3Bids

3BIDS HOME SERVICES CORP. PRIVACY POLICY

Last Updated: April 2026

3Bids Home Services Corp. (“we,” “us,” or “our”) wants you to be familiar with how we collect, use, and disclose information. This Privacy Policy describes our practices in connection with information that we collect through:

Collectively, we refer to the website(s), app(s), social media pages, and emails as the “Services.”

Personal Information

Personal Information” is information that identifies you as an individual or relates to an identifiable individual. We collect Personal Information through or in connection with the Services, such as:

Collection of Personal Information

We and our service providers collect Personal Information in a variety of ways, including:

We need to collect Personal Information in order to provide the requested Services to you. If you do not provide the information requested, we may not be able to provide the Services. If you disclose any Personal Information relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.

Text Messaging Consent Data. If you opt in to receive SMS/MMS messages from 3Bids, we collect and store your mobile telephone number, the consent language shown to you, the consent version, the date and time of consent, and the consent source, such as profile setup or job submission. We use this information to send requested account, project, bid, appointment, support, and service messages, to process HELP, STOP, and similar opt-out keywords (including STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT, and REVOKE), and to maintain compliance records. Text messaging originator opt-in data and consent will not be sold, shared, rented, or provided to third parties or affiliates for their marketing or promotional purposes.

Use of Personal Information

We and our service providers use Personal Information for the following purposes:

Disclosure of Personal Information

We disclose Personal Information:

Other Uses and Disclosures

We may also use and disclose Personal Information as we believe to be necessary or appropriate: (a) to comply with applicable law, to respond to warrants pertaining to active investigations, and to fulfil other legal obligations; (b) to enforce our terms and conditions; and (c) to protect our rights, privacy, safety, or property, and/or that of you or others. We may use, disclose, or transfer Personal Information to a third party in connection with any proposed or actual reorganization, bankruptcy, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our assets or stock.

Information COLLECTED AUTOMATICALLY

We and our service providers may collect information automatically in a variety of ways, including:

Uses and Disclosures of Information Collected Automatically

If we are required to treat such information collected automatically as Personal Information under applicable law, we may use and disclose it for the purposes for which we use and disclose Personal Information, as detailed in this Privacy Policy. In some instances, we may combine information collected automatically with Personal Information. If we do, we will treat the combined information as Personal Information so long as it is combined.

SESSION REPLAY, LIVE ANALYTICS, AND CALIFORNIA WIRETAPPING DISCLOSURE

Session Replay and Interaction Recording. The Platform may use session replay and user interaction recording technologies to capture reconstructed visual recordings of user sessions, including mouse movements, clicks, scrolls, keystrokes (subject to input masking described below), page navigation, and device or screen state (collectively, “Session Recordings”). Session Recordings help us identify usability issues, diagnose errors, and improve Platform features. Where we use Sentry’s session replay capability or a similar tool, that tool is configured to: (a) automatically mask or redact form input fields that contain passwords, payment card numbers, and similar sensitive data before any recording is transmitted; (b) exclude pages or flows that handle particularly sensitive transactions, such as Stripe payment forms and DocuSeal signing sessions; and (c) transmit session data only to the applicable vendor’s servers over encrypted connections. Session Recordings are retained for a limited period (no longer than ninety (90) days in accessible replay storage) and are accessible only to authorized 3Bids personnel for engineering and product purposes. Session Recordings are not used for targeted advertising or sold to third parties.

California Invasion of Privacy Act (CIPA) Disclosure. California Penal Code §§ 630 et seq. (the California Invasion of Privacy Act, “CIPA”) has been interpreted by some courts to apply to certain software-based session recording and replay practices, including the use of analytics tools that observe user interactions on a website or application in real time. By using the Services, you consent to our use of session replay, interaction recording, and real-time analytics technologies as described in this section. This consent is provided pursuant to Penal Code § 631(a), which permits interception with the consent of all parties. If you do not consent to session replay or interaction recording, you may disable non-essential cookies and analytics through the cookie preference controls available on the Services, or by contacting us at privacy@3bids.io. Note that disabling session replay may not be possible for certain core error-monitoring functions (such as crash reporting through Sentry) that are necessary for Platform security and stability and are therefore treated as essential services rather than optional analytics.

Non-Essential Analytics and Opt-Out. In addition to session replay, we may use third-party analytics services—including Google Analytics and similar tools—to collect information about how users navigate and interact with the Services. These tools set cookies or similar identifiers that persist across sessions and may be used to build aggregate usage profiles. We classify these analytics as non-essential because they are used for product improvement and business reporting, not for the delivery of core Platform functionality. Users who do not wish to participate in non-essential analytics may opt out by: (a) installing the Google Analytics opt-out browser add-on available at tools.google.com/dlpage/gaoptout; (b) using browser privacy settings or extensions that block third-party tracking scripts; or (c) submitting an opt-out request to privacy@3bids.io. Opting out of non-essential analytics does not affect your ability to use the Platform.

security

We seek to use reasonable organizational, technical, and administrative measures to protect Personal Information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “Contact Us” section below.

DATA RETENTION

We retain Personal Information for as long as necessary to fulfill the purposes for which it was collected, including to provide and secure the Services, maintain your account, comply with our legal obligations, and resolve disputes and enforce our agreements. The below sets out our retention periods for the principal categories of data we hold. Where a specific period is stated, it reflects our current operational practice. Legal hold obligations, active litigation, regulatory investigations, or unresolved disputes may extend any period stated below; in those cases, affected data will be isolated and held until the hold is released. Backup copies are overwritten in the ordinary course within ninety (90) days of deletion from active systems. When a retention period expires, data is deleted or de-identified using commercially reasonable methods.

