- Home
- Privacy
Legal
Privacy policy
What Captivaq collects, why, who else sees it, and what you can ask us to do with it. This website itself collects nothing. The sections below are about the application you sign in to.
Effective . Logesta Labs LLC operates Captivaq.
Contents
- 1.What this policy covers
- 2.What this website collects
- 3.What we collect in the application
- 4.Signing in with Google
- 5.Why we use it
- 6.AI processing
- 7.Who else sees your data
- 8.Cookies
- 9.How long we keep it
- 10.Where your data is stored
- 11.How it is protected
- 12.Your rights and how to use them
- 13.Children
- 14.Changes to this policy
1. What this policy covers
This policy explains what Logesta Labs LLC collects when you use Captivaq, why we collect it, who else sees it, and what you can ask us to do with it. It covers the captivaq.com website, the application at app.captivaq.com and the mobile app.
Captivaq serves companies bidding on public work in the United States and Canada, so this policy is written around US state privacy laws and the Canadian federal privacy law, PIPEDA. Section 12 lists the rights each of those gives you.
2. What this website collects
The site you are reading has no advertising pixels, no tag manager, no chat widget and no forms, and there is no account to create until you go to the application. It does count visits, so we can tell which pages get read and which links bring people here.
A visit records the page address without its query string, the site or campaign link you came from, the browser, operating system, device type and screen width, and an approximate country, region and city worked out from your IP address. The IP address itself is not stored. A random visitor ID, kept in your browser and in a cookie, lets a return visit count as the same visitor. It is not tied to your name or email address.
Your dark or light preference is kept in your own browser storage and never sent to us. The fonts are served from captivaq.com rather than from Google.
3. What we collect in the application
Account details. Your name, email address, password and whether the email has been verified. The password is stored only as a salted hash, so we cannot read it. If you sign in with Google instead, we receive your name, email address and profile picture from your Google Account, and we store the tokens that keep you signed in. Section 4 covers that in full.
Company profile and bid content. What you tell the platform about your company: capabilities, codes, certifications, past performance, resumes, rates and assumptions, uploaded documents, saved opportunities, notes and drafts. This is the substance of the product and the most sensitive material you give us. Resumes and past performance records usually contain personal data about your staff, and you are the one deciding to put it there.
Session and device. Each sign-in writes a session record holding the session token, its expiry, the IP address and the browser or app user agent. It is what keeps you signed in and what lets us spot an account being used from somewhere it should not be.
Usage. The application counts visits the same way this website does (section 2): the pages you open, which onboarding step you are on, and a few milestones such as finishing sign-up or starting a subscription. They are recorded against the random visitor ID, not against your account.
Payment. Card details go to our payment processor and never reach our servers. We keep the plan, the status, the billing period and the processor identifiers that tie a subscription to your account.
Messages to us. When you email Captivaq we keep the message and our reply so the conversation makes sense next time.
Public procurement records. The platform ingests notices, solicitations and award records published by government agencies. Those documents sometimes name a contracting officer or a vendor contact. We hold them as published, and we do not buy personal data from brokers or enrich your profile from outside sources.
4. Signing in with Google
Google is offered as a way to sign in so you do not have to keep another password. Choosing it is optional, and an email address and password work just as well.
When you use it, Google asks you to approve the request and then sends us three things from your Google Account: your name, your email address and your profile picture. We request no other scope, so we cannot see your Gmail, your Drive, your Calendar, your contacts or anything else held in your Google Account.
We use those three fields to create your Captivaq account, identify you at each sign-in, show your name and picture in the application, and email you about the service. If an account already exists for that verified email address, signing in with Google attaches to it rather than creating a second one.
Captivaq’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We transfer this information to no one, we sell it to no one, we use it for no advertising, and we put it in front of no human except where you ask us to, where the law requires it, or where it is needed to investigate abuse or a security incident.
You can disconnect Captivaq at any time from your Google Account permissions page. Doing so stops the Google sign-in route and leaves the rest of your account intact. To remove the copied name, email address and picture as well, delete the account itself, which section 12 explains.
5. Why we use it
- To run the service: match opportunities to your profile, score fit, track deadlines and produce drafts.
- To keep your account working: sign you in, keep sessions valid, verify your email and recover access.
- To bill you, and to meet the tax and accounting rules that come with taking payment.
- To send service messages such as an alert you asked for, a billing notice or a change to these policies.
- To keep the platform secure and reliable: investigate abuse, debug failures and monitor for unauthorised access.
- To improve the product in aggregate, by looking at which features are used and where they fail.
We do not use your bid content for advertising, and we run no advertising on the platform.
