Privacy Policy
Last updated: June 29, 2026
What we collect
- Account details — your email address and role.
- Sourcing briefs you submit and any project files you upload (specs, BOMs, drawings).
- Product usage and conversion events, tied to an anonymous visitor id.
- Your network (IP) address, used only as a short-lived key for abuse rate-limiting.
How we use it
To run the sourcing service: structure your brief, match and invite suppliers, prepare country-of-origin documentation, coordinate the deal, and protect the service from abuse. We do not sell your data.
Storage and security
Data is stored in managed Postgres with row-level security; uploaded files live in a private bucket and are served only through short-lived, authenticated download links. No payment card data ever touches our systems.
Who sees what
A supplier's identity is veiled from a buyer until the buyer accepts an offer, and a buyer's contact details are not exposed to suppliers through the platform. We share data only with the sub-processors needed to operate the service:
- Supabase — database, authentication, and file storage.
- Resend — transactional email (invitations, status updates).
- Anthropic — operator-initiated AI structuring of brief text.
- Sentry — error monitoring (configured to scrub emails, IPs, and request secrets).
Retention and your choices
Records may be soft-deleted so they can be reconstructed for audit and dispute resolution. To access, correct, or request deletion of your data, contact your SourceAgent operator.