Skip to main content
BidChamp
Platform How it works Pricing Sign in
Book a call Start free trial
LEGAL

Privacy Policy

Effective: 2026-05-10  ·  Last updated: 2026-08-21

This Privacy Policy describes how Tomsons Digital LLC ("BidChamp," "we," "us," or "our"), a limited liability company registered in Georgia (Identification Number: 412798110), collects, uses, stores, and shares information about you when you use the BidChamp software-as-a-service platform available at https://bidchamp.ai and related services (collectively, the "Service").

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.


1. Information we collect

1.1 Information you provide

When you create an account, use the Service, or contact us, we collect:

  • Account information: name, email address, password (hashed), company name, role
  • Profile information: company UEI, CAGE code, NAICS codes, set-aside certifications, physical address, phone number, federal contracting experience
  • Billing information: name on card, billing address, partial card number (last 4 digits), card expiration. Full card details are collected and stored exclusively by our payment processor (Fastoo / LLC New Payment System) - we do not store full payment card numbers on our servers
  • Communications: messages you send us via email, support tickets, or in-app chat
  • Past performance documents: federal contract narratives, capability statements, and other materials you upload

1.2 Information collected automatically

When you use the Service, we automatically collect:

  • Usage data: pages viewed, features used, opportunities scored, proposals drafted, time spent
  • Device data: IP address, browser type, operating system, device identifiers
  • Cookies and similar technologies: session cookies for authentication; analytics cookies (only if you consent)

1.3 Information from third parties

  • SAM.gov data: when you provide your UEI, we retrieve corresponding public registration data from SAM.gov (via GovCon API) to populate your profile and Past Performance library
  • Payment events: Fastoo provides us with transaction status, failure codes, and authorization events related to your subscription

2. How we use your information

We use information to:

  • Provide, maintain, and improve the Service
  • Process subscription payments and manage your account
  • Score federal contracting opportunities, extract Section L requirements, and draft proposals using AI
  • Send you transactional emails (account changes, payment receipts, subscription renewals, security notifications)
  • Send you marketing emails about new features (you can unsubscribe anytime; we do not send promotional emails to users who have opted out)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations (tax reporting, regulatory inquiries, law enforcement requests)
  • Conduct analytics to understand product usage patterns

3. AI processing of your data

The Service uses AI models (provided by Anthropic, Inc. - Claude API) to score opportunities, extract requirements from solicitations, and draft proposal content. When you use AI features:

  • Your input (RFP text, profile data, questions to AI Advisor) is sent to Anthropic for processing
  • Anthropic does not use your data to train its models per Anthropic's API terms
  • AI-generated outputs are stored in your account for your reference
  • We do not use your account data to train any AI models

4. How we share your information

We do not sell your personal information. We share information only with:

4.1 Service providers (data processors)

ProviderPurposeData sharedLocation
Fastoo / LLC New Payment SystemPayment processingPayment card data, transaction details, nameGeorgia
Anthropic, Inc.AI processing (Claude API)Prompts, profile context, RFP textUnited States
ResendTransactional + marketing email deliveryEmail address, name, message contentUnited States
DigitalOcean, Inc.Cloud hosting and infrastructureAll Service data (encrypted at rest)United States
GovCon API (govconapi.com)Federal contract data + SAM entity lookupYour UEI (read-only lookup)United States
Google LLCWeb analytics (Google Analytics 4). Cookieless by default and only sets cookies after you accept. Receives the page URL and referrer; on pages whose link carries a security token (password reset, email verification, invitation acceptance) it receives only the path with no tokenPage URL (path only on token pages), referrer, page title, anonymous usage eventsUnited States
Cloudflare, Inc.Web analytics (Cloudflare Web Analytics). Cookieless; sets no cookies and does not track across sites. Does not load on pages whose link carries a security tokenPage URL, referrer, aggregate visit metricsUnited States
Microsoft CorporationProduct analytics and session replay (Microsoft Clarity). For visitors in the EU/EEA/UK/Switzerland (or with a Global Privacy Control signal) it loads only after you accept; elsewhere it loads on page load in a cookie-free mode and sets cookies only if you accept. Uses strict text masking so typed text and any opportunity, RFP, or proposal text is masked. Does not load on pages whose link carries a security tokenPage URL, masked interaction and layout dataUnited States
Meta Platforms, Inc.Ad-conversion measurement (Meta Pixel). Page visits on public pages load on page load; for visitors in the EU/EEA/UK/Switzerland (or with a Global Privacy Control signal) they load only after you accept. It never loads on pages whose link carries a security token (password reset, email verification, invitation acceptance). Inside the app, only specific conversion events fire (account creation, search, viewing a tender, subscribing); the app's page navigation and your opportunity/RFP/proposal content are never sentPage visits on public pages; conversion events (registration, search terms, viewed tender id, subscription plan/value)United States
LinkedIn Corporation (a Microsoft company)Advertising measurement and retargeting via the LinkedIn Insight Tag (snap.licdn.com). Measures which LinkedIn ad campaigns lead to signups, and builds retargeting audiences. Unlike the Meta Pixel, the Insight Tag runs on every page including the signed-in app, because audience building and retargeting require the full visit stream. It never loads on pages whose link carries a security token (password reset, email verification, invitation acceptance). In regions where consent is legally required it does not load at all unless you accept the banner. Elsewhere it loads on page load, before the banner can be answered: if you then choose Decline, we send LinkedIn nothing further from that moment on (no conversion signal and no further page visit) and the tag does not load again on any later visit, but the page visit already recorded for the page you were on, and any cookie the tag has already set, cannot be recalled. We do not send names, email addresses, or any profile fields to LinkedIn - only page visits and a conversion signal on completed registration.Page visits (all pages including signed-in app); conversion signal on completed registrationUnited States
JSC Bank of GeorgiaBank account operations for the CompanyAggregated transaction settlement dataGeorgia

