Privacy Policy
Last updated 2026-08-04.
1. Who is responsible for your data
RHTPwatch ("the Service") is provided by Connectt, LLC ("Connectt," "we," or "us"). This policy explains what personal information we collect, how we use it, and the choices you have. Questions or requests: james@connectt.io.
2. Information we collect
Information you give us — the email address you sign in with, and any organization details, preferences, or messages you send us. We also keep a record of your acceptance of our Terms, which may include the version, content hash, time, account email and organization, IP address, and user agent.
Information collected automatically — standard server and security logs, including IP address, timestamps, and basic request metadata, used to operate and protect the Service. We do not use third-party advertising cookies or cross-site trackers, and we do not sell your information or use it to build an advertising profile.
How you use the signed-in Service — when you are signed in, we record how the product is used so we can operate, support, secure, and improve it. That means the pages and features you open, the opportunities and official source links you open, use of the walkthrough and Help, and when a visit starts and ends. We also record a coarse device class, browser and operating-system family, and country and region. We do not record your exact location, and we do not keep your IP address in these product records.
Protecting the Service and its content — we monitor for patterns that suggest a compromised or shared account, or systematic copying of the opportunity data, such as an unusually high rate of copying, printing, or opening records, or one login being active in two countries at once. For copying we record only that a copy happened, roughly how much was selected, and where. We do not record the text you copy or the contents of anything you print. Findings are reviewed by a person; they do not automatically restrict or suspend an account.
Cookies — we set the strictly necessary cookies that keep you signed in, plus one first-party identifier that lets us recognize the same browser returning so a visit can be measured. It is a random value, it is not a device fingerprint, and it is meaningless to any other website.
We do not collect or store payment-card numbers ourselves. Stripe handles card and other approved payment processing under its own privacy terms.
3. How we use information
To provide and secure the Service: to authenticate you, show you the opportunities relevant to your account, communicate with you about the Service (including alerts you ask for), keep records we are required to keep, and prevent abuse.
4. Automated and AI-assisted processing
The opportunity data shown by the Service is gathered from public government and procurement sources and is summarized and scored with the help of automated and AI systems. In some workflows, organization details, preferences, instructions, or messages provided by you or your account administrator may also be included to generate account-specific results. Those inputs may contain personal information and may be sent through our AI gateway and model provider as needed to provide the Service. We do not use customer-provided information to train our own AI models. Third-party providers process inputs under their applicable terms and data controls. Do not submit restricted sensitive information to the Service.
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share it only with service providers who help us run the Service, under contract and only as needed:
- a cloud hosting / edge-network provider;
- a database and authentication provider;
- a transactional email provider;
- an AI gateway and language-model provider (for processing public source data and, where applicable, customer-provided organization details, preferences, instructions, or messages);
- a payment processor, if you make a purchase.
We may also disclose information if required by law, or to protect our rights, users, or the Service.
6. Where data is stored and how it is protected
The Service and its data are hosted with our cloud providers, primarily in the United States. We use reasonable technical and organizational measures designed to protect personal information, including access controls intended to limit access based on account role and authorization. No method of storage or transmission is perfectly secure. We do not represent that the standard Service holds a particular security certification or audit report. Any data processing agreement, security addendum, audit right, certification, or special security commitment must be stated in a separate written agreement signed by both parties.
7. How long we keep information
We keep account and contact records for as long as your account is active and as needed to provide the Service, then for any period required to meet legal, tax, or recordkeeping obligations. Terms- acceptance records are kept as a record of the agreement. You can ask us to delete your information at any time (see §8). We do not promise a fixed deletion schedule under the standard Service.
The product-use records described in §2 are deleted on a schedule: records of how the Service was used are kept for 13 months, visit records and the browser identifier for 90 days, and security findings together with the decisions made about them for 24 months.
If you make a payment, we keep billing records (such as your subscription status and the dates your access is paid through) for as long as needed to provide the Service and to meet tax and accounting obligations. Those records may include payment-processor customer and event identifiers, billing email, amounts, currency, payment status, and subscription or billing-period data. We do not store the full payment-processor event payload or your payment-card number; the full payment record stays with our payment processor.
Information deleted from active systems may remain temporarily in backups and logs until those copies expire through their ordinary lifecycle. We do not use residual backup copies for ordinary business purposes and will not restore them except for legitimate recovery, security, or legal needs.
8. Your choices and rights
Depending on where you live and applicable law, you may have rights to know what personal information we hold about you, access or receive a copy of it, correct it, delete it, or limit how we use it. We do not sell personal information or share it for cross-context behavioral advertising. To make a request, email james@connectt.io; we may need to verify your identity first. We will process verified requests when and as required by applicable law, subject to exceptions that allow or require us to retain information for billing, tax, security, fraud prevention, disputes, legal compliance, and proof of your agreement to our Terms.
9. Security-incident notice
We will provide notice of a security incident when and as required by applicable law, taking account of legitimate law-enforcement, investigation, and remediation needs. The standard Service does not include a fixed 24-hour, 72-hour, or other contractual notice deadline. A different deadline applies only if stated in a separate written agreement signed by both parties.
10. Email
We send you transactional messages (such as account and opportunity alerts you have requested) and occasional service notices. You can opt out of non-essential email at any time; we still need to send essential messages about your account.
11. Children
The Service is for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18.
12. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated through the Service.
13. Contact
Questions or privacy requests: james@connectt.io.