Privacy Policy
Last updated 2026-07-23
BID Partners LLC ("we") operates parsedata.io as part of the Govparse family. This policy explains what we collect, how we use it, and what choices you have. The Service surfaces public-record data published by US federal and state agencies; the personal data we collect from visitors is limited and tied to operating the Service.
1. What we collect
Usage data — pages you visit, queries you run, and the device/browser metadata your browser sends. API account data — the organization name and contact email attached to an API key, and a per-call usage ledger (endpoint, price, timestamp) used for billing. Billing data is processed by Stripe; we do not hold card numbers. Payments made via the x402 protocol occur on a public blockchain; wallet addresses used to pay are public by the nature of that network and are not linked by us to any identity.
2. Public records about businesses
The datasets in the Service are sourced from official government publications (the US DOT Federal Motor Carrier Safety Administration, the US Department of Labor (OFLC and WHD), OSHA, the EPA, SAM.gov and Grants.gov, the IRS, the SEC, state workforce agencies, and the US Department of Health & Human Services agencies including the Centers for Medicare & Medicaid Services (CMS), the HHS Office of Inspector General, and the FDA). They describe businesses and, where the issuing agency published them, named individuals in their business capacity (e.g. registered agents or officers of record). We republish these records as filed, with provenance to the official source. We do not buy or rent personal data from data brokers, we do not target ads, and we do not set cookies for cross-site tracking.
3. How we use what we collect
To operate the Service (serve pages, authenticate API keys, meter and bill usage), to improve it (aggregate analytics, debugging), to communicate with you about your account, and to comply with legal obligations.
4. Sharing
We share with infrastructure providers strictly to run the Service — Stripe (billing), Supabase (database hosting), and Vercel (web hosting). We do not sell personal data. We may disclose information when required by law or to protect rights and safety.
5. Retention
API account data persists while your key is active. Billing and usage-ledger records are retained for tax and audit periods (typically 7 years). Web logs are retained for up to 24 months.
6. Your rights
You can access, correct, or delete your account data by emailing us. If you're in the EU, UK, or California, you have additional rights under GDPR, UK-GDPR, or CCPA respectively — including the right to data portability and to lodge a complaint with a supervisory authority. Requests concerning the underlying government records themselves should be directed to the issuing agency, which is their system of record; we refresh from the official source on a documented cadence.
7. Security
We use HTTPS everywhere, encryption at rest for database fields, hashed API keys, and least-privilege access. No system is perfectly secure; we'll notify affected users without undue delay if a breach affects their personal data.
8. Children
The Service is not directed at children under 13. If we learn we've collected data from a child under 13, we'll delete it.
9. International transfers
Our infrastructure runs primarily in the United States. If you're accessing from outside the U.S., you understand your data may be processed in the U.S.
10. Changes
We may update this policy. Material changes will be posted on parsedata.io.
11. Contact
Questions or requests: support@parsedata.io.