Legal

Privacy Policy

Effective date: August 6, 2026

1. Overview

TarmacSync, Inc. (“we,” “us,” or “our”) operates the TarmacSync procurement intelligence platform. This Privacy Policy describes how we collect, use, store, and share information when you use our Service. We are committed to protecting the privacy of the airport operators and public agencies that rely on our platform.

2. Information We Collect

We collect the following categories of information:

  • Account information: Name, email address, organization name, and role provided during sign-up.
  • Airport configuration: IATA codes, procurement thresholds, grant status, and airport policy settings you configure in the Service.
  • Session data: Procurement intake conversations, working file contents, path review results, and generated documents you create in Pathfinder.
  • Project workspace data: Project cases, lifecycle state, procurement packages, funding records, grant records, requirements, evidence, approvals, comments, activity history, and artifact versions.
  • Uploaded documents: Airport policy documents you upload for analysis during onboarding, settings configuration, or project file workflows.
  • Usage data: Log data, feature interactions, session timestamps, and error reports used to operate and improve the Service.
  • Payment information: We do not collect or process payment information through the Service.

3. How We Use Information

We use your information to:

  • Provide, operate, and maintain the Service.
  • Personalize Pathfinder outputs based on your airport’s configuration.
  • Generate procurement path reviews, checklists, and evidence packets.
  • Maintain project lifecycle, buying-file, grant-file, approval, and closeout records.
  • Maintain audit trails for procurement sessions within your organization.
  • Detect and prevent security incidents and abuse.
  • Respond to support requests and communicate service updates.
  • Improve Service quality through aggregated, de-identified analytics.

We do not use your procurement session data to train AI models without your explicit consent.

4. Data Sharing

We do not sell your personal information. We may share information in the following limited circumstances:

  • Service providers: Third-party vendors that help us operate the Service (cloud infrastructure, transactional email, AI inference, document storage, and error monitoring). Identity is self-hosted, so there is no authentication vendor, and there is no payment processor. See our subprocessors list for current vendors.
  • Within your organization: Information you enter is visible to other members of your Pathfinder workspace who have appropriate access.
  • Legal requirements: When required by law, regulation, or valid legal process.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, subject to confidentiality protections.

5. Data Retention

We retain procurement sessions, project workspace records, generated documents, approvals, evidence packets, and audit events for 7 years unless a pilot agreement or applicable law requires a different period. AI conversation messages may be retained for a shorter operational period. You may request deletion of your data by contacting us, subject to legal, security, accounting, and procurement-record retention requirements.

6. Security

We implement industry-standard security controls including encryption at rest and in transit, role-based and project-scoped access controls, database-enforced row-level isolation between organizations, optional and organization-enforceable two-factor authentication, an enforced Content-Security-Policy, distributed rate limiting, upload quarantine, append-only audit logging, and same-origin protections for browser-authenticated mutations. We conduct periodic security reviews. In the event of a breach affecting your data, we will notify you within 72 hours of confirmation, consistent with applicable law.

Initial pilots must not submit SSI, CUI, classified, export-controlled, or security-sensitive airport material unless a separate written agreement and handling process is in place.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Request deletion of your personal information.
  • Export your data in a portable format.
  • Withdraw consent where processing is based on consent.

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

8. Cookies and Tracking

We use essential cookies required to operate the Service (session management, authentication). We do not use advertising or cross-site tracking cookies. Analytics, if any, use privacy-preserving, aggregated methods only.

9. Children’s Privacy

The Service is intended for use by airport operators and procurement professionals. We do not knowingly collect personal information from individuals under 18 years of age.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy and revising the effective date. Continued use of the Service after such changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or to exercise your rights, contact our privacy team at [email protected].