Legal
Privacy Policy
Last updated September 16, 2026.
SupplierPing ("SupplierPing", "we", "us") is operated from Singapore. This policy explains what personal data we collect through the SupplierPing website and application (the "Service"), why, and what choices you have. It's written for the product as it actually works today, not as boilerplate.
1. What we collect
- Account information: the email address you sign up with, and a hashed password if you don't use Google sign-in.
- Purchase order data you upload or enter: PO numbers, supplier names and email addresses, item descriptions, dates, quantities, and prices. This is your business data; we store it to run the Service and don't use it for anything else.
- Follow-up emails: drafts, edits, and the content of emails you approve and send through the Service. If you connect Gmail, or a supplier replies to a follow-up, we also store the content of that reply.
- Gmail connection: if you connect your Gmail account, we store an OAuth refresh token that lets SupplierPing send follow-ups from your address on your behalf, and place a copy of a supplier's reply directly into your inbox so you have your own record of it. We request only the scopes needed to send mail, add that copy, and confirm your address; see Section 4 for how this data is used.
- Billing information: handled entirely by Stripe, our payment processor. We never see or store your card number. We only receive your subscription status and plan, which Stripe shares with us.
- Basic technical data: sign-in timestamps and the kind of activity logs any web application needs to operate and debug. We do not run analytics or advertising trackers on SupplierPing.
2. Why we collect it
We use your data only to run the Service you signed up for:
- Classifying your purchase orders as overdue, due soon, unconfirmed, or on track.
- Drafting follow-up emails, and reading a supplier's reply to suggest a status/date update.
- Sending an approved follow-up from your connected Gmail (or, if you haven't connected one, our shared sender), only when you click send.
- Billing your subscription and enforcing your plan's order limits.
- Account security, support, and legal compliance.
Order and email content is sent to an AI model (see Section 4) to draft messages and interpret replies. This is core to how the Service works, and it is never used to train that model on your data.
3. Legal basis
We process your data to perform the contract you enter into by creating an account (Singapore's Personal Data Protection Act treats this as deemed consent for the purposes reasonably needed to provide the service you asked for), and, where applicable, on the basis of your consent. For example, connecting your Gmail account requires you to separately authorize it through Google's own consent screen.
4. Who we share it with
We don't sell your data, and don't share it for marketing. We use the following processors to run SupplierPing, each only for what's needed to provide the Service:
- Supabase: database hosting and authentication.
- Stripe: subscription billing and payment processing.
- Groq: processes order and email text to draft follow-ups and interpret supplier replies.
- Resend: delivers follow-up emails when Gmail isn't connected, and (once configured) parses inbound supplier replies routed back to the Service.
- Google: if you connect Gmail, follow-ups send through the Gmail API using your account, and a copy of any supplier reply is added directly to your inbox the same way.
SupplierPing's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used solely to send follow-up emails you approve and to confirm the connected address. It is never used for advertising, and never read or shared beyond what the Service needs to send mail on your behalf.
We may also disclose data if required by law, or to protect the rights, property, or safety of SupplierPing, our users, or others.
5. Where it's stored and how it's protected
Data is stored with Supabase (PostgreSQL) behind row-level security, so every account's data is isolated at the database level, not just in application code. Connections to the Service are encrypted (HTTPS). Access to production data is limited to what's needed to operate the Service.
6. How long we keep it
We keep your data for as long as your account is active. Deleting an order removes its follow-up emails and drafts with it. Deleting your account (available any time from Account) permanently removes your orders, uploads, emails, Gmail connection, and subscription record immediately, not after a delay. Billing records may be retained by Stripe as required for tax and accounting law.
7. Your rights
You can access and correct your data directly in the Service at any time (editing an order, updating your account), export your purchase orders as CSV from the dashboard, or delete your account entirely. If you'd like help with any of this, or have a request we don't have a self-serve option for (such as a data export in another format), email supplierping@gmail.com. If you're in the EU/UK or a jurisdiction with its own data protection law, you may also have rights under that law (such as data portability or objecting to processing); contact us and we'll do our best to accommodate it even where not strictly required.
8. Cookies
SupplierPing uses only the cookies needed to keep you signed in. We don't use advertising or analytics cookies, so there's nothing beyond that to opt out of.
9. Children
SupplierPing is a business tool and isn't directed at, or knowingly used by, children. We don't knowingly collect data from anyone under 18.
10. Changes to this policy
If we make a material change to how we handle your data, we'll update the date at the top of this page and, where appropriate, notify you directly.
11. Contact
Questions about this policy or your data: supplierping@gmail.com.