This policy explains what personal data TenderPath collects, why, and how it is handled.
Last updated: 18 July 2026
We collect only the data needed to provide the service:
tp_session).We do not collect payment card numbers. TenderPath does not ask for government ID or special-category personal data during signup; do not upload such material unless it is genuinely required for the procurement workflow and you are authorized to provide it.
We do not sell your personal data or use it for advertising.
We use the following sub-processors. Each operates under its own privacy policy:
| Service | Purpose |
|---|---|
| Vercel | Application hosting and serverless infrastructure |
| Vercel Blob Storage | Storage of user-uploaded vault documents |
| Neon / Vercel Postgres | Primary database (user accounts, assessments, tenders) |
| Resend | Transactional email delivery (magic links, reports, digests) |
| Stripe | Card payment processing and subscription management |
| Cloudflare | Browser rendering for company website crawling (assessment stage) |
| Anthropic | AI-assisted assessment, tender analysis, document extraction, proposal drafting, and review where the feature uses Anthropic models |
| OpenAI | AI-assisted answers, discovery, and selected analysis features where the feature uses OpenAI models |
| Google Fonts | Web font delivery (Inter, Playfair Display) |
We retain your data for the following periods:
You may request earlier deletion of your data at any time by emailing info@tenderpath.me, subject to any legal retention obligations.
TenderPath is operated in Egypt and processes data in accordance with the Egyptian Personal Data Protection Law (Law No. 151 of 2020). Under that law and other applicable regulations, you may have the right to:
To exercise any of these rights, email info@tenderpath.me. We will respond within 30 days.
We use a single strictly-necessary authentication cookie (tp_session) to keep you signed in. No marketing or analytics cookies are set. See our Cookie Policy for details.
Authentication tokens are short-lived. The session cookie is httpOnly and scoped to TenderPath's domain. New customer documents and generated artifacts are stored in private object storage and delivered through owner-authenticated TenderPath routes. Staff-facing queues expose operational metadata by default; content access for human fulfillment or support requires a customer-controlled, time-limited grant for the relevant work order and is recorded in an access log. We do not store payment card data. This is an access-control model, not zero-knowledge encryption: TenderPath systems and the processors named above must handle content when you request analysis or generation.
TenderPath is intended for business use by adults. We do not knowingly collect data from anyone under 18.
We may update this policy as the product evolves. If changes are material, we will notify registered users by email before they take effect. Continued use of the service after that date constitutes acceptance of the updated policy.
For privacy-related questions or data requests: info@tenderpath.me
Tenderpath Limited, 49 Street 105 Hadayek El Maadi, Maadi, Cairo, Egypt 10543