Privacy

What TenderLead reads, stores and deletes.

Last updated: 3 September 2026

This page covers the TenderLead public site, personalised preview requests, trial setup, customer profile inputs and lightweight analytics. For the scoring-input boundary, see Source quality. For site-level cookies and analytics transparency, see Cookies. For the public-site accessibility target, see Accessibility. For site terms, see Terms.

What we collect

When you request a preview, start a trial or activate a paid account, we collect your email address and the company details you provide, such as company name, website, sectors, keywords, regions, buyer interests, frameworks and no-bid rules. Stripe handles payment details for paid plans.

For a preview request, we also keep the TenderLead entry page and any utm_source or utm_medium values carried in the preview link. We do not store the full referring URL in the preview record.

Company website profile drafts

If you ask TenderLead to draft a profile from a company website, it reads the public pages at the address you provide and may use public Companies House information. Relevant extracted text is sent to OpenAI to structure the suggestions. The OpenAI request is made with response storage disabled.

The draft endpoint returns suggestions for you to review. It records model-usage totals for cost controls, but it does not save the draft fields to your company profile. Those fields are saved only when you submit the personalised preview form.

How we use it

Your firm inputs are used to run TenderLead for your firm, send preview and briefing emails, tune scoring, manage trial or paid access and respond to support requests. We do not use one customer's private profile, feedback or bid data to tune another customer's recommendations. We do not sell customer data.

Connected agents

If you connect TenderLead to ChatGPT, Claude or another supported agent, TenderLead asks you to approve read-only access to your account. In response to your requests, the agent provider may receive your matched tender titles, buyer names, source links, summaries, deadlines, scores and saved BID or SKIP reasoning. TenderLead does not give the agent your TenderLead password, API keys or another customer's data. The agent provider handles the data it receives under its own terms and privacy policy.

You can revoke the connection in the agent provider's settings. Revocation stops new access but does not remove information already included in that provider's conversations or records.

Service providers and retention

We use service providers to operate TenderLead, including Cloudflare for hosting, Neon for the database, Resend for email, Stripe for payments and OpenAI for model processing. We share only the data needed for each service to perform its role. A connected agent provider receives account data only when you authorise the connection and use it.

We keep account and firm-profile data while the account is active. OAuth grants and refresh tokens are kept until they expire, are revoked or the account is deleted. If you request deletion, we will remove the account and connected-agent authorisations from live TenderLead systems within 30 days, except records we must keep for legal, tax, fraud-prevention or dispute purposes. Residual copies may remain in encrypted backups until those backups expire under the relevant provider's retention schedule.

Analytics and browser behaviour

The public site and signed-in app use Plausible Analytics and Ahrefs Web Analytics for aggregate page measurement, loaded only after the visitor allows analytics in the consent prompt. Plausible also receives a small number of TenderLead conversion events, such as preview requests, fixed setup-blocker choices, sign-in link requests, checkout-start clicks and post-checkout activation submissions. Google Analytics 4 may also be loaded on public pages, using measurement ID G-B70RM3QXBZ, but only after the visitor allows analytics in the consent prompt.

That analytics setup is intended to stay privacy-first: no authenticated app tracking via GA4, no advertising audience building, and no event payloads containing form contents such as email address or company name.

Public sources and firm inputs

TenderLead is designed to combine public procurement information with firm-provided context such as your website, sectors, keywords, and past wins when you choose to provide them. We keep that boundary explicit rather than pretending every score comes from public data alone.

Your rights

You can permanently delete your account from Settings while signed in, or request deletion by emailing hello@tenderlead.co.uk.

Contact

hello@tenderlead.co.uk