What we
collect.
Why. And then what.
Short version: we collect what we need to run the product, we don't sell it, and you can export or delete it anytime. The long version is below — eight sections, no surprises.
What we collect
When you sign up for Tidy, you give us:
- Your name and email address (authentication).
- The organization you create or join, and any customers, prospects, buildings, bids, and invoices you add inside it.
- Any files you upload (branding logos, attachments to bids or invoices).
When you visit tidyhq.app, our hosting provider (Cloudflare) records standard request metadata (IP, user agent, referer) for security and rate-limiting. We do not run third-party analytics on the marketing site.
How we use it
- To provide the product: store your data, render your bids and invoices, send the emails you ask us to send.
- To authenticate you (sessions are signed HTTP-only cookies; passwords are hashed with bcrypt).
- To contact you about service-affecting issues (outages, billing, security).
We do not sell your data. We do not share it with advertisers. We do not train AI models on it.
Sub-processors
The vendors that handle your data on our behalf:
- Cloudflare — hosting, edge cache, DDoS protection, and the database that stores your account.
- Resend — transactional email (bid notifications, invoice links, welcome + trial messages).
We do not use a third-party CRM. Lead capture, prospect tracking, and design-partner relationships are stored in Tidy's own database, not synced to an outside vendor.
Your data, your choice
- Export. Every entity in Tidy (bids, customers, prospects, invoices, buildings) supports CSV / JSON export. Your data is yours.
- Delete. Closing your account deletes your organization and all child rows. Email hello@tidyhq.app to start a deletion request. We action within 30 days.
- Access. Sign in to tidyhq.app/app to see everything we hold for your org.
Security
Sessions are signed and HTTP-only. Data in transit is TLS 1.2+. Data at rest is in Cloudflare's D1 (SQLite) and R2, encrypted at the storage layer. Production access is gated by Cloudflare Access (SSO + service tokens). Source code lives in private repositories with branch protection.
Children's privacy
Tidy is a B2B tool for adult business operators. We do not knowingly collect data from anyone under 18.
Changes to this policy
When we change what we collect or how we use it, we update the "Last updated" date above and email active account holders at least 14 days before the change takes effect.
Contact
Questions: hello@tidyhq.app.