Account and Profile Data. Name, email address, phone number, account credentials, profile information, and subscription tier data are retained for the life of the account and for seven (7) years following account closure. The seven-year tail supports tax reporting, fraud investigation, chargeback resolution, and statutory recordkeeping obligations. If you request account deletion, we will de-identify active profile data within thirty (30) days; the de-identified record and transaction history are retained for the remainder of the seven-year period.

Transaction, Escrow, and Payment Records. Job records, escrow funding and disbursement records, fee calculations, change orders, and payment transaction data are retained for seven (7) years following the close of the relevant transaction. This period reflects applicable federal and state tax recordkeeping requirements, mechanic’s lien exposure windows, and home improvement contract statute of limitations periods in the jurisdictions where we operate.

Signed Agreements and Electronic Signature Records. Executed Job Agreements, Change Order Agreements, Completion Certificates, and associated DocuSeal audit trails are retained for seven (7) years from the date of execution. This period aligns with the transaction record retention period and ensures that the evidentiary record of a signed agreement remains available for the full window during which a contract claim could plausibly arise.

Call Recordings and Transcripts. Audio recordings of calls routed through the Platform and their associated Deepgram transcripts are retained for two (2) years from the date of the call. This two-year period reflects our concrete operational practice. It is calibrated to cover the dispute resolution window for home improvement jobs, TCPA claim limitation periods in the majority of states, and our internal quality assurance needs, while avoiding indefinite retention of sensitive call audio. Recordings and transcripts associated with an open dispute or legal hold are retained until the hold is released, regardless of the two-year default.

AI Voice-Agent Conversation Logs. Full conversation transcripts and extracted intake fields generated by AI-assisted voice or chat flows (including sessions handled by Google Gemini and Deepgram) are retained for two (2) years from the date of the interaction. We align voice-agent data to the same two-year window as call recordings because the content and sensitivity are equivalent: both may contain names, addresses, financial details, and other Personal Information disclosed by individuals who have not created Platform accounts. Structured intake fields extracted from these conversations (such as name, address, and service type) that are incorporated into a Contractor’s CRM profile follow the CRM contact retention schedule below rather than the two-year audio/transcript period. Non-Account Holders may request deletion of their conversation log at any time, subject to any active dispute or legal hold.

Location History. Precise geolocation data collected from user devices during active Platform sessions (for example, location signals used to verify job site proximity or to display nearby jobs) is retained for ninety (90) days from the date of collection. This ninety-day window reflects our concrete operational practice and is calibrated to support post-session dispute investigations while avoiding the accumulation of a continuous movement history. Derived or approximate location data—such as a city or ZIP code inferred from IP address—is retained as part of the log record to which it is attached and follows the retention period of that record type. Job site addresses entered by Posters and Contractors as part of a job record are retained with the job record for seven (7) years as described above.

Contractor HR and Workforce Records. Personnel and workforce data submitted by Contractors through Platform HR and operational features—including employee rosters, scheduling records, payroll-adjacent data, and licensing and insurance documentation—is retained for the duration of the Contractor’s account and for four (4) years following account closure or the termination of the employment or engagement to which the record relates, whichever is later. This four-year period reflects our concrete HR-records retention practice and aligns with federal and state wage-and-hour recordkeeping requirements (including FLSA requirements) and equal employment opportunity recordkeeping obligations. Background screening reports obtained through Checkr are retained for five (5) years from the date of the report in compliance with FCRA requirements and standard adverse action documentation practices.

Door-to-Door Canvassing and Lead Data. Canvassing records for homeowners who did not convert to a scheduled appointment or active job—including door-knock notes, address and geolocation data, and contact information entered at the door—are retained for one (1) year from the date of the canvassing interaction, after which they are deleted from active systems. This one-year period is the narrowest window we believe is operationally justified: it covers a full seasonal cycle (relevant for many home improvement categories) and gives Contractors a reasonable window to re-engage cold leads, without creating a long-term database of individuals who have had no transactional relationship with 3Bids. Do-not-knock and do-not-contact suppression records are an express exception: they are retained indefinitely to ensure that a homeowner’s opt-out preference is honored on future canvassing campaigns, even if the underlying lead record has been purged. Where a canvassing interaction converts to a scheduled appointment or active job, the relevant lead data is merged into the job or appointment record and follows the transaction retention schedule above (seven years). CRM contact records for individuals who have had at least one completed service appointment are retained for three (3) years from the date of the most recent appointment.

Security, Fraud, and Error Logs. Application error logs (collected through Sentry), authentication and access logs (collected through Clerk), and security event logs are retained for ninety (90) days in active, queryable storage and for an additional twelve (12) months in compressed archive before deletion. Logs associated with a confirmed security incident or fraud investigation are retained for five (5) years or until the matter is resolved, whichever is later.

Marketing and Communications Consent Records. Records of SMS consent, opt-out requests, and revocation of consent are retained for five (5) years from the date of the consent event or opt-out, in order to demonstrate compliance with TCPA and applicable state marketing law requirements. Opt-out and do-not-contact records are retained indefinitely to ensure suppression lists remain effective.

