Privacy Policy
1. Overview
MAS Pilot LLC operates maspilot.io. This Privacy Policy explains how we collect, use, and protect information from users of our GSA MAS compliance platform.
2. Information We Collect
Account Information
When you create an account, we collect your name, work email address, organization name, and billing information. Billing information is processed by our payment provider and is not stored on MAS Pilot servers.
Transactional Data
MAS Pilot is pre-launch; the description below is the platform's target design. When you upload TDR data for checking, that data is designed to be processed in-memory for checking purposes only and not persisted to a database. Compliance results are temporarily stored to display your report and deleted after 30 days. Independent attestation of these controls (SOC 2 Type II) is planned prior to general availability; enterprise evaluators may request current status under NDA.
Usage Data
We collect information about how you use the Service to improve it. This data is not sold to third parties.
Waitlist Form
When you request Wave 3 access, we collect the information you submit on the form: name, phone number, work email, company name, contract-type category, and an optional Unique Entity ID (UEI). We store only this information to evaluate your application, consistent with the notice shown on the form. We do not store your IP address, user agent, or country from a waitlist submission.
3. How We Use Your Information
- To provide and improve the Service
- To send compliance deadline alerts
- To process billing
- To communicate service updates and policy changes
- To comply with legal obligations
We do not sell your personal information. We do not use your TDR data to train models.
4. Data Retention
Account information is retained for the duration of your subscription plus 90 days after cancellation. Compliance results are retained for 30 days. Transactional pricing data is not retained beyond the checking session. Application audit logs are retained for 7 years, aligned to federal contractor records-management practice under FAR Part 4 (including FAR 4.703 as applicable to contract-related records). FAR 4.703 governs contractor retention of contract-related records; MAS Pilot's audit-log retention is set to that baseline and is not itself a statement that FAR 4.703 prescribes a SaaS audit-log retention period.
5. Security
The Service uses encryption in transit today, and stored data in our managed database is encrypted at rest by our infrastructure provider. Additional controls — role-based access, multi-factor authentication for administrative access, and comprehensive application-level audit logging — are being implemented ahead of general availability. See our Security page for the breakdown of what is live today versus planned.
Service providers and data location
We use a small number of vendors to operate the Service, and our data is hosted in the United States: Supabase (managed database and storage, US region) for application and waitlist data; Resend for transactional email (application confirmations and internal notifications); and Cloudflare for hosting, DNS, and bot protection (Turnstile) on maspilot.io. During the current cut-over of the waitlist, a Google Apps Script mirror may also write a copy of a submission to a private Google Sheet; this mirror is retired once migration is complete. These providers process data on our behalf under their respective data-processing terms.
Breach notification
If MAS Pilot becomes aware of a security incident that has resulted in, or is reasonably believed to have resulted in, unauthorized acquisition of unencrypted personal information, we will notify affected contractors within 72 hours of confirming the incident, unless a longer delay is required by law-enforcement request. Notifications will describe the categories of information involved, the steps MAS Pilot has taken in response, and the steps we recommend the contractor take. This commitment is consistent with the Maryland Personal Information Protection Act (MD Code Com. Law §14-3504), state-equivalent breach-notification statutes, and the GDPR 72-hour controller-notification standard where applicable. Where MAS Pilot acts as a processor, we will notify the responsible Controller without undue delay upon becoming aware of a breach so the Controller can meet its own notification obligations.
6. Your Rights
You may request access to, correction of, or deletion of your personal information at any time by contacting [email protected]. We will respond within 30 days.
7. Cookies
We use essential cookies for authentication and session management only. See our Cookie Policy for full details. We do not use advertising or third-party tracking cookies.
8. Changes
Material changes will be communicated via email at least 15 days before taking effect.
9. Contact
Privacy inquiries: [email protected] · Legal notices: [email protected] · MAS Pilot LLC · Washington, DC