These providers process data only on our instructions and are bound by confidentiality and data-protection obligations.

4.2 Legal disclosure

We may disclose information if required by law, valid government request, or to protect the rights, property, or safety of BidChamp, our users, or the public.

4.3 Business transfers

If BidChamp is acquired or merged, your information may be transferred to the acquirer, subject to this Privacy Policy.


5. International data transfers

You may be located outside Georgia. By using the Service, you understand that information we collect will be transferred to and processed in the United States, Georgia, and other countries where our service providers operate. We use appropriate safeguards (encryption in transit and at rest) to protect your information during transfer.


6. Your rights

Depending on your location, you have the following rights regarding your personal data:

6.1 All users

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate data
  • Deletion: request deletion of your account and associated data (subject to legal retention requirements)
  • Export: request your data in a portable format (CSV/JSON)

6.2 European Union / EEA / UK users (GDPR)

In addition to above:

  • Restrict processing: request that we limit how we process your data
  • Object: object to processing based on legitimate interests or for direct marketing
  • Data portability: receive data in machine-readable format
  • Lodge complaint: file a complaint with your local data protection authority

6.3 California users (CCPA/CPRA)

In addition to general rights:

  • Know: request disclosure of categories of personal information collected, sold, or disclosed
  • Opt-out of sale/sharing: we do not sell your personal information; opt-out not applicable
  • Non-discrimination: we will not deny service or charge different prices based on exercising your rights

6.4 Georgian users (Georgian Personal Data Protection Law)

Rights under the Law of Georgia on Personal Data Protection apply, including data subject rights to access, correction, deletion, blocking, and objection.

To exercise any rights, contact us through our contact form. We will respond within 30 days.


7. Data retention

  • Account data: retained while your account is active and for 12 months after account closure (or longer if required by law - e.g., 6 years for tax records under Georgian law)
  • Payment records: retained for 6 years for tax and accounting purposes
  • Past performance documents: retained while your account is active; deleted within 30 days of account closure (or upon your earlier request)
  • AI-generated proposal content: retained while your account is active as part of your proposals; deleted within 30 days of account closure
  • Server logs: retained for 30 days then deleted

8. Security

We implement reasonable technical and organizational measures to protect your information:

  • HTTPS/TLS encryption for all data in transit
  • Encryption at rest for sensitive data
  • Bcrypt password hashing
  • Rate limiting and DDoS protection
  • Regular security reviews and dependency updates
  • Access controls limiting employee access to user data on a need-to-know basis
  • Payment card data is processed by Fastoo (PCI-DSS compliant); we do not store full card numbers

No security system is impenetrable, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.


9. Children's privacy

The Service is not intended for individuals under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a minor, contact us immediately and we will delete it.