THIRD-PARTY SERVICES

This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including any third party operating a website or service to which the Services link. The inclusion of a link on the Services does not imply our endorsement of the linked site or service.

In addition, we are not responsible for the information collection, use, disclosure, or security policies or practices of other organizations, such as Facebook, Twitter, Instagram, YouTube, Pinterest, LinkedIn, Stripe, AWS, Apple, Google, Microsoft, RIM, or any other app developer, app provider, social media platform, operating system provider, wireless service provider, or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with our apps or social media pages.

use of THE Services by MINORS

The Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Information from individuals under 16.

Jurisdiction and CROSS-BORDER TRANSFER

We are located in the United States. We may store and process your Personal Information in any country where we have facilities or in which we engage service providers. By using the Services, you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country.

Sensitive Information

Unless we specifically request it, we ask that you not send us, and that you not disclose, any sensitive categories of Personal Information (e.g., Social Security numbers, government-issued identification numbers, financial account numbers, racial or ethnic origin, political opinions, religious or philosophical beliefs, health or medical information, biometric or genetic data, sexual orientation, or criminal history) on or through the Services or otherwise to us. Certain of our product flows do, however, necessarily involve the collection or processing of information that qualifies as “Sensitive Personal Information” (“SPI”) under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). The following describes those categories, the purpose for which they are used, and your rights with respect to them.

Precise Geolocation. We collect precise geolocation data from Contractor and Poster devices during active Platform sessions for the purpose of verifying job site proximity, displaying nearby job opportunities, and enabling location-based Platform features. We do not use precise geolocation to build movement profiles, deliver targeted advertising, or infer sensitive characteristics about individuals. Precise geolocation data is retained for ninety (90) days as described in our Data Retention section. We do not sell or share precise geolocation data for cross-context behavioral advertising. California residents may limit our use of their precise geolocation data using the “Limit the Use of My Sensitive Personal Information” rights described below.

Government Identification and Social Security Numbers. Contractors who submit to identity verification for Stripe Connect onboarding, or who submit to background screening through Checkr, may be required to provide a Social Security number or government-issued identification number. This information is collected solely for identity verification, background screening, and tax reporting purposes, is transmitted directly to Stripe or Checkr (as applicable) over encrypted connections, and is not stored in our primary application database. We use this SPI only as necessary to complete the verification or screening transaction for which it was provided.

Workforce Personal Information (HR Records). Contractors who use the Platform’s HR and workforce management features may submit information about their employees or team members that constitutes SPI under CPRA, including precise geolocation (for field dispatch), account log-in credentials for sub-user accounts, and, where background screening is conducted, criminal history information. This SPI is used solely to provide the requested HR and workforce management features and is not used to make automated decisions that produce legal or similarly significant effects on the individuals to whom it pertains, beyond the scope of the Contractor’s own employment or engagement relationship with those individuals. 3Bids processes this data as a service provider acting on the Contractor’s instructions. The Contractor is the business under CCPA/CPRA with respect to its own employees’ data.

Limit the Use of My Sensitive Personal Information. California residents have the right to direct us to limit our use and disclosure of their SPI to what is necessary to provide the Services or as otherwise permitted by CPRA. Because we do not use SPI for purposes beyond those described in this section and do not sell or share SPI for cross-context behavioral advertising, our current practices are already within the permissible uses under CPRA. If you believe we are using your SPI beyond these purposes, you may submit a Limit SPI request to privacy@3bids.io or through our Privacy Request Portal. We will respond within forty-five (45) days of receipt.

CALIFORNIA PRIVACY RIGHTS (CCPA / CPRA)

This section applies to California residents whose Personal Information we process and supplements the rest of this Privacy Policy. Capitalized terms used but not defined here have the meanings given in the CCPA and CPRA. For purposes of this section, “Personal Information” has the meaning given in the CCPA and does not include information that is publicly available, deidentified, or aggregated.

Categories of Personal Information Collected. In the preceding twelve (12) months, we have collected the following categories of Personal Information from or about California residents: (a) identifiers (name, email address, phone number, IP address, account credentials, device identifiers); (b) personal records (postal address, payment information, billing and subscription data); (c) commercial information (transaction history, escrow and payment records, subscription tier); (d) internet or other electronic network activity (usage data, log data, cookies, browser and device information); (e) geolocation data (precise geolocation collected during active Platform sessions; approximate location derived from IP address); (f) audio and electronic data (call recordings, voice transcripts, AI conversation logs); (g) professional or employment-related information (contractor licensing credentials, insurance documentation, workforce records submitted by Contractors); (h) inferences drawn from the above to create a profile about a user (job category preferences, bid patterns); and (i) sensitive personal information as described in the Sensitive Information section of this Policy.

Sources, Purposes, and Disclosure. We collect Personal Information from the sources and for the business purposes described in the Collection, Use, and Disclosure sections of this Policy. We disclose Personal Information to the categories of service providers and third parties described in our Third-Party Service Providers and Data Processors section. We do not sell Personal Information for monetary consideration. We do not share Personal Information with third parties for cross-context behavioral advertising as defined by the CPRA.

Your California Privacy Rights. Subject to certain exceptions, California residents have the following rights with respect to their Personal Information:

Right to Know. You may request that we disclose (i) the categories of Personal Information we have collected about you; (ii) the categories of sources from which it was collected; (iii) our business or commercial purpose for collecting it; (iv) the categories of third parties with whom we share it; and (v) the specific pieces of Personal Information we have collected about you.

