Privacy policy
Last updated TODO: Month D, YYYY. Applies to users in the United States.
TODO before the Stripe account goes live: fill in the retention periods in section 8, and have counsel confirm the California disclosures in sections 3 and 10 against the business's current size — some CCPA obligations only attach once revenue or data-volume thresholds are met, though the disclosures below are written to hold either way.
1. Scope
This policy explains what TODO: registered legal entity name collects when you use Glass Bid at https://glassbid.spenserandreassen.com, why, who it is shared with, and what you can ask us to do about it.
Glass Bid is offered only in the United States, to businesses, and application data is stored in the United States. The personal information involved is work contact information — we do not build consumer profiles, we do not use your data for advertising, and we do not use it to train machine-learning models.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising — including the specific meanings California law gives those terms. We have not done so in the preceding 12 months.
2. What we collect
- Identity, from your Google sign-in. Authentication is handled by Google Firebase Authentication. We receive and store a Firebase user ID, your email address, and your display name; your profile photo is shown from Google but not stored by us. We never see your Google password.
- Organization and membership. Your organization's name and account type (glazing contractor or vendor), your role in it, and any request you make to join one.
- Marketplace content you create. Requests for quote — title, description, spec section, the date pricing is needed by, and the vendors invited — and the bids submitted in response, including quote values and reasons. Each record stores the name and email of the person who created it.
- Billing data. Payments are processed by Stripe. Stripe collects your card details directly; we never receive or store a full card number. We store your organization's subscription status, term dates, and cancellation date.
- An audit trail. Actions that change data are recorded with who did it, on whose behalf, what it affected, when, and whether it succeeded. This is a deliberate integrity record, particularly for actions our staff take on an organization's behalf (see section 6). It is a record we keep for ourselves, not a guarantee we make to you: we do not fail your action if the record cannot be written, so the trail is not certified complete.
- Technical and diagnostic data. Server request traces, error logs, and performance metrics, which include IP address, browser user agent, and the URLs requested.
- What you send us. Correspondence with customer service.
3. Categories, sources, and purposes
The same information, stated in the categories California law uses, with where it comes from and why we hold it.
| Category | What that means here | Where it comes from | Why we hold it |
|---|---|---|---|
| Identifiers | Name, work email, Firebase user ID, IP address | Your Google sign-in; your organization's admins | Signing you in; attributing your activity; security |
| Commercial information | Subscription status and term dates, payment records | You, and Stripe | Billing, refunds, and disputes |
| Professional information | The organization you belong to and your role in it | You, and your organization's admins | Deciding what you may see and do |
| Internet or network activity | Request traces, error logs, browser type, pages requested | Automatically, as you use the application | Keeping the service working and secure |
| Approximate location | Coarse location inferred from IP address | Automatically, in diagnostic data | Diagnosing faults and detecting abuse |
| Your content | Requests for quote, bids, and the messages you send us | You | Operating the marketplace and supporting you |
Sensitive personal information. We do not collect it. We do not ask for government identifiers, financial account numbers, precise geolocation, health data, biometrics, or the contents of your private communications, and we do not infer characteristics from anything we hold.
4. Why we use it
- To operate the marketplace — authenticating you, showing you your organization's requests and bids, and delivering requests to the vendors they are addressed to.
- To bill and support vendor subscriptions, and to handle refunds and disputes.
- To keep the service secure and working — detecting abuse, diagnosing faults, and investigating what happened when something goes wrong.
- To meet legal, tax, accounting, and sanctions-screening obligations.
We do not use your information for any materially different purpose without telling you first.
5. What other users see
Glass Bid exists to put two companies in touch, so some of your information is deliberately visible to others:
- A subscribed vendor organization's name appears in the vendor directory, which any signed-in user can browse.
- A vendor you send a request for quote to sees your organization's name and the request's contents, and the name and email of the person who sent it.
- A contractor sees the name of any vendor organization that bids on their request, along with the bid.
- Admins of your organization can see its members' names and email addresses, and any pending requests to join.
Treat drawings, specifications, and pricing you upload as shared with the organizations you send them to. We do not make marketplace content public or available to search engines. Disclosing your information to another organization this way is not a sale — we receive nothing for it, and it is what you asked the service to do.
