Privacy Policy
What we collect, why we collect it, and who else sees it. In plain language, because a policy you cannot read is not a policy. Last updated September 28, 2026.
Who we are
Good Stuart finds public-sector contract opportunities for businesses and writes the responses to them. This policy covers goodstuart.com and the client portal we operate at enabler.goodstuart.com.
If you want to reach a person about anything on this page, email ian@quickbrownfox.co.
What we collect, and when
We do not collect anything just because you visited. What we hold depends on what you did.
When you book a call
Booking runs on Calendly, not on our own servers. When you pick a time, Calendly collects your name, your email address, anything you type into their questions, and your time zone. They pass that to us so we can hold the meeting. Calendly sets its own cookies and has its own privacy policy, which governs what they do with it.
If you reached the booking page from a specific contract opportunity, we pass that opportunity's reference through with the booking so we know which one prompted you to get in touch. That reference identifies a public solicitation, not you.
When you send us a form or an email
We keep what you send us: your name, your email address, your phone number if you give one, and your message. Forms on this site run on Gravity Forms and the submissions are stored in our own database. Email reaches us through a mail provider that handles delivery on our behalf.
When you become a client
We hold what we need to do the work: your company details, the trades and regions you serve, your licensing, bonding and insurance position, your past contracts and references, and the contact details of whoever we deal with. We hold it because we cannot write a response for you without it.
Payments are handled by Stripe. We never see or store your card number. We keep a record that a payment happened, what it was for, and the reference Stripe gives it.
When you just read the site
Our servers keep ordinary access logs, which include your IP address, your browser, and the pages you asked for. WordPress sets a cookie if you log in, and a session cookie if you start something that needs one. Nothing on the public pages requires you to accept tracking.
If site analytics are switched on, we use Google Analytics to count visits and see which pages are useful. It is configured to anonymise IP addresses. We use it to understand traffic in aggregate, not to build a profile of you.
What we deliberately do not collect
- Card numbers. Stripe handles those. They never touch our servers.
- Buyer contacts on public opportunity pages. The catalog pages carry the work, the deadline and the documents count. The buying agency's named contacts stay in the client portal.
- Special category data. We have no reason to ask about health, race, religion, politics, union membership, sex life or biometrics, and we do not.
- Children's data. This is a service sold to businesses. It is not directed at anyone under 18 and we do not knowingly collect their data.
Why we are allowed to hold it
| What | Why | Basis |
|---|---|---|
| Booking details | To hold the meeting you asked for | Steps before a contract, at your request |
| Enquiries | To answer you | Our legitimate interest in replying |
| Client company data | To find and write your bids | Performing our contract with you |
| Payment records | Billing, accounting, tax | Legal obligation |
| Access logs | Security and keeping the site up | Our legitimate interest in running it safely |
| Analytics | Knowing which pages help | Consent where required, otherwise legitimate interest |
Who else sees it
We do not sell your data. We have never sold it and the business does not depend on selling it. We share it only with the providers that make the service work, and only what each one needs.
- Calendly, for scheduling calls.
- Stripe, for taking payments.
- Google, for analytics when enabled, for Search Console, and for business listing data on our older directory pages.
- Our email provider, for sending and receiving mail.
- Our hosting provider, which necessarily stores everything the site holds.
- A public buying authority, when you instruct us to lodge a bid on your behalf. That submission contains what the solicitation requires, and you approve it before it goes.
We will also hand over data if the law requires it, and we will tell you when we are allowed to.
Where it goes
We are based in the United States and our providers are mostly United States companies, so your data is processed there. If you are in the United Kingdom or the European Economic Area, that is a transfer outside your home jurisdiction, and we rely on the standard contractual protections our providers offer for it.
How long we keep it
| What | How long |
|---|---|
| Enquiries that go nowhere | Two years, then deleted |
| Client records | The life of the relationship, then seven years |
| Bid responses we wrote for you | Seven years, because contract disputes are slow |
| Payment and tax records | Seven years, as the law requires |
| Access logs | Twelve months |
If you ask us to delete something earlier and no law requires us to keep it, we will.
What you can ask us to do
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop using it. Email ian@quickbrownfox.co and we will answer within thirty days. We will not charge you and we will not treat you differently for asking.
If you are in the United Kingdom or the European Economic Area you also have the right to object to processing, to ask for your data in a portable format, and to complain to your data protection authority. If you are in California you have the rights the CCPA gives you, including the right to know what is collected and the right to opt out of any sale or sharing. We do not sell or share personal information as those terms are defined there.
Cookies
We use cookies that keep you logged in, keep a form working while you fill it, and, where analytics are enabled, count visits. Calendly sets its own cookies inside its booking widget. You can block or delete cookies in your browser. Blocking the essential ones will break logging in and booking; blocking the rest will not.
Keeping it safe
The site runs over an encrypted connection. Access to client data is limited to the people doing the work. Payment details never reach us. No system is perfectly secure, and anyone who tells you otherwise is selling something, but if a breach affects you we will tell you and the relevant regulator within the time the law allows.
Our older services
Good Stuart previously ran a free-website and lead-generation directory for local trades. Some of that data still exists: business profiles, enquiries sent through a profile, and the records of who was contacted. Those enquiry records include the sender's name, email, phone number, message, IP address and browser, because that is what was needed to spot fake submissions.
Profile content on those pages was in some cases drafted with the help of a third-party text generation provider, working only on the business information the owner supplied. If you own one of those profiles and want it removed, email us and we will remove it.
Changes
If we change what we collect, we change this page and move the date at the top. If the change is significant and we hold your email address, we will tell you rather than hope you notice.
Questions, or want your data. Email ian@quickbrownfox.co. We answer every one.
See also our terms and conditions.
Want to talk today?
Book twenty minutes and you’ll see what’s open right now for a business like yours. Or just email us. Our team answers within one business day.