Right to Delete. You may request that we delete Personal Information we have collected from you, subject to exceptions for information we are required to retain to complete transactions, detect fraud, comply with legal obligations, or for other purposes permitted by law.

Right to Correct. You may request that we correct inaccurate Personal Information that we maintain about you, taking into account the nature of the information and the purposes of processing.

Right to Opt Out of Sale or Sharing. As stated above, we do not sell Personal Information and do not share it for cross-context behavioral advertising. Because we do not engage in these activities, there is nothing to opt out of with respect to our current practices. If our practices change, we will update this Policy and provide a “Do Not Sell or Share My Personal Information” mechanism as required by law.

Right to Limit Use of Sensitive Personal Information. You may direct us to limit our use of your Sensitive Personal Information to what is necessary to perform the Services as described in this Policy. See the Sensitive Information section for details on the SPI we collect and how to exercise this right.

Right of Non-Discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights, including by denying you goods or services, charging you a different price, or providing you with a different quality of service.

How to Submit a California Privacy Request. To exercise your Right to Know, Right to Delete, Right to Correct, or Right to Limit SPI, submit a verifiable consumer request by: (i) emailing privacy@3bids.io with the subject line “California Privacy Request”; or (ii) using the Privacy Request Portal available at 3bids.io/privacy-request. Only you, or a person legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may submit a request on behalf of your minor child. We will respond to a verifiable request within forty-five (45) days of receipt. If we need more time (up to an additional forty-five days), we will notify you of the reason and extension period. We will not charge a fee to process your request unless it is excessive, repetitive, or manifestly unfounded.

WORKFORCE AND TEAM-MEMBER PRIVACY NOTICE

This section applies to individuals who access the Platform as an employee, subcontractor, field technician, dispatcher, or other team member of a Contractor account (each, a “Workforce Member”). It supplements the rest of this Privacy Policy and, where applicable, serves as the CPRA-required notice to employees and job applicants about the collection of their Personal Information.

What We Collect About Workforce Members. When a Contractor invites a Workforce Member to the Platform or submits their information through Platform HR features, we may collect on the Contractor’s behalf: name, email address, phone number, and job role (for account provisioning and communications); professional licensing credentials and insurance documentation (for Platform compliance verification); scheduling and dispatch data, including shift assignments and field location data during active work sessions; sub-user account credentials managed through Clerk; background screening results where the Contractor initiates a Checkr report for the Workforce Member; and payroll-adjacent data the Contractor enters for workforce management purposes. Additionally, when a Workforce Member uses their own Platform sub-account, we collect usage data (log-in activity, features accessed, actions taken) in the same manner we collect such data from any Platform user.

How We Use Workforce Member Data. We use Workforce Member data solely to: (a) provision and manage the sub-account created for the Workforce Member by their Contractor employer; (b) provide the HR, dispatch, and scheduling features the Contractor has enabled; (c) process background checks and credential verifications as directed by the Contractor; (d) comply with our legal obligations as a data processor; and (e) maintain the security and integrity of the Platform. We do not use Workforce Member data for our own marketing purposes, and we do not sell or share Workforce Member data for cross-context behavioral advertising.

Controller Relationship. The Contractor who employs or engages a Workforce Member is the data controller (or “business” under CCPA/CPRA) with respect to that Workforce Member’s Personal Information in the Platform. 3Bids processes Workforce Member data as a service provider acting on the Contractor’s instructions. Workforce Members with questions about how their employer uses their data within the Platform should direct those questions to their Contractor employer. For CPRA purposes, this section constitutes 3Bids’ notice at collection with respect to Workforce Members whose data 3Bids processes directly (for example, in connection with sub-account provisioning or the receipt of background screening results). Workforce Members who are California residents may also submit privacy requests to 3Bids using the methods described in the California Privacy Rights section; however, 3Bids’ ability to fulfill requests relating to data held on a Contractor’s behalf may require the Contractor’s cooperation.

Retention. Workforce Member data is retained in accordance with the Contractor HR and Workforce Records schedule in the Data Retention section of this Policy (four years following account closure or end of engagement; five years for Checkr reports).

AUTOMATIC RENEWAL DISCLOSURES

General. 3Bids offers subscription plans for both Contractors and Posters. All paid subscription plans automatically renew at the end of each billing period (monthly) at the then-current subscription rate unless you cancel before the renewal date. By subscribing to a paid plan, you authorize us to charge your payment method on file on a recurring basis at the applicable subscription rate until you cancel. No partial-month refunds are provided upon cancellation; your access continues until the end of the then-current billing period. You may cancel at any time through your account settings at 3bids.io or by contacting support@3bids.io. Cancellation instructions are also available at 3bids.io/cancel.

California (Automatic Renewal Law, Bus. & Prof. Code §§ 17600–17606). For California residents: your subscription will automatically renew each month at the then-current rate (the current rates are set forth in Section 4 of the Platform Participation Agreement and in your order or subscription confirmation) unless you cancel before the renewal date. We will send you a reminder notice no fewer than three (3) days and no more than thirty (30) days before the renewal charge is processed if the subscription involves a free trial, promotional price, or initial term of twelve months or longer, as required by California law. You may cancel at any time using any of the methods described above. If you cancel, you will retain access through the end of the then-current billing period. If we make a material change to your subscription price or terms, we will provide you with clear and conspicuous notice and obtain your affirmative consent to the new terms before charging you at the new rate, as required by California law. Charges made in violation of these disclosure requirements are not enforceable, and you may obtain a full refund of any such charges by contacting us at support@3bids.io.

