How we use your information.
This notice explains what personal information TenderPockets uses, why it is used, who receives it and the rights available to you under UK data-protection law.
Last updated: 19 August 2026.
The final public version must replace the bracketed entries below with the legal operator’s real information.
1. Who is responsible for your information
The controller responsible for personal information used by TenderPockets is:
[LEGAL OPERATOR NAME]Trading as TenderPockets
[GEOGRAPHIC BUSINESS OR REGISTERED ADDRESS]
Email: [PRIVACY CONTACT EMAIL]
Company number: [COMPANY NUMBER, IF APPLICABLE]
VAT number: [VAT NUMBER, IF APPLICABLE]
2. The information we collect
- Subscription information: your business email address, selected trade, selected region, plan status and the date and version of the terms you accepted.
- Payment references: Stripe customer, Checkout and subscription identifiers, payment state and renewal state. TenderPockets does not receive or store your full card number.
- Service records: which opportunities have been included in your alerts, delivery records and customer-support correspondence.
- Login and security information: short-lived sign-in token hashes, session token hashes, request dates, routes, error details and limited network/security data used to authenticate subscribers and protect the service. Raw sign-in and session tokens are not stored in the database.
- Public procurement information: contract notices obtained from Contracts Finder. These notices generally concern organisations rather than private individuals.
3. Why we use it and our lawful bases
- To enter into and perform the subscription contract: creating your chosen alert, taking payment, delivering matches, confirming the order and managing cancellation.
- For our legitimate interests: securing the service, preventing fraud and duplicate payments, diagnosing faults, keeping appropriate service records and improving matching. We balance these interests against your rights.
- To meet legal obligations: retaining records required for accounting, taxation, regulatory enquiries and legal claims.
- With consent where required: any separate promotional marketing. Buying the service does not by itself opt you into unrelated marketing.
4. Who receives the information
We use carefully selected service providers only where needed to operate TenderPockets:
- Cloudflare provides website delivery, security, Worker computing, logs and the D1 database.
- Stripe processes checkout, payments, invoices and subscription billing. Stripe acts under its own privacy information for payment processing.
- Resend delivers transactional subscription confirmations, management links and tender-alert emails when the email service is enabled.
- Professional advisers, authorities or courts may receive limited information where required by law or necessary to establish, exercise or defend legal claims.
We do not sell or rent personal information.
5. International transfers
Some providers may process information outside the United Kingdom. Where UK law requires it, we rely on an adequacy regulation or approved contractual safeguards and assess the protection applied by the provider. You may contact us for more information about the relevant safeguard.
6. How long we keep information
- Incomplete waitlist, failed-payment or abandoned-checkout records without an active Stripe subscription are deleted after 90 days.
- Active subscription information is kept while the service is provided.
- Ended subscription and contract records are kept for up to six years where needed for tax, accounting, disputes and legal claims, then deleted or anonymised.
- Stripe webhook event identifiers are kept for up to 400 days to prevent duplicate processing and investigate payment problems.
- Imported procurement notices are normally removed from our working database after 18 months.
- Single-use login links expire after 15 minutes. Used or expired login-token records are automatically removed; subscriber sessions expire after 30 days and can be ended earlier by signing out.
- Provider security logs are retained according to the shortest practical operational setting and deleted when no longer needed.
7. Your rights
Depending on the circumstances, you may ask us to provide a copy of your personal information, correct it, delete it, restrict its use or transfer information you supplied. You may also object to processing based on legitimate interests and withdraw consent to marketing at any time. Withdrawing consent does not affect earlier lawful processing.
Send a request to [PRIVACY CONTACT EMAIL]. We may need to verify your identity and will normally respond within one month.
You may complain to the Information Commissioner’s Office. We would appreciate the chance to address your concern first.
8. Automated decisions
TenderPockets uses rules to match procurement notices to the trade and region you select. This matching does not make a legal or similarly significant decision about you.
9. Cookies and local storage
When a paid subscriber signs in using a single-use email link, TenderPockets sets a strictly necessary secure cookie named tp_session. It allows that browser to open the full subscriber feed, cannot be read by page scripts and expires after up to 30 days or when you sign out. No consent is required for this essential login cookie. The site does not currently set non-essential advertising or analytics cookies. Stripe may use technologies on its hosted checkout under Stripe’s own notice. If we add non-essential cookies or analytics, we will provide appropriate information and consent controls before using them.
10. Security
We use access controls, encryption in transit, restricted secret storage, payment-signature verification and monitoring intended to protect the information we handle. No internet service can promise absolute security.
11. Changes and contact
We may update this notice when the service or the law changes. Material changes will be highlighted on the site or sent to active subscribers where appropriate.
Privacy questions can be sent to [PRIVACY CONTACT EMAIL] or posted to the controller address above.
Subscriber login · Read the Subscription Terms · Manage a subscription