Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains how IntelBid LLC ("IntelBid," "we," "us," or "our") collects, uses, shares, and protects information in connection with the IntelBid estimating and bid-management platform (the "Service"). By using the Service, you agree to the practices described here.
1. Who we are
IntelBid is a software platform for commercial flooring subcontractors that helps capture bid invitations, draft proposals and follow-up emails, and track bid pipelines. The Service is operated by IntelBid LLC. For any privacy question you can reach us at support@intelbid.app.
2. Information we collect
We collect the following categories of information:
- Account information — your name, work email, company name, and password (stored only as a secure hash) when you create an account.
- Business content you create — bids, projects, contacts, scopes, pricing, proposals, and templates you enter or generate in the Service.
- Connected mailbox, calendar & file-storage data — if you connect a Google or Microsoft account, we access email, calendar, and (if you enable file sync) Google Drive data as described in Section 4.
- Connected accounting data — if you connect QuickBooks Online, we access and create accounting records as described in Section 5.
- Call data — if your organization enables the optional voice/phone integration, we process call transcripts and metadata from that provider to log calls and, where you configure it, create leads or calendar events.
- Billing information — handled by our payment processor (Stripe). We do not store full card numbers; we receive only subscription status and limited billing metadata.
- API keys — if you enable external-agent access (Section 6), we store a one-way hash of each key you create, its name, and when it was last used — never the key itself.
- Usage and device data — basic logs such as IP address, browser type, and actions taken, used to operate and secure the Service.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service's core features (bid capture, proposal drafting, follow-ups, and analytics).
- Authenticate you and keep your account and your organization's data secure and isolated from other organizations.
- Process subscriptions and prevent fraud.
- Provide support and respond to your requests.
- Comply with legal obligations.
We do not sell your personal information, and we do not use your email content or attachments for advertising.
4. Google and Microsoft account data
Connecting a mailbox is optional and is only used to power features you turn on. When you connect a Google account, we request these permissions: read-only Gmail access (gmail.readonly) to detect and log incoming bid invitations and replies; Gmail compose (gmail.compose) to create draft proposal and follow-up emails for you to review and send; calendar events access to add booking or walkthrough events; and your email address to identify the connected mailbox. When you connect a Microsoft account, we request the equivalent permissions: Mail.Read, Mail.ReadWrite, Calendars.ReadWrite, and User.Read.
If your organization enables Google Drive file sync, we additionally request Google Drive access to mirror bid attachments and generated proposals into a folder structure in your own Drive (organized by job number), so your files stay available outside the Service. This is a broader, organization-level Drive permission — separate from the per-user Gmail/Calendar connection above — and is off by default; an administrator must turn it on in Settings → Integrations, and can disconnect it there at any time.
We never request permission to send email on your behalf automatically — proposal and follow-up emails are created as drafts that you review and send yourself. You can disconnect a mailbox at any time from Settings → Integrations, which revokes our access and stops further reading.
5. QuickBooks Online data
Connecting QuickBooks Online is optional, organization-level (one connection per company, set up by an admin in Settings → Integrations), and only used to power progress-billing features you initiate. When your organization connects QuickBooks, we request the com.intuit.quickbooks.accounting scope and use it only to: look up or create a Customer record matching the client on a job; look up or create a single reusable Service item used to itemize invoice lines; and create Invoice records that mirror the pay application you build in the Service from your Schedule of Values. We read your chart of accounts only to find an income account to attach to that Service item.
We do not read or write QuickBooks bills, vendors, payroll, banking, or reports data, and we do not access QuickBooks data for any organization other than the one that connected it. Invoices are created only when you explicitly choose to push a pay application — we never create or modify QuickBooks records automatically in the background. You can disconnect QuickBooks at any time from Settings → Integrations, which revokes our access; previously created invoices remain in your QuickBooks company and are not deleted by disconnecting.
6. API access and external agents (MCP)
The Service lets you generate organization API keys (in Settings → Integrations) and connect your own external AI agents or tools — such as Claude Desktop, Cursor, or any Model Context Protocol (MCP) client — to your workspace. This is optional and off unless an administrator creates a key.
When you connect an external agent with a key, that agent — and the third party that operates it — can read your organization's pipeline data (bids, clients, contacts, pricing, and correspondence) at your direction. This is a disclosure you initiate to a third party we do not control; that third party's handling of the data is governed by its terms and privacy policy, not ours. External agents can only read data and stageproposed changes for a member to confirm inside the Service — they cannot write to, or delete from, your workspace directly. We store only a one-way hash of each key (never the key itself), record when a key was last used, and let you revoke any key at any time in Settings → Integrations, which immediately cuts off that agent's access.
