Legal and trust
Privacy Policy
This policy explains how the operator of MaroNest, an independent commercial platform, handles information when you use the MaroNest website and account features. MaroNest is a free U.S. government contract discovery platform and is not operated by, affiliated with, or endorsed by SAM.gov, GSA, or the U.S. federal government.
1. Information we collect
Account and authentication. We store your email address, username, password hash when you register with a password, name fields you provide, signup method, verification state, legal-acceptance versions and times, and normal session/authentication records. We do not store your plaintext password.
Organization and company profile. Account members may provide an organization name; legal or doing-business-as name; website; description; industry; company size and revenue range; headquarters and preferred states; remote-work preference; NAICS codes; services; keywords; and certifications. Some fields may be commercially sensitive even when they are not marked private.
Saved work and communications. We store saved opportunities and private notes, saved-search text and filters, notification preferences, alert evaluation and delivery history, beta feedback, invitations, and data export/deletion requests. Public opportunity records imported from SAM.gov are separate from account data.
Provider requests. If you voluntarily submit a provider-specific request, we store the provider, service category, opportunity and organization context, and the name, email, phone number and message you entered. We also record the consent time, Privacy Policy version, request status, and operational delivery history.
2. Google Sign-In
MaroNest requests only the Google OpenID Connect scopes openid, email, and profile. Google may provide a stable account identifier, email address, email-verification state, name, and basic profile information. MaroNest uses these details to authenticate you, create or connect your MaroNest account, and populate basic account identity fields. A linked Google-account record may retain the provider identifier and basic profile claims supplied during authentication.
MaroNest does not request access to Gmail, Google Drive, Google Contacts, Google Calendar, or your Google password. OAuth access and refresh tokens are not stored by the application. Google processes the authentication interaction under its own policies.
3. How we use information
We use information to provide and secure accounts; maintain organization boundaries; personalize rules-based recommendations; save user work; evaluate and send enabled alerts; respond to feedback and privacy requests; prevent abuse; troubleshoot reliability; understand coarse product usage; and deliver an optional provider request you explicitly submit.
4. When information is shared
- Selected providers: only after your explicit, unchecked consent, the named provider may receive the contact fields and message you entered plus the opportunity identifier, requested service category, and consent context. Company profiles, private notes, saved searches, and unrelated activity are not copied into that request.
- Service providers: infrastructure and hosting services used to run MaroNest, Google for sign-in, and email-delivery infrastructure when configured may process information as needed to provide those functions. The current application uses self-managed web, PostgreSQL, and Redis services; error monitoring is used only if configured.
- Legal and safety needs: information may be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or secure the service.
SAM.gov is a public government data source, not a MaroNest account processor. Opening an official-notice link takes you to an external government website governed by its own terms and privacy practices.
MaroNest does not sell account or company-profile data as a general advertising dataset. Sponsored placements are labeled advertising or provider content. A placement does not itself share your account data; information is sent to a provider only through the explicit request process described above.
5. First-party analytics and operational logs
First-party product events record an allowed event type, time, optional user/organization/opportunity/provider references, a one-way session hash, and limited coarse values such as filter count, authentication state, source, or profile-completeness band. Product analytics intentionally excludes raw search text, IP addresses, user agents, browser fingerprints, private notes, email bodies, company-profile text, and credentials.
Separately, web, application, rate-limit, and security infrastructure may process IP addresses, hashed rate-limit identifiers, request IDs, timestamps, routes, response status, and security events. These records support fraud prevention, debugging, and reliability. Secrets and OAuth callback credentials are designed to be redacted from application and proxy logging, but no internet service can promise that every operational record is error-free.
6. Retention, export, and deletion
We retain account and user-created information while needed to operate the account and for legitimate security, dispute, and operational purposes. Security audit events are subject to the configured retention period (currently up to 730 days). Other application and infrastructure records are retained according to operational need; MaroNest has not promised a single automatic deletion schedule for every category.
Signed-in users may submit export or deletion requests in Account privacy requests. Requests are recorded for administrator review and are not fulfilled automatically. Fulfillment may require identity verification and may preserve limited security, consent, legal, or backup records where appropriate. Deleting an account does not delete independently sourced public SAM.gov opportunity records.
7. Security, international use, and children
MaroNest uses organization access controls, secure transport, protected cookies, CSRF controls, password hashing, rate limits, and restricted operational access. These measures reduce risk but cannot guarantee absolute security.
The service focuses on U.S. federal procurement but may be accessed from elsewhere. Information may be processed in jurisdictions where MaroNest and its infrastructure, authentication, or email providers operate. Users are responsible for determining whether use is appropriate in their location.
MaroNest is a business procurement service and is not directed to children under 13. We do not knowingly solicit children’s personal information.
8. Changes and contact
We may revise this policy as the service changes. The date and version above identify the published policy. For a future material change, MaroNest can publish a new version and require renewed acceptance before affected account activity; the current deployment does not automatically force re-consent.
Registered users can submit a privacy request from Account settings. Privacy-related requests may also be sent to support@maronest.com. The operator’s formal legal name and address remain owner and legal-review items.
Contact · Terms of Service · Data and Procurement Disclaimer