Privacy Policy
Last updated:
This page explains what Sell to State collects, why, and who else sees it. Plain language, no legalese. If something here is unclear, email us and we will fix the wording.
Who we are
Sell to State (selltostate.com) publishes public government contract award data and sells access to search, alerts, lists, and exports on top of it.
The tender record data itself comes from public government sources. It is not personal data we collected about you.
What we collect
1. When you just browse the site
We load PostHog analytics on our marketing pages. It records:
- pages you view and things you click
- your approximate location, derived from your IP address
- your browser, device type, and screen size
- a random visitor ID stored in a cookie so repeat visits are linked
PostHog is a US company. This data is stored on PostHog's US cloud.
We do not run ad-network trackers or sell this data.
2. When you ask us to add a page or send a note
Some pages have a "claim this page" form. We store the email address you type, the page you were on, your free-text note, and the time. Our staff read these in an internal admin panel.
3. When you create an account
We use BetterAuth for sign-in. Depending on how you sign up, we store:
- your email address and a password hash, or
- your account ID and basic profile from Google, GitHub, Microsoft, LinkedIn, Apple, if you use social sign-in, or
- a passkey (WebAuthn) credential
We also store sessions, email-verification tokens, and — if you connect Sell to State to another tool over our OAuth/MCP endpoint — the client registration for that tool.
We do not buy or run third-party "enrichment" on your email. No Apollo, no Clearbit, nothing similar. What you give us is what we have.
4. When you use the product
We store what you do, because the product needs it to work:
- saved searches, their filters, and how often you want alerts
- notifications we sent you
- export logs — which export you ran, when, and how many rows
- API keys, stored as a hash (we cannot read your key back)
- referral codes
- workspace invites you send
5. When you pay
Card details never touch our servers. Stripe handles payment. We store your Stripe customer ID, subscription ID, plan, status, trial end date, and totals billed.
6. Email
We send email through Resend — invites, alert digests, welcome and lifecycle messages. Our emails contain a tracking pixel and redirected links, so we can see whether a message was delivered, opened, clicked, bounced, or marked as spam.
One thing worth stating clearly: for email events that happen before you have an account, we send your lowercased email address to PostHog as the identifier for that event. So PostHog holds raw email addresses for those events. If that is not acceptable to you, ask us to delete them (see below) and do not open our emails.
We have no one-click unsubscribe link today. To stop hearing from us, reply to any message or email alerts@selltostate.com and we take you off the list by hand.
Who else sees your data
These are the companies that process data on our behalf:
| Company | What it handles |
|---|---|
| PostHog (US) | Product analytics, email-funnel events, support widget |
| Stripe | Payments and subscriptions |
| Resend | Outbound email |
| Railway | Our servers and Postgres database |
| Cloudflare | CDN, R2 storage, serving the public site |
| Typesense | Search index |
| Google / GitHub / Microsoft / LinkedIn / Apple | Only if you choose social sign-in |
We do not sell your personal data and we do not share it with advertisers or data brokers.
Data you send out yourself
If you set up an integration, we push your data where you tell us to — your webhook, your Google Sheet, or a scheduled CSV. That destination is yours. Once the data leaves, their privacy terms apply, not ours.
Cookies
We use cookies for two things:
- Keeping you signed in.
- PostHog analytics — a cookie holding a random visitor ID.
That's it. No advertising cookies. You can block cookies in your browser; sign-in will stop working if you do.
Company names and logos
We name real organisations in our marketing, since the underlying data is public. If you want your organisation's name or logo removed from our marketing material, email us. The rules for this are in the "Use of your name and logo in our marketing" section of our Terms & Conditions.
How long we keep things
- Account and product data — while your account exists, then deleted within 30 days of you closing it.
- Billing records — kept up to 7 years, because tax and accounting rules require it.
- Analytics events in PostHog — kept under PostHog's default retention; we do not extend it.
- Claim-form notes and email logs — 24 months.
- Anonymous, aggregated counts (e.g. "how many searches ran last month") — kept indefinitely. These cannot be traced back to you.
Your rights
You can ask us to:
- Show you everything we hold about you
- Correct anything wrong
- Delete your account and data
- Export your data in a machine-readable file
- Stop emailing you — reply to any message from us, or email the address below, and we take you off the list
Email alerts@selltostate.com. We reply within 30 days. We do not require a lawyer's letter or a specific format — just tell us what you want.
All of these are manual today: you email us and a human does it. There is no self-serve account-deletion or data-export button. You can delete a workspace yourself from settings, but that removes the workspace's contents, not your account.
Security
Passwords are hashed. API keys are hashed. Traffic runs over HTTPS. Database access is limited to the people who need it.
We are not going to claim certifications we do not hold. We have no SOC 2 report and no ISO certification today. If that matters for your procurement process, ask us and we'll tell you exactly where we stand.
Children
Sell to State is a business tool. It is not for anyone under 16, and we do not knowingly collect their data.
Where data lives
Our servers and database run on Railway. Analytics data sits in PostHog's US cloud. If you are in the EU or UK, your data will be processed in the United States.
Changes to this page
If we change how we handle data, we update this page and change the "Last updated" date. For changes that meaningfully affect you, we email account holders.
Contact
Tell us what you need. A plain email is enough.