Effective date: January 1, 2025  ·  Last updated: September 22, 2026

What changed on September 22, 2026. We added marketing of RateCards' own services, featuring of public provider profiles (which you can opt out of), and publication of de-identified rate benchmarks to Section 3. We described how we handle booking and payment data in Sections 2, 4, 5, 6, and 7, and added self-serve opt-outs to Section 8. We still do not sell your personal data. New uses in Section 3 take effect on October 22, 2026.
This policy explains what data RateCards collects, why we collect it, who we share it with, and what control you have over it. We do not sell your personal data. We do not share your personal data for cross-context behavioral advertising without your prior consent.

1. Overview

Short version: we collect what we need to run the service. We don't sell your data, and we don't share it for advertising without your permission.

RateCards Inc. ("RateCards," "we," "us," or "our") operates the ratecards.app platform. This Privacy Policy describes how we collect, use, and share information about you when you use our Service, and the choices you have regarding that information.

This policy applies to all users of the Service — freelancers, agencies, and businesses — including visitors who access Shareable Links generated by users.

RateCards is intended for use by residents of the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to and processed in the United States.

2. What We Collect

We collect account info you give us, the rate card content you create, and usage data from your browser automatically.

2.1 Information You Provide

  • Account information: name, email address, password (hashed and salted — never stored in plain text), company name, and profile details
  • Rate card content: service descriptions, pricing and rate information, client-facing terms, branding assets, and other content you enter into the Service
  • Communications: messages you send to our support team or via in-app feedback tools
  • Billing information: subscription plan selection; payment details are handled directly by our third-party payment processor (Stripe) and are not stored by RateCards
  • Public profile content: the trade, service area, business profile, portfolio, and rate cards you choose to publish
  • Booking and transaction information: for Sellers, Buyers, and Guest Buyers, this includes the services booked, amounts, dates, booking and payment history, and payout status, plus the name, email, and phone number (if provided) of the person booking. Card and bank details are collected and processed by Stripe; RateCards does not store full card or bank account numbers

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, time spent, actions taken within the Service
  • Device and browser data: IP address, browser type and version, operating system, device identifiers
  • Cookies and tracking technologies: see our Cookie Policy for full details. Certain non-essential cookies (including analytics and advertising cookies) are only set after you provide consent via our cookie banner
  • Rate card engagement: when your Shareable Links are viewed, including viewer IP address and timestamp (no viewer account required). See Section 5 for full details

2.3 Information from Third Parties

We may receive information about you from third-party analytics providers where you have authorized such sharing. We do not purchase or receive personal data from data brokers.

3. How We Use It

We use your data to run the service, improve it (using anonymized data), communicate with you, and promote RateCards. We never sell your data, and we never use your rate card content to train advertising models.
  • Provide the Service: store, display, and transmit your rate cards and account data
  • Improve the Service: analyze anonymized, aggregated usage patterns to develop new features and improve performance — your individual rate card content is never used for this purpose in identifiable form. You can opt out of having data derived from your account used for AI or ML model training (see Section 8 and Terms of Service §4.3)
  • Communications: send transactional emails (account activity, billing, booking and payment confirmations), product updates, and support responses
  • Marketing RateCards: send newsletters, feature announcements, offers, and other promotional messages about RateCards' own products and services by email or in-app. Every marketing email includes an unsubscribe link. Unsubscribing does not stop transactional, account, or booking messages. We do not send marketing on behalf of third parties
  • Showcasing providers: if you have made a profile or rate card public, we may feature that public content on RateCards channels, including our website, social media accounts, newsletters, and advertising for RateCards, to help clients discover providers (Terms of Service §4.5). You can switch this off at any time in your account settings. We will not quote you or use you as a testimonial without your separate consent
  • Publishing aggregate insights: publish de-identified, aggregated statistics, such as typical rate ranges by trade and region, derived from at least ten users. These statistics never identify you, your clients, or your individual rates
  • Security and fraud prevention: detect and prevent unauthorized access or misuse of the Service
  • Legal compliance: respond to lawful requests from government authorities and meet our legal obligations
  • Analytics: understand how users interact with the Service through tools described in Section 6, subject to your consent preferences
  • Advertising measurement: where you have provided explicit prior consent, we use advertising measurement tools (including Meta Pixel) to measure the effectiveness of our marketing campaigns. We do not use these tools to serve you ads without your consent

We do not sell your personal data to third parties. We do not share your personal data for cross-context behavioral advertising without your prior opt-in consent.

4. How We Share It

We share your data only with vendors who help us run RateCards, or when required by law. Never to advertisers without your consent.