6. AI processing
Matching, summarising and drafting run on AI models operated by a model provider, currently Google. When you use one of those features, the relevant part of your content leaves our systems and goes to that provider so the model can act on it. We send what the request needs and no more.
Our agreement with the model provider prohibits using your content to train its models. We do not train models on your content either. If the provider changes or the terms change, this page changes with it.
Fit scores and rankings are produced automatically. They rank opportunities rather than people, they produce no legal effect on any individual, and a person decides what to do with them. Nothing on the platform makes an automated decision about you.
One practical note. If a document is classified, export controlled, or under a non-disclosure agreement that forbids third-party processing, do not upload it.
7. Who else sees your data
We do not sell personal information, and we do not share it for cross-context behavioural advertising, in the sense those terms carry under California law. We have never done either.
We use a small number of service providers to run the platform. Each works on our instructions, under contract, and may not use your data for anything else:
- Google LLC
- Runs the AI models behind matching, summarising and drafting. The solicitation text, the profile details and the documents that go into a request, plus the draft that comes back.
- Stripe, Inc.
- Takes subscription payments and holds the billing record. Name, email, billing address and card details, entered on Stripe's own form. Card numbers never reach our servers.
- Cloud application hosting
- Serves captivaq.com and app.captivaq.com. Everything you send to the app passes through in transit. Request logs hold IP address, user agent and the URL requested.
- Managed database hosting
- Stores the account, the company profile and the bid content at rest. Everything in your account, encrypted at rest and reachable only by the application.
The other cases where data leaves us are narrow. We may disclose information if the law requires it, after checking that the demand is valid and telling you unless we are forbidden to. We may disclose it to protect the rights or safety of people or of the service. And if the business is sold or merged, account data transfers with it, with notice to you before that happens.
9. How long we keep it
- Account details and your content: for as long as the account is open. When you close it, we delete them within 30 days, and copies in encrypted backups roll off within a further 90 days.
- Session records: until the session expires, then cleared on the normal cleanup cycle.
- Billing records: for as long as tax and accounting law requires us to keep them, which is generally seven years.
- Support email: up to 24 months after the conversation ends.
- Public procurement records: kept as a public dataset, independent of any account.
You can ask us to delete your content sooner. See section 12.
10. Where your data is stored
The platform and every provider listed in section 7 operate in the United States, and that is where your data is stored and processed. If you are in Canada, using Captivaq means your information is transferred to and held in the United States, where it may be reachable by US courts and authorities under US law. Using the service is your consent to that transfer.
11. How it is protected
Traffic runs over TLS. Data is encrypted at rest by our database and hosting providers. Passwords are stored as salted hashes and never in readable form. Access to production data is limited to the people who need it to operate the service, and sessions expire and can be revoked.
Captivaq is an early-stage product and holds no third-party security certification today. When that changes it will be stated on the security page, not implied here. No system is perfectly secure. If you believe an account or a document has been exposed, email contact@captivaq.com and we will treat it as urgent.
12. Your rights and how to use them
Wherever you live, you can ask us to do any of the following, and we will do it for you:
- Tell you what personal information we hold about you, why we hold it and who has received it.
- Correct anything that is wrong.
- Delete your account and the content in it.
- Send you a copy of your data in a portable format.
- Withdraw consent, or object to a particular use, understanding that some uses are what makes the service work.
United States. California residents have these rights under the CCPA as amended by the CPRA, along with the right not to be treated differently for using them. Residents of other states with comprehensive privacy laws have equivalent rights. We do not sell or share personal information and do not collect sensitive personal information for inference, so the opt-out and limitation rights attached to those activities have nothing to apply to. An authorised agent may act for you if they prove it.
Canada. Under PIPEDA you can ask for access to your personal information and for correction of it, and you can withdraw consent subject to legal and contractual limits. If our answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada.
Making a request. Email contact@captivaq.com from the address on your account, which is how we verify who you are. We answer within 30 days, and within 45 days for a request under a US state law, extending only where that law allows and telling you if we do. There is no charge. If we refuse a request we will say why, and you can reply to appeal it.
When you use Captivaq to process personal information about your own staff or clients, you are the one who decides why and how, and we act on your instructions. The data processing agreement covers that arrangement, and a request from one of your own people should come to you rather than to us.
13. Children
Captivaq is a business tool and is not for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, email contact@captivaq.com and we will delete it.
14. Changes to this policy
We update this page when what we do changes, and the effective date at the top always shows the current version. If a change materially affects how we handle your data, we will email account holders before it takes effect rather than change the page quietly. Past versions are available on request.
Ask us about this
Questions about this page, a privacy request, or a security review from your team all reach the same inbox: contact@captivaq.com. Say which section you are asking about and we will answer it directly.