↑↓ navigate open esc close
← Back

Privacy Policy

Last updated:

This page explains what Sell to State collects, why, and who else sees it. Plain language, no legalese. If something here is unclear, email us and we will fix the wording.

Who we are

Sell to State (selltostate.com) publishes public government contract award data and sells access to search, alerts, lists, and exports on top of it.

The tender record data itself comes from public government sources. It is not personal data we collected about you.

What we collect

1. When you just browse the site

We load PostHog analytics on our marketing pages. It records:

  • pages you view and things you click
  • your approximate location, derived from your IP address
  • your browser, device type, and screen size
  • a random visitor ID stored in a cookie so repeat visits are linked

PostHog is a US company. This data is stored on PostHog's US cloud.

We do not run ad-network trackers or sell this data.

2. When you ask us to add a page or send a note

Some pages have a "claim this page" form. We store the email address you type, the page you were on, your free-text note, and the time. Our staff read these in an internal admin panel.

3. When you create an account

We use BetterAuth for sign-in. Depending on how you sign up, we store:

  • your email address and a password hash, or
  • your account ID and basic profile from Google, GitHub, Microsoft, LinkedIn, Apple, if you use social sign-in, or
  • a passkey (WebAuthn) credential

We also store sessions, email-verification tokens, and — if you connect Sell to State to another tool over our OAuth/MCP endpoint — the client registration for that tool.

We do not buy or run third-party "enrichment" on your email. No Apollo, no Clearbit, nothing similar. What you give us is what we have.

4. When you use the product

We store what you do, because the product needs it to work:

  • saved searches, their filters, and how often you want alerts
  • notifications we sent you
  • export logs — which export you ran, when, and how many rows
  • API keys, stored as a hash (we cannot read your key back)
  • referral codes
  • workspace invites you send

5. When you pay

Card details never touch our servers. Stripe handles payment. We store your Stripe customer ID, subscription ID, plan, status, trial end date, and totals billed.

6. Email

We send email through Resend — invites, alert digests, welcome and lifecycle messages. Our emails contain a tracking pixel and redirected links, so we can see whether a message was delivered, opened, clicked, bounced, or marked as spam.

One thing worth stating clearly: for email events that happen before you have an account, we send your lowercased email address to PostHog as the identifier for that event. So PostHog holds raw email addresses for those events. If that is not acceptable to you, ask us to delete them (see below) and do not open our emails.

We have no one-click unsubscribe link today. To stop hearing from us, reply to any message or email alerts@selltostate.com and we take you off the list by hand.

Who else sees your data

These are the companies that process data on our behalf:

CompanyWhat it handles
PostHog (US)Product analytics, email-funnel events, support widget
StripePayments and subscriptions
ResendOutbound email
RailwayOur servers and Postgres database
CloudflareCDN, R2 storage, serving the public site
TypesenseSearch index
Google / GitHub / Microsoft / LinkedIn / AppleOnly if you choose social sign-in

We do not sell your personal data and we do not share it with advertisers or data brokers.

Data you send out yourself

If you set up an integration, we push your data where you tell us to — your webhook, your Google Sheet, or a scheduled CSV. That destination is yours. Once the data leaves, their privacy terms apply, not ours.

Cookies

We use cookies for two things:

  1. Keeping you signed in.
  2. PostHog analytics — a cookie holding a random visitor ID.

That's it. No advertising cookies. You can block cookies in your browser; sign-in will stop working if you do.

Company names and logos

We name real organisations in our marketing, since the underlying data is public. If you want your organisation's name or logo removed from our marketing material, email us. The rules for this are in the "Use of your name and logo in our marketing" section of our Terms & Conditions.

How long we keep things

  • Account and product data — while your account exists, then deleted within 30 days of you closing it.
  • Billing records — kept up to 7 years, because tax and accounting rules require it.
  • Analytics events in PostHog — kept under PostHog's default retention; we do not extend it.
  • Claim-form notes and email logs — 24 months.
  • Anonymous, aggregated counts (e.g. "how many searches ran last month") — kept indefinitely. These cannot be traced back to you.

Your rights

You can ask us to:

  • Show you everything we hold about you
  • Correct anything wrong
  • Delete your account and data
  • Export your data in a machine-readable file
  • Stop emailing you — reply to any message from us, or email the address below, and we take you off the list

Email alerts@selltostate.com. We reply within 30 days. We do not require a lawyer's letter or a specific format — just tell us what you want.

All of these are manual today: you email us and a human does it. There is no self-serve account-deletion or data-export button. You can delete a workspace yourself from settings, but that removes the workspace's contents, not your account.

Security

Passwords are hashed. API keys are hashed. Traffic runs over HTTPS. Database access is limited to the people who need it.

We are not going to claim certifications we do not hold. We have no SOC 2 report and no ISO certification today. If that matters for your procurement process, ask us and we'll tell you exactly where we stand.

Children

Sell to State is a business tool. It is not for anyone under 16, and we do not knowingly collect their data.

Where data lives

Our servers and database run on Railway. Analytics data sits in PostHog's US cloud. If you are in the EU or UK, your data will be processed in the United States.

Changes to this page

If we change how we handle data, we update this page and change the "Last updated" date. For changes that meaningfully affect you, we email account holders.

Contact

alerts@selltostate.com

Tell us what you need. A plain email is enough.

Sign Up