Effective date: January 1, 2025 · Last updated: September 22, 2026
1. Overview
RateCards Inc. ("RateCards," "we," "us," or "our") operates the ratecards.app platform. This Privacy Policy describes how we collect, use, and share information about you when you use our Service, and the choices you have regarding that information.
This policy applies to all users of the Service — freelancers, agencies, and businesses — including visitors who access Shareable Links generated by users.
RateCards is intended for use by residents of the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to and processed in the United States.
2. What We Collect
2.1 Information You Provide
- Account information: name, email address, password (hashed and salted — never stored in plain text), company name, and profile details
- Rate card content: service descriptions, pricing and rate information, client-facing terms, branding assets, and other content you enter into the Service
- Communications: messages you send to our support team or via in-app feedback tools
- Billing information: subscription plan selection; payment details are handled directly by our third-party payment processor (Stripe) and are not stored by RateCards
- Public profile content: the trade, service area, business profile, portfolio, and rate cards you choose to publish
- Booking and transaction information: for Sellers, Buyers, and Guest Buyers, this includes the services booked, amounts, dates, booking and payment history, and payout status, plus the name, email, and phone number (if provided) of the person booking. Card and bank details are collected and processed by Stripe; RateCards does not store full card or bank account numbers
2.2 Information Collected Automatically
- Usage data: pages visited, features used, time spent, actions taken within the Service
- Device and browser data: IP address, browser type and version, operating system, device identifiers
- Cookies and tracking technologies: see our Cookie Policy for full details. Certain non-essential cookies (including analytics and advertising cookies) are only set after you provide consent via our cookie banner
- Rate card engagement: when your Shareable Links are viewed, including viewer IP address and timestamp (no viewer account required). See Section 5 for full details
2.3 Information from Third Parties
We may receive information about you from third-party analytics providers where you have authorized such sharing. We do not purchase or receive personal data from data brokers.
3. How We Use It
- Provide the Service: store, display, and transmit your rate cards and account data
- Improve the Service: analyze anonymized, aggregated usage patterns to develop new features and improve performance — your individual rate card content is never used for this purpose in identifiable form. You can opt out of having data derived from your account used for AI or ML model training (see Section 8 and Terms of Service §4.3)
- Communications: send transactional emails (account activity, billing, booking and payment confirmations), product updates, and support responses
- Marketing RateCards: send newsletters, feature announcements, offers, and other promotional messages about RateCards' own products and services by email or in-app. Every marketing email includes an unsubscribe link. Unsubscribing does not stop transactional, account, or booking messages. We do not send marketing on behalf of third parties
- Showcasing providers: if you have made a profile or rate card public, we may feature that public content on RateCards channels, including our website, social media accounts, newsletters, and advertising for RateCards, to help clients discover providers (Terms of Service §4.5). You can switch this off at any time in your account settings. We will not quote you or use you as a testimonial without your separate consent
- Publishing aggregate insights: publish de-identified, aggregated statistics, such as typical rate ranges by trade and region, derived from at least ten users. These statistics never identify you, your clients, or your individual rates
- Security and fraud prevention: detect and prevent unauthorized access or misuse of the Service
- Legal compliance: respond to lawful requests from government authorities and meet our legal obligations
- Analytics: understand how users interact with the Service through tools described in Section 6, subject to your consent preferences
- Advertising measurement: where you have provided explicit prior consent, we use advertising measurement tools (including Meta Pixel) to measure the effectiveness of our marketing campaigns. We do not use these tools to serve you ads without your consent
We do not sell your personal data to third parties. We do not share your personal data for cross-context behavioral advertising without your prior opt-in consent.
4. How We Share It
RateCards does not sell, rent, or trade personal data. We share information only in these circumstances:
- Service providers and sub-processors: vendors we use to operate the Service (see Section 6 for a full list). Each vendor is required to process your data only on our behalf and consistent with this policy
- Advertising partners (with consent only): if you have opted in to advertising cookies via our cookie consent banner, certain pseudonymized identifiers (such as hashed email or pixel events) may be shared with advertising measurement partners (e.g. Meta) solely for campaign measurement and attribution. You may withdraw this consent at any time via our Cookie Preference Center
- Between Buyers and Sellers: when a booking is made, we share the details needed to fulfill it. The Seller receives the Buyer's name, contact details, and booking details, and the Buyer receives the Seller's business details
- Public content at your direction: anything you publish to your public profile is visible to anyone, including where we feature it as described in Section 3
- Legal requirements: when required by law, regulation, subpoena, or court order, or to protect the rights, property, or safety of RateCards, our users, or the public
- Business transfers: in connection with a merger, acquisition, or sale of assets, we will provide notice to affected users and the acquiring party will be required to honor this Privacy Policy or obtain fresh consent
- With your consent: in any other circumstance where you have explicitly authorized sharing
6. Sub-processors & Vendors
RateCards uses the following categories of third-party service providers. We conduct due diligence on new vendors before granting access to personal data and require each to process your data only for the purposes described in this policy.
