1. Information We Collect

At PromptBid, we are committed to transparency about data collection. We collect only the minimum information necessary to operate our platform effectively.

Account Information

When you create an account, we collect your name, email address, company name, and billing information. You may also provide additional profile information such as job title and industry focus.

API Usage Data

We collect metadata about API requests made through our platform, including request timestamps, API endpoints accessed, and response status codes. This data is used exclusively for performance monitoring, billing, and service improvement.

Campaign Metadata

When you run campaigns, we collect aggregated performance metrics including impressions, clicks, conversions, and spend. We never store individual user identifiers or personally identifiable information about your users.

Interaction Data

We collect information about how you interact with our platform, including pages visited, features used, and time spent on various sections. This helps us understand product usage patterns and improve the user experience.

Privacy First Design

We never collect, store, or have access to personally identifiable information about end-users of your applications. PromptBid works with aggregated, anonymized campaign data only.

2. How We Use Information

We use the information we collect for specific, legitimate business purposes:

Service Delivery

  • Processing API requests and maintaining platform functionality
  • Billing and financial transactions
  • Technical support and customer service
  • Account verification and security

Product Improvement

  • Analyzing platform usage to identify enhancement opportunities
  • Monitoring performance metrics and system reliability
  • Developing new features based on customer feedback
  • Testing new functionality before general release

Legal Compliance

  • Complying with legal obligations and regulatory requirements
  • Enforcing our Terms of Service
  • Protecting against fraud and illegal activity

We do not use personal information for marketing purposes without explicit consent, and we never sell customer data to third parties.

3. Data Sharing

We maintain strict controls over who has access to customer data.

Service Providers

We share information with carefully selected service providers who assist us in operating the platform, including payment processors, cloud infrastructure providers, and analytics tools. All service providers are bound by confidentiality agreements and contractual data protection obligations.

Legal Requirements

We may disclose information when required by law, court order, or government authority. We will notify you of such requests unless legally prohibited from doing so.

Business Transfers

In the event of a merger, acquisition, or sale of assets, customer information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.

Never Sold to Third Parties

PromptBid does not sell, rent, or trade customer data to third parties. Period. This is not a conditional statement or a buried provision—it is a core principle of our business.

4. Cookies & Tracking

We Don't Use Cookies

PromptBid does not use cookies, pixels, or fingerprinting technology. We rely instead on server-side session management and explicit authentication. Your browsing behavior is not tracked across websites.

What This Means

Without cookies or persistent identifiers, PromptBid cannot and does not create profiles of your behavior across the web. Each session is separate and authenticated, and we have no mechanism to identify you outside of our platform.

Our Approach

We use server-side session tokens for authentication, which are stored securely and expire when you log out or after a period of inactivity. These tokens contain no personal information and are not used for tracking.

Analytics

Any analytics we implement are privacy-respecting, aggregate-only, and do not involve persistent user identification. We may use tools that provide anonymized usage insights without enabling individual user tracking.

5. Data Retention

We retain customer data only as long as necessary to provide our services and comply with legal requirements.

Active Accounts

Account and campaign data is retained for the duration of your subscription and for up to 30 days after account termination to allow for recovery or export requests.

Billing Records

Financial and billing records are retained for 7 years to comply with tax and accounting regulations.

System Logs

Technical logs and server access records are retained for 90 days for security and performance monitoring purposes, then automatically deleted.

Account Deletion

When you request account deletion, we securely remove all associated data within 30 days, except where legally required to retain records. Personal information is irreversibly deleted from all systems.

6. Your Rights

You have rights regarding your personal data. The specific rights available depend on your location.

GDPR Rights (EU, EEA, UK)

  • Right of Access: You can request a copy of the personal information we hold about you
  • Right of Correction: You can request correction of inaccurate or incomplete data
  • Right of Erasure: You can request deletion of your personal data in certain circumstances
  • Right of Restriction: You can restrict processing of your data
  • Right of Portability: You can request your data in a portable format
  • Right to Object: You can object to processing of your data

CCPA Rights (California)

  • Right to Know: You can request what personal information we collect, use, and share
  • Right to Delete: You can request deletion of personal information collected from you
  • Right to Opt-Out: You can opt-out of the sale or sharing of your personal information
  • Right to Correct: You can request correction of inaccurate personal information
  • Right to Non-Discrimination: We will not discriminate based on privacy choices

How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@promptbid.ai with your request and verification information. We will respond within the timeframe required by applicable law (typically 30 days).

7. Children's Privacy

PromptBid is not intended for individuals under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete such information immediately.

If you believe we have inadvertently collected information from a child, please contact us at privacy@promptbid.ai.

8. International Transfers

PromptBid operates globally, and your information may be transferred to, stored in, and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from your home country.

When we transfer personal data internationally, we implement appropriate safeguards including Standard Contractual Clauses and adequacy determinations to ensure adequate protection of your information.

By using PromptBid, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules than your home country.

9. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by email or by posting a prominent notice on our website.

Your continued use of PromptBid after changes become effective constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.

10. Contact Us

If you have questions about this Privacy Policy, concerns about our privacy practices, or wish to exercise any of your rights, please contact our Privacy Team:

PromptBid Privacy Team
Email: privacy@promptbid.ai
Address: PromptBid Inc., New York, NY
Response Time: Within 30 days

If you are located in the EU and believe we have violated your privacy rights, you also have the right to lodge a complaint with your local data protection authority.