PrivacyPolicy
Last updated 9/13/2026
Privacy Policy
Version 1.0 — effective 11 September 2026.
This is a courtesy translation. The binding version of this document is the Spanish one, available at /es/privacidad. Costa Rican law requires consumer contract terms to be in Spanish.
This document explains what data we collect, what for, who else sees it, and what you can do about it. It follows Law No. 8968, the Costa Rican Personal Data Protection Law, and its Regulation.
Please read it before creating an account. If anything is unclear, write to us — we would rather answer a question now than a complaint later.
1. Who is responsible
OVERSEAS CRC S.A., a Costa Rican corporation, corporate ID 3-101-408786, domiciled in San José, Costa Rica.
- Email for data protection matters: contacto@overseascrc.com
- Phone: +506 2258-1870
We are the data controller. No one else makes decisions about your data.
2. That a database exists, and which one
It does. When you create an OVERSEAS Prospecta account, your data is stored in a database we administer, hosted on Railway servers in the United States.
It is an internal database: its contents are not sold, published, transferred or exchanged with third parties. It exists only to provide you the service you contracted.
3. Exactly what we store
Not a generic list. This is what is there:
About your account
- Your email address. Required: it is your username and the channel we use to confirm your account and let you recover your password.
- Your name and company. Both optional. Without them the account works the same.
- Your password, never in readable form. We store only a cryptographic hash computed with bcrypt at a cost factor of 12. We cannot read or recover your password: if you forget it, it is reset, not looked up.
- Timestamps and status: when you created the account, when you confirmed your email, when you last changed credentials, whether the account is active or suspended, how many failed sign-in attempts you have, and until when it is locked after repeated attempts.
About your Telegram connection
- Your numeric chat identifier, if you choose to link the bot. It is what lets us deliver alerts.
- Until when you asked not to receive alerts, if you use the holiday feature.
Your Telegram name and username (@) are sent to us by Telegram with each message. We do not store them in the database; they do appear in the service's technical logs when you first start the conversation with the bot.
About what you are looking for
- Your filters: the name you gave them and the conditions that make them up — product categories, keywords, institutions, minimum or maximum amounts, and exclusions.
We treat this with particular care, and we want you to understand why: the list of your filters is, in practice, the written declaration of what your company sells, which government institutions you target, and from what amount you are interested in competing. To us it is not a notification preference; it is your commercial information.
- Your alerts: which tenders matched, when they were sent, and which condition of your filter triggered them.
What we do NOT store
Saying this matters as much as the above:
- We do not store your IP address. No table in our database has a column for it.
- We do not store your phone number, national ID, postal address or billing data.
- We use no advertising, analytics or tracking cookies. The panel's only cookie is your session cookie, which is strictly necessary to keep you signed in.
- We do not process sensitive data within the meaning of article 9 of Law 8968.
We do process your IP address momentarily and only in server memory, to limit sign-in and registration attempts per minute. It is never written anywhere and disappears when the service restarts. We tell you because "we do not process your IP" would be inaccurate.
4. What we use your data for
For one thing and its direct consequences:
- Providing the service: comparing the tenders published by the State against your filters, and alerting you when one matches.
- Letting you into your account and letting you recover access if you lose your password.
- Protecting the account from automated sign-in attempts.
- Managing your subscription: when it starts, when it ends, whether it is current.
- Writing to you about service matters, such as confirming your email or notifying you of a change to these terms.
We do not use your data for advertising, for building commercial profiles, for selling you something else, or for cross-referencing with other databases. If we ever wanted to use it for something outside this list, we would ask you first and you could say no without losing the service.
5. What is required and what happens if you withhold it
- Email address — required. Without it an account cannot be created: it is your identifier and the only channel for recovering access.
- Password — required. Without it an account cannot be created.
- Name — optional. Without it the account works the same; emails and the bot greet you impersonally.
- Company — optional. Without it the account works the same.
- Telegram chat — optional. The account works without linking it, but you will receive no alerts: Telegram is currently the only delivery channel.
- Filters — optional to hold an account, necessary to receive. Without at least one filter there is nothing to compare and no alert is generated.
6. Who else sees your data
Operating the service requires the following providers. None of them receives your data to use on their own account: they process it on our instructions, and we remain responsible to you.
Telegram
What reaches it: your chat identifier and the full text of every alert. And here we want to be explicit, because the convenient phrasing would be false: the alert includes the label of the filter that triggered it and the specific tender line that matched. In addition, the weekly summary sends the list of names of your active filters.
