Clear data boundary
Public opportunities and private territories stay separate
Public opportunity pages contain procurement details derived from public USAC records. They do not publish BidTerrain customer names, email addresses, company profiles, saved territories, ZIP selections, report tokens, billing records, or workflow activity.
A customer’s selected counties, places, and ZIPs are used to screen public records for that customer. They are not turned into a public serviceability map or presented as a network ownership claim.
Private report delivery
Scan contents use opaque access links
Private report, dashboard, and preference access uses opaque tokens. Secret token values are not stored in plain text for lookup, and personal report content is not embedded in a public, descriptive URL. After a private report opens, its read-only credential is removed from the address bar and can remain only in that browser tab's session storage so the report survives a refresh.
Access links should be treated like a password: do not forward them, place them in public documents, or reuse them on a shared device. If a link may have been exposed, contact BidTerrain by email.
Collect what the workflow needs
BidTerrain avoids property-level network data
The territory workflow accepts broad service-area identifiers: state, selected counties or Census places, and optional five-digit ZIPs. It tells customers not to submit ZIP+4 codes, customer addresses, facility locations, network routes, or other property-level network details.
Document evidence is also bounded. BidTerrain retains structured procurement signals and provenance rather than raw extracted text, applicant contacts, street addresses, site names, or health care provider identifiers.
Hosted payment boundary
Payment-card entry stays with Stripe
Checkout and payment-card collection use Stripe-hosted pages when purchasing is available. BidTerrain stores limited customer, subscription, invoice, and payment-status identifiers needed to operate the service; it does not receive or store a customer’s full card number.
Customer-facing billing access is enabled only through BidTerrain’s configured Stripe environment. See the privacy policy for the processing and retention overview.
Measured with restraint
Acquisition does not require publishing personal information
Campaign labels and limited ad click identifiers may be associated with a submitted scan so BidTerrain can measure which source produced the request. The territory-scan page does not use a Meta Pixel or Meta Conversions API. BidTerrain does not sell customer personal information.
A free scan authorizes that requested scan; it does not silently enroll the visitor in recurring marketing. Recurring alerts require an active service or separate opt-in and include preference and unsubscribe controls when email delivery is enabled.
Shared responsibility
What customers should do
- Use a work email controlled by the subscribing company.
- Do not submit customer addresses, routes, credentials, or confidential bid content.
- Keep private report and dashboard links out of shared or public systems.
- Verify all dates and requirements at the official USAC source.
- Email suspected access or privacy issues to bidterrain@gmail.com.
This page describes BidTerrain’s current security design and operating boundaries. It is not a third-party certification or a guarantee that any online service can eliminate all risk.