Privacy policy
Last updated: 2 July 2026
Written in plain language, because terms you cannot read protect nobody. Questions: ravid@tendervane.com.
1. Who is responsible
Tendervane (operated by its founder, Ravid Efroni) is the controller for personal data processed through tendervane.com and the Tendervane application. Contact for all privacy matters: ravid@tendervane.com.
2. What data we collect
- Account data: name, work email, authentication identifiers (via Clerk).
- Billing data: subscription status and invoices via Stripe. We never receive card numbers.
- Product data you enter: pipeline stages, notes, tasks, outcomes.
- Usage data: server logs and privacy-friendly, cookieless analytics (Vercel Analytics, PostHog EU).
- Session replays on our public marketing pages (PostHog EU): an anonymised recording of page interactions that helps us improve the site. Form inputs are masked, no cookies are set, and pages behind login are never recorded.
- Acquisition data: if you arrive via a campaign link (utm parameters), we keep the campaign name and landing page in your browser's local storage and, if you sign up within 30 days, store it with your workspace so we know which channel brought you. First party only: no advertising cookies, no click identifiers, nothing is shared back to the advertising platform.
- Professional contact details of contracting-authority staff, as published by those authorities themselves on official public procurement notices (TED, TenderNed).
3. Why we process it (purposes and legal bases)
- Providing the service you signed up for (performance of contract).
- Billing and account administration (performance of contract, legal obligation).
- Sending product emails such as digests and alerts you can configure (performance of contract).
- Service security, debugging and abuse prevention (legitimate interest: keeping the service safe).
- Displaying buyer contact details from public notices (legitimate interest: these are professional contacts published by public bodies for the purpose of market engagement).
4. Who receives data
Only the subprocessors needed to run the service, listed with their purposes on our security page: Vercel (hosting), Neon (database, EU), Clerk (authentication), Stripe (payments), Resend (email), Anthropic (AI processing of public notice text only). We do not sell personal data.
5. International transfers
Our database is hosted in the EU (Frankfurt). Some subprocessors may process limited data outside the EEA under their own GDPR transfer mechanisms (standard contractual clauses or adequacy decisions), per their data processing agreements.
6. Retention
Account and product data are kept while your account exists and deleted on request after cancellation. Billing records are kept as long as tax law requires. Operational logs are kept briefly.
7. Your rights
Under the GDPR you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. Email ravid@tendervane.com and we act on it. You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
8. Automated decision-making
We do not make automated decisions with legal or similarly significant effects about you. Opportunity scores and briefings concern public contracts, not people.
9. Security
See the security page for our practices: encryption in transit and at rest, EU hosting, minimal access.
10. Changes
We will update this policy as the service evolves and change the date above. Material changes will be announced by email.