RateCards does not sell, rent, or trade personal data. We share information only in these circumstances:

  • Service providers and sub-processors: vendors we use to operate the Service (see Section 6 for a full list). Each vendor is required to process your data only on our behalf and consistent with this policy
  • Advertising partners (with consent only): if you have opted in to advertising cookies via our cookie consent banner, certain pseudonymized identifiers (such as hashed email or pixel events) may be shared with advertising measurement partners (e.g. Meta) solely for campaign measurement and attribution. You may withdraw this consent at any time via our Cookie Preference Center
  • Between Buyers and Sellers: when a booking is made, we share the details needed to fulfill it. The Seller receives the Buyer's name, contact details, and booking details, and the Buyer receives the Seller's business details
  • Public content at your direction: anything you publish to your public profile is visible to anyone, including where we feature it as described in Section 3
  • Legal requirements: when required by law, regulation, subpoena, or court order, or to protect the rights, property, or safety of RateCards, our users, or the public
  • Business transfers: in connection with a merger, acquisition, or sale of assets, we will provide notice to affected users and the acquiring party will be required to honor this Privacy Policy or obtain fresh consent
  • With your consent: in any other circumstance where you have explicitly authorized sharing

6. Sub-processors & Vendors

Here's every third-party service that may touch your data, and what they do. We conduct due diligence on each vendor before granting access to personal data.

RateCards uses the following categories of third-party service providers. We conduct due diligence on new vendors before granting access to personal data and require each to process your data only for the purposes described in this policy.

Analytics & Marketing (Consent-Gated)

The following vendors are only activated after you provide cookie consent. You may modify or withdraw consent at any time via our Cookie Preference Center.

VendorPurposeData Shared
Google AnalyticsWeb analytics, user behavior trackingAnonymized usage data, device/browser info, IP address (truncated)
MixpanelProduct analytics, feature usage trackingUser actions, feature engagement (pseudonymized)
Meta PixelAdvertising measurement and attribution only — activated only with your explicit opt-in consentPage visits, conversion events (hashed email where applicable). Not used for ad targeting without consent.
mParticleCustomer data platform, event routing to consented analytics destinationsUser identity data, behavioral events (routing to consented vendors only)

Data Infrastructure & Processing

VendorPurposeData Shared
Google Cloud (BigQuery)Data warehousing and analytics infrastructureAggregated usage data, product metrics
Google Cloud AI / NVIDIAAI-assisted product features (where applicable)Anonymized or pseudonymized feature interaction data only
SnowflakeCloud data platform and analytics storageAggregated operational data
LookerBusiness intelligence and internal reportingAggregated internal metrics (no individual PII in reports)
Stripe (incl. Stripe Connect)Subscription billing; processing of bookings and payments between Buyers and Sellers; Seller identity verification and payoutsBilling and contact information, transaction details, payment method tokens. Stripe collects Sellers' identity and payout details directly. RateCards does not store full card or bank account numbers.

We review our sub-processor list at least annually. Material additions to this list will be reflected in updates to this Privacy Policy with at least 30 days' advance notice.

7. Data Retention

We keep your data for specific, defined periods — not indefinitely. Here's exactly how long we hold each type.

We retain personal data only for as long as necessary for the purposes described in this policy. The following table sets out our retention periods by data category:

Data CategoryRetention PeriodBasis
Account profile dataDeleted within 45 days of account deletion requestService provision
Rate card contentDeleted within 45 days of account deletion requestService provision
Usage & analytics data12 months from collection, then aggregated or deletedProduct improvement
Support communications2 years from last interactionDispute resolution
Billing records7 years from transaction dateLegal / tax obligation
Booking & transaction records7 years from transaction dateLegal / tax obligation, dispute resolution
Marketing opt-out recordsAs long as needed to honor your opt-outHonoring your choices
Shareable Link viewer IP logs90 days from collection dateFraud prevention / analytics
Security & access logs12 monthsSecurity monitoring
Aggregated, anonymized dataIndefinitely (no longer tied to individuals)Product analytics

When you delete your account, we will initiate deletion of your personal data within 45 days. Certain categories of data (billing and transaction records, security logs) may be retained longer as specified above to meet legal obligations.

8. Your Rights

You can access, correct, export, or delete your data at any time. Just email us — we'll respond within 25 business days.

Depending on your location, you may have rights under applicable privacy law including:

  • Access: request a copy of the personal data we hold about you
  • Correction: request that we correct inaccurate or incomplete data
  • Deletion: request deletion of your personal data, subject to legal retention obligations
  • Portability: request an export of your data in a machine-readable format (JSON or CSV)
  • Objection: object to processing based on our legitimate interests
  • Opt-out of marketing: unsubscribe from marketing emails at any time via the unsubscribe link in any such email, or by contacting us directly
  • Opt out of promotional features: turn off "Feature my profile in RateCards marketing" in your account settings, or email privacy@ratecards.app. We will stop using your public content in new promotional materials within 30 days
  • Opt out of AI training: turn off the AI training setting in your account settings, or email privacy@ratecards.app, to stop data derived from your account being used to train AI or ML models
  • Withdraw cookie consent: modify or withdraw your cookie and tracking preferences at any time via our Cookie Preference Center
  • Opt out of advertising data sharing: if you have previously consented to advertising cookies, you may withdraw that consent at any time. Withdrawal will prevent future sharing but does not affect data already shared prior to withdrawal

To exercise any of these rights, contact us at privacy@ratecards.app. We will acknowledge your request within 5 business days and respond substantively within 25 business days. We may need to verify your identity before fulfilling your request. We will not discriminate against you for exercising any of these rights.

