Privacy Policy
Last updated 26 August 2026
1. What we collect
Account details (name, e-mail, workspace), documents and data you upload, generated content, usage metrics and billing information handled by our payment processor.
2. How we use it
To provide and improve the Service, to send transactional e-mail (invitations, deadline reminders, receipts) and, if you opt in, product updates. We do not sell personal data.
3. Processors
Cloud hosting and database (Vercel, Supabase), AI provider (Anthropic), e-mail (Resend) and billing (Paddle). Each processes data only on our instructions and under contractual safeguards.
4. The shared rate index (optional, off by default)
A workspace contributes anonymised priced observations to HuntFlow's cross-customer rate index only while a user with the finance role or higher — finance, technical lead, bid manager or admin — has turned on Rate Library → "Contribute anonymised rates". The setting is off for every new workspace.
A contributed observation records the catalogue item, the country and region, the unit, the price and its currency, the observation date, the evidence class and a confidence weight. Inside HuntFlow it is also tagged with your workspace and, where the price came from a supplier quote, an uploaded price list or an RFQ, with that supplier, the name of the source document and the wording of the line the price was read from — that is what lets you withdraw or correct it afterwards. Whole documents are never copied into the index.
None of those tags is published. Other customers see a shared rate blended into the recomputed estimate for its item and country, and — once at least three customers have contributed for that item and country — may also see it individually and anonymised: price and currency, unit, evidence class, confidence and the month only. Never the exact date, the supplier, the document, your notes, or which customer it came from.
Turning the setting off marks your existing contributions unshared and triggers a recompute of the affected countries, which deletes any estimate that no longer has qualifying evidence behind it. It cannot recall a figure another customer has already used. Deleting your workspace deletes its observations.
5. Retention and deletion
Workspace data is retained while your account is active. An admin can delete the whole workspace from Settings → Workspace & data; the page lists what will be destroyed and asks for the workspace name to be typed back before it will proceed. If no admin is reachable, write to privacy@huntflows.io from the address on your account and we act once we have confirmed you are an admin of it. A workspace whose subscription is still billing is not deleted until the subscription has been cancelled, so that nobody is charged for a workspace that no longer exists.
The deletion itself is immediate and irreversible, applies to every member of the workspace, and destroys its bids, tender documents, analyses, BOQs, generated documents, exports, RFQs and supplier quotes, evidence vault, library, lessons, suppliers, rate observations, comments, notifications and activity. The stored files behind those records — tender documents, evidence-vault items, uploaded price lists and exports — are deleted from object storage in the same operation; any file that cannot be removed at the time is logged and cleared within 30 days.
Where you would rather we acted for you — including deletion of a user account, or of personal data held outside a workspace — write to privacy@huntflows.io. We complete a verified request within 30 days, except where retention is required by law.
6. Your rights
You may access, correct, export or delete your data. An admin can download the workspace's own data at any time from Settings → Workspace & data, as one machine-readable JSON file together with a manifest of every stored file so the originals can be fetched; no request to us is needed. For anything else — a copy of your personal data, a correction, or erasure, including where you are not an admin — write to privacy@huntflows.io.
7. Security
Data is encrypted in transit and at rest; access is role-based and logged. Report security concerns to security@huntflows.io.