Effective date: September 9, 2026 · Version 1.0
Privacy policy
This Privacy Policy describes how Vantage Tactical Group LLC (Greenlight, we, us) collects, uses, and shares information in connection with the Greenlight platform (the Service). It is incorporated into our Terms of Service. By using the Service you agree to this Policy.
1. Information we collect
Account information. Name, email address, password credentials (stored hashed by our authentication provider), role, and organization membership.
Customer content. Documents your organization uploads or connects (such as solicitation files), your criteria and settings, pipeline records, supplier and contact entries, notes, tasks, and files placed in your document library.
Billing information. Plan, subscription status, and transaction history. Payment card details are collected and stored by our payment processor (Stripe); we never store full card numbers.
Connected email accounts. If you connect a Google or Microsoft account, we store encrypted OAuth tokens and the connected address so the Service can create email drafts or send messages you explicitly approve. See Section 6.
Automatically collected information. Log data (IP address, browser type, pages viewed, timestamps), device information, and usage events (such as features used and actions taken), collected to operate, secure, and improve the Service.
Public procurement data. The Service retrieves publicly available opportunity data from government and third-party sources (for example SAM.gov and Grants.gov). This data relates to public solicitations, not to you personally.
2. How we use information
We use information to: provide and operate the Service, including running analyses and producing verdicts against your organization's criteria; maintain security, prevent abuse, and enforce plan limits; process payments and manage subscriptions; send service communications (verdict notifications, digests, deadline reminders, billing and account notices) according to your notification settings; provide support; comply with legal obligations; and improve the Service using aggregated, de-identified usage data.
We do not sell personal information, and we do not use your Customer Content for advertising.
3. AI processing
The Service uses third-party large language model providers to analyze documents and generate outputs. Content sent for analysis is transmitted securely, used only to produce results for your organization, and is not used by us or permitted by our agreements to be used by AI providers to train their models. Analyses of publicly available government documents retrieved by our own connectors may be cached and reused across customer accounts for speed; documents uploaded by your organization are never shared with other customers.
4. How we share information
We share information only with: service providers that host and operate the Service on our behalf, including cloud hosting and database infrastructure, our payment processor (Stripe), email delivery providers, and AI model providers, each bound to use the data only to provide their service to us; your organization, where content and activity within an organization is visible to its members according to their roles, and organization owners control membership; legal recipients, where required by law, subpoena, or to protect rights, safety, or the integrity of the Service; and successors, in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Tenant isolation
Each organization's data is segregated with row-level security controls. Members of one organization cannot access another organization's data. Platform administrators may access an organization's data only for support, security, or legal compliance purposes, and such access is logged.
6. Connected Google and Microsoft accounts
If you connect an email account, we request only the scopes needed to create drafts and send messages you approve (for Google: Gmail compose scopes). Tokens are stored encrypted, are never visible to other users, and are deleted immediately when you disconnect the account.
Google API Limited Use disclosure: Greenlight's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the email drafting features you request; we do not use it for advertising, do not allow humans to read it except with your permission or for security and legal purposes, and do not transfer it except as necessary to provide the feature, comply with law, or as part of a merger or acquisition with notice to you.
7. Cookies and similar technologies
We use cookies and local storage for authentication sessions, security, remembering preferences (such as view settings), and understanding product usage. We do not use third-party advertising cookies. You can control cookies through your browser, though the Service requires session cookies to function.
8. Data retention
We retain Customer Content while your organization's account is active. After account deletion, Customer Content is deleted within 90 days, except for backup copies removed on our standard rotation and records we must keep to comply with legal, tax, or accounting requirements. Log and usage data is retained for up to 24 months. If a subscription lapses, data is retained per the Terms of Service (at least 90 days) so you can return or export it.
9. Security
We use industry-standard measures to protect information, including encryption in transit and at rest, row-level access controls, encrypted storage of integration tokens, role-based permissions, and logging of administrative access. No system is perfectly secure; we will notify affected customers of a data breach as required by applicable law.
10. Your rights and choices
You may access, correct, export, or delete your organization's data through the Service, or by contacting us. Depending on your location, you may have additional rights, such as access, deletion, correction, and portability under laws like the California Consumer Privacy Act or the EU/UK GDPR, which you can exercise by emailing privacy@greenlightapp.online. We will respond within the time required by applicable law and will not discriminate against you for exercising your rights. Marketing emails (if any) include an unsubscribe link; service and billing notices are sent as needed to operate your account. Report digests and notification emails are configurable in your settings and include unsubscribe options.
11. Children
The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children.
12. International users
The Service is operated from the United States and information is processed in the United States. If you use the Service from another jurisdiction, you consent to processing in the United States.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced in the application and by email at least 30 days before they take effect, and the current version will always be available on our Privacy Policy page.
14. Contact
Vantage Tactical Group LLC · privacy@greenlightapp.online
For data rights requests, security reports, or privacy questions, contact privacy@greenlightapp.online.