SupplierPing

Trust

Security

What we actually do to keep your account and your suppliers' data safe, not a marketing checklist.

Nothing sends without you

Every follow-up is a draft until you review and approve it, and every send is a separate click. There is no bulk-automated sending you haven't explicitly triggered.

Your data is isolated by design

Every account's orders, drafts, and connections are enforced at the database level (row-level security), not just in application code. One account's data is never reachable through another's session.

Encrypted in transit

All traffic to SupplierPing runs over HTTPS. Passwords are hashed, never stored in plain text.

Payments never touch our servers

Card details are handled entirely by Stripe, a PCI-DSS-compliant payment processor used by millions of businesses. We only ever see your subscription status, never your card number.

Gmail access is scoped and revocable

Connecting Gmail requests only the permission to send mail, add a copy of a supplier's reply to your inbox, and confirm your address, never to read your existing mail. You can disconnect it at any time from Account, which immediately revokes SupplierPing's access.

Delete means delete

Deleting your account immediately and permanently removes your orders, uploads, drafts, and any connected Gmail token. It is not a soft delete sitting around indefinitely.

Found a security issue?

Tell us directly at supplierping@gmail.com before disclosing it publicly, and we'll investigate and respond as quickly as we can.