New York (General Obligations Law § 5-903). For New York residents whose subscription has an initial term of more than one month: we will send you a written reminder notice by email to the address on file not fewer than fifteen (15) days and not more than thirty (30) days before the cancellation deadline for the upcoming renewal period, as required by New York General Obligations Law § 5-903. This notice will specify the date by which you must cancel to avoid renewal charges for the next billing period and will include instructions for how to cancel. If we fail to provide the required advance reminder notice, you may cancel within the first thirty (30) days of the renewal period and receive a pro-rated refund for the unused portion of that renewal period.

THIRD-PARTY PAYMENT SERVICE

The Services may provide functionality allowing you to make payments using a third-party payment service with which you have created your own account. When you use such a service to make a payment to us, your Personal Information will be collected by such third party and not by us and will be subject to the third party’s privacy policy, rather than this Privacy Policy. We have no control over, and are not responsible for, any such third party’s collection, use, or disclosure of your Personal Information.

DATA BREACH NOTIFICATION

Notice to Affected Individuals. In the event of a security incident that results in the unauthorized acquisition, access, use, or disclosure of Personal Information that compromises the security, confidentiality, or integrity of such information (a “Security Breach”), we will provide notification to affected individuals and, where required, to relevant regulatory authorities, in accordance with applicable state and federal breach notification laws, including the laws of each U.S. state and territory that has enacted such requirements. Such notice will be provided without unreasonable delay and, in all cases, within the timeframe required by the law of the applicable jurisdiction. Where state law prescribes a specific outer deadline, we will comply with that deadline. Where no specific period is prescribed, we will provide notice as promptly as practicable under the circumstances, but in no event later than sixty (60) days following our determination that a reportable Security Breach has occurred, unless a law enforcement agency has requested a delay in notification.

Content of Notice. To the extent permitted and required by applicable law, our notice to affected individuals will include: (a) a description of the nature of the Security Breach, including the categories and approximate number of individuals and records involved, to the extent known at the time of notification; (b) the contact information of a person or department from whom affected individuals can obtain additional information; (c) a description of the steps we have taken or are taking to investigate, contain, and remediate the Security Breach; (d) a description of what affected individuals can do to protect themselves from potential harm resulting from the Security Breach; and (e) information about any additional protections or services we are offering to affected individuals, such as credit monitoring or identity theft protection.

Method of Notice. We will deliver breach notices primarily by email to the address associated with your account. Where we do not have a current email address for an affected individual, or where email notice is otherwise insufficient under applicable law, we may provide notice by mail, telephone, or, where the number of affected individuals and cost make direct notice impracticable, through prominent posting on our website or Platform and notice to major statewide media. Where we are required to notify a state Attorney General, state agency, or other regulatory body prior to or simultaneously with individual notice, we will comply with those requirements.

Reporting a Suspected Security Incident. If you believe that your Personal Information has been accessed or disclosed without authorization, or if you have information about a potential security vulnerability in the Services, please notify us immediately at support@3bids.io with the subject line “Security Incident Report.”

THIRD-PARTY SERVICE PROVIDERS AND DATA PROCESSORS

We share Personal Information with third-party service providers and sub-processors who perform functions on our behalf as part of delivering the Services. Each such provider is contractually required to use Personal Information only as necessary to perform its services and to maintain appropriate security measures. The following describes the primary third-party processors and service providers currently implicated in our product flows, the categories of data they handle, and the purpose for which they receive it. This list reflects our current operations and will be updated as our vendor relationships change.

Stripe (payment processing and connected accounts). We use Stripe to process all payment card transactions, manage escrow funding and disbursements, and onboard Contractor and Affiliate payout accounts via Stripe Connect. Stripe receives billing information, bank account or debit card details, identity verification data submitted for Stripe Connect onboarding, and transaction records. Stripe’s use of this data is governed by the Stripe Privacy Policy and the Stripe Connected Account Agreement.

Clerk (authentication and identity management). We use Clerk to manage user registration, login, session management, and multi-factor authentication. Clerk receives account credentials, email addresses, phone numbers used for MFA, and device/session metadata. Clerk processes this data solely to authenticate users and secure account access.

Twilio (voice, SMS, and messaging infrastructure). We use Twilio to route and deliver voice calls and SMS/MMS messages between Platform users and, where applicable, to and from inbound callers who contact Contractors through Platform-provisioned numbers. Twilio receives telephone numbers (caller and recipient), call metadata (duration, timestamps, call direction), SMS message content, and, where calls are recorded, call audio. Twilio acts as a communications infrastructure provider and processes this data to deliver and route communications as directed by the Platform.

Deepgram (speech-to-text transcription). We use Deepgram to transcribe voice calls and audio recordings handled through the Platform, including inbound caller audio, AI-assisted call sessions, and recorded Contractor-Poster calls. Deepgram receives audio data and returns text transcripts. Transcripts may contain any information spoken during a call, including names, addresses, financial details, and other Personal Information disclosed by callers. Transcripts are stored by us and used for dispute resolution, quality assurance, AI training, and intake-data extraction as described in this Privacy Policy.