7. How we share information
We share information only in these limited cases:
- Within your organization — your bids, contacts, and other workspace content are visible to other members of your organization, per their role.
- Service providers (sub-processors) — vendors who help us run the Service under contract, including Supabase (database and authentication), Vercel (hosting), Stripe (payments), Google and Microsoft (the mailboxes, calendars, and Drive files you connect), Intuit/QuickBooks Online (the accounting connection you connect), our voice-call provider (if you enable that integration), address-lookup providers used to geocode job-site addresses, and AI providers used to extract bid details and draft emails. These providers may only process data to perform services for us.
- External agents you connect — if you create an API key and connect your own AI agent or MCP client, your workspace data is shared with that agent and its operator at your direction, as described in Section 6.
- Legal and safety — when required by law or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
8. AI processing
The Service uses third-party AI providers to read bid documents and email content you submit and to draft proposals and follow-ups. This content is sent to those providers solely to perform that task for you. We do not permit your Google or Microsoft user data, your QuickBooks data, or your email content, to be used to train generalized AI models.
9. Data retention
We keep your account and workspace data for as long as your account is active. When you disconnect a mailbox, Google Drive, or QuickBooks, we delete the stored access and refresh tokens for that connection. When you close your account or request deletion, we delete or de-identify your personal data within a reasonable period, except where we must retain it to comply with law, resolve disputes, or enforce our agreements. Disconnecting QuickBooks does not delete invoices or other records already created in your QuickBooks company — those remain under your control in QuickBooks.
10. Security
We protect data with encryption in transit, encrypted storage of credentials and OAuth tokens, organization-level access controls (row-level security so one organization cannot see another's data), and least-privilege access for our systems. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit access to it.
11. Cookies and local storage
We use a small number of first-party cookies and browser storage entries. We do not use advertising, marketing, or third-party analytics cookies, and we do not embed advertising pixels or cross-site trackers. Nothing is stored on your device when you simply visit our public pages — our marketing site, pricing, and legal pages set no cookies at all.
What we do set, once you sign in or change a setting:
- Authentication (strictly necessary) — session cookies set by our authentication provider (Supabase), named sb-*, that keep you signed in and let us verify each request. Without these the Service cannot function.
- Security during account linking (strictly necessary) — short-lived cookies such as google_oauth_state, microsoft_oauth_state, qbo_oauth_state, drive_oauth_state, onedrive_oauth_state, and oauth_return_to, set only while you are connecting a Google, Microsoft, or QuickBooks account. They protect that connection against cross-site request forgery and return you to the right page, then expire within minutes.
- Preferences (functional) — cookies such as ib_theme (your light/dark theme choice, sent with page requests only so we can render the page in the right theme immediately instead of flashing the wrong one), ib_sidebar_collapsed (whether your navigation sidebar is collapsed) and, for platform administrators only, ib_active_org (which organization is currently being viewed).
- Browser local storage (functional) — kept on your device and never transmitted to us: a second copy of your theme choice, your preferred layout and filters on list and calendar pages (for example ib_bids_view, ib_intake_view, ib_projects_view), flags recording that you have already dismissed a welcome or tour prompt, and a short-lived cache of data already shown to you so pages reload faster.
Because these are limited to what is strictly necessary to deliver the Service and to remembering choices you made yourself, we do not display a cookie consent banner. If we later introduce analytics or marketing technologies that require consent, we will ask for it before they are set and update this Policy. You can clear or block cookies and local storage through your browser settings at any time, though blocking the authentication cookies will prevent you from signing in.
12. Your choices and rights
You can:
- Access and update your account information in the Service.
- Disconnect any connected Google, Microsoft, or QuickBooks account at any time in Settings → Integrations.
- Revoke any API key — and with it an external agent's access — at any time in Settings → Integrations.
- Request a copy or deletion of your personal data by emailing support@intelbid.app.
If you are a California resident, the CCPA/CPRA gives you rights to know, delete, and correct your personal information, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law. To exercise any right, contact support@intelbid.app.
13. Children's privacy
The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you in the Service. Your continued use after changes take effect means you accept the updated Policy.
15. Contact us
Questions about this Policy or your data? Email support@intelbid.app or write to us at IntelBid LLC.