Privacy Policy
Last updated 6 September 2026
AI Tender Desk handles confidential company information — financial statements, work orders, certifications and commercial preferences. This page explains what we hold, why, and what we will not do with it.
Who we are
AI Tender Desk is operated by Synergy Lease. References to “we” and “us” mean that entity. You can reach our privacy contact at privacy@aitenderdesk.com.
What we collect
- Account information — name, work email, mobile number and password (stored only as a hash by our authentication provider).
- Organisation information — company name, type, GSTIN if you provide it, location, website and the description of what your business does.
- Tender preferences — categories, keywords, locations, value ranges, buyer types and alert settings.
- Documents you upload — whatever you choose to place in your Company Document Vault.
- Usage and delivery records — which alerts were sent to which channel and whether they were delivered, plus an audit log of significant account actions.
- Payment records — order and payment identifiers from Razorpay. We never see or store your card number, UPI PIN or bank credentials.
How we use it
To find and rank tenders for you, to deliver your alerts, to operate your account and billing, to support you when you ask, and to keep the service secure. That is the whole list.
What we do not do
- We do not sell your data.
- We do not share your documents, preferences or bid activity with other customers.
- We do not use one customer’s confidential documents to build features for another customer.
- We do not send your data to advertising networks.
Isolation between organisations
Every record in AI Tender Desk that belongs to a customer is tied to an organisation and protected by database-level row security. An account that is not a member of your organisation cannot read your documents, preferences, saved tenders, alerts or billing — not through the application, and not through the API.
Storage and security
- Data is hosted on Supabase infrastructure in the Asia Pacific (Mumbai) region.
- Uploaded documents live in a private storage bucket. They are never publicly addressable and are served only through short-lived signed links generated for an authorised member of your organisation.
- Access to production systems is limited to authorised personnel.
- Significant account actions are recorded in an audit log your administrators can read.
Processors we rely on
- Supabase — database, authentication and file storage.
- Razorpay — payment processing.
- Resend — transactional and digest email.
- Meta (WhatsApp Business Platform) — WhatsApp digest delivery.
- Vercel — application hosting.
Retention
We keep your data for as long as your organisation has an account. If you close your account, we delete your documents and personal data within 90 days, except records we are required to retain for tax and statutory purposes.
Your rights
You can access, correct, export or delete your information. Email privacy@aitenderdesk.com and we will respond within 30 days.
Changes
If we change this policy in a way that materially affects you, we will tell you by email before the change takes effect.
