
Client portal
Privacy Notice
Last updated August 17, 2026
1. Who this covers
This notice covers the client portal at portal.thinkbigdobig.com — the signed-in area where clients review proposals, sign them, receive deliverables, exchange messages, and see invoices.
The portal is operated by Think Big, Do Big, a trade name of Aspen Ridge Capital, LLC, 2601 N. Broken Circle Rd., Flagstaff, AZ 86004. The marketing site at thinkbigdobig.com has its own separate privacy policy.
2. Signing in with Google
If you sign in with Google, we request only Google's basic sign-in scopes — openid, email, and profile. From those we receive your name, email address, and profile picture.
We use that information for one purpose: to authenticate you and identify your account. We do not read your Gmail, contacts, calendar, files, or any other Google data, because we never request access to them.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, use it for advertising, or allow humans to read it except where you ask us to, where required by law, or as needed for security or abuse investigation.
Google sign-in is optional. You can use an email address and password, or a one-time sign-in link, instead.
3. What else the portal stores
Because the portal is where we do business with you, it holds the working record of that relationship:
- Account and contact details — your name, email, organization, and any phone number or address you give us.
- Proposals and signatures. When you accept a proposal we record a legally meaningful signature: the signer name and email, the exact proposal version, a hash of the document shown, the consent wording displayed, the timestamp, and the IP address and browser user-agent of the device used. That record proves what was agreed and cannot be edited afterwards.
- Work product — deliverables and documents we upload for you, and files you upload to us, stored in a private bucket that is never publicly readable.
- Messages and notes — support threads and their attachments, and tasks assigned between us.
- Billing records — invoices, orders, and subscription status. We never see or store your card details; payment pages are hosted by Stripe.
- An activity log of significant actions, kept so both sides can reconstruct what happened and when.
4. No tracking
The portal runs no analytics, advertising, or tracking of any kind. There is no Google Analytics, no advertising pixel, and no third-party tracker. The only cookies are the ones that keep you signed in.
We also send no SMS or text messages of any kind.
5. Who we share it with
We do not sell your information or share it for advertising. It reaches only the vendors that run the service, each under its own privacy terms and only as needed:
- Supabase — database, sign-in, and file storage
- Vercel — application hosting
- Stripe — invoicing and card payments
- Resend — transactional email (sign-in links, notifications)
- Google — only if you choose Google sign-in
We may also disclose information where the law requires it, or to protect our rights, safety, or the integrity of the service.
6. How long we keep it
We keep your account and project records for as long as you are a client and afterwards for as long as we need them for the purpose they were collected — principally to honour our contract with you, to resolve disputes, and to meet tax and accounting obligations.
Signature and billing records are kept longer than ordinary account data, because they evidence agreements and payments. If you ask us to delete your account, we will remove what we are not required to retain and tell you plainly what we kept and why.
7. Your choices
You can ask us to see, correct, export, or delete your information at any time by emailing hello@tbdb.ai. We will respond within 30 days.
You can also disconnect Google sign-in at any time from your Google account permissions, and continue signing in with a password instead.
Notification emails from the portal are part of the service rather than marketing, but tell us if the volume is wrong for you and we will adjust it.
8. Security
Access is restricted to your own organization's records and enforced in the database itself, not only in the interface. Uploaded files live in a private bucket reachable only through short-lived links issued after an access check. Sign-in is handled by Supabase Auth; we never store your password in readable form.
No system is perfectly secure. If a breach ever affects your information, we will tell you.
9. Changes and contact
If we change this notice materially we will update the date above and, for significant changes, tell you in the portal or by email.
Questions about privacy go to hello@tbdb.ai.
Think Big, Do Big, a trade name of Aspen Ridge Capital, LLC · thinkbigdobig.com