Privacy

What we hold, and what we do not

Everything BidCaliper knows about you and your company, item by item, with the reason it is held. Nothing here is described in the abstract — if it is stored, it is named.

BidCaliper is operated by James Worthing, carrying on business as BidCaliper, from Winnipeg, Manitoba.

Last updated 23 August 2026.

The short version

We do not sell anything about you, to anybody.

There is no advertising on this product, no data broker in the stack, and nothing here is packaged and sold on. The business model is a subscription.

What you upload is yours and stays inside your company.

Documents, takeoffs and everything read out of them belong to the company that uploaded them. They are never pooled between customers and never used to improve what another customer sees, and that boundary is checked continuously rather than assumed.

There are no tracking cookies, and nothing on the page is watching you.

Two cookies, both ours: one keeps you signed in, and one carries a confirmation message across a page load and lasts half a minute. Neither can be read by anything else. There is no analytics tag, no advertising pixel, and no script, font or image loaded from another company's server anywhere on this site.

Alert emails carry no tracking pixel and no click redirect.

A link in a digest goes straight to the tender. It carries a marker saying it came from an email, which is how we know digests are worth sending — and that is the whole of the measurement.

We cannot read your password.

It is never stored — only a one-way scrambled version of it. Nobody here can recover it, which is why a reset sets a new password rather than telling you the old one.

Everything it stores

Listed one item at a time rather than described in the abstract, because “your business information” is exactly the phrase that lets a policy quietly cover anything. Where something is marked you give us this, nothing is collected unless you type it in.

Your account

Who you are
Email address, an optional name, when the account was made, and when it was last used.
Why: To sign you in and to name who made a decision on the decision record.
Your password
A one-way scrambled version of it, with a random value mixed in that is unique to your account. The password itself is never stored, and nobody at BidCaliper can read or recover it.
Why: To check it without being able to read it.
Where you are signed in
A random session identifier, which company the browser is looking at, when it started, when it expires, and the browser's own description of itself (its user-agent string).
Why: So a session can be ended, and so you can see the list and end others.
A password reset, while one is outstanding
A scrambled version of the link's one-time code — never the code itself — with its expiry and whether it has been used.
Why: To let you set a new password from an email link.

Your company

This is the part that makes a verdict yours rather than generic. All of it is typed in by you, and none of it is bought from anybody.

Who the company isyou give us this
Company name and legal name, street address, postal code, a contact name, email and phone, WCB account number and GST/HST number.
Why: It goes on the bid package, which is a document you sign and send.
What the company can doyou give us this
Trades, home city and province, how far you will travel, field and office head count, bonding capacity, insurer and liability limit, and any certificates you record with their expiry dates.
Why: It is what the gate engine screens against.
What an hour costs youyou give us this
Utilization, annual overhead pool, blended field wage, burden rate, paid hours per head, target margin, material markups and overtime multiplier.
Why: To price a job against your own costs instead of an industry average.

Your work

Documents you uploadyou give us this
The file name, its size, its page count, a fingerprint used to spot the same file twice, who uploaded it, and the text read out of it. The file itself is never kept.
Why: To read the requirements and the dates out of them.
Notices you bring in yourselfyou give us this
What you paste, of which the first 8,000 characters are kept — enough to quote the sentence a finding came from, and not a copy of the notice.
Why: So work no open feed carries still gets screened.
Takeoffs you uploadyou give us this
Line number, description, quantity, unit, unit cost and labour hours, plus the original row as it arrived.
Why: To price a job line by line.
What you decided, and what came of ityou give us this
The verdict and every finding behind it as it stood on the day, whether you bid, won, lost, completed or passed, who decided and when, and why you passed. Jobs you record carry a title, buyer, place, value, dates, a scope summary, and — where you enter one — a reference's name, role, email and phone.
Why: It is the decision record, and it is the half of a COR audit nothing else can evidence.
Answers to questions we askyou give us this
The question, the answer or 'not sure', who answered it, when, and which tender prompted it.
Why: So the same question is never asked twice.

How the product is used

This is the one thing here that is not about you or your company, and it is deliberately built so that it cannot become so.

Product events
The name of the action from a fixed list, which company and person it belongs to, and a small number of properties limited to counts, yes/no values and short codes. Free text cannot be recorded at all: there is no way for a tender title, a dollar figure or anything you typed to end up in this data, and every stored record is re-checked against that rule.
Why: To see where people get stuck — how many finish setting up, how long until a first verdict, what gets opened.
Alerts we have sent
The company, the tender, its verdict and when the email was sent.
Why: So the same job is never emailed to you twice.
Rate-limit counters
A counter keyed on the email address being tried or the IP address it is coming from, with the time its window ends. Removed once the window has passed.
Why: To stop somebody guessing passwords or making accounts in bulk.

Paying for it, and getting in touch

Your subscription
The plan, its status, when the paid period ends and whether it is set to end, plus the identifiers Stripe gives us for your customer and subscription records. No card number, expiry or security code — those are entered on Stripe's own pages and never reach BidCaliper.
Why: To know which plan you are on and whether it is current, which is what decides what the product will do for you.
Messages you send us
Your name, company, email address, the reason you chose and what you wrote.
Why: So a message sent through the contact form reaches a person and can be replied to. The record is written before the email is sent, so nothing is lost if delivery fails.

Who else can see it

Two companies, both because the product cannot run without them. There is no third, and nothing is shared with anybody for any other purpose.