6. Access by our staff
Staff of TODO: registered legal entity name can, for support and demonstration purposes, use the application as a member of an organization. Such actions are written to the audit trail against the real staff member's identity, not the organization's, so they are attributable to the person who took them rather than to you. We restrict this to staff who need it.
7. Who we share it with
Beyond the other organizations described in section 5, we use these service providers, and share only what each needs to do its job. Each is bound by contract to use the information only to provide its service to us:
- Google (Firebase Authentication) — sign-in and identity.
- Microsoft Azure — application hosting and the database, in a United States region.
- Stripe — payment processing, subject to Stripe's own privacy policy.
- New Relic — application performance monitoring and error diagnostics.
We also disclose information where the law requires it or in response to valid legal process, and to professional advisers or an acquirer in connection with a sale of the business (we would tell you first). Our providers are national or global companies and may process data outside the United States in the course of operating their own infrastructure.
8. How long we keep it, and security
- Account and organization records — for as long as the account is open. After a deletion request we remove them within TODO: e.g. 30 days.
- Requests for quote and bids — kept as the commercial record of a transaction between two organizations. Because they are shared records, we cannot delete one organization's copy on the other's request; when an organization is closed, its records are retained but hidden from the directory and from new activity.
- Audit trail — TODO: e.g. 24 months. It is append-only by design and is not edited on request.
- Billing records — as long as tax and accounting law requires.
- Diagnostic data — for the retention window configured with our monitoring provider, which is short.
Traffic is encrypted in transit (HTTPS) and data is encrypted at rest. Sign-in is delegated to Google; we hold no passwords. The application reaches the database using a managed identity rather than shared keys, and staff access is limited to those who need it. No system is perfectly secure. If a breach affects your personal information we will notify you, and the authorities where required, in line with the breach notification law of your state.
9. Cookies, browser storage, and opt-out signals
We use no advertising or analytics cookies and no third-party trackers. The application stores your Firebase sign-in session in your browser so you stay signed in, and — for platform staff only — which organization is being acted as. Both are functional and cannot be turned off without breaking sign-in.
Because we neither sell nor share personal information, there is nothing for a browser opt-out preference signal such as Global Privacy Control to opt out of. We honor those signals in the sense that our behavior already matches them.
10. Your privacy rights
California residents have the rights below under the California Consumer Privacy Act. Several other states give their residents similar rights, though most of those laws do not cover people acting for a business. Rather than treat users differently by state, we extend all of these rights to every user in the United States:
- Know what personal information we have collected about you, where it came from, why, and who we disclosed it to.
- Access a copy of it in a portable form.
- Correct inaccurate personal information.
- Delete personal information we hold about you, subject to the limits in section 8 and to records we must keep by law.
- Opt out of sale or sharing — we do neither, so there is nothing to opt out of, and we provide no "Do Not Sell or Share My Personal Information" link for that reason.
- Limit the use of sensitive personal information — we collect none.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights.
How to make a request. Email TODO: privacy@your-domain from the address on your account, or write to us at the address in section 13. We confirm receipt within 10 business days and respond within 45 days; if we need more time we will tell you why and may take up to another 45 days.
Verification. We verify a request by matching it to the email address on the account, and may ask you to confirm details only the account holder would know. We do this to avoid handing your information to someone else. An authorized agent may act for you if they provide your written permission; we may still verify with you directly.
Two practical limits. We cannot delete records that are shared with another organization, and we do not alter the audit trail — both are explained in section 8. You can leave your organization, or ask an admin to remove you, from within the application at any time.
11. Children
Glass Bid is for business use by people aged 18 or over. It is not directed at children, we do not knowingly collect information from anyone under 16, and we do not sell or share the information of minors (we do not sell or share anyone's). If you believe a child has given us personal information, email us and we will delete it.
12. Changes
We will post any update here and change the date at the top. If a change materially affects how we use your information, we will email organization admins at least 30 days beforehand.
13. Contact
TODO: registered legal entity name
TODO: Street address
TODO: City, State ZIP
United States
TODO: privacy@your-domain ·
TODO: +1 (555) 555-0100