Privacy notice
What we collect
- When you request a key: your e-mail address, the time, and the IP address the request came from.
- When you call the API: the time, the endpoint, your key's fingerprint (never the key itself in logs), the response status, and the IP address. The web server keeps standard access logs for the same purpose.
- Billing: if you move to a paid plan, our payment processor collects what it needs to charge you. We never see or store card numbers.
Activity we record
For every request made with your key we record the operation, its parameters, the number of results, the opportunity id where one applies, the units consumed, the status, the latency, the key fingerprint, the client name your AI sends and a hashed IP address. That is a record of what NextBid returned to you. We do not receive or store your AI's conversation, and we never copy document contents into request logs. An opportunity is marked as watched, pursued, submitted, won, lost or dropped only when you or your authorized agent tell us so through the API; reading a bid is never treated as pursuing it. Your business profile (trades, service areas, target markets, optional certifications) is what you choose to tell us. We use this activity to run your allowance, show your numbers on your account page, support you, and bill paid plans; the billing authority receives usage events with the same identifiers. You can read everything we hold about your account through the account endpoints, and ask us to delete it.
Why
To issue and operate keys, to meter and bill usage, to enforce quotas and rate limits, to investigate abuse and outages, and to contact you about your key, your plan, price changes or breaking changes. We do not sell your information and we do not use it for advertising.
Retention
Key records and usage ledgers are kept for as long as your key exists and for the period tax and accounting rules require afterwards. Access logs are rotated and kept for a short operational window. Closing your key removes it from service; ledger entries needed for accounting stay.
The data the API serves
The corpus consists of public procurement records published by government agencies, including the buyer contacts those agencies publish with each solicitation. We serve those contacts only in the context of their solicitation and prohibit their redistribution as lists (see the terms). If you are a buyer whose contact details appear in a record and you want them removed from the Service, email us and we will act on it.
Where it lives
The Service runs on servers in the United States. Backups of originals are stored with a US object-storage provider under encryption at rest.
Your rights and contact
You can ask what we hold about you, ask for it to be corrected or deleted, or close your key at any time: keys@nextbid.us. Residents of California and other jurisdictions with privacy laws have the rights those laws provide; we honour them on request.
NextBid