Privacy
What we collect, and what we do with it.
Short version: we hold the vendor documents you upload, the account details of the people who log in, and the record of what your team did with those documents. We do not sell any of it and we do not use your vendors' reports to train anything.
Effective 23 August 2026 · Computer Systems Plus, Inc.
A note on this document. It describes how the service actually works and is written to be read, not to be impenetrable. It has not been reviewed by an attorney. If you are procuring on behalf of a public agency, send it to your counsel — and tell us what they need changed. We would rather sign your paper than argue about ours.
Who this covers
GOVvpat is operated by Computer Systems Plus, Inc., 2134 North Fine Ave, Fresno, CA 93727, United States. This policy covers the GOVvpat website and the application behind it.
Where a public agency uses GOVvpat, that agency is the controller of the records it uploads and we process them on its instructions.
What we collect
Account information
- Name, work email address, and the organization you belong to.
- A password hash — we never store the password itself and cannot recover it.
- Sign-in time and IP address, kept as a security record so an unrecognised sign-in can be investigated.
Documents you upload
- The conformance reports you submit for review, and the vendor and product names you attach to them.
- What our review extracted from them, and any adjustment your team recorded — including who made it and the reason they gave.
- Correspondence you choose to log against a vendor, which is whatever you paste in.
These are ordinarily business documents rather than personal information. If you paste personal information into a correspondence note, it is held under this policy like anything else.
Requests you send us
- What you enter in the quote form: your name, email, organization, and what you need reviewed.
Website analytics
On the public pages of this site — the ones you can read without signing in — we use Google Analytics to count visits and see which pages people actually read. It records the page you viewed, roughly where in the world you are, and what kind of device and browser you used, and it sets a cookie in your browser to tell one visit from the next. IP addresses are shortened by Google before they are stored, and we have not turned on the advertising features that would let Google link your visit to you across other sites.
The signed-in application is deliberately excluded. There is no analytics tag on any page behind the login, so which vendors your team is reviewing, and which reports you opened, is never sent to Google. Nor is there one on the sign-in and password-reset pages.
If you would rather not be counted, any browser setting or extension that blocks Google Analytics will stop it, and nothing on the site depends on it working.
What we do not collect
- No advertising or cross-site tracking, and no advertising cookies. The analytics described above count visits to our public pages; they are not used to follow you anywhere else.
- No payment card details — we do not take card payments through the site.
- No special categories of personal data, and none should be uploaded.
Why we hold it
- To provide the service — reading the documents you send and returning findings is the product.
- To keep the record defensible — an assessment is only useful in a procurement file if it is dated and attributable, so we keep who did what and when.
- To keep accounts secure — sign-in records exist so unauthorised access can be detected.
- To answer you — a quote request is used to reply to that request.
What we do not do
- We do not sell personal information, and never have.
- We do not use your uploaded documents to train machine-learning models.
- We do not share one agency’s documents or findings with another agency, or with the vendor whose report it is, unless you send it to them yourself.
- We do not publish which agency reviewed which vendor as marketing.
Who else sees it
We use a small number of service providers to run the product — hosting, email delivery for notifications and password resets, and Google Analytics on the public pages described above. They process data on our instructions and for no other purpose. We will name our current providers on request; ask before you sign if your policy needs the list in writing.
We disclose information to a third party otherwise only where the law requires it. If we receive a legal demand for an agency’s records, we will tell that agency unless we are prohibited from doing so.
Data is stored in the United States.
How long we keep it
- Uploaded reports and findings — for as long as your account is active, because a procurement record is meant to outlast the purchase. You can delete an entry at any time.
- Account records — until the account is closed.
- Sign-in and audit records — retained while the account is active, as the security and accountability record.
- Quote requests — kept while we are corresponding with you and for a reasonable period afterwards.
On written request we will delete an organization’s data and confirm when it is done, subject to anything we are legally required to retain.
Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Account holders can also export their organization’s data from within the application. Email sales@govvpat.com and we will respond.
California residents have specific rights under the CCPA, including the right to know what is collected and the right to deletion. We do not sell or share personal information as those terms are defined there, so there is nothing to opt out of.
Security
Access is restricted to the organization that uploaded a document. Passwords are stored hashed. Sessions are authenticated per request, and an account belonging to one organization cannot read another organization’s records. We will describe our controls in more detail in a security questionnaire — see procurement.
If we discover a breach affecting your data we will tell you promptly and tell you what we know, including what we do not yet know.
Children
The service is sold to organizations and is not directed at children. We do not knowingly collect information from anyone under 13.
Changes
If we change this policy in a way that affects how we handle your information, we will change the effective date above and tell account holders. We will not apply a materially different practice to data we already hold without saying so first.
Contact
sales@govvpat.com, or Computer Systems Plus, Inc., 2134 North Fine Ave, Fresno, CA 93727, (559) 251-7767.
Questions about this page: sales@govvpat.com. For procurement paperwork, see the procurement page.