Privacy Policy
Effective August 13, 2026
HRC Ledger is a service of Healthcare Remittance Corporation. This policy explains what we collect about you, why, who else sees it, and how to get it removed. It covers hrcledger.com, the app, the API, and the email we send.
The short version
- We do not sell your personal information. We never have.
- We run no advertising trackers and no third-party analytics. There is no Google Analytics, no ad pixel, and no session recording on this site.
- We set two cookies: one that keeps you signed in, and one that remembers who referred you.
- We do not store your IP address or your card number.
- You can delete your account yourself, at any time, from /account.
1. What we collect about you
Account information. Your email address, and your name if you give one. Sign-in is handled by Clerk, our authentication provider, which holds your name and login credentials. We store your email address so we know who you are and where to send what you asked for. We never see or store your password.
Your company profile. What you tell us about the business you are bidding for, so we can match you to the right work: company name, website, headquarters city and state, size, year founded, entity type, what you do, the certifications and set-aside eligibility you hold, your public registration identifiers such as UEI, CAGE or DUNS, and the jurisdictions, buyer types, codes, keywords and contract sizes you care about. All of this is optional, and it is about your business rather than about you personally.
What you create in the product. Saved contracts and the notes and status you put on them, saved searches, the organizations you follow, your pursuit packages, and your team memberships and invitations.
Billing information. Your subscription tier, your trial end date, and the customer identifier Stripe gives us. Card numbers are entered on a page hosted by Stripe and never reach our servers. We cannot see your full card number.
Email engagement. What we sent you, when, and whether it was delivered, opened, clicked or dismissed. Resend, our email provider, reports this back to us. We use it to keep alerts relevant and to stop mailing addresses that bounce.
API usage. If you hold an Enterprise API key, we store a hashed version of the key, its scopes, when it was last used, and request counts for rate limiting.
What we do not collect. We do not store your IP address. We read it briefly to limit signup abuse, then turn it into a one-way hash, so the address itself is never written to our database. We do not store browser or device fingerprints, and we do not record what pages you browse for advertising or profiling.
2. Public data we hold about organizations
Most of what is in HRC Ledger is not about you at all. It is public information about contracts and about the healthcare organizations that buy and sell them, gathered from sources such as:
- SAM.gov and USAspending
- State, county, city, and health-system purchasing portals and open data sites
- CMS hospital data, HRSA health-center data, and the NPPES provider registry
- IRS records for tax-exempt organizations, including Form 990 filings, which is where nonprofit finances and named board members and executives come from
Some of these public records name individuals — a contracting officer, a hospital executive, a board member. That information comes from the public source and stays tied to their professional role, not to their private life. If you are named in that data and want it corrected or removed, write to us and we will look at it.
3. How we use what we collect
- To run your account and sign you in
- To find contracts worth your attention and push them to you, which is the core of the product
- To send the digest, the alerts you set up, and messages about your account
- To take payment and manage your subscription
- To decide what your tier includes, and to apply rate limits fairly
- To keep the service secure, to prevent abuse and fraud, and to fix faults
- To understand in aggregate what is working, so we can improve the product
- To meet our legal obligations
We use AI models to summarize contracts, pull out key details, enrich organization profiles, and generate the numeric representations that power recommendations. Your company profile can be part of that when it is used to match you to opportunities. We do not permit our AI providers to train their models on your data.
4. Who we share it with
We do not sell your personal information, and we do not share it for advertising. We use a small number of service providers to run HRC Ledger. They may only handle your data to do work for us:
- Clerk — accounts, sign-in, and session security
- Stripe — subscriptions and payments
- Resend — sending email and reporting delivery
- Render — hosting the application and the database
- Anthropic and OpenAI — AI processing for enrichment, summaries, and recommendations
- Sentry — error reports, when error tracking is switched on. It records crashes, not browsing behavior, and performance tracing and session replay are both off.
We will also share information when:
- You ask us to, or you use a team feature, in which case your teammates see the lists and searches your team shares
- The law requires it, such as a valid legal request, or we need to protect our rights, our users, or the public from harm
- The business is sold or merged, in which case your data may transfer with it. We will tell you if that happens and this policy will continue to apply until we give you notice of a new one.