Analytics & Marketing (Consent-Gated)
The following vendors are only activated after you provide cookie consent. You may modify or withdraw consent at any time via our Cookie Preference Center.
| Vendor | Purpose | Data Shared |
|---|---|---|
| Google Analytics | Web analytics, user behavior tracking | Anonymized usage data, device/browser info, IP address (truncated) |
| Mixpanel | Product analytics, feature usage tracking | User actions, feature engagement (pseudonymized) |
| Meta Pixel | Advertising measurement and attribution only — activated only with your explicit opt-in consent | Page visits, conversion events (hashed email where applicable). Not used for ad targeting without consent. |
| mParticle | Customer data platform, event routing to consented analytics destinations | User identity data, behavioral events (routing to consented vendors only) |
Data Infrastructure & Processing
| Vendor | Purpose | Data Shared |
|---|---|---|
| Google Cloud (BigQuery) | Data warehousing and analytics infrastructure | Aggregated usage data, product metrics |
| Google Cloud AI / NVIDIA | AI-assisted product features (where applicable) | Anonymized or pseudonymized feature interaction data only |
| Snowflake | Cloud data platform and analytics storage | Aggregated operational data |
| Looker | Business intelligence and internal reporting | Aggregated internal metrics (no individual PII in reports) |
| Stripe (incl. Stripe Connect) | Subscription billing; processing of bookings and payments between Buyers and Sellers; Seller identity verification and payouts | Billing and contact information, transaction details, payment method tokens. Stripe collects Sellers' identity and payout details directly. RateCards does not store full card or bank account numbers. |
We review our sub-processor list at least annually. Material additions to this list will be reflected in updates to this Privacy Policy with at least 30 days' advance notice.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy. The following table sets out our retention periods by data category:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account profile data | Deleted within 45 days of account deletion request | Service provision |
| Rate card content | Deleted within 45 days of account deletion request | Service provision |
| Usage & analytics data | 12 months from collection, then aggregated or deleted | Product improvement |
| Support communications | 2 years from last interaction | Dispute resolution |
| Billing records | 7 years from transaction date | Legal / tax obligation |
| Booking & transaction records | 7 years from transaction date | Legal / tax obligation, dispute resolution |
| Marketing opt-out records | As long as needed to honor your opt-out | Honoring your choices |
| Shareable Link viewer IP logs | 90 days from collection date | Fraud prevention / analytics |
| Security & access logs | 12 months | Security monitoring |
| Aggregated, anonymized data | Indefinitely (no longer tied to individuals) | Product analytics |
When you delete your account, we will initiate deletion of your personal data within 45 days. Certain categories of data (billing and transaction records, security logs) may be retained longer as specified above to meet legal obligations.
8. Your Rights
Depending on your location, you may have rights under applicable privacy law including:
- Access: request a copy of the personal data we hold about you
- Correction: request that we correct inaccurate or incomplete data
- Deletion: request deletion of your personal data, subject to legal retention obligations
- Portability: request an export of your data in a machine-readable format (JSON or CSV)
- Objection: object to processing based on our legitimate interests
- Opt-out of marketing: unsubscribe from marketing emails at any time via the unsubscribe link in any such email, or by contacting us directly
- Opt out of promotional features: turn off "Feature my profile in RateCards marketing" in your account settings, or email privacy@ratecards.app. We will stop using your public content in new promotional materials within 30 days
- Opt out of AI training: turn off the AI training setting in your account settings, or email privacy@ratecards.app, to stop data derived from your account being used to train AI or ML models
- Withdraw cookie consent: modify or withdraw your cookie and tracking preferences at any time via our Cookie Preference Center
- Opt out of advertising data sharing: if you have previously consented to advertising cookies, you may withdraw that consent at any time. Withdrawal will prevent future sharing but does not affect data already shared prior to withdrawal
To exercise any of these rights, contact us at privacy@ratecards.app. We will acknowledge your request within 5 business days and respond substantively within 25 business days. We may need to verify your identity before fulfilling your request. We will not discriminate against you for exercising any of these rights.