That means Telegram can infer what your company sells, not merely that you receive alerts. It is not a blind carrier. If this concerns you, do not link Telegram: the account and the panel work without it, though you will not receive alerts as they happen.
Resend
Our email provider. It sees your email address and the text of the messages we send you — account confirmation and password reset. It does not see your filters or your alerts.
Railway
Where the service runs and the database lives. It technically has access to the infrastructure holding everything described in section 3. Servers in the United States.
Vercel
Where the website runs. Beyond serving the pages, panel traffic passes through Vercel on its way to our server — this is what makes your session work correctly across all browsers. That means that, technically, your password at the moment of signing in and your session cookie traverse Vercel's infrastructure. It does not store them, but we would rather say so than have you work it out.
Make.com — only if you subscribe to the newsletter
The footer of every page on this site, including the Prospecta pages, has a form to subscribe to our newsletter. It is voluntary and unrelated to your Prospecta account.
If you use it, your email address and your browsing language are sent to Make.com, the tool we use to run that newsletter. If you do not use it, Make.com receives nothing of yours.
Subscribing to the newsletter and holding a Prospecta account are two separate things: you can do one without the other, and unsubscribing from one does not affect the other.
No one else
Beyond the above, there is no third-party analytics, no pixels and no advertising networks. The source of the tenders is the Observatorio de Compra Pública, open data from the Costa Rican State: we read from it, and we send no data of yours to anyone.
7. That your data leaves Costa Rica
Our providers host information outside the country, mainly in the United States. By accepting this policy and ticking the consent box when registering, you consent to that transfer.
If you do not consent, we cannot provide the service, because we do not operate our own infrastructure in Costa Rica. We prefer to say so plainly rather than bury it in a clause.
8. How long we keep it
- While your account exists, we keep what section 3 describes.
- If you request deletion, we carry it out within five business days, as described in section 9.
- If your subscription expires and you do not renew, we keep the account for twelve months in case you return, and then delete it or dissociate it from you.
- Alerts already sent to you are kept while the account exists, because they are the record of what we delivered.
- Technical logs are kept according to our hosting provider's policy and are used for nothing other than diagnosing faults.
In no case do we keep data that could affect you for more than ten years from the end of the purpose of processing, as required by article 11 of Law 8968.
9. Your rights, and how to exercise them
At any time, and at no cost, you may:
- Access everything we hold about you.
- Correct anything wrong or incomplete.
- Delete your data and your account.
- Withdraw your consent, which stops processing going forward without affecting what was already done.
How: write to contacto@overseascrc.com from your account's email address, saying what you want. If you write from another address we will ask for some way to confirm the account is yours — not as red tape, but because it is what stops a third party from requesting your data while pretending to be you.
Deadlines, which are the law's and not ours:
- We respond within five business days of receiving your request.
- If you withdraw consent, we execute the withdrawal within five business days and notify our providers.
- If you request confirmation that processing has ceased, we provide it within three business days.
We will respond even if it turns out we hold no data about you, and the response will cover your entire record even if you asked about a single point.
If you believe we handled your request poorly, you may turn to the Agencia de Protección de Datos de los Habitantes (PRODHAB).
10. What we do if there is a security breach
If a breach affecting your data occurs, we will inform you and PRODHAB within five business days of becoming aware of it, stating what happened, which personal data was compromised, what we did immediately, and where to obtain further information. Within that same period we will begin a full review of the incident.
We would rather write this here, where it becomes a commitment, than work it out on the day it is needed.
11. How we protect the information
The specifics, not adjectives:
- Passwords are stored as bcrypt hashes at cost 12, never in readable form.
- The session travels in a cookie that the browser does not let any script read, and it is invalidated automatically when you change your password.
- Confirmation and recovery links expire after thirty minutes, are stored hashed, and are invalidated on use.
- There are sign-in attempt limits per IP address and per account, to slow automated attacks.
- All traffic between your browser and our servers is encrypted.
No system is infallible and we will not tell you otherwise. What we will tell you is what is in place and what we will do if something fails.
12. Minors
The service is aimed at companies and at adults. We do not offer it to minors nor knowingly collect their data.
13. Changes to this policy
If we change it, we will publish the new version here with its date and notify you by email before it takes effect when the change materially affects you. We do not treat a change as accepted merely because you keep using the service: if the change requires your consent, we will ask for it.
Last updated: 11 September 2026.