US Grants Database ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. We operate in compliance with US's Personal Information Protection and Electronic Documents Act (PIPEDA).
2. Information We Collect
2.1 Information You Provide
Account Information: Email address, name, and profile photo when you create an account
Business Eligibility Data: Business size, industry, geographic location, revenue range, business stage, and demographic information (e.g., women-owned, Indigenous-owned) that you voluntarily provide to receive personalized program recommendations
Saved Preferences: Programs you save, search criteria you store, and notification preferences
Payment Information: When you subscribe to our premium service, payment processing is handled by Stripe. We do not store your credit card details directly.
2.2 Information Collected Automatically
Usage Data: Pages visited, features used, search queries, and interaction patterns
Device Information: Browser type, operating system, and device identifiers
IP Address: Used for security, rate limiting, and anonymous usage tracking
Cookies and Similar Technologies: Session cookies to maintain your login state and preferences
3. How We Use Your Information
We use the information we collect to:
Provide and maintain our services, including personalized program recommendations
Generate AI-powered eligibility scores based on your business profile
Send email notifications about saved searches and program updates (with your consent)
Process subscription payments and manage your account
Improve our services and develop new features
Prevent fraud and ensure security of our platform
Comply with legal obligations
4. Third-Party Services
We use the following third-party services that may collect and process your data:
Supabase: Database hosting and user authentication
Stripe: Payment processing for subscriptions
Vercel: Website hosting, Web Analytics, and Speed Insights
Google (Gemini AI): AI-powered program categorization and eligibility scoring
PostHog: Product analytics — anonymous pageviews, clicks, and conversion events. Anonymous visitors are not assigned a persistent profile; only authenticated users are identified.
Microsoft Clarity: Aggregate session-level usability analytics (heatmaps, scroll depth)
Google Ads: Conversion measurement for our advertising on Google
Ahrefs Web Analytics: Aggregate SEO and traffic analytics
Each of these services has their own privacy policy governing their use of your data. We encourage you to review their policies. You can opt out of PostHog product analytics in the Analytics Preferences section below.
5. Analytics Preferences
We rely on product analytics to understand how visitors use the site and to identify rough edges in the signup and purchase flows. You can opt out at any time. The toggle below controls whether PostHog — our product analytics tool — keeps a persistent anonymous identifier on your device. When opted out, analytics events may still be captured for the current page but will not be linked across pages or sessions.
Product analytics
By default we record anonymous usage events (pageviews, clicks, conversion steps) to improve the product. Turn this off to have your distinct_id kept only in memory — events may still be captured but won't be linked across sessions.
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your information only in the following circumstances:
Service Providers: With third-party vendors who assist us in operating our services (as listed above)
Legal Requirements: When required by law, court order, or government request
Protection of Rights: To protect our rights, privacy, safety, or property, or that of our users
Business Transfers: In connection with a merger, acquisition, or sale of assets
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you services. If you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or legitimate business purposes.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption of data in transit and at rest, secure authentication, and regular security assessments. However, no method of transmission over the Internet is 100% secure.
9. Your Rights Under PIPEDA
Under US privacy law, you have the right to:
Access: Request a copy of the personal information we hold about you
Correction: Request correction of inaccurate or incomplete information
Withdrawal of Consent: Withdraw your consent to the collection, use, or disclosure of your information
Deletion: Request deletion of your personal information (subject to legal retention requirements)
Complaint: File a complaint with the Office of the Privacy Commissioner of US
To exercise these rights, please contact us using the information provided below.
10. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of our services after any changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at:
US Grants Database Email: privacy@usgrantsdatabase.com