Privacy Policy
Effective Date: April 8, 2026
1. Introduction
Stackrate, Inc., a Delaware C corporation ("Stackrate," "we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use the Stackrate platform at stackrate.ai, including any associated services, APIs, and downloadable content (collectively, the "Service").
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with these practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Email addresses: Provided voluntarily when you request report delivery or sign up for notifications.
- Process descriptions and requirements: Text you enter describing your software evaluation needs.
- Uploaded documents: PDF, DOCX, or TXT files you upload for analysis (RFPs, process documents, requirements).
- Vendor portal information: If you are a software vendor using our vendor features, you may provide a business email, company name, documentation URLs, and commentary on report findings.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, report generation requests, and interaction patterns.
- Device and browser information: Browser type, operating system, screen resolution, and language preference.
- IP address: Used for security, fraud prevention, and approximate geographic location.
- Cookies and similar technologies: See Section 7 below.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To generate comparison reports, process your requirements, and deliver results to you.
- Communication: To send you report-ready notifications, respond to inquiries, and provide customer support.
- Service improvement: To analyze usage patterns, diagnose technical issues, and improve the quality and accuracy of our analyses.
- Security: To detect, prevent, and respond to fraud, abuse, security incidents, and technical issues.
- Legal compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
We do not sell your personal information. We do not use your personal information for behavioral advertising or profiling.
4. Third-Party Service Providers
We share information with the following categories of third-party service providers, solely to operate and improve the Service:
- AI processing (Anthropic, PBC):Your process descriptions and requirements are sent to Anthropic's API to generate analyses. Anthropic's data processing is governed by their privacy policy. Anthropic does not use API inputs for model training.
- Email delivery (Resend): Your email address is shared with Resend to deliver report-ready notifications. Resend processes this data solely for email delivery purposes.
- Hosting and infrastructure (Vercel): The Service is hosted on Vercel. Vercel may collect server logs, IP addresses, and performance metrics as part of their infrastructure services.
- Database (Supabase): When enabled, report data and user-provided information may be stored in Supabase-hosted databases.
We require all third-party service providers to handle your data in a manner consistent with this Privacy Policy and applicable data protection laws.
5. Data Retention
We retain your information only as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Reports and analyses: Retained for as long as the Service is operational, unless you request deletion.
- Email addresses: Retained until you request removal or unsubscribe.
- Uploaded documents: Processed for report generation and may be retained for service improvement. You may request deletion at any time.
- Usage and log data: Retained for up to 12 months for security and analytics purposes.
6. Data Security
We implement commercially reasonable administrative, technical, and physical safeguards to protect your information against unauthorized access, alteration, disclosure, or destruction. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. You use the Service at your own risk.
7. Cookies and Tracking Technologies
The Service may use cookies, local storage, and similar technologies for essential functionality (such as vendor portal session management). We minimize the use of tracking technologies and do not use third-party advertising trackers.
If we deploy analytics tools in the future, this section will be updated to reflect the specific technologies used and your choices regarding them. You can control cookie behavior through your browser settings.
8. Your Rights and Choices
8.1 All Users
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may request correction of inaccurate personal information.
- Deletion: You may request deletion of your personal information, subject to legal retention requirements.
- Unsubscribe: You may opt out of email communications at any time by using the unsubscribe link in any email or by contacting us.
8.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:
- The right to know what personal information we collect, use, and disclose.
- The right to request deletion of your personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA/CPRA.
- The right to non-discrimination for exercising your privacy rights.
To exercise any of these rights, contact us at privacy@stackrate.ai. We will verify your identity before processing your request and respond within 45 days as required by law.
8.3 European Economic Area and United Kingdom (GDPR)
If you are located in the EEA or UK, you may have additional rights under the General Data Protection Regulation (GDPR), including rights of access, rectification, erasure, restriction of processing, data portability, and objection. Our legal basis for processing your information is: (a) your consent; (b) performance of a contract; or (c) our legitimate interests in operating and improving the Service. To exercise your rights, contact us at privacy@stackrate.ai.
9. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
10. International Data Transfers
Your information may be transferred to and processed in the United States and other jurisdictions where our service providers operate. By using the Service, you consent to the transfer of your information to jurisdictions that may have different data protection laws than your jurisdiction of residence.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Effective Date." Your continued use of the Service after any changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically.
12. Contact Us
For questions, requests, or complaints regarding this Privacy Policy or our data practices, contact us at:
Stackrate, Inc.
Email: privacy@stackrate.ai