Privacy

Canadian Recompete Radar watches federal contracts and tells you when one looks like it may be coming up for renewal. This policy covers the signed-in application. The public website at recompeteradar.ca has no accounts and is not covered here.

What we store, and why

Your email address. It is how you sign in and where alerts will be sent. It is the only thing we hold that identifies you.

Your watchlist. The contracts you follow, stored as the published reference number and department code; the suppliers you follow, stored as a simplified form of the supplier name as it appears in the published records; and the date you added each.

Your alert preferences. How often you want to hear from us, and the contract value below which you do not want to be told.

Your sign-in sessions. One row for each device you are signed in on. Each holds a one-way fingerprint of a random value, never the value itself, so reading our database would not let anyone sign in as you.

That is the whole list.

What we deliberately do not store

No password. There is none to store, none to leak, and none to reset. You sign in with a link sent to your address.

No IP address, and no record of your browser or device. We considered keeping them and chose not to; an address tied to an email is personal data we have no use for.

No tracking, no advertising, and no third-party analytics in the signed-in application.

Never your address in our logs. Our logs record what happened, such as that a sign-in link was requested, never who it involved. This is enforced in code rather than by care: the only function that writes to a log discards any value containing an at sign, and refuses any field that is not on a short approved list.

How long we keep it

Sign-in links: usable for 15 minutes. The record of one is erased within about an hour after that, the next time anyone asks for a link. We keep it for that extra hour so repeated requests can be rate-limited.

Sessions: 30 days. They do not extend themselves; after 30 days you sign in again. Signing out removes that device’s session immediately.

Your account: until you delete it.

Where it is stored

In the United States. Our database is in Northern Virginia, our application runs in Washington, and our email is sent by a United States company.

Data held there is subject to United States law, including lawful access requests, in ways data held in Canada is not.

Deleting your account

There is a Delete account button on your account page. It removes your account, your sessions, your watchlist and your preferences. Rows are deleted, not hidden, and not marked inactive.

Two things we cannot reach, stated plainly rather than left for you to find:

Our email provider keeps a copy of the sign-in emails already sent to you, including your address, and deletes it within 30 days. We cannot reach that copy.

Our database provider keeps short-term point-in-time backups that expire on their own schedule. We cannot reach those either.

Your rights

Under PIPEDA you may ask what we hold about you, ask us to correct it, and withdraw your consent. The fastest route to all of it is the Delete account button. For anything else, write to us at the address below.

Alerts, and your consent

Alert emails are commercial electronic messages under CASL. We send them only after you have asked for them, every one carries an unsubscribe link that works, and unsubscribing stops them. Alerts are not switched on in this release.

Who we are

Canadian Recompete Radar
PO Box 1184, Pembroke, Ontario K8A 6Y6
hello@recompeteradar.ca

Changes

If this policy changes in a way that affects what we store or who we share it with, we will say so on this page and by email before it takes effect.

Back to the start