California Residents
California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):
- Right to Know / Access: the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of third parties we disclose it to. See our Notice at Collection for the category-level summary.
- Right to Delete and Right to Correct personal information, subject to legal exceptions.
- Right to Opt Out of Sale/Sharing: RateCards does not sell personal information and does not share it for cross-context behavioral advertising without prior opt-in consent. You may opt out at any time via our Do Not Sell or Share My Personal Information page. We honor Global Privacy Control signals.
- Right to Limit Sensitive Personal Information: see Limit the Use of My Sensitive Personal Information.
- Right to Data Portability and Right to Non-Discrimination for exercising any right.
You may submit requests through our California Privacy Rights Request form or by emailing privacy@ratecards.app with the subject line "California Privacy Request." For California requests we confirm receipt within 10 business days and respond within 45 calendar days (extendable once by an additional 45 days with notice); opt-out and limit requests are processed within 15 business days. Authorized agents may submit requests on your behalf with proof of authorization. We do not offer any financial incentive program tied to personal information; if we introduce one, we will publish a Financial Incentive Notice and obtain opt-in consent first.
Residents of Other US States
Residents of Virginia, Colorado, Connecticut, Texas, Florida, and other states with applicable consumer privacy laws may have similar rights to access, correct, delete, or obtain a copy of their personal data, and to opt out of certain uses of it. To exercise any such rights, contact us at privacy@ratecards.app and include your state of residence. We will respond in accordance with applicable law.
9. Children
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected personal data from a minor, we will take steps to delete that information promptly. If you believe we may have collected data from a minor, please contact us at privacy@ratecards.app.
10. Security
RateCards implements the following technical and organizational security measures to protect personal data against unauthorized access, loss, or destruction:
- Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
- Encryption at rest: personal data stored in our databases is encrypted at rest using AES-256
- Access controls: access to personal data is restricted to authorized personnel on a need-to-know basis, enforced through role-based access controls
- Incident response: we maintain an incident response plan and will notify affected users of material data breaches within the timeframes required by applicable law
- Vendor security: all sub-processors are evaluated for security practices prior to onboarding and are bound by contractual security obligations
No security system is impenetrable. We cannot guarantee the absolute security of your data. You are responsible for maintaining the security of your account credentials. Please use a strong, unique password and enable any available multi-factor authentication. Notify us immediately at security@ratecards.app if you suspect any unauthorized access to your account.
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights or interests, we will notify affected users without undue delay and in accordance with applicable state breach notification laws (including California Civil Code § 1798.29 and § 1798.82). Notification will be provided by email to the address associated with your account.
11. International Data Transfers
RateCards is headquartered in the United States and the Service is designed for use by US-based users. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.
RateCards does not actively market to or solicit users in the European Union, United Kingdom, or EEA. If you are located in one of these jurisdictions and choose to use the Service, please be aware that US privacy law differs from the laws of your home jurisdiction. By using the Service, you acknowledge this transfer.
12. Do Not Track & Global Privacy Control
Global Privacy Control (GPC): RateCards honors the GPC browser signal as a valid opt-out of the sharing of personal information for cross-context behavioral advertising. If your browser or browser extension transmits a GPC signal when you visit ratecards.app, we will treat this as a request to opt out of advertising data sharing and will not activate consent-gated advertising tools (including Meta Pixel) for your session.
Do Not Track (DNT): Some browsers include a "Do Not Track" feature that sends a signal to websites you visit. RateCards does not currently alter its data collection practices in response to browser-level DNT signals, as there is no uniform standard for interpreting these signals. We disclose this practice as required by California law (CalOPPA). You can control tracking preferences more precisely through our cookie consent banner and Cookie Preference Center.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email to the address associated with your account and by posting a prominent notice within the Service at least 30 days before the change takes effect. Non-material changes (such as clarifications or corrections) may be made at any time and will be reflected in the "Last Updated" date at the top of this page. Your continued use of the Service after the effective date of any change constitutes acceptance of the updated policy.
14. Contact
For questions, requests, or concerns regarding this Privacy Policy:
RateCards Inc.
Privacy Team
privacy@ratecards.app
For security concerns or to report a suspected breach:
RateCards Inc.
Security Team
security@ratecards.app
We aim to acknowledge all privacy inquiries within 5 business days.