10. Cookies and analytics

We use cookies for:

  • Essential cookies: authentication, session management (cannot be disabled - required for the Service to function)
  • Analytics cookies: understanding feature usage (only with your consent on first visit)

We use the following analytics providers to understand aggregate, real-human usage of the site:

  • Cloudflare Web Analytics: cookieless. It sets no cookies and does not track you across sites, so it runs by default and is not covered by the consent choice below. It does not load on pages whose link carries a security token (password reset, email verification, invitation acceptance).
  • Google Analytics 4: uses cookies. It loads in a consent-denied, cookieless state by default and only sets analytics cookies after you accept. On pages whose link carries a security token (password reset, email verification, invitation acceptance) it still loads, but it receives only the page path with no token, and any referrer that itself carries a token is stripped to its path before it is sent.
  • Microsoft Clarity: uses cookies. It provides heatmaps and session replays. If you are in the EU, EEA, UK, or Switzerland, or your browser sends a Global Privacy Control signal, it does not load at all unless you accept. Elsewhere it loads on page load in a cookie-free mode: it sets no Clarity cookie and cannot link your visit to any other visit, and it sets cookies only if you then accept. If you decline, we tell Clarity to erase any cookie it has set and to stop tracking, and it does not load again on any later visit. Replays use strict text masking, so text content (including anything you type or any opportunity, RFP, or proposal text) is masked and not captured in readable form. It does not load on pages whose link carries a security token (password reset, email verification, invitation acceptance).
  • Meta Pixel: uses cookies. It measures ad conversions. On our public marketing pages it records a page visit (loading on page load, or, if you are in the EU, EEA, UK, or Switzerland or your browser sends a Global Privacy Control signal, only after you accept). Inside the signed-in app it sends only specific conversion events (creating an account, running a search, opening a tender's detail, and subscribing); it never sends the app's page navigation, and it never sends your opportunity, RFP, or proposal content. It never loads on pages whose link carries a security token (password reset, email verification, invitation acceptance).
  • LinkedIn Insight Tag: uses cookies. It measures which LinkedIn ad campaigns lead to signups and builds retargeting audiences. Unlike the tools above, it runs on every page including the signed-in app - LinkedIn audience building and retargeting require the full visit stream. It never loads on pages whose link carries a security token (password reset, email verification, invitation acceptance). In regions where consent is legally required it does not load at all unless you accept. Elsewhere it loads on page load, before the banner can be answered: if you then choose Decline, we send LinkedIn nothing further from that moment on (no conversion signal and no further page visit) and the tag does not load again on any later visit, but the page visit already recorded for the page you were on, and any cookie the tag has already set, cannot be recalled. We do not send names, email addresses, or any profile fields to LinkedIn.

On your first visit a consent banner lets you Accept or Decline analytics cookies. Google Analytics loads in a consent-denied, cookieless state and sets analytics cookies only if you Accept. Microsoft Clarity, the LinkedIn Insight Tag, and the Meta Pixel do not load at all for visitors in the EU, EEA, UK, or Switzerland (or with a Global Privacy Control signal) unless you Accept; everywhere else they load on page load, with Clarity in a cookie-free mode until you Accept. If you Decline, we immediately stop firing the Meta Pixel and the LinkedIn Insight Tag - no further page visit and no further conversion event is sent, on that visit or any later one - Google Analytics returns to its consent-denied state, and we tell Microsoft Clarity to erase its cookies and stop tracking; because outside consent-required regions the two ad tags load on page load, the one page visit sent before you answered the banner, and any cookie they already set, cannot be recalled. Your choice is remembered on your device. On pages whose link carries a security token (password reset, email verification, invitation acceptance) none of these tools receive the token: the Meta Pixel, the LinkedIn Insight Tag, Cloudflare Web Analytics, and Microsoft Clarity do not load there at all, and Google Analytics receives only the page path with no token. You can also control cookies via your browser settings. Disabling essential cookies will prevent the Service from working.


11. Third-party links

The Service may contain links to third-party websites (e.g., SAM.gov). We are not responsible for the privacy practices of those websites. Review their privacy policies before submitting information.


12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before they take effect. The "Last Updated" date at the top reflects the most recent version. Continued use of the Service after changes take effect constitutes acceptance.


13. Contact us

For questions, requests, or concerns about this Privacy Policy or our handling of your personal data:

Tomsons Digital LLC (operator of BidChamp)
Identification Number: 412798110
Registered in: Georgia
Email: [email protected]

For Georgian users: you may also contact the Personal Data Protection Service of Georgia (https://personaldata.ge) regarding any complaints.


This Privacy Policy is provided in English. Translations may be available on request, but the English version controls in case of discrepancy.

BidChamp

Bid intelligence for federal contractors. Built for the people who read every Section L.

PLATFORM
Smart Match Bid Analysis Requirements Competitors Proposals
RESOURCES
SAM.gov
COMPANY
About Accessibility Press Contact
LEGAL
Terms Privacy Security Refund Policy
© 2026 BidChamp · BUILT FOR FEDERAL CONTRACTORS
BidChamp is an independent software platform and is not affiliated with SAM.gov or the U.S. Government. SAM.gov registration is free through the official SAM.gov website.