Privacy Policy
Last updated July 25, 2026
Who we are
BSonar is operated by Arbitoz Capital LLC, a Wyoming limited liability company registered to do business in New Jersey. This policy explains what the BSonar service collects, why, who else handles it, and how long we keep it. BSonar is a business tool sold to organizations; it is not directed at children, and an account holder must be at least 18 and able to enter a contract. Questions go to sales@quietcraftsolutions.com.
What we collect
BSonar collects account and workspace details, authentication identifiers, billing customer and subscription identifiers, saved searches, notices, proposal content, uploaded source material, notification settings, usage records, and security/audit events. If your workspace connects its own SAM.gov API key or AI provider key, we store that key encrypted. Payment-card details are collected by Stripe and do not pass through BSonar.
How we use information
We use this information to provide and secure the service, scope data to your workspace, process subscriptions, deliver alerts, generate requested analysis or proposal content, provide support, prevent abuse, and meet legal obligations. We do not sell personal information, and we do not train AI models on your workspace content. Content sent to an AI provider is also governed by that provider's terms.
Service providers
BSonar relies on Stripe for payments, Neon for managed PostgreSQL, Resend for transactional email, Hostinger for server hosting, and the AI provider a workspace selects for AI features. Identity and e-signing run on infrastructure we operate rather than a third-party service. Data is sent to an AI provider only for features that require it; customers should not submit classified information, export-controlled data, or information they are not authorized to process.
No advertising or tracking
BSonar carries no advertising, no advertising trackers, and no third-party analytics scripts. Cookies are limited to what signing in and running the app require; the sign-in session cookie is signed and expires after 8 hours.
Where data is processed
BSonar and the providers above operate in the United States, and workspace data is stored and processed there. If you use BSonar from outside the United States, your information is transferred to the United States for processing.
Retention and deletion
Workspace data is retained while an account is active. An owner can request an export or workspace deletion from Account & security; deletion runs after a 7-day cooling-off window and can be canceled during it. Evidence for completed signature envelopes is held about 3 years under a retention hold before purge, and API request audit records are kept 90 days. Some billing, security, backup, and audit records may remain longer where required for fraud prevention, legal compliance, disaster recovery, or dispute resolution.
Security
We use tenant-scoped access controls, encrypted transport, signed sessions, role-based permissions, and managed infrastructure. SAM.gov and AI provider keys are encrypted at rest, and account exports are encrypted (AES-256-GCM) and expire 24 hours after they are produced. No system is perfectly secure.
Your rights and requests
Depending on applicable law, you may request access, correction, export, or deletion of your information. Owners can do most of this directly from Account & security; otherwise contact sales@quietcraftsolutions.com. We will verify the requester before acting.
Changes and contact
Material changes will be posted here with a new date. Questions or privacy requests may be sent to sales@quietcraftsolutions.com.