Google Gemini and Google Cloud AI (AI conversation, intake extraction, and document analysis). We use Google Gemini and related Google Cloud AI services to power AI-assisted call and chat interactions, extract structured intake fields (such as name, address, service type, and appointment preference) from call transcripts and chat logs, and analyze uploaded photos and documents for Platform features such as job scoping and damage assessment. These services may receive Personal Information contained in call transcripts, chat messages, uploaded images, and documents submitted to the Platform. We configure these services in a mode that restricts Google’s use of submitted data for model training outside of our account, but you should review Google’s enterprise data processing terms for the definitive terms applicable to your data.

Google Maps, Places, and Street View APIs (location and address services). We use Google Maps Platform APIs, including Maps, Places, and Street View, to display job site locations, validate and autocomplete address entries, calculate distance and routing estimates, and display property-level imagery for job scoping. These APIs may receive the addresses and approximate or precise geolocation data that users enter into or that the Platform derives from user inputs. Google’s use of data submitted through its Maps Platform APIs is governed by the Google Maps Platform Terms of Service and Google’s Privacy Policy.

SendGrid (transactional and marketing email). We use SendGrid (a Twilio company) to deliver transactional emails (such as account verification, job award notifications, escrow updates, and dispute alerts) and, where applicable, marketing communications. SendGrid receives recipient email addresses, the content of outbound emails, and email engagement metadata (such as open and click events). SendGrid acts as our email delivery agent and does not use this data for its own marketing purposes.

DocuSeal (electronic signature and document execution). We use DocuSeal to prepare, present, and capture electronic signatures on Platform documents, including Job Agreements, Change Order Agreements, and Completion Certificates. DocuSeal receives the names, email addresses, and IP addresses of signatories, as well as the content of the documents being signed and audit trail data (timestamps, signature events). DocuSeal stores signed documents on our behalf for the retention periods described in this Privacy Policy.

Checkr (background screening). Where we offer background screening as an optional or required service for Contractors, we use Checkr to conduct consumer reports, which may include criminal history, identity verification, and other screening checks. When a Contractor initiates or consents to a background check, Checkr receives the Contractor’s name, date of birth, Social Security number, address history, and other information required by law to conduct a consumer report. Checkr is a consumer reporting agency and its collection and use of Contractor data is governed by the Fair Credit Reporting Act (FCRA) and Checkr’s own Privacy Policy. Contractors have the rights described in the FCRA with respect to their consumer report, including the right to dispute inaccurate information.

Sentry (application error monitoring). We use Sentry to detect, log, and diagnose software errors and performance issues in the Platform. Sentry may receive error payloads that include device and browser metadata, IP addresses, account identifiers, and, depending on the context of the error, fragments of session data or user-submitted inputs. We configure Sentry to scrub or mask sensitive fields (such as payment card numbers and passwords) from error reports, but error payloads may incidentally contain other Personal Information. Sentry data is used exclusively for engineering and reliability purposes.

Slack (internal operations and alerting). We use Slack for internal team communications and for receiving automated Platform alerts (such as new job postings, dispute flags, and payment events). Platform event notifications routed to Slack may include user identifiers, job details, and other information generated in the ordinary course of Platform operations. Access to Slack is restricted to authorized 3Bids personnel. Slack is not used to store Personal Information as a system of record.

RevenueCat (mobile subscription management). If we offer mobile application subscriptions through the iOS App Store or Google Play Store, we use RevenueCat to manage subscription state, entitlements, and renewal events across platforms. RevenueCat receives device identifiers, app store transaction identifiers, subscription status and history, and the account identifier we associate with the subscribing user. RevenueCat does not process payment card data directly; payment processing for in-app purchases is handled by the applicable app store platform. If mobile subscriptions are discontinued, this disclosure will be removed from the Policy.

INFORMATION ABOUT NON-ACCOUNT HOLDERS

The Services are designed to allow Contractors to manage leads, schedule appointments, and communicate with homeowners and other individuals who may never create a 3Bids account (collectively, “Non-Account Holders”). This section describes how we collect, use, and retain information about Non-Account Holders in connection with those product flows.

Inbound Callers and Call Recordings. When an individual calls a telephone number provisioned to a Contractor through the Platform, the Platform may answer, route, or record that call using Twilio as our telephony infrastructure provider. We collect the caller’s telephone number (ANI/caller ID), call metadata (time, duration, call direction), and, where the call is recorded or processed by an AI-assisted flow, call audio and AI-generated transcripts. Calls handled through the Platform may be recorded and transcribed for quality assurance, dispute resolution, AI training, and intake data extraction purposes. As described in our Terms of Service, callers who continue to participate in a call after receiving a recording disclosure consent to such recording. Callers who do not wish to be recorded may disconnect the call. Audio recordings and transcripts of inbound calls are retained for a period of not less than two (2) years, or longer if required for an active dispute or legal hold.

AI Conversation Logs and Extracted Intake Data. Where the Platform uses AI-assisted voice or chat flows to handle inbound calls or messages from Non-Account Holders, the Platform may collect and retain the full conversation transcript, including any personal information the caller or chat participant voluntarily provides during the interaction (such as name, address, phone number, description of the service needed, and availability for appointments). Our AI systems, powered by Deepgram for transcription and Google Gemini for language understanding and extraction, may automatically extract structured intake fields from these conversations and store them in the Contractor’s CRM profile associated with that lead. Non-Account Holders who interact with an AI-assisted Platform flow will be informed, at or before the start of the interaction, that they are communicating with an AI system.