California Residents

California residents have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):

  • Right to Know / Access: the categories and specific pieces of personal information we collect, the sources, our purposes, and the categories of third parties we disclose it to. See our Notice at Collection for the category-level summary.
  • Right to Delete and Right to Correct personal information, subject to legal exceptions.
  • Right to Opt Out of Sale/Sharing: RateCards does not sell personal information and does not share it for cross-context behavioral advertising without prior opt-in consent. You may opt out at any time via our Do Not Sell or Share My Personal Information page. We honor Global Privacy Control signals.
  • Right to Limit Sensitive Personal Information: see Limit the Use of My Sensitive Personal Information.
  • Right to Data Portability and Right to Non-Discrimination for exercising any right.

You may submit requests through our California Privacy Rights Request form or by emailing privacy@ratecards.app with the subject line "California Privacy Request." For California requests we confirm receipt within 10 business days and respond within 45 calendar days (extendable once by an additional 45 days with notice); opt-out and limit requests are processed within 15 business days. Authorized agents may submit requests on your behalf with proof of authorization. We do not offer any financial incentive program tied to personal information; if we introduce one, we will publish a Financial Incentive Notice and obtain opt-in consent first.

Residents of Other US States

Residents of Virginia, Colorado, Connecticut, Texas, Florida, and other states with applicable consumer privacy laws may have similar rights to access, correct, delete, or obtain a copy of their personal data, and to opt out of certain uses of it. To exercise any such rights, contact us at privacy@ratecards.app and include your state of residence. We will respond in accordance with applicable law.

9. Children

RateCards is for adults only (18+). We don't knowingly collect data from minors.

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected personal data from a minor, we will take steps to delete that information promptly. If you believe we may have collected data from a minor, please contact us at privacy@ratecards.app.

10. Security

We use specific, documented security measures to protect your data — not just "industry-standard" boilerplate. If there's ever a breach, we'll notify you promptly.

RateCards implements the following technical and organizational security measures to protect personal data against unauthorized access, loss, or destruction:

  • Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
  • Encryption at rest: personal data stored in our databases is encrypted at rest using AES-256
  • Access controls: access to personal data is restricted to authorized personnel on a need-to-know basis, enforced through role-based access controls
  • Incident response: we maintain an incident response plan and will notify affected users of material data breaches within the timeframes required by applicable law
  • Vendor security: all sub-processors are evaluated for security practices prior to onboarding and are bound by contractual security obligations

No security system is impenetrable. We cannot guarantee the absolute security of your data. You are responsible for maintaining the security of your account credentials. Please use a strong, unique password and enable any available multi-factor authentication. Notify us immediately at security@ratecards.app if you suspect any unauthorized access to your account.

Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights or interests, we will notify affected users without undue delay and in accordance with applicable state breach notification laws (including California Civil Code § 1798.29 and § 1798.82). Notification will be provided by email to the address associated with your account.

11. International Data Transfers

RateCards is a US product. If you're outside the US, your data will be processed here under US law.

RateCards is headquartered in the United States and the Service is designed for use by US-based users. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.

RateCards does not actively market to or solicit users in the European Union, United Kingdom, or EEA. If you are located in one of these jurisdictions and choose to use the Service, please be aware that US privacy law differs from the laws of your home jurisdiction. By using the Service, you acknowledge this transfer.

12. Do Not Track & Global Privacy Control

We honor the Global Privacy Control (GPC) opt-out signal. We do not currently respond to browser-level Do Not Track (DNT) signals.

Global Privacy Control (GPC): RateCards honors the GPC browser signal as a valid opt-out of the sharing of personal information for cross-context behavioral advertising. If your browser or browser extension transmits a GPC signal when you visit ratecards.app, we will treat this as a request to opt out of advertising data sharing and will not activate consent-gated advertising tools (including Meta Pixel) for your session.

Do Not Track (DNT): Some browsers include a "Do Not Track" feature that sends a signal to websites you visit. RateCards does not currently alter its data collection practices in response to browser-level DNT signals, as there is no uniform standard for interpreting these signals. We disclose this practice as required by California law (CalOPPA). You can control tracking preferences more precisely through our cookie consent banner and Cookie Preference Center.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to the address associated with your account and by posting a prominent notice within the Service at least 30 days before the change takes effect. Non-material changes (such as clarifications or corrections) may be made at any time and will be reflected in the "Last Updated" date at the top of this page. Your continued use of the Service after the effective date of any change constitutes acceptance of the updated policy.

14. Contact

For questions, requests, or concerns regarding this Privacy Policy:

RateCards Inc.
Privacy Team
privacy@ratecards.app

For security concerns or to report a suspected breach:

RateCards Inc.
Security Team
security@ratecards.app

We aim to acknowledge all privacy inquiries within 5 business days.