training
- Incident response protocol
4.3 Physical Safeguards
- Secure cloud infrastructure (e.g., Vercel, Upstash, Neon)
- Redundancy and recovery plans
5. Data Retention
- Account Data: Kept as long as account is active
- Uploaded Files: Retained per your subscription and deletion requests
- Analytics: Retained up to 2 years
- Legal: Retained as required
6. Your Rights and Choices
- Access & Portability: Request and receive your data
- Correction: Update inaccurate information
- Deletion: Request deletion of your account and content
- Restriction & Objection: Limit or object to processing
- Marketing: Opt out of promotional emails
Requests can be sent to: contact@rfpm.ai
7. International Data Transfers
Your data may be processed in countries outside your own. Safeguards include:
- Standard Contractual Clauses
- Adequacy decisions
8. Children’s Privacy
RFPM does not target or knowingly collect data from individuals under 13 years of age.
9. California Privacy Rights
Residents of California are entitled to:
- Know what data is collected
- Request deletion
- Opt-out of data selling (RFPM does not sell data)
- Non-discrimination rights
10. European Privacy Rights
Under GDPR, EEA/UK users have rights similar to Section 6. Our legal bases include:
- Contractual necessity
- Legitimate interests
- Consent
- Legal obligation
11. Cookies and Tracking Technologies
Cookies are used to:
- Save preferences
- Enable platform functionality
- Analyze behavior
You may manage cookie settings in your browser.
12. Third-Party Links
Our platform may link to third-party websites. We are not responsible for their data practices.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Notification methods include:
- Posting on our site
- Email notices
- In-app updates
Continued use of our platform after updates signifies consent.
14. Contact
For any inquiries or requests:
Email: contact@rfpm.ai
EU/UK users may also contact our Data Protection Officer via the same address.
15. Effective Date
This Privacy Policy is effective as of September 15, 2025.