Railway
Runs the application and hosts the database. United States.
Everything listed above.
Resend
Delivers email — opportunity digests, addendum notices and password resets. United States.
The recipient's address and the contents of the message. That includes tender titles and buyers in a digest, because that is what the email is.
Stripe
Takes subscription payments and hosts the checkout and billing pages. United States and Ireland.
Your email address, your card details and your invoice history. The card is entered on Stripe's own pages and never reaches BidCaliper — we hold only the identifiers Stripe gives us for your customer and subscription records.

BidCaliper also reads public tender data from CanadaBuys and SEAO. That traffic goes out from us to them and carries nothing about you — what is read, and under which licence.

What gets deleted, and when

Each line below is something the software does on a schedule, not an undertaking. The last one is the important one, and it is the honest answer rather than the reassuring one.

While your account is active
Your profile, documents, jobs and decision record are kept for as long as the account is active, because that is what the product runs on. Nothing here expires while you are using it — the decision record in particular is the evidence a COR auditor asks for, and quietly ageing it out would destroy the thing it is for.
After your account ends — thirty days
For thirty days after an account or subscription ends, your data stays where it is so it can be recovered or exported. Ask sooner and it is removed sooner.
After those thirty days
Operational data is deleted from the live systems: your company profile, certificates, uploaded documents and their text, takeoffs, verdicts and the findings behind them, jobs and the decision record, answers you gave, addendum changes, alert history and product events, and any notices you brought in yourself. What can remain is only what is genuinely required for legal obligations, accounting and tax records, preventing fraud, resolving a dispute or enforcing an agreement.
Backups
Deleted information can persist for a while in routine backups until those backups rotate out. It is not restored into use, except in a genuine disaster recovery. We are not going to quote you a backup retention period, because we have not set and verified one — when we have, it will say so here.
Sign-in sessions
Expire thirty days after you sign in, and are removed automatically once expired.
Password reset links
Expire one hour after they are requested and work only once. Used and expired ones are removed automatically.
Security counters
The counters that stop password guessing hold an email address or an IP address for at most an hour, and are removed automatically once their window has passed. This is the only place an IP address is kept.
Text from documents you upload
The uploaded file is never kept. The text read out of it is, and it is capped — enough to quote the sentence a requirement came from, not a copy of the document.
Notices you bring in yourself
Capped in the same way, and for the same reason.

What we do not claim

The three things a privacy policy is most often padded with. Saying plainly that we have not done them is more use to you than a badge nobody checked.

We do not claim a certification we have not been through
No SOC 2, no ISO 27001, no audit report. What there is instead is the list above — specific measures you can hold us to. If we are ever certified against something, it will say so with the certificate beside it.
Canadian privacy law applies to us, and we do not dress that up
BidCaliper is a Canadian business handling personal information in the course of commercial activity, and the federal and provincial privacy rules that come with that apply whether or not a web page says so. We are not going to claim a compliance programme we have not built, and we are not going to claim rights frameworks from other jurisdictions that we have not implemented.
We are not promising where the data will live in future
It is in the United States today and the section above says so plainly. Committing contractually to a country is a real constraint on future infrastructure, so we have not made that promise. If that matters to your business, ask before you sign up — the answer will be a fact rather than a brochure.

How it is protected

Each of these is something the product does rather than a posture it takes. There is no certification claimed here and no audit to point at — what there is, is a list of specific measures you can hold us to.

Your password is never stored
It is put through a deliberately slow one-way scramble with a value unique to your account. Nobody here can read it or recover it, which is why a reset sets a new one rather than telling you the old one.
Sign-in cookies cannot be read by anything else
The cookie that keeps you signed in is marked so that no script on the page can read it, so that it is only ever sent over an encrypted connection, and so that other websites cannot cause it to be sent.
Which company you can see comes from our records, not your browser
Nothing your browser sends decides which company's data a request may reach — that is checked against your membership every time. There are standing checks that plant a decoy in one company and fail if it is ever visible from another.
Documents you upload are scoped to your company
The text and every requirement read out of it belong to the company that uploaded them, and are never pooled with another customer's or used to improve what anybody else sees.
Sign-in, sign-up and password resets are rate limited
Counted centrally rather than per server, so somebody guessing at passwords is slowed down wherever the attempt lands.
Password reset links expire and work once
One hour, single use, and using one signs out every other browser you were signed in on.
Everything is served over an encrypted connection
And no page loads a script, a font or an image from anybody else's server, so there is nothing on this site in a position to watch you.

What you can do about it

Only things that exist today. Where the answer is “ask us”, that is because the button has not been built, and saying so is better than implying one is there.

See and change what your company holds

Your shop, in the app, is the whole of it — every cost input, certificate, address and limit, editable.

Turn alert emails off

One switch on your account page, and a one-click link at the foot of every digest that works without signing in.

See where you are signed in, and end a session

Your account page lists every browser holding a live session, and signs any of them out.

Change your password

Changing it ends every other session, which is the point of changing it.

End your account and have the data removed

There is no self-serve button for this yet — ask, and it is done. Once an account ends, the thirty-day clock above starts, and after it your operational data is deleted automatically rather than when somebody remembers.

Get a copy of your decision record

The decision record prints from the app to PDF through your browser. It is COR evidence and it is yours.

How to reach us

For anything on this page — a copy of what we hold, a correction, a deletion, or a question this does not answer — write to us and a person will reply. Say it is about privacy and it goes to the right place.

The contact form is the route, and it reaches a person rather than a queue. Formal privacy notices can be sent the same way.