5. Cookies
We set two cookies, and neither one is for advertising.
- Sign-in cookies, set by Clerk. They keep you signed in and keep your session secure. Without them you could not stay logged in.
- A referral cookie named ref. If you arrive through a referral link, we store that short code for 30 days so the person who referred you gets credit if you sign up. It holds a referral code and nothing else.
Your browser also stores two small preferences on your own device, which never reach us: your light or dark theme choice, and whether you dismissed the profile-completion banner.
We do not use advertising cookies, third-party analytics, tracking pixels, or session recording, which is why you do not see a cookie banner here.
6. Email and your choices
Marketing and alert email is opt-in. When you sign up for the weekly digest we send a confirmation email first and only start sending once you confirm, so nobody can sign up an address that is not theirs. Confirmation links expire after 72 hours.
Our optional email streams are the weekly digest, saved-search and tracking alerts, and introductory emails. Every one of them carries an unsubscribe link, and one-click unsubscribe works from your mail app. Unsubscribing stops that stream; you can also opt out of all marketing email at once. We keep a suppression list and honor it, and we follow CAN-SPAM, so our messages identify us and carry a postal address.
Transactional email is different. Receipts, security notices, team invitations, and messages about your account are part of having an account. We keep sending those while your account exists. To stop them, close the account.
7. How long we keep it
We keep your account data for as long as your account is open. When you delete it, we remove it as described below. Records we must keep for tax, accounting, or legal reasons — payment records, for example — are kept for as long as the law requires. Public data about organizations is kept as long as it is useful, because it is public and it is not about you.
8. Deleting your account
You can delete your account yourself, at any time, from /account. You confirm by typing your own email address. It cannot be undone.
When you do, we:
- Cancel any active subscription first, so billing stops
- Delete your sign-in record with Clerk
- Delete your profile, saved contracts and notes, saved searches, follows, pursuit packages, delivery history, API keys, and team memberships
Two things are deliberately kept, and we would rather say so:
- A dated record that an account was deleted. It stores a one-way hash of the email address, never the address itself, so we can prove the deletion happened without keeping the person.
- Your email address on our do-not-contact list, so that deleting your account cannot accidentally put you back on a mailing list later. Ask us and we will remove that too.
If you own a team that still has other members, we will ask you to transfer or remove them first, so deleting your account cannot wipe out the shared work of your colleagues.
You can also email support@hrcledger.com and ask us to do it for you.
9. Your privacy rights
Depending on where you live — for example California under the CCPA, or the UK and the European Economic Area under the GDPR — you may have the right to:
- Know what personal information we hold about you and why
- Get a copy of it
- Correct it if it is wrong
- Have it deleted
- Object to or restrict certain uses of it
- Take it elsewhere in a portable form
- Opt out of the sale or sharing of it, which we do not do
- Not be treated worse for exercising any of these rights, which we will never do
To use any of these rights, email support@hrcledger.com. We will verify that the request is really from you, usually by confirming you control the account email, and we aim to reply within 30 days. There is no charge.
Where the GDPR applies, our legal grounds for using your data are: performing our contract with you, which covers running your account and sending what you subscribed to; our legitimate interests in securing, supporting and improving the service; your consent for marketing email, which you may withdraw at any time; and compliance with the law. We are based in the United States and your data is processed there. If you are in the EEA or the UK and you are not happy with our response, you may complain to your local data protection authority.
10. Security
We protect your data with encryption in transit, hashed API keys, hosted payment pages so card numbers never touch our systems, and access limited to the people who need it. No service can promise perfect security, and we do not claim any security certification or audit. If a breach affects you, we will tell you as the law requires.
11. Children
HRC Ledger is a business tool for adults. It is not meant for anyone under 18, and it is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child has given us information, email us and we will delete it.
12. Changes to this policy
If we change this policy, we will update the effective date at the top of this page. When a change is material, we will tell account holders by email or in the app before it takes effect.
13. Contact us
Questions about privacy, or want to exercise a right above? Email support@hrcledger.com. We read everything sent there.
See also the Terms of Service.