How we keep tenders private and companies accountable
This page is maintained by the Craftex team to answer common security and privacy questions about the platform. It describes current practices — it is not an independent audit or certification.
Account verification
New accounts are reviewed by our admin team before they are marked verified. Contractors submit company name, registration number and any licences or certifications; we check the submitted details and grant a verification badge when they hold up. Badges can be revoked and accounts suspended if information proves inaccurate.
Verification confirms that we reviewed the documents provided. It is not a guarantee of workmanship, solvency or insurance cover — always run your own due diligence before awarding a contract.
Access control
Every user signs in with an email and password managed by our authentication provider; passwords are stored as salted hashes and are never visible to us. Access to data is enforced at the database level with row-level security: a tender, its attachments and its bids are readable only by the developer who published it and the contractors involved.
Administrative actions — verification, suspension, dispute handling — are limited to accounts holding an explicit admin role, held in a separate roles table rather than on user profiles.
Data in transit and at rest
All traffic to Craftex is served over HTTPS/TLS. Application data and uploaded files are stored with our managed cloud database and storage provider, which encrypts data at rest and takes automated backups.
What we collect and why
We collect what the platform needs to work: your account email, role, company profile, tenders, bids, messages, reviews and files you upload. We record product activity such as profile views and bid events so contractors can see the value they get from a subscription. We do not sell personal data, and we do not share it with third parties beyond the processors listed below.
Subprocessors
Supabase — authentication, database, file storage and backups.
Paddle — Merchant of Record for subscription billing, payment processing and tax. Card details go directly to Paddle; we never see or store card numbers.
Cloudflare — hosting and content delivery for the web application.
Moderation and disputes
Any user can report a profile or a listing from within the platform. Reports go to a moderation queue where our team can request more information, remove content, cancel a listing or suspend an account. Disputes between a developer and a contractor are reviewed on the evidence held on the platform — messages, bids and tender documents.
Your rights and controls
You can edit or delete your profile content at any time, export the tender and bid data you are party to by request, and close your account. Deletion requests remove personal data except records we must keep for billing and legal reasons. Write to privacy@craftex.com.
Reporting a vulnerability
If you believe you have found a security issue, email trust@craftex.com with steps to reproduce. Please give us a reasonable window to fix the issue before disclosing it publicly. We do not pursue legal action against good-faith researchers.
Shared responsibility
We secure the platform, its access controls and its infrastructure. You are responsible for keeping your credentials safe, inviting only the parties who should see a tender, and confirming that the documents you upload are ones you have the right to share.
Full detail on data handling is in the Privacy Policy and Terms of Service.