Privacy Policy
Effective July 1, 2026
Data Controller
Desert Oasis Digital LLC, a Washington limited liability company based in Puyallup, WA, is the data controller for personal information processed through AwardReady. Contact the controller through the Contact page.
Categories of Data Collected
We collect: (a) account data — your email address, hashed password, name if provided, and multi-factor authentication settings; (b) entity and registration data — company names, UEI, CAGE, NAICS codes, certification statuses, expiration dates, and any notes you enter; (c) uploaded documents — files you upload to the document vault (encrypted at rest); (d) usage and log data — pages visited, features used, IP address, browser and device information, timestamps; (e) payment data — handled directly by Stripe under Stripe's privacy policy; AwardReady stores only Stripe customer and subscription identifiers, never full card numbers.
Legal Basis for Processing
We process personal data on the following legal bases: performance of a contract with you (account, subscription, delivery of the Service); legitimate interests (product improvement, fraud prevention, security); consent (marketing communications, optional SMS alerts); and compliance with legal obligations (tax, accounting, lawful requests).
How We Use Data
To operate the Service, sync with public federal APIs, send you the alerts you configured, process payments, respond to support requests, secure the Service against fraud and abuse, and improve the product. We do not use your data for advertising, and we do not sell or rent it.
Storage and Security
All data is transmitted over TLS 1.3 and stored encrypted at rest with AES-256. Row-level security policies restrict every database record to its owner and their authorized team members. Uploaded documents are served through signed URLs that expire after one hour. Login events and mutations are logged with IP address for security audit.
Retention
Active-account data is retained for as long as your account is active. If you delete your account, all associated data is deleted from our production systems within 30 days, and from encrypted backups within 90 days, except where retention is required by law.
Your Rights
Depending on your jurisdiction (including under the GDPR and CCPA), you have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; export your data in a machine-readable format; object to certain processing; and withdraw consent for optional communications. To exercise these rights, contact us through the Contact page. We will respond within 30 days.
Third-Party Processors
We use a small set of trusted subprocessors to operate the Service: Supabase (database, authentication, storage), Stripe (payments), Brevo (transactional email), Twilio (SMS alerts), Cloudflare (network security, DDoS protection). Each subprocessor is bound by its own contractual and legal data-protection obligations. We do not share your data with any other third party except when required by law.
Cookies and Tracking
We use only functional cookies necessary to keep you signed in and to maintain your session. We do not use advertising cookies. We do not use third-party analytics that fingerprint or track users across sites.
Children
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect data from children.
International Transfers
Data may be processed in the United States. Where required (for example, for EU/UK data subjects), transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.
Changes to This Policy
We will update this policy from time to time. Material changes will be communicated by email or in-app notice at least 30 days before they take effect.
Contact for Data Requests
For access, correction, deletion, export, or objection requests, or any other privacy inquiry, contact us through the Contact page.