Legal

Privacy Policy

Last updated: June 29, 2026

What we collect

  • Account details — your email address and role.
  • Sourcing briefs you submit and any project files you upload (specs, BOMs, drawings).
  • Product usage and conversion events, tied to an anonymous visitor id.
  • Your network (IP) address, used only as a short-lived key for abuse rate-limiting.

How we use it

To run the sourcing service: structure your brief, match and invite suppliers, prepare country-of-origin documentation, coordinate the deal, and protect the service from abuse. We do not sell your data.

Storage and security

Data is stored in managed Postgres with row-level security; uploaded files live in a private bucket and are served only through short-lived, authenticated download links. No payment card data ever touches our systems.

Who sees what

A supplier's identity is veiled from a buyer until the buyer accepts an offer, and a buyer's contact details are not exposed to suppliers through the platform. We share data only with the sub-processors needed to operate the service:

  • Supabase — database, authentication, and file storage.
  • Resend — transactional email (invitations, status updates).
  • Anthropic — operator-initiated AI structuring of brief text.
  • Sentry — error monitoring (configured to scrub emails, IPs, and request secrets).

Retention and your choices

Records may be soft-deleted so they can be reconstructed for audit and dispute resolution. To access, correct, or request deletion of your data, contact your SourceAgent operator.