CRM Contacts and Dispatch Data. Contractors may manually enter or import contact records for homeowners and other individuals into the Platform’s CRM and dispatch features. Such records may include name, address, telephone number, email address, service history, job notes, and appointment information. This data is stored by us on the Contractor’s behalf and is accessible to the Contractor and, where necessary for Platform operations, to 3Bids personnel. Contractors, as the data controllers for their own CRM contacts, are responsible for ensuring that their collection and submission of this data complies with applicable privacy laws, including any required notice to or consent from the individuals whose data they enter.

Public-Chat Messages, Attachments, and Uploaded Media. The Platform may include chat or messaging features accessible without a full account, including public-facing chat widgets or embeddable forms that allow Non-Account Holders to communicate with Contractors. Messages sent through these features, as well as any attachments (including photos, documents, and other files) submitted through them, are stored by 3Bids and accessible to the receiving Contractor and to 3Bids. Uploaded photos and documents may be processed by AI features (including Google Gemini) to extract job-relevant information, such as dimensions, damage descriptions, and material types. Individuals submitting messages or files through these features should not include sensitive personal information (such as Social Security numbers or financial account numbers) in their messages or attachments.

Door-to-Door Canvassing and Homeowner Lead Data. The Platform includes features that support Contractors’ door-to-door canvassing and lead generation activities. In connection with these features, the Platform may collect and store: (a) homeowner name, street address, and geolocation data associated with properties visited or targeted by Contractors; (b) brief notes entered by Contractors following a canvassing interaction, which may include the homeowner’s expressed interest, service needs, or other information shared at the door; (c) do-not-knock or do-not-contact suppression designations, indicating properties where the resident has requested not to be contacted; (d) appointment-setting records created through the Platform, including the scheduled date, time, and type of follow-up; and (e) any contact information (name, phone number, email) voluntarily provided by the homeowner during or following a canvassing interaction and entered into the Platform by the Contractor. This data is collected on the Contractor’s behalf, is stored by 3Bids as a data processor for the Contractor, and is accessible to the Contractor for the purpose of managing their leads and scheduling follow-up visits or appointments. Contractors are solely responsible for compliance with applicable canvassing ordinances, do-not-knock registries, and any other local regulations governing door-to-door solicitation, and for ensuring that they have any required legal basis to collect and enter homeowner information into the Platform.

Off-Market and Private Follow-Up Workflows. The Platform may support Contractor workflows for managing private or off-market jobs—that is, jobs that are being scoped and negotiated directly between the Contractor and a homeowner outside the Contractor's public intake channels. In connection with these workflows, the Platform stores communications, job notes, photos, and other materials exchanged between the Contractor and the homeowner lead. This information is held by 3Bids in a processor capacity for the Contractor. If a private lead converts to a Platform job, the relevant lead data is associated with the resulting Platform job record and retained in accordance with our general data retention policy.

Rights of Non-Account Holders. Non-Account Holders whose Personal Information has been collected by or submitted to the Platform may submit a privacy request—including a request to access, correct, or delete their information—by contacting us at support@3bids.io. We will respond to verifiable requests from Non-Account Holders in accordance with applicable privacy law. Please note that because much of the data described in this section is collected by Contractors using Platform tools, fulfillment of certain requests may require the cooperation of the relevant Contractor and may be subject to limitations under law (for example, where the data is subject to a legal hold or is required to resolve a pending dispute).

PUSH NOTIFICATIONS AND DEVICE TOKENS

Permission and Token Collection. If you use the Platform’s mobile application (iOS or Android), we may request your permission to send you push notifications. If you grant this permission, your device operating system issues a unique device push token (“Push Token”) that we use to route notifications to your specific device. We collect and store your Push Token in association with your account. Push Tokens are device-level identifiers; they do not, by themselves, identify you as an individual, but when associated with your account they can be used to identify you indirectly. We transmit Push Tokens to the notification delivery infrastructure described below to deliver notifications you have requested or consented to receive.

Notification Types and Delivery Providers. We use push notifications to deliver transactional and operational communications, including: job award alerts, bid activity, escrow funding and payout confirmations, dispute status updates, message notifications from other Platform users, and appointment reminders. Where you have separately consented to marketing communications, we may also send promotional push notifications. Push notifications are delivered through Apple Push Notification Service (APNs) for iOS devices and Firebase Cloud Messaging (FCM) for Android devices. Both APNs and FCM receive your Push Token and the notification payload (including notification title, body, and any associated data) in order to deliver the message to your device. These services are operated by Apple Inc. and Google LLC, respectively, and their handling of Push Tokens and notification data is governed by their applicable privacy policies and developer terms. We do not use push notification delivery data for advertising targeting.

User Controls. You may revoke push notification permission at any time through your device’s operating system settings (iOS: Settings > Notifications > 3Bids; Android: Settings > Apps > 3Bids > Notifications). You may also manage notification preferences at a granular level—such as enabling only transactional notifications while disabling marketing notifications—through the notification settings within the Platform app. When you revoke push notification permission, your device stops delivering new notifications from the Platform immediately; however, we may retain your Push Token in our systems for a brief period pending our next token refresh cycle, after which the stale token is deactivated and deleted. Push Tokens associated with accounts that have been inactive for twelve (12) consecutive months are deleted from our active notification systems.

CAMERA, PHOTO LIBRARY, AND MEDIA UPLOADS

Camera and Photo Library Access. The Platform’s mobile application may request permission to access your device camera and photo library in order to support features such as job photo documentation, damage or scope-of-work photography, profile images, and media uploads for Design Studio. Camera and photo library access is used only in the moment you actively initiate a photo capture or selection; we do not access your camera or photo library in the background. On iOS, the system-level permission prompt will describe the purpose for which camera or photo library access is requested. On Android, permissions are requested at the point of use within the app. You may revoke camera or photo library permission at any time through your device’s operating system settings, which will prevent the app from accessing these features until permission is re-granted.

What We Collect When You Upload Media. When you upload a photo, video, or document through the Platform, we collect and store: (a) the media file itself; (b) file metadata automatically embedded in or associated with the file, which may include the date and time the image was captured, device model, and, if location services were active on your device at the time of capture, the GPS coordinates at which the photo or video was taken (EXIF geolocation data); and (c) the filename and file type. We use uploaded media to facilitate job documentation, support dispute resolution, enable AI-assisted features such as job scoping and Design Studio outputs, and, where you have separately granted the license described in our User Content section, for marketing and training purposes. EXIF geolocation data embedded in uploaded photos may reveal the location of a property or job site. If you do not wish to share embedded location data, you should strip EXIF metadata from photos before uploading, which can be done through your device’s operating system settings or through third-party apps. We do not represent that we will remove or ignore EXIF geolocation data embedded in uploaded files.

AI Processing of Uploaded Media. Photos, videos, and documents uploaded to the Platform may be processed by AI systems, including Google Gemini and related Google Cloud Vision or document processing APIs, to extract structured information relevant to a job—such as dimensions, material types, damage assessments, and scope descriptions. This processing occurs on our instruction and subject to our data processing agreements with Google. You should not upload media that contains personal information unrelated to the job or project (such as images containing faces, financial documents, or medical records) unless specifically required for a Platform workflow, as that information may be processed by AI systems as part of the upload.

Uploaded Media Retention. Photos and documents uploaded in connection with a specific job are retained as part of the job record for seven (7) years following job closure, consistent with our transaction record retention schedule. Profile photos and media uploaded outside a specific job context are retained for the life of the account and for thirty (30) days following account deletion. You may delete individual uploaded files through your account settings at any time, subject to any retention obligation arising from an active dispute or legal hold.

CONNECTED THIRD-PARTY ACCOUNTS AND OAUTH INTEGRATIONS

The Platform offers optional integrations that allow Contractors to connect third-party accounts and services—such as calendar applications, accounting software, marketing platforms, and review management tools—to their 3Bids account (each, an “Integration”). This section describes how we collect, use, and store data in connection with Integrations.

Authorization and Token-Based Connections. When you enable an Integration, you will be redirected to the third-party service’s authorization flow (typically OAuth 2.0) where you grant 3Bids permission to access specified data or functionality within your third-party account. Upon your authorization, the third-party service issues an access token and, where applicable, a refresh token (collectively, “Integration Tokens”) that 3Bids stores on your behalf to maintain the connection. Integration Tokens are stored in encrypted form and are used solely to perform the sync and automation functions you have activated for that Integration. We do not share Integration Tokens with other users or use them for purposes unrelated to the Integration you have authorized.

Data Synced Through Integrations. The categories of data exchanged depend on the Integration and the permissions you grant. Examples include: calendar Integrations may sync job appointment dates, times, and location details to your connected calendar service; accounting Integrations may sync job amounts, payment records, and customer contact information to your connected accounting platform; marketing Integrations may sync completed job data or customer information to an email marketing or CRM platform you operate; review platform Integrations may transmit post-job prompts or customer contact details to solicit reviews. Data synced to a third-party service through an Integration is processed by that third party under its own privacy policy, terms of service, and security practices, and is no longer subject to this Privacy Policy once it leaves the Platform. You are responsible for ensuring that your use of any Integration—including the data you cause to be synced to third-party services—complies with applicable privacy laws, including any obligations to your customers arising from your sync of their Personal Information to third-party marketing or CRM platforms.

Integration Availability and Third-Party Policy Changes. Integrations depend on the continued availability of the third-party service’s API and its compliance with applicable developer policies. 3Bids does not control and is not responsible for changes to a third-party service’s APIs, terms of service, privacy policies, or data practices, and cannot guarantee that any Integration will remain available or functional over time. If a third-party service modifies or revokes API access, suspends your account, or changes its policies in a way that affects the Integration, the Integration may be disabled without advance notice from 3Bids. We will make reasonable efforts to notify you of Integration disruptions that we are aware of, but we are not liable for any data loss, sync failures, or service interruptions resulting from third-party API changes or outages.

Disconnecting an Integration. You may disconnect any Integration at any time through your account settings. Upon disconnection, we will delete the stored Integration Tokens within thirty (30) days, and data sync between the Platform and the third-party service will cease. Disconnecting an Integration does not delete data that was previously synced to the third-party service; to request deletion of data held by a third-party service, you must contact that service directly. Data within the Platform that was received from a third-party service through a now-disconnected Integration is retained in accordance with our general data retention policy.

UPDATES TO THIS PRIVACY POLICY

The “Last Updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.

CONTACT US

If you have any questions about this Privacy Policy, please contact us at [support@3bids.io]. Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.